Anthropic restricted public release of its Mythos AI model after internal and external testing showed unusual strength in software vulnerability research, including the ability to analyze code, identify previously unknown flaws, and assess likely exploitability. The company said the concern was not the usual set of AI risks such as misinformation or hallucinations, but the possibility that advanced models could sharply accelerate vulnerability discovery and reduce a longstanding bottleneck in cyber operations.
A U.S. official told the Associated Press that, during joint testing with U.S. intelligence agencies under Anthropic’s Project Glasswing, Mythos identified vulnerabilities in highly sensitive U.S. government systems within hours. Senator Mark Warner later said at a Senate hearing that the tool had broken into almost all classified systems within hours, citing information attributed to NSA and U.S. Cyber Command leadership, while Anthropic and outside experts argued the model’s capabilities could help defenders patch systems faster even as they raise the risk of faster exploit development and weaponization.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Anthropic said the US government partially lifted restrictions on its Mythos 5 model, allowing limited access for a select group of cyber defenders and infrastructure providers while broader review continues. The move followed earlier limits tied to cybersecurity and national security concerns about advanced AI vulnerability discovery.
More than 100 cybersecurity experts and leaders from companies including Adobe and Nvidia urged the Trump administration to relax restrictions on Anthropic's advanced models, arguing Mythos is strong at vulnerability discovery and exploit weaponization but not uniquely capable versus other models.
During a joint testing exercise under Anthropic's Project Glasswing, Mythos identified vulnerabilities in highly sensitive US government computer systems, with a US official saying some flaws were found within hours.
On June 11, Senator Mark Warner publicly referenced the testing at a Senate hearing, saying the tool broke into almost all classified systems within hours and attributing the information to NSA and US Cyber Command leader Gen. Joshua Rudd.
Anthropic withheld broader public release of its Mythos AI model because it showed an unusual ability to identify previously unknown software vulnerabilities, raising cybersecurity concerns beyond typical AI risk categories.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
securityweek.com
Open sourcesecurityweek.com
Open sourceapnews.com
Open sourceteiss.co.uk
Open sourceblog.cloudflare.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.