Everyone is suddenly talking about Mythos, and for good reason. Claims that the AI model can uncover previously invisible, high criticality vulnerabilities in widely used software, could mark a turning point for cybersecurity. Used defensively, this capability is powerful. Used offensively it could be critical.
If all the claims are true, organisations must rethink how quickly they patch, how they validate complex, layered systems, and how they prepare for a future where attackers may identify weaknesses faster than defenders can respond. Marc Taymans, Managing Director of Nexova, says that the issue isn’t just the technology; it’s governance and operational resilience in a world where AI-driven vulnerability discovery is accelerating.
Why are people talking about Mythos now?
Mythos is the latest generation of Anthropic's Large Language Model. It has hit the headlines because Anthropic claims that Mythos has been able to identify previously uncovered vulnerabilities, some of high criticality, in widely distributed software.
Mythos is therefore a potentially highly useful but also extremely dangerous tool, depending on whether it is used for defensive or offensive purposes.
To date, Anthropic has only allowed a very limited number of companies – and only US companies – to have access to Mythos through the Glasswing Project. But its use won’t be restricted forever.
How have we got here?
Over the last few years, Anthropic has developed a leading position when it comes to models that support the development, review and testing of code. Its models are now widely used by software engineers in leading companies.
Typically, Anthropic releases a new version of its models every couple of months and a new generation on an annual basis. Mythos is the latest generation model.
As a model that is optimised for coding, Mythos seems to provide extremely advanced capabilities: far superior to what existed before. In particular, according to Anthropic’s communications, and some claims from (a very small number of) security experts who have been exposed to the model, it seems to be able to discover software vulnerabilities that were previously totally hidden – and especially those that can only be seen in complex situations.
One well-known expert claimed that he discovered more vulnerabilities during two weeks of using Mythos than he had done during the rest of his career. Anthropic itself claims to have discovered vulnerabilities that were present for many years in widely used and extensively reviewed software: for example a vulnerability that had existed in the OpenBSD operating system for 26 years.
What is true about Mythos and what is false?
Anthropic has already demonstrated that its current generation – the Claude Code version – is extremely good for building robust software and identifying vulnerabilities. Based on that, its claim that the next generation model provides a real advance in detection capabilities seems very credible.
This is supported by several signs, including the organisation of a crisis meeting by the US Treasury Secretary and the Chair of the US Federal Reserve with the leaders of the major US banks, urging them to consider the associated risks.
However, there has been no independent analysis of the true capabilities of the new model, as its use is still limited to a very controlled number of stakeholders. The only information currently available is the very limited set of statistics that Anthropic has published on its website.
What is at stake?
If the claims are true, this would be a major security issue because every company and organisation globally could be exposed to major risks through previously unidentified vulnerabilities present in their software. As a consequence, they would all have to implement corrective measures extremely quickly or be exposed to the risk of attack once those vulnerabilities were widely shared.
In terms of governance, there are multiple issues at stake. Firstly, Anthropic is a private company and hence will almost certainly be expecting to release its new model to the wider public at a given stage. It has invested billions in its development and will not wait indefinitely before commercialising it.
Secondly, the Glasswing initiative is mainly made up of large American companies, with just a very limited number of non-commercial organisations, like the Linux Foundation. European companies and, more importantly, public entities have not been invited to use Mythos at this stage: at least not to my knowledge. Some discussions have started, but most non-US parties were only alerted to the issues raised by Mythos via the communication by Anthropic.
This is problematic on several accounts:
- That a private company has so much power
- That this is mainly a US-driven initiative
- That there is, at least at this stage, no independent review of the true technical capabilities of the Mythos solution.
What can be done?
At the moment, Anthropic is not providing extensive access to Mythos – but as mentioned, this will almost certainly happen at some point. In any case, there is a high likelihood that Anthropic’s competition will attain the same level of technical capability during the next few weeks or months. Open AI (ChatGPT) has already said that it will soon publish a new version of its coding model that has similar capabilities to Mythos.
In parallel, although Chinese models typically lag 6 to 12 months behind leading US foundation models, they will one day also reach the same level of capabilities.
The main risk is therefore that attackers will eventually have at their disposal tools to identify and exploit vulnerabilities before companies and organisations are able to patch them.
So, to start with, companies and organisations must ensure they continue to patch their systems as quickly as possible. This is still a problem for many companies as they tend to patch their systems more slowly than would be considered optimal, often due to organisational or technical limitations. Many companies prefer to wait to see whether the patch will impact operational systems, or because they do not have the operational bandwidth to absorb the implementation of the patch.
There is a strong likelihood that companies providing foundational software – those that are already part of the Glasswing project – will start publishing many updates over the next days and weeks. By releasing those patches, they will also be indicating the vulnerabilities that were addressed, which will then be public. Companies that haven’t implemented those patches will be exposed to high risks.
In parallel, companies and organisations will have to use the new model (when available) to verify that their systems, including those developed internally, are not exposed. Indeed, the strength of Mythos seems to be in its ability to identify vulnerabilities when multiple layers of software are closely embedded.