Anthropic's New Model 'Mythos'—Discovers Thousands of Zero-Day Vulnerabilities, 12 Companies Including Apple, Microsoft, and Amazon Participate
In April 2026, Anthropic announced a preview of its new frontier model, 'Mythos.' Positioned by the company as 'one of the most powerful models to date,' it is being released to a limited group of 12 major partner organizations, including Apple, Microsoft, and Amazon, as part of a new project called 'Project Glasswing' dedicated to cybersecurity defense.
Mythos is said to have already discovered thousands of zero-day vulnerabilities. We summarize its capabilities, the strategy behind it, and the key points that investors and business professionals should watch.
1. What is Mythos—The Most Powerful Frontier Model in Anthropic's History
1-1. Model Positioning and Basic Performance
Mythos is a general-purpose frontier model developed for Anthropic's Claude AI system. The company's frontier models are positioned as its most advanced and high-performance group, designed to handle complex tasks such as agent construction and coding.
According to Anthropic, Mythos possesses 'powerful agentic coding capabilities and reasoning skills,' and significantly outperforms the company's currently available models in areas such as software coding, academic reasoning, and cybersecurity.
1-2. Development Background Revealed by Leaked Internal Documents
In fact, the existence of Mythos had already come to light about a month before the official announcement. In a data security incident reported by Fortune magazine, a draft blog post about the model, then codenamed 'Capybara,' was discovered in an unsecured cache on a publicly accessible data lake.
The leaked document contained the following statements:
'"Capybara" is the new name for a new model tier, which is larger and more intelligent than the Opus model, previously our most powerful model.'
'It is by far the most powerful AI model we have ever developed.'
Anthropic attributed this leak to 'human error.' Ironically, the announcement of a project aimed at strengthening cybersecurity resulted in a leak caused by the company's own security issues.
2. Project Glasswing—A New Framework for AI-Driven Cyber Defense
2-1. Project Overview and Participating Companies
Project Glasswing is a new security initiative aimed at 'defensive security operations' and the protection of critical software using Mythos. The 12 participating partner organizations are as follows:
Amazon
Apple
Broadcom
Cisco
CrowdStrike
Linux Foundation
Microsoft
Palo Alto Networks
Four other undisclosed organizations
In addition, 40 organizations outside the partnership will be granted access to the Mythos preview. However, there are no plans for a public release.
2-2. Specific Use Cases
Mythos is not a model trained exclusively for cybersecurity. However, it will leverage its general-purpose reasoning and coding capabilities to scan for code vulnerabilities in both proprietary and open-source software.
Partner organizations aim to eventually share the insights gained through the project, creating a mechanism where the entire tech industry can benefit. This is a significant initiative for the open-source community as well.
3. Discovery of Thousands of Zero-Day Vulnerabilities—Significance and Impact
3-1. Scale of Discovered Vulnerabilities
According to Anthropic's announcement, Mythos has identified "thousands of zero-day vulnerabilities, many of which are critical" during its operation over the past few weeks. Even more noteworthy is the fact that many of these vulnerabilities have existed for one to two decades.
Zero-day vulnerabilities are security flaws that software developers or vendors are not yet aware of (or have not yet patched). The fact that these have remained undiscovered for over a decade highlights the limitations of traditional manual security audits and existing tools.
3-2. Why AI is Changing Security
Traditional code auditing has relied on human security researchers and existing static analysis tools. In large codebases—especially open-source projects—it is practically impossible to comprehensively check all code.
If AI models can scan vast amounts of code at high speed while understanding context, this could fundamentally change productivity in cybersecurity. On the other hand, as Anthropic itself admitted in leaked documents, this capability also carries the risk that malicious actors could use it to discover bugs and exploit them rather than fix them.
4. Contradictions and Challenges Facing Anthropic
4-1. Internal Security Incidents
While Anthropic champions the strengthening of cybersecurity, ironically, the company has experienced multiple security issues of its own.
Mythos Leak Incident: Internal documents were discovered on a public data lake
Claude Code Source Code Leak: During the release of version 2.1.88, approximately 2,000 source code files and over 500,000 lines of code were made public
GitHub repository deletion incident: During the aforementioned repair work, a situation occurred where thousands of code repositories were accidentally deleted
The current situation where companies attempting to make security a pillar of their business are causing problems in their own security management is a point that should be closely watched from the perspective of reliability.
4-2. Legal conflict with the Trump administration
Anthropic is currently facing legal issues with the Trump administration. This stems from the Department of Defense designating Anthropic as a 'supply chain risk,' which is said to be rooted in Anthropic's stance of refusing to use AI for autonomous targeting and surveillance of U.S. citizens.
Under these circumstances, Anthropic states that it is in 'ongoing discussions' with federal authorities regarding the use of Mythos, but it is not hard to imagine that these negotiations are complex.
5. Points for investors and business professionals to note
5-1. Expansion of the AI security market
Initiatives like Project Glasswing suggest the growth of a new market segment: AI-powered cybersecurity. Participating companies include security specialists like CrowdStrike and Palo Alto Networks, as well as Amazon and Microsoft, which possess cloud infrastructure, suggesting a broad market base.
5-2. Anthropic's competitiveness and evaluation
If Mythos possesses performance exceeding that of the Opus model, Anthropic could further increase its presence in the frontier model race against OpenAI and Google DeepMind. However, as it is not currently publicly available, independent performance verification by third parties has not been conducted, and one must be cautious about whether to accept the company's claims at face value.
5-3. Risk factors
Deteriorating relations with the government could become a barrier to business expansion
Deficiencies in internal security management pose a risk to the trust of corporate partners
Weaponization risk: Concerns that the model's capabilities could be diverted for attack purposes
Limited release model: Direct contribution to short-term revenue is unclear
