Anthropic withholds Mythos Preview and starts Project Glasswing
Anthropic published its assessment of Claude Mythos Preview and said it would not make the model generally available. The unreleased model had found vulnerabilities in every major operating system and every major web browser and had written working exploits for them without human guidance, among them a 27-year-old bug in OpenBSD, a 16-year-old flaw in FFmpeg, and a 17-year-old unauthenticated remote code execution in FreeBSD's NFS server (CVE-2026-4747). More than 99% of the vulnerabilities it had found were still unpatched, the company said, which was why it would not ship the model. Alongside the assessment it launched Project Glasswing, a joint effort to secure critical software, with AWS, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, the Linux Foundation, Microsoft, NVIDIA and Palo Alto Networks. Around fifty organisations were given access, backed by $100 million in model usage credits and $4 million donated to open-source security groups. At the time, deciding not to ship a frontier model because of what it could do, and handing it only to the defenders, was a new shape of decision.