The point: Claude Mythos identifies critical security gaps at scale – Anthropic limits access through Project Glasswing and offers a guardrailed parallel model called Claude Fable 5.
Anthropic has distributed Claude Mythos, a specialized AI model for cybersecurity applications, to selected partners under controlled conditions. Access restrictions are designed to prevent attackers from using the technology to automate zero-day exploits.
Claude Mythos is a language model developed by Anthropic, optimized specifically for cybersecurity and healthcare applications. Mythos 5 was initially released in April 2024 to a small group of trusted technology partners, before broader availability was planned. To control access, Anthropic established Project Glasswing, a consortium that grants infrastructure providers, open-source developers, and large technology companies limited, controlled access to Mythos.
The 50 initial Project Glasswing partners were able to identify over 10,000 vulnerabilities of high or critical severity across all major operating systems and web browsers using Mythos. The model uncovers security flaws that even experienced security researchers have overlooked for years – including a 27-year-old bug in OpenBSD. Additionally, Mythos is capable of chaining multiple vulnerabilities together to demonstrate more complex attack chains.
Anthropic deliberately limits general availability to mitigate misuse potential. In June, it expanded to an additional 150 organizations. All Mythos partners must accept a 30-day data retention policy for security monitoring. The United States imposed export controls on Claude Fable 5 and Claude Mythos 5 on June 15, 2024, intended to block access for foreign nationals domestically and abroad – these were, however, lifted again on June 30.
For broader application, Anthropic offers Claude Fable 5, which is based on the same underlying technology but equipped with strict safeguards that restrict operations in risk-sensitive cybersecurity domains. Flagged requests are automatically routed to the less capable Opus 4.8 model. Cisco, one of the Project Glasswing partners, has open-sourced its Foundry Security Spec – a model-agnostic tool for security testing that allows other vendors and enterprise defenders to build similar workflows without redevelopment. Cisco internally uses AI to scan 1.8 billion lines of code across its entire product portfolio.
Other AI providers such as OpenAI with GPT-5.4-Cyber offer comparable models for vulnerability analysis. Claude Mythos is therefore not the only system available for automated zero-day detection, but one of the most prominent examples on the market.
Source: www.csoonline.com · Published July 20, 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.