Anthropic’s Claude Mythos found 10,000 critical vulnerabilities in one month. The patches can’t keep up.


TL;DR

Anthropic’s Glasswing project found 10,000+ critical flaws across 1,000 open-source projects in a month. Only 97 have been patched.

Anthropic disclosed on Friday that Project Glasswing, its restricted cybersecurity initiative, has uncovered more than 10,000 high- or critical-severity vulnerability candidates across some of the most systemically important software in the world since the programme went live one month ago. Of those, 1,726 have been validated as true positives. 1,094 are confirmed high- or critical-severity flaws. Only 97 have been patched.

The gap between those numbers is the story. Anthropic’s Claude Mythos Preview, a frontier model with specialised capabilities for finding vulnerabilities in source code, can identify flaws at a pace that the open-source ecosystem cannot absorb. The 6,202 high- or critical-severity candidates affect more than 1,000 open-source projects. Eighty-eight advisories have been issued. The rate of discovery is orders of magnitude faster than the rate of remediation.

The relative ease of finding vulnerabilities compared with the difficulty of fixing them amounts to a major challenge for cybersecurity,” Anthropic acknowledged. The company is urging software developers to shorten patch cycles and make security fixes available as quickly as possible. Oracle has already shifted from quarterly to monthly patch releases to address the acceleration. Microsoft has warned that the number of monthly patches it expects to release will “continue trending larger for some time.

The 💜 of EU tech

The latest rumblings from the EU tech scene, a story from our wise ol’ founder Boris, and some questionable AI art. It’s free, every week, in your inbox. Sign up now!

The most notable finding so far is a critical flaw in WolfSSL (CVE-2026-5194, CVSS score 9.1), a widely used embedded TLS library, that could allow an attacker to forge certificates and impersonate a legitimate service. WolfSSL is deployed across IoT devices, automotive systems, and industrial control environments where a certificate forgery vulnerability carries consequences well beyond conventional web security.

Glasswing operates through a restricted partnership model. Approximately 50 organisations, described by Anthropic as the most systemically important cyber defenders, have access to Claude Mythos Preview. The model has not been released to the general public. XBOW, an autonomous offensive security platform, described Mythos Preview as “a major advance” that is “substantially better than prior models at finding vulnerability candidates” and “adept at analysing source code with a security mindset.” Cloudflare’s analysis found the model excels at turning individual vulnerabilities into end-to-end attack chains, a capability that is as useful for defenders building threat models as it is dangerous in the wrong hands.

The defensive applications extend beyond vulnerability discovery. In one case, a Glasswing partner bank used Claude Mythos to detect and prevent a fraudulent $1.5 million wire transfer after an attacker breached a customer’s email account and made spoof phone calls. The model identified the fraud pattern before the transfer was executed. The use case illustrates Anthropic’s argument that frontier AI models can provide asymmetric advantages to defenders, but only if access is restricted to organisations with the maturity to use them responsibly.

The timing aligns with a broader acceleration in AI-related security disclosures. Cyera’s Claw Chain vulnerabilities in OpenClaw, disclosed earlier this month, demonstrated how attackers can weaponise an AI agent’s own sandbox privileges. Koi Security’s audit of ClawHub found 341 malicious entries among 2,857 available AI agent skills. The pattern is consistent: AI is simultaneously creating new attack surfaces and providing more powerful tools to find flaws in existing ones. The question is which side of the equation moves faster.

Anthropic has launched a Cyber Verification Program that allows vetted security professionals to use Claude without guardrails for legitimate purposes including vulnerability research, penetration testing, and red teaming. OpenAI has introduced a parallel programme called Daybreak, which provides similar access to GPT-5.5-Cyber. Neither Mythos Preview nor GPT-5.5-Cyber has been released to the general public due to concerns that adequate safeguards to prevent large-scale misuse do not yet exist.

The competitive dynamic between Anthropic and OpenAI in the cybersecurity space is intensifying. Both companies are positioning their frontier models as essential infrastructure for national and corporate cyber defence, while simultaneously restricting access to prevent the same capabilities from being used offensively. The dual-use nature of the technology creates a policy challenge that neither company has fully resolved: if models with Mythos-level capabilities become broadly available, as Anthropic itself acknowledges is likely in the near future, the current model of restricting access to 50 trusted partners will not hold.

Anthropic’s publicly available Claude models are already among the most capable coding assistants on the market. The gap between what Mythos can do and what the public-facing Claude can do is narrowing with each release. Anthropic is urging organisations to prepare for a world in which these capabilities are widely accessible by hardening network configurations, enforcing multi-factor authentication, and maintaining comprehensive logs for detection and response.

Ten thousand vulnerability candidates in one month from 50 partners using one model. The software ecosystem now has a tool that can find flaws faster than developers can fix them. That is both the promise and the problem. Anthropic calls Glasswing an asymmetric advantage for defenders. It is. But asymmetric advantages tend to be temporary, and the clock on this one is already running.



Source link

Leave a Reply

Subscribe to Our Newsletter

Get our latest articles delivered straight to your inbox. No spam, we promise.

Recent Reviews


The iPhone Shortcuts app reminds me of Minecraft. It might be relatively easy to jump into, but it offers nearly limitless potential, allowing you to build anything you want. The same holds true for the Shortcuts app, and that endless possibilities are what many iPhone users might find intimidating. But you don’t have to.

If you are new to iPhone shortcuts, think of them as little automated helpers. You can build them yourself or find ones that others have built and use them. And that’s the beauty of shortcuts. If you don’t want to get your hands dirty, you can find shortcuts others have created and tailor them to your needs. 

With that said, let’s check out my favorite shortcuts. These are not the best shortcuts on everyone’s list, but they are the ones I use daily to get things done faster and more efficiently.

App settings: stop digging through the settings app

Anyone who has spent more than five minutes hunting for an app’s permissions inside the Settings app knows how frustrating it can be. You have to open the Settings app, scroll all the way down, open the Apps section, scroll again to find your app, and only then can you enter its settings. 

This shortcut fixes that completely. It uses the Get Current App and Open URLs actions in the Shortcuts app to detect which app you are currently in and jump straight to its settings page. Once you set it up and add it to your Control Center, all you have to do is open the app, swipe down from the top, and tap the shortcut. 

It will automatically open the current app’s settings. It is genuinely one of the most practical shortcuts I have ever created, and you can download it using the link below. 

Get App settings shortcut

Apple Frames 4: make your screenshots look professional

If you ever share screenshots on social media, a blog post, or a presentation, this shortcut is for you. Apple Frames 4 is a free shortcut by Federico Viticci of MacStories, which can wrap your screenshots in a proper device frame.

The latest version is noticeably faster, supports all recent Apple devices, and even lets you choose frame colors and scale the images proportionally. What I love most about this shortcut is that it can take multiple screenshots as input and combine them in one image. 

All the images in this article have been created using the same shortcut. If you also take screenshots regularly, I can highly recommend this shortcut. I would also recommend you check out my favorite screenshot utility for Mac. It offers all the missing features of Mac’s built-in screenshot tool and then some. 

Get Apple Frames shortcut

Scan document: your pocket scanner is already in your hand

You don’t need a third-party app to scan documents on an iPhone. You don’t even need to open the Notes or Files app the usual way. With this shortcut, you can open the document scanner instantly and scan and save papers without any extra steps.

I have it in my Home Screen and use it whenever I need to quickly scan a receipt, a letter, or any paper document. It’s one of those shortcuts that sounds simple until you realize how much time it saves you every week.

Get Scan Documents shortcut

Resize & convert: resize images without downloading a third-party app

How many times have you shared a photo only to find out it was too large, or in the wrong format for where you needed it? Since the iPhone Photos app doesn’t let you resize an image or change its format, I found a simple shortcut to do it. 

The steps are pretty easy, too. You pick the image, set the size, and the shortcut handles the rest. I use this a lot when I need to send images for articles or posts that require specific dimensions. 

It handles a task I would otherwise have to do on my Mac or download a third-party app on my iPhone to complete. 

Get Resize & convert shortcut

Extract PDF pages: pull out only what you need

I deal with a lot of PDFs, and sometimes I need to extract a few pages to share or save. So I downloaded a shortcut that lets you select specific pages from a PDF and extract them into a new file.

It sounds like a small thing, but if you have ever had to send someone just two pages from a 40-page PDF, you know how handy this is. You don’t need to download any app, pay a subscription, or open your Mac. Your iPhone handles it in seconds.

Get Extract PDF shortcut

Clipboard history: because you always lose what you copied

This is one of the most underrated shortcuts on this list. While macOS has finally added a clipboard history feature with the macOS Tahoe update, the iPhone still doesn’t have a clipboard history. That means every time I copy something on my iPhone, it erases all the previously copied items. 

So I built a shortcut to work around it. Now, every time I copy something on my iPhone, it saves to a note, creating a running clipboard history I can refer back to whenever I need it. The only issue is that I have to run the shortcut manually for it to work. 

So that’s why I have added it to the Back Tap gesture (go to Settings → Accessibility → Touch → Back Tap) on my iPhone. Once I copy something I want to save, I simply tap the back of my iPhone three times to trigger the shortcut and save the copied item in a preassigned note. 

When you download the shortcut, make sure to edit it by tapping the three-dot menu and selecting the note you want to use as your clipboard history.

Get Clipboard History shortcut

Turn off mobile data when iPhone connects to Wi-Fi

To balance the manual activation of the last shortcut, I give you one that is pure automation. Once you set it up, you never have to think about it again. The shortcut uses the Shortcuts automation feature to detect when your iPhone connects to a Wi-Fi network and automatically turns off your mobile data.

I have also set up the companion automation that turns mobile data back on when you leave Wi-Fi. It saves battery life and prevents your phone from uselessly using mobile data when it doesn’t need to. Since this is an automation, there’s no way to share a downloadable link, but you can learn how to create this shortcut. The screenshot should give you the basics of how to do it.

My 7 favorite iPhone shortcuts

I know the Shortcuts app can feel intimidating at first, but most of these require very little setup, and the payoff is immediately obvious. Start with one that solves a problem you have right now, and before long, you will be building your own.

If you have an iPhone and are not using Shortcuts, you are missing out on one of the most powerful tools Apple has built. So, definitely give this a try, and your life will never be the same.



Source link