Quick access to main page (top) Direct access to main contents Quick access to main page (bottom)

How Anthropic’s New AI Model ‘Mythos’ Revolutionizes Cybersecurity: 50 Organizations Get Early Access

Daniel Kim Views  

Translation result

Bruce
Bruce Schneier. [Photo: Bruce Schneier website]

[Digital Today reporter Hwang Chi-gyu] Anthropic has granted limited early access to its new AI model, Claude Mitos, to roughly 50 organizations, saying the model is too effective at finding and exploiting software vulnerabilities. The rollout is being conducted under “Project Glasswing.”

Anthropic says Mitos identified thousands of vulnerabilities across major operating systems and browsers, including a 27-year-old OpenBSD bug and a 16-year-old FFmpeg flaw. Anthropic also reported that Mitos produced 181 pieces of exploit code for a Firefox vulnerability—compared with just two from the company’s prior flagship model.

Global cryptographer and security expert Bruce Schneier wrote on his website that Anthropic’s approach resembles the “responsible disclosure” process security researchers have long advocated, but that there is too little information to properly evaluate the company’s decision. The published cases are notable, he said, but they don’t reveal how often Mitos was wrong.

Anthropic reported that external security contractors concurred with Mitos’s vulnerability-severity ratings 89% of the time. Schneier called that figure “impressive but incomplete.” Independent researchers studying similar models have found that systems good at catching real bugs also tend to generate plausible false positives in code that has already been fixed. Without an error-rate breakdown, the 89% statistic is insufficient to draw firm conclusions.

That distinction matters for operational risk. “A model that reliably finds and weaponizes hundreds of vulnerabilities would be a game changer,” Schneier wrote. “A model that spits out thousands of false positives still requires skilled humans. If we don’t know Mitos’s error rate, we can’t tell whether Anthropic’s examples represent the whole picture or are cherry-picked successes.”

Large language models like Mitos perform best on inputs similar to their training data. In practical terms, Anthropic trained Mitos heavily on publicly available code: open-source projects, major browsers, the Linux kernel, and widely used web frameworks.

Concentrating initial access with major software vendors is sensible because it gives defenders a chance to patch before attackers can exploit findings. That advantage erodes, however, when the focus shifts to software domains that were underrepresented in Mitos’s training data.

Schneier warned that Mitos would likely struggle with vulnerabilities in industrial control systems, medical-device firmware, bespoke financial infrastructure, regional bank software, and legacy embedded systems. An attacker who does have domain expertise could weaponize Mitos’s advanced reasoning to probe systems where Anthropic’s engineers lack deep knowledge. The real danger is not that Mitos fails in those fields, but that it succeeds in the hands of skilled adversaries.

To reduce that asymmetry, Schneier urged Anthropic to broaden access to experts such as medical-device security cardiologists, control-systems engineers, and researchers familiar with less common languages and ecosystems. “No matter how carefully you select partners, 50 companies cannot substitute for the distributed expertise across the research community,” he said. “Anthropic is a private company with limits on staff, budget, and expertise. It will unilaterally decide which critical infrastructure to prioritize—and it will miss some. If what’s missed includes hospital or power-grid software, the costs will be borne by people who had no voice in that decision.”

AI-driven security risks are not unique to Mitos. Schneier noted that OpenAI chose not to release GPT-5.3-Codex publicly because of safety concerns, and that security firm Aisle reproduced many of Anthropic’s published cases using smaller, cheaper open-source AI models.

Schneier said regulation will ultimately be necessary, but that crafting effective rules takes time and public debate. In the interim, he argued, companies like Anthropic should share more information with a broader community of experts.

“I’m not calling for a broad public release of a powerful model like Mitos,” he wrote. “But Anthropic should share as much data and supporting information as possible so the community can make informed, collective decisions. It should support international cooperation for independent audits, require publication of aggregated performance metrics, and enable access for academic and civil-society researchers.”

Daniel Kim
content@tenbizt.com

Comments0

300

Comments0

[Military] Latest Stories

  • 30 of 33 Iran Missile Bases Still Active: Intelligence Defies Trump Claims
    30 of 33 Iran Missile Bases Still Active: Intelligence Defies Trump Claims
  • US Javelin Missiles Deployed in Taiwan’s High-Stakes Live-Fire Drill
    US Javelin Missiles Deployed in Taiwan's High-Stakes Live-Fire Drill
  • North Korea’s 10-Year Nuclear Threat: Is a Limited Strike Imminent?
    North Korea's 10-Year Nuclear Threat: Is a Limited Strike Imminent?
  • AI vs. Video Compression: How RMX is Redefining Tactical Edge Tech
    AI vs. Video Compression: How RMX is Redefining Tactical Edge Tech
  • US-South Korea Security Meeting Sparks Tension Over Military Control
    US-South Korea Security Meeting Sparks Tension Over Military Control
  • Iran Claims Missile Strikes on U.S. Military Bases: Did They Hit?
    Iran Claims Missile Strikes on U.S. Military Bases: Did They Hit?

Weekly Best Articles

  • Choi Dong-seok’s Family Bond: How a Simple Engraving Reveals Deep Love for His Children
  • Kwak Sun-hee’s Stunning Wedding Photos: A Celebration of Love and Courage
  • Is ‘I Am a Natural Person’ Just a Big Lie? Comedian Yoon-taek Reveals Shocking Secrets!
  • Health Scare: Why Fans Are Worried About Go Ji Yong’s Dramatic Weight Loss
  • Discover the Winter Gongju Chestnut Festival: A Taste of Korea at H-Mart in the USA!
  • 2026 Spring Wildfire Prevention: How Gyeryong City is Cutting Response Time to 30 Minutes!

You May Also Like

  • 1
    Trump Slashes AI Review Window to 30 Days Amid National Security Debate

    Politics 

    Trump Slashes AI Review Window to 30 Days Amid National Security Debate
  • 2
    Ukraine’s EU Bid Surges as Hungary Drops Opposition Amid Russian Attacks

    Politics 

    Ukraine’s EU Bid Surges as Hungary Drops Opposition Amid Russian Attacks
  • 3
    Trump Backs Colombia's 'El Tigre' — What It Means for U.S. Relations

    Politics 

    Trump Backs Colombia’s ‘El Tigre’ — What It Means for U.S. Relations
  • 4
    Trump Backs Colombia's Far-Right Outsider—What's at Stake?

    Politics 

    Trump Backs Colombia’s Far-Right Outsider—What’s at Stake?
  • 5
    12.5% Tariff Hit: South Korea Faces New U.S. Trade Penalties

    Politics 

    12.5% Tariff Hit: South Korea Faces New U.S. Trade Penalties

Popular Now

  • 1
    12.5% Tariff Alert: Why the U.S. Is Targeting South Korean Imports

    Politics&nbsp

  • 2
    Marta Kostyuk Makes History at French Open Amid Ukraine Crisis

    Politics&nbsp

  • 3
    37 Years in Exile: The Tiananmen Leader Who Just Wants to Go Home

    Politics&nbsp

  • 4
    South Korea's Cheongju Airport Faces Crisis as Passenger Numbers Explode

    Politics&nbsp

  • 5
    Nuclear Submarine Race: South Korea's High-Stakes Bid for U.S. Fuel

    Politics&nbsp

Weekly Best Articles

  • Choi Dong-seok’s Family Bond: How a Simple Engraving Reveals Deep Love for His Children
  • Kwak Sun-hee’s Stunning Wedding Photos: A Celebration of Love and Courage
  • Is ‘I Am a Natural Person’ Just a Big Lie? Comedian Yoon-taek Reveals Shocking Secrets!
  • Health Scare: Why Fans Are Worried About Go Ji Yong’s Dramatic Weight Loss
  • Discover the Winter Gongju Chestnut Festival: A Taste of Korea at H-Mart in the USA!
  • 2026 Spring Wildfire Prevention: How Gyeryong City is Cutting Response Time to 30 Minutes!

Must-Reads

  • 1
    Trump Slashes AI Review Window to 30 Days Amid National Security Debate

    Politics 

    Trump Slashes AI Review Window to 30 Days Amid National Security Debate
  • 2
    Ukraine’s EU Bid Surges as Hungary Drops Opposition Amid Russian Attacks

    Politics 

    Ukraine’s EU Bid Surges as Hungary Drops Opposition Amid Russian Attacks
  • 3
    Trump Backs Colombia's 'El Tigre' — What It Means for U.S. Relations

    Politics 

    Trump Backs Colombia’s ‘El Tigre’ — What It Means for U.S. Relations
  • 4
    Trump Backs Colombia's Far-Right Outsider—What's at Stake?

    Politics 

    Trump Backs Colombia’s Far-Right Outsider—What’s at Stake?
  • 5
    12.5% Tariff Hit: South Korea Faces New U.S. Trade Penalties

    Politics 

    12.5% Tariff Hit: South Korea Faces New U.S. Trade Penalties

Popular Now

  • 1
    12.5% Tariff Alert: Why the U.S. Is Targeting South Korean Imports

    Politics 

  • 2
    Marta Kostyuk Makes History at French Open Amid Ukraine Crisis

    Politics 

  • 3
    37 Years in Exile: The Tiananmen Leader Who Just Wants to Go Home

    Politics 

  • 4
    South Korea's Cheongju Airport Faces Crisis as Passenger Numbers Explode

    Politics 

  • 5
    Nuclear Submarine Race: South Korea's High-Stakes Bid for U.S. Fuel

    Politics