{"id":45226,"date":"2026-04-08T19:17:33","date_gmt":"2026-04-08T11:17:33","guid":{"rendered":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/2026\/04\/08\/anthropics-claude-mythos-finds-thousands-of-zero-day-flaws-across-major-systems\/"},"modified":"2026-04-08T19:17:33","modified_gmt":"2026-04-08T11:17:33","slug":"anthropics-claude-mythos-finds-thousands-of-zero-day-flaws-across-major-systems","status":"publish","type":"post","link":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/2026\/04\/08\/anthropics-claude-mythos-finds-thousands-of-zero-day-flaws-across-major-systems\/","title":{"rendered":"Anthropic&#8217;s Claude Mythos Finds Thousands of Zero-Day Flaws Across Major Systems"},"content":{"rendered":"<div style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEihvGfSh39Lhl5ird3iuR-T4gkaVejmXgtJ4VwbkLxAqG2hBZWkqQ8LR5k8wfuapt8oUdtifp8Le-uA6Xep8kGe3BRCx5qM1vY9DiMCnMgTFeFK8bc0wBSUR62TjZgPZ9dviGiM8-4-xW1N-ZGSDxIY0uJLFmEKDt1Z9rbttd7Lg_mma6Kt_2qk89vjq9Ed\/s1600\/claude-mythos.png\" style=\"display: block; padding: 1em 0; text-align: center; clear: left; float: left;\"><img decoding=\"async\" border=\"0\" data-original-height=\"470\" data-original-width=\"900\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEihvGfSh39Lhl5ird3iuR-T4gkaVejmXgtJ4VwbkLxAqG2hBZWkqQ8LR5k8wfuapt8oUdtifp8Le-uA6Xep8kGe3BRCx5qM1vY9DiMCnMgTFeFK8bc0wBSUR62TjZgPZ9dviGiM8-4-xW1N-ZGSDxIY0uJLFmEKDt1Z9rbttd7Lg_mma6Kt_2qk89vjq9Ed\/s1600\/claude-mythos.png\" alt=\"Anthropic's Claude Mythos Finds Thousands of Zero-Day Flaws Across Major Systems\"\/><\/a><\/div>\n<p>Artificial Intelligence (AI) company Anthropic announced a new cybersecurity initiative&nbsp;called <strong>Project&nbsp;Glasswing&nbsp;<\/strong>that&nbsp;will use a preview version of its new frontier model, <b>Claude Mythos<\/b>,&nbsp;to find and address security vulnerabilities.<\/p>\n<p>The model will&nbsp;be <a href=\"https:\/\/www.anthropic.com\/glasswing\">used<\/a> by&nbsp;a small&nbsp;set of organizations, including Amazon Web Services, Apple, Broadcom, Cisco, CrowdStrike,&nbsp;Google, JPMorgan Chase, the Linux Foundation, Microsoft, NVIDIA, and Palo Alto&nbsp;Networks, along&nbsp;with Anthropic, to secure critical&nbsp;software.<\/p>\n<p>The company said it&#8217;s forming this initiative in response to capabilities observed in its general-purpose frontier model that demonstrate a &#8220;level of coding capability where they can surpass all but the most skilled humans at finding and exploiting software vulnerabilities.&#8221; Because&nbsp;of its cybersecurity capabilities and concerns&nbsp;that they&nbsp;could be&nbsp;abused, Anthropic has opted not to&nbsp;make the&nbsp;model generally available.<\/p>\n<p>Mythos&nbsp;Preview, Anthropic&nbsp;claimed, has&nbsp;already <a href=\"https:\/\/red.anthropic.com\/2026\/mythos-preview\/\">discovered<\/a> thousands of high-severity zero-day vulnerabilities in every major operating system and web browser. Some&nbsp;of these include a now-patched 27-year-old bug in OpenBSD, a 16-year-old flaw in FFmpeg, and a memory-corrupting vulnerability in a memory-safe virtual machine&nbsp;monitor.<\/p>\n<p>In one instance highlighted by the company, Mython Preview is said to have autonomously come&nbsp;with a web browser exploit that chained together four vulnerabilities to escape the renderer and operating system sandboxes. Anthropic&nbsp;also <a href=\"https:\/\/www-cdn.anthropic.com\/53566bf5440a10affd749724787c8913a2ae0841.pdf\">noted<\/a> in the preview&#8217;s system card that the model solved a corporate network attack simulation that would have taken a human expert more than 10&nbsp;hours.<\/p>\n<p> <a name=\"more\"><\/a> <\/p>\n<p>In perhaps what&#8217;s one of the most eyebrow-raising findings, Mythos Preview managed to follow instructions from a researcher running an evaluation to escape a secured &#8220;sandbox&#8221;&nbsp;computer it was provided&nbsp;with, indicating a &#8220;potentially dangerous capability&#8221; to bypass its own safeguards.<\/p>\n<p>The model did not stop there. It&nbsp;further went on to perform a series of additional actions, including devising a multi-step exploit to gain broad internet access from the sandbox system and send an email message to the researcher, who was eating a sandwich in a&nbsp;park.<\/p>\n<p>&#8220;In addition, in a concerning and unasked-for effort to demonstrate its success, it posted details about its exploit to multiple hard-to-find, but technically public-facing, websites,&#8221; Anthropic&nbsp;said.<\/p>\n<div style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjwhuYxxSM4kptfZoIgiohnImnABWE6UrgXudIryxKlTVcpUhmWZOjeb7G7wOf2O6D2o_M05qAsvN6nb1Ufa_kq3MIL8gwrVRhgdUKQHQzC_oiJ_IzBKKqsces5QoXk9DJLokcmnyBrxX5F09dJOb4DsquXsQZlEWzccDSgV5n7bmdD-BW5a8QUF4j0N9hV\/s1600\/firefox.png\" style=\"clear: left; display: block; float: left; padding: 1em 0px; text-align: center;\"><img decoding=\"async\" border=\"0\" data-original-height=\"2160\" data-original-width=\"3840\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjwhuYxxSM4kptfZoIgiohnImnABWE6UrgXudIryxKlTVcpUhmWZOjeb7G7wOf2O6D2o_M05qAsvN6nb1Ufa_kq3MIL8gwrVRhgdUKQHQzC_oiJ_IzBKKqsces5QoXk9DJLokcmnyBrxX5F09dJOb4DsquXsQZlEWzccDSgV5n7bmdD-BW5a8QUF4j0N9hV\/s1600\/firefox.png\" alt=\"Anthropic's Claude Mythos Finds Thousands of Zero-Day Flaws Across Major Systems\" \/><\/a><\/div>\n<p>The&nbsp;company pointed&nbsp;out that <b>Project Glasswing<\/b> is an &#8220;urgent attempt&#8221;&nbsp;to employ frontier model capabilities for defensive purposes before those same capabilities are&nbsp;adopted by hostile&nbsp;actors. It&#8217;s also committing up to $100 million in usage credits for Mythos Preview across, as well as $4 million in direct donations to open-source security organizations.<\/p>\n<p>&#8220;We did not explicitly train Mythos Preview to have these capabilities,&#8221; Anthropic said. &#8220;Rather, they emerged as a downstream consequence of general improvements in code, reasoning, and autonomy. The&nbsp;same improvements that make the model substantially more effective at patching vulnerabilities also make it substantially more effective at exploiting&nbsp;them.&#8221;<\/p>\n<p>News of&nbsp;Mythos <a href=\"https:\/\/thehackernews.com\/2026\/04\/claude-code-tleaked-via-npm-packaging.html\">leaked<\/a> last month after details about the&nbsp;model were inadvertently&nbsp;stored in a publicly accessible data cache due to human error. The&nbsp;draft material described it as the most powerful and capable AI model built to date. Days&nbsp;later, Anthropic suffered a second security lapse that accidentally exposed nearly 2,000 source code files and over half a million lines of code associated with Claude Code for about three&nbsp;hours.&nbsp;<\/p>\n<p>The leak also led to the discovery of a security issue that bypasses certain safeguards when the AI coding&nbsp;agent is&nbsp;presented with a command composed of more than 50 subcommands. The issue has since been formally addressed by&nbsp;Anthropic in Claude&nbsp;Code <a href=\"https:\/\/github.com\/anthropics\/claude-code\/releases\/tag\/v2.1.90\">version&nbsp;2.1.90<\/a>, released last&nbsp;week.<\/p>\n<p>&#8220;Claude Code, Anthropic&#8217;s flagship AI coding agent that executes shell commands on developers&#8217; machines, silently ignores user-configured security deny rules when a command contains more than 50 subcommands,&#8221; AI security company&nbsp;Adversa <a href=\"https:\/\/adversa.ai\/claude-code-security-bypass-deny-rules-disabled\/\">said<\/a>. &#8220;A developer who configures &#8216;never run rm&#8217; will see rm blocked when run alone, but the same &#8216;rm&#8217; runs without restriction if preceded by 50 harmless statements. The&nbsp;security policy silently vanishes.&#8221;<\/p>\n<p>&#8220;Security analysis costs&nbsp;tokens. Anthropic&#8217;s&nbsp;engineers hit a performance problem: checking every subcommand froze the UI&nbsp;and burned&nbsp;compute. Their fix: stop checking after 50. They&nbsp;traded security for speed. They&nbsp;traded safety for&nbsp;cost.&#8221;<\/p>\n<div><\/div>\n<div>Found this article interesting?  Follow us on <a href='https:\/\/news.google.com\/publications\/CAAqLQgKIidDQklTRndnTWFoTUtFWFJvWldoaFkydGxjbTVsZDNNdVkyOXRLQUFQAQ' rel='noopener' target='_blank'>Google News<\/a>, <a href='https:\/\/twitter.com\/thehackersnews' rel='noopener' target='_blank'>Twitter<\/a> and <a href='https:\/\/www.linkedin.com\/company\/thehackernews\/' rel='noopener' target='_blank'>LinkedIn<\/a> to read more exclusive content we post.<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Artificial Intelligence (AI) company Anthropic announced a new cybersecurity initiative&nbsp;called Project&nbsp;Glasswing&nbsp;that&nbsp;will use a preview version of its new frontier model, Claude Mythos,&nbsp;to find and address security vulnerabilities.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[],"class_list":["post-45226","post","type-post","status-publish","format-standard","hentry","category-thehackernews"],"_links":{"self":[{"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/posts\/45226","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/comments?post=45226"}],"version-history":[{"count":0,"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/posts\/45226\/revisions"}],"wp:attachment":[{"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/media?parent=45226"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/categories?post=45226"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/tags?post=45226"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}