Anthropic’s Claude Mythos Preview drew attention for reported advances in vulnerability discovery and exploit development, but subsequent open-source maintainer feedback challenged the practical value of its findings. An April ReliaQuest briefing described claimed discoveries of longstanding FreeBSD and OpenBSD vulnerabilities, an autonomous four-vulnerability browser sandbox escape, and stronger Firefox exploit-development results than Opus 4.6. Anthropic withheld public access and offered restricted access through Project Glasswing to help participating organizations identify and fix software flaws. By September, Anthropic claimed its models had found 26,000 vulnerabilities, but only 2,000 had been reported to affected projects, with independent human review identified as the bottleneck.
An October Pivot to AI report cited curl maintainers as saying Glasswing produced just one genuine new vulnerability, characterized as minor. Linux kernel maintainer Greg Kroah-Hartman described reports containing uninformative crashes, fabricated findings, and issues already discovered and fixed by others, while acknowledging four minor bugs credited to Anthropic. These accounts highlight substantial validation and triage costs rather than establishing that AI-assisted discovery has no value. For security leaders, the priority is to pair AI-assisted research with human verification, track validated and actionable findings rather than raw discovery totals, and maintain rapid vulnerability mitigation and detection workflows. The references raise concerns about faster exploit development but do not document an actual malicious campaign using Mythos.

See affected versions and whether adversaries are exploiting it.
12 events from the most recent confirmed update back to the earliest known activity.
At Kernel Recipes 2026, Greg Kroah-Hartman said his review of Anthropic's raw Linux kernel findings identified 24 uninformative findings, 14 that were not bugs, and three containing fabricated data. He also said 11 reported vulnerabilities had already been publicly discovered and fixed by other researchers, while remaining supportive of AI-assisted scanning with human review.
Patrick Garrity published an assessment following Anthropic's disclosure-list update. Anthropic claimed 26,000 discovered vulnerabilities by September 2026, with only 2,000 reported to affected projects, and identified independent human triage and review as the disclosure bottleneck.
Anthropic launched Project Glasswing to help secure critical software using Claude Mythos Preview and other Claude models. Participating organizations, including Apple, Microsoft, and Amazon Web Services, reportedly received limited access to identify and fix vulnerabilities in their software.
Curl reported that Project Glasswing found one genuine new vulnerability in its software. Pivot to AI described the vulnerability as minor.
Anthropic issued its first update to the Glasswing disclosure list since May 2026. The update preceded Patrick Garrity's September assessment of the project.
Linux kernel maintainer Greg Kroah-Hartman credited Anthropic with four minor bugs that were fixed. His examples included issues involving authenticated NFS servers and authenticated clients.
An April report cited by Pivot to AI described another company finding the same bugs as Mythos using small, inexpensive, open-weight models.
Anthropic reportedly withheld public access to Mythos because of the cybersecurity capabilities observed during evaluation.
After an initial prompt, Mythos reportedly chained four browser vulnerabilities to escape both renderer and operating-system-level sandboxes without further human involvement.
Mythos reportedly identified a previously unknown flaw in OpenBSD's TCP implementation dating back 27 years.
Mythos reportedly identified a previously unknown, 17-year-old remote code execution vulnerability in FreeBSD's NFS server.
Anthropic's Frontier Red Team reportedly discovered the model's cybersecurity capabilities during safety evaluations. Mythos recorded 181 successes on a Firefox autonomous exploit-development benchmark, compared with two for Opus 4.6.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.