AI Security Pulse

Anthropic Claude Mythos/Glasswing Cyber Capabilities and Incidents

Anthropic Claude Mythos/Glasswing Cyber Capabilities and Incidents

Key Questions

What is Anthropic's Claude Mythos and what are its main capabilities?

Mythos is an AI model from Anthropic specialized in cybersecurity, particularly uncovering high and critical vulnerabilities in open-source software with a 90.6% true positive rate. It has identified over 10,000 such issues, though only 75 have been patched so far. CISA is using it under Project Glasswing to audit government code.

Why is the remediation of vulnerabilities found by Mythos considered a bottleneck?

Despite Mythos's high detection accuracy, the vast majority of the 10,000+ identified vulnerabilities remain unpatched, highlighting critical delays in the fix process. Reports like Orca Security's note that 99.9% of fixable AI vulnerabilities stay unaddressed. This creates ongoing risks even as detection improves.

What new open-weight models have been released for vulnerability detection?

Cisco introduced Antares, a family of small, efficient open-weight models designed specifically for finding code vulnerabilities at lower cost than frontier models. Google also released Gemini 3.5 Flash Cyber, which outperforms earlier models like Claude Opus 4.6 for government use cases. Capital One open-sourced VulnHunter as another tool in this space.

How has the US government responded to Mythos and related AI tools?

The US lifted export controls on Mythos 5 and Fable 5 while CISA adopted Mythos for code audits. However, federal warnings were issued to banks about Mythos risks, and access was restricted for months. OSFI also alerted banks to Mythos-powered phishing threats.

What is GLM-5.2 and how does it compare to Mythos?

GLM-5.2 is an open-weight model that matches Mythos 5's ability to find vulnerabilities but operates without the same guardrails. This raises concerns about potential misuse in less controlled environments. It exemplifies the growing availability of capable AI security tools outside major providers.

What competing projects or tools are emerging against Mythos?

Microsoft's Project Perception is positioned as a direct competitor in AI-driven security analysis. Deloitte launched an AI remediation platform, and Lineaje introduced CVEF for rapid 24-hour vulnerability detection and fixing. These tools aim to address both discovery and remediation gaps.

What was the Bad Epoll case involving Mythos?

The Bad Epoll incident revealed that Mythos missed a subtle concurrency bug despite its strong overall performance. This highlights limitations in detecting certain complex or edge-case vulnerabilities. It underscores the need for complementary human review and diverse detection methods.

How are organizations like Thales and CSET viewing the Mythos era?

Thales leaders describe it as a pivotal 'Mythos moment' in cybersecurity transformation. CSET argues that blocking access to such models provides only temporary relief. Broader industry shifts include Windows 11's July 2026 update addressing 570 vulnerabilities amid these AI advances.

Mythos uncovers 10,000+ high/critical vulns across OSS (90.6% true positive), only 75 patched—remediation bottleneck critical. CISA using Mythos to audit government code under Project Glasswing. US lifts export controls on Mythos 5 and Fable 5. GLM-5.2 open-weight model matches Mythos 5's vuln-finding ability without guardrails. Bad Epoll case shows Mythos missed a subtle concurrency bug. New tools: Cisco Antares open-weight models for bug hunting (small, cost-effective), Lineaje CVEF for 24-hour find-and-fix, Google Gemini 3.5 Flash Cyber for government vuln finding (outperforms Claude Opus 4.6). Fed warned banks about Mythos but couldn't access it for months. Orca Security: 99.9% fixable AI vulns unpatched. OSFI warns banks of Mythos-powered phishing. Thales leaders emphasize Mythos moment. Microsoft Project Perception competes. Windows 11 July 2026 update fixes 570 vulns. Deloitte AI remediation platform, Capital One VulnHunter. CSET argues blocking models temporary.

Sources (10)
Updated Jul 22, 2026