Anthropic Announces Claude Mythos Preview and Launches Project Glasswing
Anthropic revealed its most powerful model — a 10-trillion-parameter system that autonomously found thousands of zero-day vulnerabilities in every major OS and browser. Not publicly available; only ~40 vetted partners including AWS, Apple, Google, and Microsoft get access for defensive cybersecurity.
Anthropic has announced Claude Mythos Preview and Project Glasswing, a new cybersecurity-focused AI effort that the company says can find software flaws at a scale well beyond previous systems. According to Anthropic, the model behind the effort is a 10-trillion-parameter system that was able to autonomously identify thousands of zero-day vulnerabilities across major operating systems and browsers.
The company framed the release as a controlled preview rather than a broad launch. Access is limited to about 40 vetted partners, including AWS, Apple, Google, and Microsoft, and the model is being positioned for defensive security work rather than general public use.
That distinction matters because large language models are increasingly being used for code review, software testing, and security research, but most of those systems still depend on human guidance. Anthropic is claiming something more aggressive here: a model that can independently inspect code and surrounding software behavior, then surface weaknesses without being explicitly guided to each target.
A zero-day vulnerability is a flaw that is unknown to the vendor or has not yet been patched. Those are valuable to attackers because defenders have no ready fix, and to security teams because they can expose weaknesses before criminals do. If Anthropic’s account is accurate, a system that can find thousands of them autonomously would be a major escalation in automated vulnerability research.
The list of major operating systems and browsers in the summary suggests the model was tested across the kinds of software that form the backbone of modern computing. That includes desktop and server environments, browser engines, and the shared components that often become attack paths when they contain memory safety bugs, parser errors, or privilege escalation issues.
Anthropic has generally pitched its safety work as a counterweight to the risks of powerful AI systems. In this case, the company appears to be emphasizing controlled access, partner vetting, and defensive use cases, which is a familiar pattern in high-risk cybersecurity research where the same tooling that helps defenders can also be misused.
The partner list also signals the intended audience. AWS, Apple, Google, and Microsoft sit at the center of software ecosystems where a vulnerability in one layer can affect millions of devices or users. Giving such companies early access suggests Anthropic wants the model used in internal security workflows, code auditing, and broader hardening efforts.
Project Glasswing appears to be the umbrella name for the program built around the Mythos Preview model. Anthropic has not described it as a consumer product, and the limited access model indicates this is being treated more like a specialized research capability than a general-purpose chatbot release.
What makes the announcement notable is not just the size of the model, but the nature of the task it reportedly handled. Finding vulnerabilities is one of the hardest parts of security work, and doing it across multiple major software platforms points to a system that can reason about code paths, memory handling, and implementation details at a level that is still rare among AI tools.