← Back to list

Anthropic’s Mythos: Zero-Day Speeds and the Glasswing Defensive Bunker

Anthropic builds products at the speed of a zero-day exploit.

Virginia Backaitis in Digitizing Polaris · 2026-04-08 03:59 · 0 claps · 2.1 min read paywalled
#anthropics #anthropic-claude #chatgpt #ai-safety #cybersecurity
Open on Medium ↗
Wiki topics: LLM · Large Language Models SAF · Safety & Alignment 🔒 · Cybersecurity

Anthropic’s Mythos: Zero-Day Speeds and the Glasswing Defensive Bunker

Anthropic builds products at the speed of a zero-day exploit.

The lab went public Tuesday with Claude Mythos Preview, a frontier model so effective at finding software vulnerabilities that the company is too spooked to release it. Instead of a general rollout, we’re getting Project Glasswing — a coordinated defensive effort bringing together Amazon, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, the Linux Foundation, Microsoft, NVIDIA, and Palo Alto Networks to get ahead of an incoming wave of AI-generated attacks that could make current security stacks look like Swiss cheese.

That roster is basically the backbone of enterprise infrastructure. They’re not just lending their names — they’re getting exclusive access to Mythos to scan critical software before bad actors build their own version. The clock is ticking: Anthropic has committed to reporting initial findings to the public within 90 days.

For decades, the industry banked on a comfortable lag — the gap between a bug being discovered and an exploit being coded. That window is gone.

Mythos is an agentic hunter, not a scanner. It found a 27-year-old vulnerability in OpenBSD — one of the most security-hardened operating systems in the world, used to run firewalls and critical infrastructure — that allowed an attacker to remotely crash any machine just by connecting to it. It also found a 16-year-old flaw in FFmpeg, the video encoding software baked into countless applications, in a line of code that automated testing tools had hit five million times without flagging. Five million times. And then it chained together multiple vulnerabilities in the Linux kernel to escalate from ordinary user access to complete control of the machine. No human in the loop after the initial prompt.

OpenAI is the notable absence from the Glasswing roster. Google signed on — which is its own kind of signal, given that Google is both a rival and a backer of Anthropic, and its Gemini models aren’t in the same conversation on this capability.

The rollout is politically messy. Anthropic is coordinating with the U.S. government despite an active legal fight — the Pentagon recently labeled the lab a “supply chain risk” after Anthropic refused to allow its technology to be used for autonomous weapons targeting or surveillance of U.S. citizens. Anthropic is briefing federal officials on Mythos while suing the Defense Department in court. Washington contains multitudes.

The source code leak from last month wasn’t a footnote either. Anthropic accidentally exposed nearly 2,000 source code files and over half a million lines of code during a routine update to its Claude Code package, then took down thousands of GitHub repositories trying to clean it up. If the people building Mythos can leak that much through human error, Glasswing isn’t just a precaution — it’s an admission that one mistake is all it takes.

Anthropic has already privately warned top government officials that Mythos makes large-scale cyberattacks significantly more likely this year. The window to build defenses is open. It won’t be for long.


메타데이터
post_id
9f7235a1f40b
slug
anthropics-mythos-zero-day-speeds-and-the-glasswing-defensive-bunker-9f7235a1f40b
url
https://digitizingpolaris.com/anthropics-mythos-zero-day-speeds-and-the-glasswing-defensive-bunker-9f7235a1f40b
canonical_url
https://digitizingpolaris.com/anthropics-mythos-zero-day-speeds-and-the-glasswing-defensive-bunker-9f7235a1f40b
author_url
https://medium.com/@actbrilliant
status
ok
fetched_at
2026-06-14 11:28:49