Gen. partnerAlgotech

Project Glasswing: Anthropic claims that AI model Mythos Preview found thousands of critical vulnerabilities

The company claims that a number of partners observed a significantly higher rate of bug discovery than with regular manual testing.

|
May 24, 2026
Project Glasswing: Anthropic claims that AI model Mythos Preview found thousands of critical vulnerabilities

The company Anthropic published the first details about the project Project Glasswing, an initiative focused on finding vulnerabilities in critical software using advanced AI models.

According to the released information, around 50 partners joined the project and during the first month they used the model Claude Mythos Preview to find more than 10 000 critical or high-severity vulnerabilities. Anthropic also states that the current limit is no longer the discovery itself, but people's ability to verify, report, and fix these vulnerabilities.

Anthropic describes a significant acceleration in vulnerability discovery

The company claims that a number of partners observed a significantly higher rate of bug discovery than with regular manual testing.

For example, Cloudflare reportedly found via Mythos Preview more than 2 000 bugs in its critical systems, of which approximately 400 were of high or critical severity. The company allegedly also stated that the number of false positives was lower than with usual human testing.

Similar results are also reported by other organizations, according to Anthropic:

AI Security Institute ve Velké Británii said that Mythos Preview was the first model that could completely solve both of their cyber 'ranges' simulating multi-stage attacks.

Mozilla during testing of the model fixed 271 vulnerabilities in Firefox 150, which according to Anthropic is more than ten times compared to previous tests with the Claude Opus 4.6 model.

Security platform XBOW called Mythos Preview a significant step up from previous models and highlighted in particular its accuracy in exploit analysis.

However, many of these claims so far come directly from Anthropic or its partners, and detailed technical information on most of the found vulnerabilities has not yet been released. The company argues that, due to the coordinated disclosure process, it does not want to publish details before fixes are available.

Over 6 thousand critical findings in open source projects

Anthropic also said that over several months it analyzed more than 1 000 open source projects.

There, according to the company, the model identified over 23 000 potential vulnerabilities, of which more than 6 200 were marked as high-severity or critical.

Of the 1 752 findings manually verified so far, Anthropic says over 90 % were confirmed as valid bugs. Approximately 62 % of them were actually classified as high or critical severity.

One concrete case was a bug in the wolfSSL library, which is used by billions of devices worldwide. Anthropic claims that the AI model created an exploit enabling certificate forgery, which could potentially allow the creation of convincingly believable phishing sites for, for example, banks or email services.

The vulnerability was assigned CVE 2026 5194 and has already been fixed.

Open source project maintainers are struggling to respond

Anthropic also points to a practical problem of the whole process: human capacity.

According to the company, maintainers of open source projects face a large volume of AI-generated reports, some of which are low quality or difficult to verify. Some maintainers have reportedly asked Anthropic to slow the rate of reporting new bugs because they can't keep up with preparing fixes.

The average time to fix a critical vulnerability found using Mythos Preview is currently around two weeks, according to the company.

Anthropic also said that of the 530 high-severity or critical vulnerabilities reported so far, only 75 have been fixed.

Anthropic introduces new security tools

Part of Project Glasswing also includes several new tools for security teams.

Anthropic launched a beta version of the Claude Security service for Claude Enterprise customers. The tool allows analyzing source code, searching for vulnerabilities, and suggesting fixes.

According to the company, more than 2 100 vulnerabilities were fixed in the first three weeks using Claude Opus 4.7.

The company also announced the Cyber Verification Program, which will allow verified security professionals to use advanced models for legitimate security research without some of the protective restrictions.

Anthropic will not publicly release Mythos yet

Anthropic concludes that models at the Mythos Preview level are not yet considered sufficiently safe for public release.

The company claims that current safeguards are not able to reliably prevent abuse of similarly capable models for large-scale cyberattacks. It also expects that other companies will develop similar AI models in the future.

According to Anthropic, Project Glasswing thus represents an effort to prepare the security community for a situation where similar capabilities will be available to a broader range of organizations and attackers.

Loading comments...

Stay in the loop

Subscribe to our newsletter and get the latest cybersecurity news delivered straight to your inbox.

Your data is safe. You can unsubscribe from the newsletter at any time.