Anthropic disclosed that its Claude Mythos Preview model autonomously discovered and, in some cases, exploited vulnerabilities across major software targets, including Firefox, OpenBSD, FreeBSD, Linux, FFmpeg, cryptography libraries, and a memory-safe virtual machine monitor. The company said the system produced browser exploit chains involving JIT heap sprays and sandbox escapes, chained Linux kernel flaws into local privilege escalation, and developed a fully autonomous exploit for CVE-2026-4747, a FreeBSD NFS issue that reportedly enables unauthenticated remote root access. Anthropic said most findings remain under coordinated disclosure because fewer than 1% had been patched at the time of publication.
Publicly described examples included a 27-year-old OpenBSD SACK denial-of-service bug that was later addressed in an OpenBSD patch, and a 16-year-old FFmpeg H.264 out-of-bounds write. Anthropic also said it partnered with Mozilla to improve Firefox security, underscoring that modern AI systems are now capable of meaningful autonomous vulnerability research against widely deployed platforms. To limit immediate misuse, the company withheld most technical details and published SHA-3 commitments for future disclosure while urging defenders to accelerate AI-assisted bug hunting, patching, disclosure coordination, and incident-response automation.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Anthropic reported that Claude Mythos Preview had autonomously discovered and in some cases exploited zero-day and N-day vulnerabilities across software including OpenBSD, FreeBSD, Linux, FFmpeg, browsers, and cryptography libraries. It publicly highlighted examples including an OpenBSD SACK denial-of-service bug, an FFmpeg H.264 out-of-bounds write, and a FreeBSD NFS remote root issue tracked as CVE-2026-4747, while withholding most details under coordinated disclosure.
OpenBSD published patch 025 for version 7.8 addressing a SACK-related issue, as indicated by the patch signature file in the OpenBSD patches repository. This aligns with later reporting that a long-standing OpenBSD SACK denial-of-service bug had been found.
The paper "AddressSanitizer: A Fast Address Sanity Checker" was presented at the 2012 USENIX Annual Technical Conference in Boston, Massachusetts. The conference entry identifies the authors as Konstantin Serebryany, Derek Bruening, Alexander Potapenko, and Dmitriy Vyukov.
Anthropic published a post about partnering with Mozilla to improve Firefox's security. The reference indicates this announcement was published on 2026-03-06, but the synopsis provides no additional dated event details.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
anthropic.com
Open sourceftp.openbsd.org
Open sourcered.anthropic.com
Open sourceusenix.org
Open sourceusenix.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.