On April 8, 2026, Anthropic officially announced its new model, Claude Mythos Preview, and stated that due to safety concerns, it will not be made available to general users.
Anthropic stated that this is a brand-new general-purpose language model that performs exceptionally well across various dimensions, particularly demonstrating outstanding capabilities in computer security tasks.
In Anthropic's testing, the new model demonstrated extraordinary capabilities in the cybersecurity domain, showing the ability to identify and exploit zero-day vulnerabilities in all major operating systems and web browsers under user instruction.
Below are the application examples provided by Anthropic:
- Discovered a vulnerability in OpenBSD that had existed for 27 years (OpenBSD is an operating system renowned for its security).
- Wrote a web browser exploit that chained four vulnerabilities together to bypass the browser's sandbox protection.
- Mythos Preview autonomously identified a 16-year-old vulnerability in H.264, one of FFmpeg's most popular codecs.
- Mythos Preview fully autonomously identified and exploited a 17-year-old remote code execution vulnerability in FreeBSD, which allows anyone to gain root access to a machine running NFS.
- Mythos Preview discovered several Linux kernel vulnerabilities that allow attackers to perform out-of-bounds writes (for example, through buffer overflows, use-after-free, or double-free vulnerabilities).
For specific details, check out the original post link: Assessing Claude Mythos Preview's cybersecurity capabilities
Based on the capabilities displayed by Mythos Preview during testing, Anthropic stated that this reveals a sobering reality: the coding proficiency of AI models has reached extremely high levels, enabling them to almost surpass all but the most skilled humans in discovering and exploiting software vulnerabilities.
Consequently, Anthropic has launched the Glasswing initiative, bringing together leading organizations including Amazon, Anthropic, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorgan Chase, the Linux Foundation, Microsoft, NVIDIA, and others, with the goal of securing the world's most critical software.
If things are indeed as Anthropic describes, this will mark a turning point where AI begins rewriting the foundational rules of cybersecurity. The digital defense lines we have built over decades are facing an unprecedented crisis, and "identifying vulnerabilities" will shift from a lengthy audit by human experts to a native instinct of AI models.
As for everyday users, we will not have access to this model in the near term, which is bound to be a disappointment.
Comments