Anthropic’s Claude Mythos is Just the Beginning
Anthropic's Project Glasswing initiative, announced this week, sent shockwaves across the cybersecurity world.

Anthropic's Project Glasswing initiative, announced this week, sent shockwaves across the cybersecurity world.
April 10, 2026 | 3 min read

Anthropic’s Project Glasswing, announced this week as an initiative that “could reshape cybersecurity,” sent shockwaves across the industry – but it’s only the beginning.
The heart of the announcement is Claude Mythos Preview, an unreleased model that Anthropic boasts “can surpass all but the most skilled humans at finding and exploiting software vulnerabilities.” Anthropic said its model has already found thousands of high-severity flaws across every major operating system and browser.
Anthropic launched Project Glasswing in collaboration with several partners, including big names like Microsoft, Apple, and more. It has privately been working with these companies after disclosing bugs to them, and said within 90 days it will report publicly on what researchers have learned and the flaws that have been fixed. Anthropic said it doesn’t plan to make Claude Mythos Preview generally available.
Katie Moussouris, founder and CEO of Luta Security, said we’re at the beginning of a “tidal wave” of vulnerability reporting.
“This is the first time that thousands of vulnerabilities are being discovered and disclosed all at once to a number of different companies,” said Moussouris. “I think we’re going to see a lot more outages, even though the release of this model is being structured in a way which is absolutely admirable in trying to do this as efficiently as possible, the open source models will catch up, our adversaries with their distillation tactics will catch up.”
"You’re not going to become Halvar Flake by strapping on Mythos."
The speed at which new AI tools and models such as Claude Mythos are being developed and deployed for security-centric tasks like vulnerability research and exploit development is wild. Mythos Preview specifically has found a 27-year old flaw in OpenBSD, a 16-year-old bug in FFmpeg, and a chain of flaws in the Linux kernel, according to Anthropic. Anthropic researchers also said Mythos Preview could write exploits in hours “that expert penetration testers said would have taken them weeks to develop.” Other researchers, like Thai Duong, have been using Claude to find bugs like a recent auth bypass in Ghidra.
Early results like these have been impressive, but early is the key word here, and it's important to remember that finding bugs is just one link in a complex chain.

"One side of this discussion is the elite bug hunters saying, These models won’t be as good as me, which is true. You’re not going to become Halvar Flake by strapping on Mythos," said Gary McGraw, a pioneer in machine learning and AI research in the security field, and founder of the non-profit Berryville Institute of Machine Learning.
"We really need people who know what an actual bug is as opposed to what Mythos thinks is a bug. There’s a big difference between finding a bug and writing a working exploit."
The results that researchers achieve with Claude Mythos depend on a number of factors, not least the training data the model uses.
"Think about what is in the training set. Is it going to find a pile of bugs that it wasn't trained on? No. But my bottom line on this whole thing is anything that gets bugs fixed is good. Anything that helps get software security up above the line of who cares is good."
“The repo man for technical debt is coming."
Models like Claude Mythos will also reshape vulnerability management, as organizations deal with a potential sharp increase in the amount of bugs found in their environments, both by whitehat hackers and threat actors.
To meet this influx of vulnerabilities, software vendors will need to increase their investments in building more secure software, using AI during the development process to prevent vulnerabilities and to catch bugs before they go out the front door, said Moussouris. For everyone else who uses software, it’s going to be a technical debt problem.
“The repo man for technical debt is coming when it comes to all these new AI-generated vuln reports,” said Moussouris.

Perhaps the most important question about Claude Mythos Preview is what will happen when threat actors adopt similar models – assuming they haven’t already. Anthropic researchers talked about developing cybersecurity safeguards that detect and block models’ most dangerous outputs, and said these safeguards will be launched in an upcoming Claude Opus model.
“In the long run, we expect that defense capabilities will dominate: that the world will emerge more secure, with software better hardened—in large part by code written by these models,” according to Anthropic. “But the transitional period will be fraught. We therefore need to begin taking action now.”
April 10, 2026 | 3 min read
Lindsey O’Donnell-Welch is an award-winning journalist who strives to shed light on how security issues impact not only businesses and defenders on the front line, but also the daily lives of consumers.