Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
OpenClaw AI Agent Exploits Gym API to Steal Workout Slot
August 10, 2026
Microsoft Teams to Gain New Security Detection Reporting Feature
August 9, 2026
Critical Metabase Vulnerability Exploited to Gain Admin Access
August 9, 2026
Home/CyberSecurity News/Anthropic Claude Mythos Preview Finds 10,000 Zero-Days in Project Glasswing
CyberSecurity News

Anthropic Claude Mythos Preview Finds 10,000 Zero-Days in Project Glasswing

Key Takeaways Anthropic’s Project Glasswing, using the unreleased Claude Mythos Preview AI, autonomously discovered over 10,000 high- and critical-severity zero-day vulnerabilities in its first...

Jennifer sherman
Jennifer sherman
May 23, 2026 4 Min Read
74 0

Key Takeaways

  • Anthropic’s Project Glasswing, using the unreleased Claude Mythos Preview AI, autonomously discovered over 10,000 high- and critical-severity zero-day vulnerabilities in its first month.
  • The AI model demonstrated the capability to both identify flaws and construct functional exploits, prompting Anthropic to restrict its public release due to severe dual-use risks.
  • Major tech companies like Microsoft, Apple, Google, and Cloudflare partnered with Anthropic, with Cloudflare reporting 2,000 bugs and Mozilla patching 271 vulnerabilities in Firefox 150.
  • A significant bottleneck has emerged: the human capacity to triage and patch vulnerabilities cannot keep pace with AI-driven discovery, with only a small fraction of identified flaws being patched upstream.
  • Organizations must move beyond solely relying on patching and adopt comprehensive defense strategies, including strict configurations, multi-factor authentication, and behavioral analytics.

Anthropic AI Uncovers Over 10,000 Zero-Days in Critical Systems

Anthropic has unveiled the initial, startling findings from Project Glasswing, a collaborative cybersecurity initiative designed to fortify critical infrastructure against malicious exploitation through advanced artificial intelligence.

Table Of Content

  • Key Takeaways
  • Anthropic AI Uncovers Over 10,000 Zero-Days in Critical Systems
  • Mythos Preview’s Unmatched Discovery and Exploitation Capabilities
  • Critical Flaws in Open-Source Projects Revealed
  • The Patching Dilemma: Human Capacity vs. AI Discovery
  • What You Should Do

During its inaugural month, Project Glasswing deployed the unreleased Claude Mythos Preview model, which autonomously identified more than 10,000 high- and critical-severity zero-day vulnerabilities across vital global software systems. This unprecedented discovery rate highlights a new era in vulnerability research.

Mythos Preview’s Unmatched Discovery and Exploitation Capabilities

Anthropic collaborated with over 50 leading technology organizations, including industry giants like Microsoft, Apple, Google, and Cloudflare. The Claude Mythos Preview model was applied to highly targeted codebases, demonstrating an extraordinary ability not only to pinpoint security flaws but also to independently develop functional exploits for them.

Cloudflare, one of the participating partners, reported the discovery of 2,000 bugs, with 400 classified as high or critical severity. Cloudflare noted that the AI model’s false-positive rate surpassed that of human security testers, indicating a significant leap in precision.

Independent assessments further validate these capabilities. The UK’s AI Security Institute confirmed that Mythos Preview is the first model to successfully complete its multi-step cyberattack simulations. Mozilla leveraged the model to uncover and subsequently patch 271 vulnerabilities within Firefox 150, a yield ten times greater than previous testing efforts with Claude Opus 4.6.

Given the profound dual-use risks associated with the model’s autonomous exploit generation capabilities, Anthropic has chosen to withhold Mythos from public release. Its use is currently restricted to members of the defensive consortium.

Critical Flaws in Open-Source Projects Revealed

Beyond proprietary enterprise systems, Anthropic directed Claude Mythos Preview to scan over 1,000 widely used open-source projects. Among its significant findings was CVE-2026-5194, a critical vulnerability identified in the wolfSSL cryptography library.

Mythos Preview successfully engineered an exploit for CVE-2026-5194, enabling the forgery of security certificates. This attack vector could allow threat actors to invisibly spoof banking or email domains, posing a severe risk to digital trust and security.

The Patching Dilemma: Human Capacity vs. AI Discovery

The sheer volume of vulnerabilities unearthed by Project Glasswing has exposed a critical structural weakness within the software industry: the human capacity to triage, report, and patch vulnerabilities is severely outpaced by AI-driven discovery.

The initial scanning phase of the project generated 23,019 candidate findings. A review of 1,900 of these by external security firms confirmed 1,726 (90.8%) as valid true positives.

Despite Anthropic reporting a total of 1,596 vetted findings directly to maintainers, only 97 vulnerabilities have been patched upstream to date, resulting in just 88 published security advisories. This substantial disparity underscores the severe capacity constraints faced by volunteer open-source maintainers, who are now overwhelmed by the influx of high-quality AI-generated vulnerability disclosures.

The industry is now entering a transitional phase where the traditional 90-day coordinated vulnerability disclosure window presents new risks. As Mythos-class models reduce the cost and time of zero-day discovery to nearly zero, the lag between discovery and widespread patch deployment creates a highly dangerous exploit window for threat actors.

What You Should Do

  • Strengthen Network Defenses: Implement and enforce strict default configurations across all systems and networks.
  • Mandate Multi-Factor Authentication (MFA): Ensure MFA is required for all accounts, especially those with privileged access, to mitigate credential compromise risks.
  • Utilize Advanced Behavioral Analytics: Deploy tools that monitor network and user behavior for anomalies to reduce the mean time to detect (MTTD) post-breach activity.
  • Prioritize Patching: While recognizing the challenges, prioritize the application of available patches, particularly for critical vulnerabilities in widely used software.
  • Explore AI-Assisted Security Tools: For enterprises, consider adopting tools like Anthropic’s Claude Security (currently in public beta), which leverages the Opus 4.7 model to assist in vulnerability patching.
  • Engage with Open-Source Initiatives: Support and contribute to efforts like Cisco’s Foundry Security Spec to help build robust AI-assisted evaluation systems for managing future vulnerability data.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackBreachCVECybersecurityExploitPatchSecurityThreatVulnerabilityzero-day

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

World Cup Phishing Campaign Surges: 203 Unique IP Addresses Target Fans

Next Post

Critical Flaw in Laravel-Lang Packages Exposed 700 GitHub Repos

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Levi Strauss Data Breach Exposes Customer and Employee Data
August 8, 2026
OpenAI Pauses Astra Model Development to Assess Cybersecurity Risks
August 8, 2026
Critical Linux Kernel SCTP Vulnerability Lets Attackers Gain Root
August 7, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us