Anthropic's Claude Mythos Preview autonomously identified thousands of zero-day vulnerabilities across every major operating system and popular web browser during a controlled test conducted by the United Kingdom's AI Security Institute. The model was evaluated on a benchmark known as The Last Ones, a series of challenges designed as the final hurdle for AI systems before automating complex, real-world cyber-attacks from start to finish.

The AI Security Institute is a research organisation within the British government's Department for Science, Innovation and Technology. The vulnerabilities surfaced by Mythos Preview were unknown to the software's own developers, and some had remained undetected for up to 27 years despite the affected software having been checked millions of times. Under controlled conditions, a skilled human operator typically requires around 20 hours to complete the vulnerability identification exercise.

In ten independent runs of the benchmark, Mythos Preview achieved full success three times. According to Anthropic, the model is the first AI system to solve the entire cyber-attack chain end-to-end, demonstrating autonomous chaining of complex sequential actions. The company describes Mythos Preview as the latest and most advanced model in the Claude family of AI systems, capable of acting as an autonomous agent that plans and executes multi-step tasks over extended periods with minimal human intervention.

Anthropic has restricted public access to Mythos Preview through an initiative called Project Glasswing, which provides selected technology companies and critical infrastructure providers with controlled access to the model. Companies named as participants include Apple, Google, Microsoft, Cisco, and Amazon. Anthropic states that its purpose for Mythos Preview is to identify and fix security weaknesses in operating systems, browsers, and critical libraries before they can be exploited, and that it plans to deploy Mythos more widely as a general-purpose AI system only after critical software has been secured.

The emergence of Mythos creates a dual-use dilemma, with the potential to strengthen cyber defense while also lowering barriers for offensive operations. Many ransomware attacks succeed by exploiting known or easily discoverable weaknesses in unpatched systems, though sophisticated attacks using stolen credentials, social engineering, or compromised accounts bypass traditional software vulnerabilities. There is no public evidence that Mythos Preview has reached criminal groups or nation-state adversaries.