May 22, 2026 · View original article

Anthropic's Project Glasswing Update: Mythos Finds 10,000+ Critical Flaws, Few Patched

Anthropic's 22 May 2026 update says its restricted Mythos model surfaced over 10,000 high-severity vulnerabilities across partners and 1,000+ open-source projects, with a 90% true-positive rate.

On 22 May 2026 Anthropic published an initial update on Project Glasswing, the programme under which roughly 50 organisations have been given controlled access to Claude Mythos Preview, a model the company withholds from general release because of its offensive-security capability. The numbers were striking: more than 10,000 high- or critical-severity vulnerabilities identified across partner systems, and a scan of over 1,000 open-source projects that produced an estimated 6,202 high or critical findings. Of a sample validated by six security firms, 1,587 were confirmed true positives, a 90.6 percent accuracy rate.

Partner results were reported individually. Cloudflare said the model found around 2,000 bugs in its codebase; Mozilla attributed 271 Firefox vulnerabilities to it, more than ten times its previous testing yield; Microsoft, Oracle and Palo Alto Networks also took part. A demonstration against wolfSSL, an embedded TLS library present in billions of devices, showed certificate forgery was possible. The UK AI Security Institute reported that Mythos Preview was the first model to complete both of its cyber ranges end to end.

The less comfortable statistic concerned remediation. At publication only 75 of the open-source findings had been patched and 65 carried public advisories, which is why Anthropic announced a partnership with the OpenSSF Alpha-Omega project to help maintainers triage the backlog. The company separately said it had used the generally available Claude Opus 4.7 to patch about 2,100 vulnerabilities in three weeks, and that it intends to release Mythos-class models to all customers once its cyber safeguards mature.

The update landed in a tense month. Google's threat intelligence unit had just documented the first AI-assisted zero-day in criminal hands, and unauthorised access to Mythos had already been reported in April after a contractor data breach exposed internal naming conventions. By mid-June the US government would order Anthropic to cut off foreign nationals' access to its two most capable models on export-control grounds. Glasswing therefore reads both as a defensive success story and as a preview of an asymmetry problem: discovery is now automated, patching is not.

What it means for leaders

  • Expect a wave of advisories. Thousands of validated open-source findings will translate into CVEs over coming months; vulnerability-management teams should budget for elevated patch volume in common libraries, TLS stacks and browsers.
  • Ask vendors about AI-assisted assurance. Suppliers of critical software should be able to say whether they use frontier models for code review and how they handle the backlog; make it a procurement question alongside SBOM requirements.
  • Prioritise embedded and legacy components. The wolfSSL example shows where risk concentrates: widely deployed, rarely updated code. Map such dependencies in OT, IoT and appliance estates.
  • Govern internal use of offensive-capable models. If your organisation gains access to Mythos-class tooling, define scope, authorisation, logging and disclosure rules before use; ISO/IEC 42001 impact assessments and NIST AI RMF "Map" activities apply directly.
  • Support open-source maintainers you depend on. The find-fix gap is a shared-infrastructure problem; funding or contributing to triage is now a risk-reduction measure, not philanthropy.

Comments

No comments yet. Be the first to comment.