{"id":20873,"date":"2026-04-09T13:31:15","date_gmt":"2026-04-09T13:31:15","guid":{"rendered":"https:\/\/ideainthebox.com\/index.php\/2026\/04\/09\/anthropic-keeps-new-ai-model-private-after-it-finds-thousands-of-external-vulnerabilities\/"},"modified":"2026-04-09T13:31:15","modified_gmt":"2026-04-09T13:31:15","slug":"anthropic-keeps-new-ai-model-private-after-it-finds-thousands-of-external-vulnerabilities","status":"publish","type":"post","link":"https:\/\/ideainthebox.com\/index.php\/2026\/04\/09\/anthropic-keeps-new-ai-model-private-after-it-finds-thousands-of-external-vulnerabilities\/","title":{"rendered":"Anthropic keeps new AI model private after it finds thousands of external vulnerabilities"},"content":{"rendered":"<div>\n<p>Anthropic\u2019s most capable AI model has already found thousands of AI cybersecurity vulnerabilities across every major operating system and web browser. The company\u2019s response was not to release it, but to quietly hand it to the organisations responsible for keeping the internet running.<\/p>\n<p>That model is Claude Mythos Preview, and the initiative is called\u00a0<a target=\"_blank\" href=\"https:\/\/www.anthropic.com\/glasswing\" rel=\"noreferrer noopener\">Project Glasswing<\/a>.<\/p>\n<p>The launch partners include Amazon Web Services, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, the Linux Foundation, Microsoft, Nvidia, and Palo Alto Networks.\u00a0<\/p>\n<p>Beyond that core group, Anthropic has extended access to over 40 additional organisations that build or maintain critical software infrastructure. Anthropic is committing up to US$100 million in usage credits for Mythos Preview across the effort, along with US$4 million in direct donations to open-source security organisations.\u00a0<\/p>\n<h3 class=\"wp-block-heading\" id=\"h-a-model-that-outgrew-its-own-benchmarks\">A model that outgrew its own benchmarks<\/h3>\n<p>Mythos Preview was not specifically trained for cybersecurity work. Anthropic said the capabilities \u201cemerged as a downstream consequence of general improvements in code, reasoning, and autonomy\u201d, and that the same improvements making the model better at patching vulnerabilities also make it better at exploiting them.\u00a0<\/p>\n<p>That last part matters. Mythos Preview has\u00a0<a target=\"_blank\" href=\"https:\/\/red.anthropic.com\/2026\/mythos-preview\/\" rel=\"noreferrer noopener\">improved<\/a>\u00a0to the extent that it mostly saturates existing security benchmarks, forcing Anthropic to shift its focus to novel real-world tasks\u2013specifically, zero-day vulnerabilities. These flaws were previously unknown to the software\u2019s developers.\u00a0<\/p>\n<p>Among the findings: a 27-year-old bug in OpenBSD, an operating system known for its strong security posture. In another case, the model fully autonomously identified and exploited a 17-year-old remote code execution vulnerability in FreeBSD\u2013CVE-2026-4747\u2013that allows an unauthenticated user anywhere on the internet to obtain complete control of a server running NFS. No human was involved in the discovery or exploitation after the initial prompt to find the bug.\u00a0<\/p>\n<p>Nicholas Carlini from Anthropic\u2019s research team described the model\u2019s ability to chain together vulnerabilities: \u201cThis model can create exploits out of three, four, or sometimes five vulnerabilities that in sequence give you some kind of very sophisticated end outcome. I\u2019ve found more bugs in the last couple of weeks than I found in the rest of my life combined.\u201d\u00a0<\/p>\n<h3 class=\"wp-block-heading\" id=\"h-why-is-it-not-being-released\">Why is it not being released?<\/h3>\n<p>\u201cWe do not plan to make Claude Mythos Preview generally available due to its cybersecurity capabilities,\u201d Newton Cheng, Frontier Red Team Cyber Lead at Anthropic, said. \u201cGiven the rate of AI progress, it will not be long before such capabilities proliferate, potentially beyond actors who are committed to deploying them safely. The fallout\u2013for economies, public safety, and national security\u2013could be severe.\u201d\u00a0<\/p>\n<p>This is not hypothetical. Anthropic had previously disclosed what it described as the first documented case of a cyberattack largely executed by AI\u2013a Chinese state-sponsored group that used AI agents to autonomously infiltrate roughly 30 global targets, with AI handling the majority of tactical operations independently.\u00a0<\/p>\n<p>The company has also privately briefed senior US government officials on Mythos Preview\u2019s full capabilities. The intelligence community is now\u00a0<a target=\"_blank\" href=\"https:\/\/www.nextgov.com\/cybersecurity\/2026\/04\/anthropics-glasswing-initiative-raises-questions-us-cyber-operations\/412721\/\" rel=\"noreferrer noopener\">actively<\/a>\u00a0weighing how the model could reshape both offensive and defensive hacking operations.\u00a0<\/p>\n<h3 class=\"wp-block-heading\" id=\"h-the-open-source-problem\">The open-source problem<\/h3>\n<p>One dimension of Project Glasswing that goes beyond the headline coalition: open-source software. Jim Zemlin, CEO of the Linux Foundation, put it plainly: \u201cIn the past, security expertise has been a luxury reserved for organisations with large security teams. Open-source maintainers, whose software underpins much of the world\u2019s critical infrastructure, have historically been left to figure out security on their own.\u201d<\/p>\n<p>Anthropic has\u00a0<a target=\"_blank\" href=\"https:\/\/www.anthropic.com\/glasswing\" rel=\"noreferrer noopener\">donated<\/a>\u00a0US$2.5 million to Alpha-Omega and OpenSSF through the Linux Foundation, and US$1.5 million to the Apache Software Foundation\u2013giving maintainers of critical open-source codebases access to AI cybersecurity vulnerability scanning at a scale that was previously out of reach.<\/p>\n<h3 class=\"wp-block-heading\" id=\"h-what-comes-next\">What comes next<\/h3>\n<p>Anthropic says its eventual goal is to deploy Mythos-class models at scale, but only when new safeguards are in place. The company plans to launch new safeguards with an upcoming Claude Opus model first, allowing it to refine them with a model that does not pose the same level of risk as Mythos Preview.\u00a0<\/p>\n<p>The competitive picture is already shifting around it. When OpenAI released GPT-5.3-Codex in February, the company called it the first model it had classified as high-capability for cybersecurity tasks under its Preparedness Framework. Anthropic\u2019s move with Glasswing signals that the frontier labs see controlled deployment\u2013not open release\u2013as the emerging standard for models at this capability level.<\/p>\n<p>Whether that standard holds as these capabilities spread further is, at this point, an open question that no single initiative can answer.<\/p>\n<p><strong>See Also: <a href=\"https:\/\/www.artificialintelligence-news.com\/news\/anthropic-uk-expansion-london-pentagon\/\">Anthropic\u2019s refusal to arm AI is exactly why the UK wants it<\/a><\/strong><\/p>\n<figure class=\"wp-block-image aligncenter size-full is-resized\"><a href=\"https:\/\/www.ai-expo.net\/?utm_source=AI-News&amp;utm_medium=Footer-banner&amp;utm_campaign=world-series\"><img fetchpriority=\"high\" fetchpriority=\"high\" decoding=\"async\" width=\"728\" height=\"90\" src=\"https:\/\/www.artificialintelligence-news.com\/wp-content\/uploads\/2026\/03\/image-5.png\" data-orig-src=\"https:\/\/www.artificialintelligence-news.com\/wp-content\/uploads\/2026\/03\/image-5.png\" alt=\"Banner for AI &amp; Big Data Expo by TechEx events.\" class=\"lazyload wp-image-112554\" style=\"width:800px;height:auto\" srcset=\"data:image\/svg+xml,%3Csvg%20xmlns%3D%27http%3A%2F%2Fwww.w3.org%2F2000%2Fsvg%27%20width%3D%27728%27%20height%3D%2790%27%20viewBox%3D%270%200%20728%2090%27%3E%3Crect%20width%3D%27728%27%20height%3D%2790%27%20fill-opacity%3D%220%22%2F%3E%3C%2Fsvg%3E\" data-srcset=\"https:\/\/www.artificialintelligence-news.com\/wp-content\/uploads\/2026\/03\/image-5.png 728w, https:\/\/www.artificialintelligence-news.com\/wp-content\/uploads\/2026\/03\/image-5-300x37.png 300w\" data-sizes=\"auto\" data-orig-sizes=\"(max-width: 728px) 100vw, 728px\"><\/a><\/figure>\n<p><strong>Want to learn more about AI and big data from industry leaders?<\/strong> Check out <a href=\"https:\/\/www.ai-expo.net\/?utm_source=AI-News&amp;utm_medium=Footer-banner&amp;utm_campaign=world-series\">AI &amp; Big Data Expo<\/a> taking place in Amsterdam, California, and London. The comprehensive event is part of <a href=\"https:\/\/techexevent.com\/?utm_source=AI-News&amp;utm_medium=Footer-banner&amp;utm_campaign=world-series\">TechEx<\/a> and is co-located with other leading technology events including the <a href=\"https:\/\/cybersecuritycloudexpo.com\/?utm_source=CloudTech-News&amp;utm_medium=Footer-banner&amp;utm_campaign=world-series\">Cyber Security &amp; Cloud Expo<\/a>. Click <a href=\"https:\/\/techexevent.com\/?utm_source=AI-News&amp;utm_medium=Footer-banner&amp;utm_campaign=world-series\">here<\/a> for more information.<\/p>\n<p>AI News is powered by <a href=\"https:\/\/techforge.pub\/?utm_source=AI-News&amp;utm_medium=Footer-banner&amp;utm_campaign=world-series\">TechForge Media<\/a>. Explore other upcoming enterprise technology events and webinars <a href=\"https:\/\/techforge.pub\/events\/?utm_source=AI-News&amp;utm_medium=Footer-banner&amp;utm_campaign=world-series\">here<\/a>.<\/p>\n<\/p>\n<p>The post <a href=\"https:\/\/www.artificialintelligence-news.com\/news\/anthropic-keeps-new-ai-model-private-after-it-finds-thousands-of-external-vulnerabilities\/\">Anthropic keeps new AI model private after it finds thousands of external vulnerabilities<\/a> appeared first on <a href=\"https:\/\/www.artificialintelligence-news.com\/\">AI News<\/a>.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Anthropic\u2019s most capable AI model has already found thousands of  [&#8230;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"content-type":"","footnotes":""},"categories":[226],"tags":[],"class_list":["post-20873","post","type-post","status-publish","format-standard","hentry","category-technology"],"acf":[],"_links":{"self":[{"href":"https:\/\/ideainthebox.com\/index.php\/wp-json\/wp\/v2\/posts\/20873","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ideainthebox.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ideainthebox.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ideainthebox.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/ideainthebox.com\/index.php\/wp-json\/wp\/v2\/comments?post=20873"}],"version-history":[{"count":0,"href":"https:\/\/ideainthebox.com\/index.php\/wp-json\/wp\/v2\/posts\/20873\/revisions"}],"wp:attachment":[{"href":"https:\/\/ideainthebox.com\/index.php\/wp-json\/wp\/v2\/media?parent=20873"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ideainthebox.com\/index.php\/wp-json\/wp\/v2\/categories?post=20873"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ideainthebox.com\/index.php\/wp-json\/wp\/v2\/tags?post=20873"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}