On April 8, 2026, Anthropic announced Claude Mythos Preview, a frontier AI model that represents a watershed moment for cybersecurity. Unlike previous frontier models released for general use, Mythos Preview was deliberately restricted to a small group of partners for defensive cybersecurity purposes — a decision driven by the model's striking capability to autonomously discover and exploit zero-day vulnerabilities in production software.
The Capabilities
In testing, Mythos Preview identified and exploited zero-day vulnerabilities in every major operating system and every major web browser. The vulnerabilities it found were often subtle or difficult to detect, many of them ten or twenty years old. The oldest discovered was a now-patched 27-year-old bug in OpenBSD — an operating system known primarily for its security.
The exploits the model constructs go well beyond simple stack-smashing techniques. In one case, Mythos Preview wrote a web browser exploit that chained together four vulnerabilities, writing a complex JIT heap spray that escaped both renderer and OS sandboxes. It autonomously obtained local privilege escalation exploits on Linux by exploiting subtle race conditions and KASLR-bypasses. It wrote a remote code execution exploit on FreeBSD's NFS server that granted full root access to unauthenticated users by splitting a 20-gadget ROP chain over multiple packets.
Perhaps most strikingly, non-experts can leverage Mythos Preview to find and exploit sophisticated vulnerabilities. Engineers at Anthropic with no formal security training asked the model to find remote code execution vulnerabilities overnight and woke up to complete, working exploits.
Project Glasswing
Given these capabilities, Anthropic made the unusual decision not to release Mythos Preview publicly. Instead, the model was offered through Project Glasswing, a consortium giving controlled access to infrastructure providers, open-source developers, and major technology companies for defensive purposes.
The 50 initial Glasswing partners used Mythos to find more than 10,000 high- or critical-severity vulnerabilities across major operating systems and browsers — a volume that would have taken traditional security teams years to discover.
Implications for Cybersecurity
The release signals a fundamental shift in the cybersecurity landscape. As Anthropic stated in the system card: "We have demonstrated a striking leap in cyber capabilities relative to prior models, including the ability to autonomously discover and exploit zero-day vulnerabilities in major operating systems and web browsers."
The Five Eyes intelligence alliance — including the US NSA and UK NCSC — issued a statement warning that frontier AI models like Claude Mythos are "fundamentally transforming both offensive and defensive cyber capabilities" on a timeline of months rather than years.
The Responsible Release Question
Anthropic's decision to restrict Mythos Preview rather than release it generally represents a new paradigm in AI deployment. The company's system card notes that Mythos Preview is "the first model for which we have written a system card without making the model generally commercially available."