Anthropic’s Mythos Raises the Cyber Threat Level 5 min read In November 2022, ChatGPT 3.5 debuted, marking a major milestone for generative AI. Since then, new tools and models have emerged rapidly—bringing distinct capabilities and new security risks. As these technologies evolve toward more advanced reasoning and agentic capabilities, security leaders are evaluating what they could mean for vulnerability discovery, exploit development, and defense.On April 7, 2026, Anthropic announced its latest frontier model, Claude Mythos, and warned that the unreleased system had reportedly identified thousands of previously unknown, exploitable vulnerabilities across major operating systems and web browsers. If those claims are substantiated, they could accelerate the pressure on traditional patch cycles, increase the need for rigorous code review, and elevate the importance of segmentation and access controls to limit impact. Topics Digital Transformation Technology Enablement Artificial Intelligence Even so, this development changes the speed and scale of vulnerability discovery more than it changes the fundamentals of cybersecurity. Organisations can still rely on established best practices—while preparing for a world where new vulnerabilities are identified faster than teams can remediate them.What Is Claude Mythos?Claude Mythos is an unreleased, general-purpose AI model built by Anthropic with strong coding and reasoning capabilities. Combined with autonomous security logic, it is designed to identify software vulnerabilities by reviewing code for weaknesses, analysing potential exploit paths, and proposing patch options. It can also chain multiple weaknesses into an attack path and generate proof-of-concept outputs for exploitation testing.Anthropic has not released the model publicly, choosing instead to provide limited access to a small set of large technology companies—positioning the approach as a way to give defenders a head start before similar capabilities become widely available.Anthropic has reported that the model has identified thousands of potential zero-day vulnerabilities across major operating systems and web browsers. Publicly discussed examples include:A 27-year-old OpenBSD integer-overflow vulnerability that can induce a remote crashA reported FFmpeg vulnerability that evaded detection across millions of automated test runsA Linux kernel exploit chain that links multiple weaknesses for privilege escalationAt present, Mythos is not available for public use, which limits immediate risk. However, given the pace of AI development, comparable capabilities could become broadly accessible within the next 12 to 18 months, including through open-source models.What Is Project Glasswing?To harness these capabilities defensively, Anthropic created Project Glasswing—an initiative that brings together major technology organisations to collaborate on secure development and improved defensive measures. Participants reportedly include AWS, Apple, Broadcom, Cisco, CrowdStrike, Google, Microsoft, Nvidia, the Linux Foundation, Palo Alto Networks, JPMorgan Chase, and others. In total, roughly 40 organisations are participating.Anthropic has committed $100 million in usage credits and has donated $4 million to open-source security organisations. Early reports suggest Linux kernel maintainers have already used the model to uncover vulnerabilities previously missed by traditional approaches.Early testing also highlights an important limitation: while AI can accelerate vulnerability discovery and propose fixes, remediation still requires significant human validation, engineering judgment, and defence-in-depth thinking. Security teams should prepare for faster discovery cycles by strengthening foundational controls across multiple layers.Call to ActionIf current trends continue, the race to identify and fix vulnerabilities before threat actors exploit them may become increasingly difficult to sustain. That reality makes it even more important to reinforce the fundamentals of a holistic cybersecurity program—preventing exploitation where possible, limiting impact when incidents occur, enabling resilience, and accelerating recovery.Start with attack surface visibility and asset governance. As environments expand, incomplete inventories create blind spots. Make asset inventories a routine discipline—similar to user access reviews—covering IP space, cloud and physical assets, software, and third-party relationships. Pair that work with attack surface management to document externally exposed services and reduce exposure through access controls, configuration hardening, and removal or restriction of unnecessary services.Next, review the full vulnerability management program—from scanning and prioritisation through patching and remediation. Many organisations scan well but struggle to patch consistently within SLAs and risk tolerance. Strengthen coordination between security operations and IT operations, reduce patch timelines where feasible, and address backlog risk before it compounds.Then evaluate the software development life cycle. AI can accelerate coding, but speed should not erode secure engineering. Invest in developer training, code scanning, testing, and disciplined release and remediation processes to maintain cyber hygiene. Truly integrating security into the development life cycle is essential.Finally, test resilience. Ensure monitoring is comprehensive, incident response is practiced, backups are recoverable, and the organisation can safely isolate and restore systems when needed. Don’t wait for a crisis to validate these fundamentals.In SummaryMythos is an early signal of how AI may reshape the security landscape. AI tools can rapidly explore “what if” scenarios to identify weaknesses, but reliable remediation remains complex and often depends on human decision-making and layered controls. That dynamic makes foundational security disciplines—asset visibility, vulnerability management, secure engineering, and resilience—more important, not less.Organisations should use this moment to reassess defence-in-depth strategies and communicate clearly with executives and the board about how AI-driven discovery could compress response timelines. The organisations that prepare now will be best positioned to reduce risk later.How Protiviti Can HelpProtiviti’s cybersecurity experts help organisations design, assess, and enhance information security strategies and privacy risk management.We take a holistic business and technology view of risk posture, using industry-recognised frameworks to assess current capabilities and identify gaps. Based on your environment, we develop pragmatic roadmaps to guide cybersecurity investments that protect customers and support sustainable growth. Find out more about our solutions: Pro Digital Hightech Artificial Intelligence At Protiviti, we deliver cutting edge artificial intelligence solutions, helping you leverage existing Al technologies or build custom solutions for your enterprise. Pro Screen System Integration Emerging Technologies Protiviti’s cloud services and Emerging Technologies team help organisations embrace new technologies to support business strategies, optimise business processes, and mine data to bring new solutions to market and gain a competitive advantage. Pro Tools Gear Technology Our tech consulting services range from strategy, design and development through implementation, risk management and managed services. Leadership Shane Silva Shane leads Protiviti Australia's Canberra office, overseeing national technology assurance, project confidence, and data governance. With 20 years' experience, he advises government departments on system transformation and manages federal accounts across social ... Learn More Rita Gatt As managing director, technology and cybersecurity at Protiviti, Rita leads a dedicated team focused on solving complex organisational challenges, with a particular emphasis on leveraging data, AI and technology to do so. With over 20 years of experience navigating ... Learn More Featured insights SURVEY No AI visibility, no confidence | AI Pulse - Vol.4 10 min read AI risks are rising fast. Learn about shadow AI, cyber threats, and governance strategies to improve visibility and decision-making in Protiviti’s AI Pulse Survey Vol. 4. BLOGS Navigating Australia's Cybersecurity Obligations: SOCI, PSPF and the Essential Eight – A Strategic Guide for Government and Critical Infrastructure Organisations 18 min read As Australia confronts an evolving and intensifying cyber threat landscape, public and private sector entities are under increasing pressure to fortify their cyber resilience. Central to this effort are three frameworks that define the country's... RESEARCH GUIDE Guide to AI Governance – Frequently Asked Questions 153 min read Learn more about AI governance frameworks, risks, ROI, compliance and enterprise strategy. Explore key insights in this AI Governance FAQs guide for CFOs, CIOs, CISOs and business leaders. NEWSLETTER AI Oversight: A Board Governance Imperative 2 min read AI board governance boosts ROI and confidence—Protiviti’s survey reveals that engaged, responsible oversight empowers boards to drive value and accountable AI outcomes. BLOGS Cybersecurity and Resiliency in the Age of AI: Taming the Digital Genie Before It Gossips 5 min read Artificial intelligence (AI) is rapidly reshaping the enterprise landscape, promising a leap in productivity and efficiency. Yet, as organisations rush to deploy these digital agents, they risk unleashing forces they do not fully understand or... SURVEY Driving innovation: key risks, opportunities and growth strategies for technology leaders 5 min read Download Protiviti’s Top Risks Report 2026 to explore how CIOs and CTOs are addressing challenges in AI adoption, cybersecurity, data management, and digital transformation. BLOGS Protiviti's Perspectives on the Silver Review 5 min read This four-part blog series presents Protiviti’s perspectives on how the Victorian Public Service can turn the Silver Review from a cost‑cutting exercise into a system‑level reform opportunity that strengthens financial sustainability, digital... BLOGS Australian Public Sector Integrity Frameworks: Rebuilding Trust Amid Ongoing Scrutiny 9 min read In the wake of high-profile failures — ranging from unlawful debt recovery programs to politicised grant schemes and procurement missteps —the Australian government has rolled out a series of reforms, including the Australian Public Service (APS)... Previous Article Pagination Next Article