Media & Culture

A new Anthropic model found security problems ‘in every major operating system and web browser’

Claude Mythos Preview autonomously flagged thousands of high-severity vulnerabilities for elite partners.

Deep Dive

Anthropic has unveiled Project Glasswing, a cybersecurity initiative powered by its new, privately-held Claude Mythos Preview model. In partnership with tech giants like Nvidia, Google, AWS, Apple, and Microsoft, alongside security firms and financial institutions, the project aims to give defenders a massive advantage. The model autonomously scans code and systems, having already identified "thousands of high-severity vulnerabilities, including some in every major operating system and web browser," and developed related exploits without human steering. For now, access is tightly controlled and offered only to a vetted group of about 50 "defensive security" organizations to prevent malicious use.

Anthropic is committing up to $100 million in usage credits to subsidize the program for launch partners, which include JPMorgan Chase, CrowdStrike, and the Linux Foundation. The company has also briefed senior U.S. government officials on the model's offensive and defensive cyber capabilities. While Claude Mythos Preview wasn't specifically trained for security, Anthropic credits its success to "strong agentic coding and reasoning skills." The program represents a potential future revenue stream for Anthropic, evolving into a paid service if proven effective. This launch follows a recent data leak about the model, which the company attributes to human error.

Key Points
  • Claude Mythos Preview autonomously found flaws in every major OS (Windows, macOS, Linux) and browser (Chrome, Safari, etc.).
  • Access is restricted to ~50 elite 'defensive' partners like Google and JPMorgan, backed by $100M in Anthropic credits.
  • The model develops exploits autonomously and has been briefed to senior U.S. government officials for cyber defense.

Why It Matters

This shifts cybersecurity from human-led patching to AI-powered, autonomous vulnerability hunting at an unprecedented scale and speed.