Updated
Updated · InfoWorld · Jul 27
Anthropic Previews Claude Mythos Finding 27-Year-Old Zero-Days Across Major OSes and Browsers
Updated
Updated · InfoWorld · Jul 27

Anthropic Previews Claude Mythos Finding 27-Year-Old Zero-Days Across Major OSes and Browsers

3 articles · Updated · InfoWorld · Jul 27

Summary

  • Anthropic said Claude Mythos can identify and exploit zero-day flaws across every major operating system and web browser it tested, including a 27-year-old OpenBSD bug.
  • In one example, Mythos built a browser exploit by chaining four separate vulnerabilities, underscoring claims that it can outperform human researchers and conventional scanning tools.
  • Anthropic has not released the model publicly; under Project Glasswing, access is limited to selected companies using it for defensive work on critical software infrastructure.
  • The warning lands as AI coding tools spread through software development, raising the risk that attackers can analyze open-source codebases at machine speed while defenders race to patch faster.
  • For Java users, the report points to rapid patch deployment as the key defense, noting OpenJDK security fixes ship quarterly and some providers release updates within an hour of embargoes lifting.

Insights

If frontier AI can uncover thousands of critical software flaws in weeks, what happens when adversaries use these same models first?
As artificial intelligence drastically lowers the barrier for mass cyberattacks, are standard consumer devices becoming fundamentally unsafe for everyday use?
Could restricting global access to advanced chips accidentally accelerate a rival's independent technological dominance instead of preserving American supremacy?