Back to Blog
AI Models May 17, 2026 5 min read

Anthropic's Mythos AI Previewed to 40+ Partners: Autonomous Zero-Day Discovery at Scale

Anthropic's most capable model, Mythos, is being previewed under the restricted Project Glasswing program to partners including Amazon, Apple, Cisco, and Microsoft. It autonomously found thousands of zero-days across major operating systems and browsers.

Anthropic's Mythos AI Previewed to 40+ Partners: Autonomous Zero-Day Discovery at Scale

Anthropic’s Mythos is not a product launch. It is a capability demonstration that raises genuine questions about where AI-assisted offense is headed — and how fast.

Under Project Glasswing, Mythos Preview has been made available to more than 40 partner organizations, including Amazon, Apple, Broadcom, Cisco, CrowdStrike, the Linux Foundation, Microsoft, and Palo Alto Networks. The framing is defensive: partners get access to understand the threat surface so they can harden their systems before this capability proliferates. The subtext is harder to ignore — a model now exists that can autonomously find and exploit vulnerabilities at a scale no human team could match.

What Mythos actually did

During Anthropic’s internal evaluation, Mythos Preview autonomously identified thousands of zero-day vulnerabilities across every major operating system and browser. It required no human involvement after the initial prompt. The most striking result: Mythos found and exploited a 17-year-old remote code execution vulnerability in FreeBSD with zero guidance post-task-assignment. Seventeen years of that bug sitting unnoticed by human researchers.

Anthropic describes Mythos as a “step change” — a phrase the company has historically avoided for marketing reasons and reserves for genuine capability jumps. In this context it means the model surpasses all but the most skilled human offensive security researchers on standard vulnerability discovery benchmarks.

Project Glasswing: what it is and what it is not

Glasswing is a restricted preview, not a product. There is no general availability date. Partners signed NDAs and participate under a structured responsible use framework. Anthropic is effectively betting that early disclosure to defenders creates a net positive versus keeping the capability internal — a defensible position, though not a universally shared one in the security community.

The model’s existence leaked on March 26 through a misconfigured CMS on an Anthropic subdomain. Anthropic formally previewed it to partners on April 7. The company has not commented on the timeline between the leak and the formal announcement.

Why this matters beyond Anthropic

Every frontier lab is building toward this capability. Google DeepMind, OpenAI, and Meta all have active programs in AI-assisted vulnerability research. What makes the Mythos disclosure notable is that Anthropic published specifics — thousands of zero-days, named a concrete exploit, named the partners — rather than speaking in general terms.

The 17-year FreeBSD RCE is the number that should get attention. Old codebases, legacy infrastructure, embedded systems — these are precisely the targets where human audit cycles are longest and the reward for a patient attacker is highest.

For defenders, the immediate implication is not fear of Mythos itself, which remains under controlled access. It is that every threat actor with the resources to build or acquire something similar now has a clearer picture of what is achievable.

Patching velocity needs to match discovery velocity. Right now, it does not.

Anthropic AI cybersecurity Claude Mythos