Sunday, August 30, 2026
LIVEGiveWP plugin flaw let unauthenticated attackers run commands on 100,000+ WordPress sites///Manchester Airports Group breach was worse than first disclosed, extortion gang tells BleepingComputer///PaperCut ships second emergency patch after researchers break the first fix within days///ATF confirms cyberattack after Qilin ransomware gang lists the agency on its leak site///McKesson breach tied to vishing and Okta compromise, ShinyHunters claims 284 million patient records///Berlin refuses ransom after Rhysida gang steals 5.79 terabytes weeks before city elections///Russia's drone-strike decree turns physical attacks into an ownership question///A Saudi Arabic AI model on Microsoft's platform raises the sovereignty question///Embassy warning on visa agents describes a textbook social-engineering market///Critical Zimbra flaw has already compromised 270+ mail servers, CISA confirms active exploitation///Two HTTP requests were enough to hijack any Keycloak account, researchers found///Microsoft patches a maximum-severity Entra ID flaw, then walks back its exploitation claim///GiveWP plugin flaw let unauthenticated attackers run commands on 100,000+ WordPress sites///Manchester Airports Group breach was worse than first disclosed, extortion gang tells BleepingComputer///PaperCut ships second emergency patch after researchers break the first fix within days///ATF confirms cyberattack after Qilin ransomware gang lists the agency on its leak site///McKesson breach tied to vishing and Okta compromise, ShinyHunters claims 284 million patient records///Berlin refuses ransom after Rhysida gang steals 5.79 terabytes weeks before city elections///Russia's drone-strike decree turns physical attacks into an ownership question///A Saudi Arabic AI model on Microsoft's platform raises the sovereignty question///Embassy warning on visa agents describes a textbook social-engineering market///Critical Zimbra flaw has already compromised 270+ mail servers, CISA confirms active exploitation///Two HTTP requests were enough to hijack any Keycloak account, researchers found///Microsoft patches a maximum-severity Entra ID flaw, then walks back its exploitation claim///
Subscribe
Cyber Security
Independent · Digital
The Hacking Post
NewsAI-assisted

Anthropic Unveils 'Mythos' Model to Secure Critical Software via Project Glasswing

Anthropic debuts Mythos, a powerful new AI model designed to find critical zero-day vulnerabilities through its defensive 'Project Glasswing' initiative.

Anthropic Unveils 'Mythos' Model to Secure Critical Software via Project Glasswing

Anthropic’s New Frontier Model Tackles Decades-Old Code Vulnerabilities

Anthropic has officially unveiled a preview of Mythos, its latest and most formidable frontier AI model. Positioned as a direct successor to the high-performance Opus tier, Mythos is being deployed through a specialized security initiative titled Project Glasswing.

Under this program, a select group of over 40 partner organizations will utilize the model’s advanced reasoning and agentic coding capabilities to bolster defensive cybersecurity. The cohort includes industry giants such as Amazon, Apple, Broadcom, Cisco, CrowdStrike, Microsoft, Palo Alto Networks, and the Linux Foundation.

A New Standard for Defensive AI

While Mythos is a general-purpose model within the Claude ecosystem, its initial application focuses on securing software infrastructure. Anthropic reports that during early testing, the model identified thousands of zero-day vulnerabilities, many of which were categorized as critical. Notably, some of these security flaws had remained undetected in software systems for one to two decades.

The initiative aims to scan both proprietary and open-source codebases. Findings from Project Glasswing will eventually be shared with the broader technology sector to improve global software resilience.

Strategic Tensions and Regulatory Friction

Despite the model's defensive potential, its release comes amid significant geopolitical and legal tension. Anthropic confirmed it has held "ongoing discussions" with federal officials regarding Mythos. However, these talks are shadowed by a legal dispute with the Trump administration.

Anthropic has officially unveiled a preview of Mythos , its latest and most formidable frontier AI model.
Inès Chevalier · The Hacking Post

The Pentagon recently designated the AI laboratory a supply-chain risk. This friction stems from Anthropic’s firm refusal to permit its technology to be used for autonomous targeting or the surveillance of American citizens.

From Leaked "Capybara" to Official Debut

The existence of Mythos was first revealed through a high-profile data leak last month, where it was originally referenced under the internal codename "Capybara." At the time, Anthropic attributed the leak (which occurred via an unsecured document cache) to human error.

The leaked documents described the model as "by far the most powerful AI model we’ve ever developed," specifically highlighting its superiority over the Opus series in academic reasoning and software engineering.

Advertisement

Safety Concerns and Ethical Guardrails

Anthropic has acknowledged the dual-use risks inherent in a model this powerful. Internal assessments noted that while Mythos is a breakthrough for defensive security, it could pose a significant threat if weaponized by malicious actors to exploit the very bugs it is designed to fix.

This launch also follows a period of operational turbulence for the company. Last month, Anthropic inadvertently exposed nearly 2,000 source code files during a software update, a mistake that led to the accidental takedown of thousands of GitHub repositories during the subsequent cleanup effort.

Anthropic has stated that the current preview of Mythos remains restricted to its partner group and will not be released for general public availability at this time.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories