Anthropic Says Claude Mythos Found 10,000 Security Flaws

Anthropic says its Project Glasswing program has helped uncover more than 10,000 high- or critical-severity vulnerabilities since launching last month. The company said a subset of partners using Claude Mythos Preview also helped patch findings and issue advisories, while urging faster patching and stronger defenses.

Anthropic Says Claude Mythos Found 10,000 Security Flaws

Anthropic said Friday that Project Glasswing has helped uncover more than 10,000 high- or critical-severity vulnerabilities in widely used software since the cybersecurity program launched last month. The company described the effort as focused on some of the world’s most “systemically” important software and said a small group of about 50 partners received access to Claude Mythos Preview, a frontier model designed to find vulnerabilities in widely used code.

According to Anthropic, 6,202 of the vulnerabilities identified through the program were classified as high- or critical-severity and affected more than 1,000 open-source projects. The company said later analysis found 1,726 of the candidates were valid true positives, and that 1,094 of those were assessed to be high- or critical-severity flaws.

⚡ New to this?

This story matters because AI is now being used to find serious software bugs much faster than people can. A vulnerability is a weakness attackers can exploit, and a high- or critical-severity flaw is one that can cause major damage, including impersonation or data theft. The news also shows that defenders are racing to keep up by patching faster and using AI for security testing.

🦞 OpenClaw angle

If you run self-hosted agents or automation that depends on open-source components, tighten your patch intake and testing process now. Track upstream advisories for the libraries you use, and make sure certificate handling, authentication, and logging are reviewed regularly. For internal security work, separate defensive red-teaming agents from production systems and require MFA plus detailed audit logs on any model or tool that can inspect source code or network traffic.

One example Anthropic highlighted was a critical weakness in WolfSSL, tracked as CVE-2026-5194 and given a CVSS score of 9.1. The company said the flaw could let an attacker forge certificates and impersonate a legitimate service.

Anthropic said the work has already led to 97 findings being patched upstream and 88 advisories being issued. Upstream patching means the fix is made in the original software project so downstream users can pick it up.

The company also acknowledged a broader problem: finding bugs is easier than fixing them. “The relative ease of finding vulnerabilities compared with the difficulty of fixing them amounts to a major challenge for cybersecurity,” Anthropic said. “Confronting this challenge successfully will make our software far safer than before.”

The disclosure comes as software vendors are shipping more fixes, in part because AI tools are helping researchers find bugs faster. Microsoft has said the number of monthly patches it expects to release will continue trending larger for some time. Autonomous offensive security platform XBOW said Mythos Preview is “a major advance” and described it as substantially better than earlier models at finding vulnerability candidates and analyzing source code with a security mindset.

Anthropic said the model is also useful beyond vulnerability discovery. In one case, the company said, a Glasswing partner bank used the model to detect and prevent a fraudulent $1.5 million wire transfer after an unknown threat actor breached a customer’s email account and made spoofed phone calls.

The company warned that models with similar capabilities could become broadly available in the near future, and said software developers should shorten patch cycles and release security fixes faster. Anthropic pointed to Oracle’s recent move to a monthly patch cycle for critical security issues as an example of that shift.

“Network defenders should shorten their patch testing and deployment timelines,” Anthropic said. It also recommended hardening default network configurations, enforcing multi-factor authentication, and keeping comprehensive logs for detection and response.

To support legitimate security work, Anthropic said it has launched a Cyber Verification Program that lets security professionals use its models without guardrails for tasks such as vulnerability research, penetration testing, and red teaming. The company said this is similar to OpenAI’s Daybreak program, which gives defenders access to GPT-5.5-Cyber for specialized workflows.

Anthropic said models like Mythos Preview and GPT-5.5-Cyber have not been released publicly because it believes there are still no adequate safeguards to prevent large-scale misuse. The company said Glasswing is intended to give major cyber defenders an advantage, but added that many organizations still need to improve their security posture.

Source: The Hacker News ↗

More from Security News