Anthropic Launches Project Glasswing as New Mythos Model Detects Thousands of Vulnerabilities
Anthropic has launched Project Glasswing, bringing together 12 technology companies, including Apple and Microsoft, for defensive cybersecurity research. At its core is the unreleased Claude Mythos, which aims to identify zero-day vulnerabilities in widely used systems and open-source software before attackers can exploit them, addressing the risks posed by AI-accelerated cyber offense and defense.
One month into the project, Anthropic said Mythos had scanned more than 1,000 open-source projects and identified over 30,000 security vulnerabilities, outperforming Claude Opus 4.6 across all tests. The partnership has recently expanded to 150 organizations across industries in 15 countries, with Trend Micro and IBM among those joining. The next phase will extend the technology to businesses more broadly.
All Coverage
25 original reportsThe Backstory
The history behind this eventAnthropic’s Mythos Finds Bugs Faster Than Microsoft Can Patch Them
Anthropic launched Project Glasswing on April 7, 2026, giving about 50 initial partners controlled access to Claude Mythos Preview, an unreleased model built to identify and exploit software flaws. The group includes major technology and infrastructure providers such as Microsoft. Partners found more than 10,000 high- or critical-severity vulnerabilities in the first month, shifting cybersecurity’s constraint from finding bugs to verifying disclosures, producing patches and deploying fixes before attackers gain comparable AI capabilities.
ProPublica reported on July 29 that Mythos uncovered 90 critical and 141 important flaws in Microsoft SharePoint in April alone, outpacing engineers’ ability to patch them; hundreds more surfaced across Microsoft 365, Teams and Copilot. Microsoft fixed more than 200 bugs in June’s Patch Tuesday, then broke that record on July 14 with patches for more than 600. The company said volumes would not plateau soon and that it had invested in staff and AI-powered triage.
Anthropic’s Claude Mythos Release Raises Security Concerns in Crypto Community
Anthropic has introduced Claude Mythos, also known as Fable 5, touting stronger code-analysis and vulnerability-detection capabilities. Such models can help defenders patch smart contracts but may also lower the technical barriers to launching cyberattacks, fueling concerns in the crypto community about the security of assets and protocols.
Anthropic said the new model includes general-purpose safety safeguards and routes cybersecurity-related queries to a specialized model to reduce the risk of misuse. The Uniswap founder, however, criticized the design of its “safety filter” as poorly calibrated. Related reports did not disclose the exact release date, any losses or the value of assets affected.
Anthropic Targets Japan’s Cybersecurity Market With Claude Mythos
Anthropic is targeting Japan’s cybersecurity market with its next-generation AI model Claude Mythos, focusing on vulnerability detection and pursuing Japanese government agencies and financial institutions. The strategy raises questions about cross-border reliance on critical computing power and cybersecurity capabilities. It has also drawn the U.S. government’s attention to computing sovereignty, prompting Japan to accelerate development of advanced domestic cybersecurity models.
As of July 20, 2026, the latest reports indicate that Anthropic is aggressively positioning itself in Japan’s government and financial markets, with Claude Mythos’s vulnerability-detection capabilities emerging as a key competitive focus. The Japanese government and industry are simultaneously advancing the development of sovereign models. Available information does not disclose the model’s release date, investment amount, procurement scale or any formal partner institutions.
Anthropic’s Mysterious Mythos AI Model Helps Uncover macOS Security Flaw
macOS isolates applications through kernel permissions and multiple layers of security. If those protections are bypassed, attackers could gain elevated system privileges. Cybersecurity research firm Calif combined Anthropic’s internal Mythos AI model with human experts to analyze the system, underscoring generative AI’s growing ability to tackle complex vulnerability research.
In 2026, Calif’s team had Mythos identify a way to bypass macOS security protections and uncover a privilege-escalation vulnerability within five days. The flaw was subsequently designated CVE-2026-28952 and affects the macOS 26.5 kernel. Apple has received the report and begun verification, while the related acknowledgments also credit Anthropic’s Claude with discovering the vulnerability.
Anthropic Flagship AI Model Claude Mythos Leaked, Raising Cybersecurity Concerns
Anthropic is developing its flagship Claude Mythos model with advanced coding, reasoning and autonomous cybersecurity capabilities. Its ability to rapidly chain vulnerabilities together could lower the barrier to cyberattacks, making the leak more than a product-secrecy issue. It also raises concerns about zero-day exploitation, responsible disclosure mechanisms and the defense of critical infrastructure worldwide.
As of July 19, 2026, Anthropic was investigating unauthorized access caused by a system configuration error. Reports said vulnerabilities could be attacked within as little as four hours of disclosure. The company is not making Mythos broadly available for now, instead prioritizing trials by cyber defense organizations and addressing risks through its Glasswing program and threat-intelligence sharing.
Anthropic’s Mythos Finds One Vulnerability and 20 Code Defects in First Real-World Test on curl
curl is a widely used open-source data-transfer tool whose code security affects numerous operating systems, applications and online services. Anthropic deployed its AI security model Mythos for its first real-world scan of the curl project, testing whether AI could identify vulnerabilities within an actual open-source maintenance workflow and how false positives affect security teams’ review costs.
In its initial scan, Mythos accurately identified 20 code defects and flagged five potential security vulnerabilities. After reviewing each one, curl’s security team confirmed only one as a genuine low-severity vulnerability and did not validate the other four. The results show that the model can add value to code reviews, but vulnerability assessments still require human verification. No monetary amounts were involved, and the available information does not specify an announcement date.
Anthropic Plans to Offer Mythos AI Model to British Banks to Bolster Cyber Defenses
Anthropic plans to offer its Mythos AI model to British banks as part of an expansion of “Project Glasswing.” Mythos is designed to identify vulnerabilities in cyber defenses, helping financial institutions uncover attack surfaces earlier. Because banks hold large volumes of sensitive data, model security and the risk of false positives are particularly important.
Anthropic recently said it was ready to offer Mythos to British banks, but as of July 20, 2026, it had not disclosed the participating banks, deployment date, contract value or pricing model. The model’s release was previously delayed for safety testing, and the initiative signals that the company is moving ahead with real-world deployment in the financial sector.
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →