So this is Anthropicās case for why Mythos is staying off the public shelf, out of fear of what damage it could cause š¤Æ
Massive leap in capabilities, especially in cybersecurity. It's being used internally at Anthropic and shared only with a small group of vetted partners (Apple, Google, Microsoft, Amazon, NVIDIA, and others) via a new $100M initiative called Project Glasswing.
- The most concerning power in the report is autonomous exploit chaining, where Claude Mythos Preview does not just find a bug but keeps reasoning until it turns that bug, or 2, 3, or 4 bugs together, into a working path to root, kernel, or remote code execution.
- That is a much bigger jump than ordinary bug-finding, because many defenses are built on the hope that even if one flaw exists, turning it into a real attack will still take weeks of rare human skill.
- it surfaced zero-days across every major operating system and web browser, including a now-patched 27-year-old OpenBSD bug.
- Mythos found a 17-year-old FreeBSD flaw and built a fully autonomous remote root exploit for it, found browser bugs and chained them into JIT heap sprays, sandbox escape, and even kernel write access, and built Linux privilege-escalation chains that bypassed protections like KASLR.
- All this happened on fully hardened systems and often with no human help after the initial prompt.
- The second disturbing part is accessibility, because Anthropic says even staff with no formal security training could ask for a remote code execution bug overnight and wake up to a working exploit.
Claude Mythos - honestly cannot remember seeing a jump this huge in years.
Too bad Anthropic is not releasing it anytime soon, although there is not much pressure when they are still the leader.