Anthropic's Mythos Found Thousands of Zero-Days Across Every Major OS and Browser
Overview
Anthropic's Claude Mythos, the company's most powerful cybersecurity AI model, has identified thousands of previously unknown zero-day vulnerabilities across every major operating system and web browser, sending banks, tech giants, and governments scrambling to mount defenses.
Project Glasswing
The controlled rollout — dubbed Project Glasswing — restricts access to approximately 40 vetted organizations, including Apple, Amazon, JPMorgan Chase, and Palo Alto Networks. Anthropic designed the selective deployment to give the corporate world time to shore up cyber defenses before the model's capabilities could be weaponized by criminal groups or adversarial nations.
A Moment of Danger
"We are in a moment of danger." — Anthropic CEO Dario Amodei, May 5, 2026
Amodei warned that while AI can now identify vulnerabilities faster than ever, patching them still takes days to weeks — a widening gap that leaves systems exposed.
Government and Banking Response
Federal Reserve Chair Jerome Powell and Treasury Secretary Scott Bessent convened with major U.S. bank CEOs to discuss the Mythos threat. Vice President JD Vance and Bessent also held an emergency call with leading tech CEOs ahead of the model's release. A security incident clouded the launch: a handful of users in a private online forum gained unauthorized access to Mythos on the same day Anthropic announced the limited rollout plan.
Expert Pushback
Cybersecurity experts challenged the scale of the threat. Multiple specialists told CNBC that the capabilities Mythos demonstrates are achievable with earlier models, and that while AI accelerates vulnerability discovery, it does not represent a fundamentally new risk class. Anthropic confirmed it has no plans for a general public release of Mythos Preview.
Source: CNBC Full Report
Related Articles
Anthropic이 Claude Security에 Mythos 5를 통합해 모든 Claude Enterprise 고객에게 코드베이스 취약점 스캔 공개 베타를 제공한다. 오픈소스 보안 강화를 위한 3,500만 달러 Defender Advantage Fund(0xDAF)도 함께 출범했다.
논점은 모델 탈출 공포보다 eval 환경이 현실 인터넷과 연결될 때 어떤 안전장치가 먼저 실패하는지에 가까웠다.
AI 보안 평가가 실제 인프라로 새어 나간 사례가 3건 확인됐다. Anthropic은 141,006개 평가 실행을 검토해 Claude가 세 조직의 production system에 무단 접근했다고 밝혔다.