Copy article

Mythos: Has Anthropic overstated the cyberthreat threat to boost its profile?

ended 27. April 2026

Anthropic says Claude Mythos Preview marks a dramatic cyber shift. Its Project Glasswing announcement says Mythos “has already identified thousands of zero-day vulnerabilities across critical infrastructure” and describes it as Anthropic’s “most capable yet for coding and agentic tasks”. Anthropic’s own framing is clear: a model that can “deeply understand and modify complex software” can also “find and fix its vulnerabilities”.

That is serious. But it is not the same as proving a brand-new threshold has been crossed.

The awkward detail is that Anthropic had already said its prefious flagship model, Claude Opus 4.6, could do the same class of work. In its own red-team write-up, Anthropic said Opus 4.6 was tested without “special instructions”, without “a custom harness”, and without specialised knowledge being supplied. It said this directly tested Claude’s “out-of-the-box” capability.

Anthropic’s conclusion on Opus 4.6 was even clearer: “Claude Opus 4.6 can find meaningful 0-day vulnerabilities in well-tested codebases, even without specialized scaffolding.” It added that language models are “already capable of identifying novel vulnerabilities” and may soon exceed the “speed and scale” of expert human researchers.

There is further evidence that this risk is not new. IBM’s write-up of the 2024 paper LLM Agents can Autonomously Exploit One-day Vulnerabilities says GPT-4 “was able to correctly exploit one-day vulnerabilities 87% of the time”. The other methods tested, including GPT-3.5 and open-source scanners, “were unable to exploit any vulnerabilities”. IBM also says the study showed LLMs have the ability to “autonomously exploit one-day vulnerabilities”, though GPT-4’s performance fell sharply without CVE descriptions.

So the claim is not that AI cyber capability is fake. It is that Mythos does not yet look like the sudden arrival of a new species of threat.

The Register’s Jessica Lyons reported the same pattern from the security community. Aisle’s replication study tested Mythos showcase vulnerabilities on “small, cheap, open-weights models” and found they produced “much of the same analysis”. The same report quotes Snehal Antani of Horizon3.ai saying: “attackers didn’t need Mythos to accelerate vulnerability research, 4.6 and open source models have already been accelerating the vulnerability process.” His verdict on panic over Mythos access was blunt: “It’s a nothingburger.”

That small-model point matters. If models in the 3B to 5B parameter range can reproduce core parts of the showcased analysis when given scoped code, then the public claim should become much narrower. Mythos may be faster. It may need less hand-holding. It may be valuable for defenders. But that is not the same as proving Anthropic has crossed a cyber Rubicon.

Georgetown University professor of computer science Cal Newport puts the distinction sharply: “Mythos did not introduce a new scary capability… it continues slow and steady progress on an existing type of issue.” He adds: “Independent researchers are yet to identify a vulnerability uncovered by Mythos that earlier models couldn’t find… There is no Rubicon that has been crossed.” On the launch framing, he says: “It is a marketing decision… to present this as a cyber security monster.” His written piece reaches the same conclusion, arguing that there is not yet evidence Mythos “significantly changed this reality”.

Newport then turns the story back on Anthropic’s business narrative. If he were an investor, he says, the question he would want answered is: “Where’s my flying car?” His point is that Anthropic’s leadership has spent years talking about white-collar bloodbaths, AGI, ‘data centres full of geniuses’ and automation powerful enough to justify enormous investment. Yet when its biggest model arrives, the headline claim is not mass automation or a clear leap toward AGI. It is better bug finding. That may be useful. It may be commercially valuable. But it is not the future investors were sold."

This is the real story. Cyber risk is real. AI-assisted exploitation is real. Defensive teams should take it seriously. But if old capability plus louder packaging becomes “superintelligence has arrived”, the public is no longer evaluating risk. It is being handed a mood.

And that mood benefits the vendor. It shapes regulation. It attracts attention. It makes ordinary scrutiny look reckless. That is not safety. It is threshold theatre in a penetration-testing hoodie.

We’d like your views:

  • When an AI company says a model is too dangerous to release, what independent evidence should be required before regulators, investors or journalists repeat the claim?
  • If Opus 4.6, GPT-4 and small open models already showed similar cyber capability, is Mythos a new threat category, or an incremental improvement with better PR?
  • Does fear-based model marketing help defenders prepare, or does it reward frontier labs for inflating public dread?
  • Should cyber capability claims from AI vendors be treated like drug trial claims, requiring independent validation before public alarm?
  • Who benefits when AI risk is framed as sudden and exceptional rather than ongoing, measurable and governable?

4 responses from the Newspage community

Copy all

Star Quote
Copy

This plays into a growing unease among the general population that AI doom is harming mental health. Commentators know doom gets clicks, while AI boosters must stay upbeat about cutting costs by replacing humans to keep CEOs buying and investment flowing.

But the lived experience for many workers is less “AI revolution” and more role creep. Supposed productivity gains are eaten up by sifting slop, rewriting outputs, rephrasing prompts and checking chunky churned presentations for mistakes. Eyeballs are no longer on the deliverable ball. They are on the frustrating cleaning up after the machine.

We need to hold tech companies to account because, like Professor Cal Newport, we’re still wondering when the “flying car” will arrive. For most businesses, there has been leaps in automation, yes, but few earth-shattering AI advances in the past two years.
Copy

AI cyber capability is advancing, but the real issue is not whether Mythos is a step change or an iteration. It is that there is still no independent, enforceable framework to verify these claims. Vendors are setting the narrative, while regulators, investors and the public are expected to respond in real time. That creates risk in both directions.

Overstated threats can distort policy and trust, while understated ones leave systems exposed. The focus now should be on standardised testing, third party validation and clear benchmarks so capability is measured consistently, not communicated selectively.
Copy

The capability itself isn’t the surprise. AI has been moving this way for some time.

The more important question is what standard of evidence we expect when companies frame something as a step change risk.

If a model is positioned as crossing a meaningful threshold, that claim should stand up to independent replication. Otherwise we’re asking regulators and the public to react to narrative rather than proof.

On Mythos, it looks more like acceleration than transformation. Faster, more efficient, less hand holding. That matters operationally, especially for defenders, but that’s not the same as a new threat category.

The bigger issue is incentive. Dramatic framing attracts attention, capital and regulatory influence. That doesn’t make it wrong, but it does mean claims need proper scrutiny.
Copy

If a model is genuinely too dangerous to release, the burden of proof cannot sit with the company making the claim. Regulators, journalists and investors should expect independent testing, clear baselines, and evidence that the capability is materially different from what strong public or commercial models already do. Otherwise we are not measuring risk. We are amplifying a press strategy.

The deeper issue is not whether cyber misuse matters. It does. The issue is whether frontier labs are incentivised to frame incremental capability as exceptional danger because fear attracts attention, policy influence and commercial advantage. That creates a very unhealthy loop where the firms defining the threat are also the ones cashing in on the mystique around it.

Cyber capability claims should be treated much more like safety critical product claims: testable, comparable and independently verified before they become received wisdom.