viberg.tech

Anthropic built a model that finds security holes better than most experts, and is keeping it from the public

Claude Mythos Preview has found thousands of unknown vulnerabilities in the software the world runs on. Anthropic is giving it only to a group of mostly American companies to fix their code first. For European businesses, the time between a flaw being found and being exploited just got shorter.

Illustration: viberg.tech

On April 7 Anthropic announced Claude Mythos Preview, a model it says finds and exploits software vulnerabilities better than all but the most skilled human experts, and said it will not release it to the public. Instead, a group of large technology companies and around 40 organisations that maintain critical software get access under a programme called Project Glasswing, to find and fix flaws in their own code before attackers find them. It is the most capable model a leading lab has held back because of what it could do in the wrong hands, and a clear signal that AI-assisted hacking has moved from research papers into practice.

What the model found

According to Anthropic, Mythos Preview has identified thousands of previously unknown vulnerabilities in major operating systems and web browsers. The examples it gives are specific. A flaw in OpenBSD, an operating system known for its security record, had gone unnoticed for 27 years. A flaw in FFmpeg, the video library inside a vast amount of software, had survived 16 years and some five million automated tests. In the Linux kernel, the model chained several weaknesses into an attack that gives full control of a machine.

The comparison with Anthropic’s previous best model is the striking part. In the company’s own testing, reported by PostQuantum, Mythos Preview produced working exploits against Firefox’s JavaScript engine 181 times, where Claude Opus 4.6 managed it twice. More than 99% of the vulnerabilities it found were still unpatched when Anthropic disclosed that they existed. The same report notes that the system card describes earlier versions of the model concealing what they were doing when working around access controls, behaviour Anthropic says it partly corrected before this version.

Who gets it

The founding partners are Amazon Web Services, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, the Linux Foundation, Microsoft, Nvidia and Palo Alto Networks. Anthropic is putting up $100 million in usage credits and $4 million in donations to open-source security organisations. It says it is in discussions with the US government, and that the safeguards it develops will go into a future Claude Opus model before anything with these capabilities is released more widely.

The reasoning is easy to follow. Software defenders need time to fix these flaws, and attackers with the same tool would not wait. CrowdStrike’s technology chief put it bluntly on Anthropic’s page: adversaries will inevitably exploit these same capabilities.

Two reasons for caution

The first is that most of what we know comes from Anthropic. The company has an interest in a dramatic launch, and the benchmark numbers are its own. The partners’ involvement gives the claims weight, since companies like the Linux Foundation and CrowdStrike would not lend their names to something trivial, but the vulnerability counts need independent confirmation as the patches come out.

The second is who is on the list. Every founding partner is American. The software they will now fix faster (operating systems, browsers, cloud platforms, open-source libraries) is the same software European banks, hospitals and utilities run. Europe will benefit from the patches. It has no seat at the table where the fixes are prioritised, and European security teams have no access to the tool itself.

I think Anthropic made the right call on release, and I think the approach has a short shelf life. Other labs are working on the same capabilities, and open models tend to follow the frontier within a year or so. The head start Glasswing gives defenders is valuable because it is temporary.

What European businesses should do now

Patch faster. The main consequence of this announcement is that the gap between a vulnerability existing and being exploited is shrinking, for defenders and eventually for attackers. If your organisation takes weeks to apply critical updates, that is now the biggest risk in your security programme. Under NIS2, and for financial companies under DORA, it is also a compliance problem.

Expect a wave of updates. Thousands of fixes for widely used software will ship over the coming months, many for flaws that have existed for years. Make sure the teams and suppliers who maintain your systems are ready to test and deploy them quickly, and ask your managed service providers how they will handle the volume.

Know your open-source dependencies. Much of what Mythos found sits in libraries buried deep inside commercial products. A software bill of materials, a list of what your systems are built from, is how you find out whether a newly published flaw affects you. If your software suppliers cannot give you one, ask them why.

And plan for attackers with similar tools. Anthropic is keeping this model back. Someone else will eventually release something close to it, or a criminal group will build it. Security plans that assume attackers are slow and human are out of date.

Keep reading

All analysis →