Anthropic says it plans broader release of Mythos-class AI bug-finding models after expanding restricted access to governments

Anthropic says it intends to eventually make Mythos-class vulnerability-finding artificial intelligence available more broadly, but for now is expanding its restricted Project Glasswing program to additional partners including U.S. and allied governments. The company says Mythos has scanned more than 1,000 open-source projects, estimated 6,202 high-or-critical-severity vulnerabilities and 23,019 total flaws, and validated many findings through coordinated disclosure; no CVE list or release date for public access was provided.
Why it matters: This matters because a powerful AI system for finding software flaws could help defenders patch faster, but could also accelerate criminal discovery of exploitable bugs if released without effective guardrails. Security teams should expect faster vulnerability discovery pressure in widely used open-source components and be prepared for heavier disclosure and patching volume.

Sources

CISA Reportedly Using Anthropic’s Mythos to Scan Government Software for Flaws
Mike Lennon 2026.07.07 81% relevant
This advances that same underlying development by reporting a specific real-world government use case: CISA is reportedly using Mythos to scan federal agency code repositories, with the Attack Surface Evaluation team leading audits and reportedly finding many flaws.
Trump Administration Lifts Restrictions on Anthropic’s Claude Models After Cybersecurity Alarm
Associated Press 2026.07.02 64% relevant
This updates the same underlying Anthropic/Mythos access-control story with new facts: the Trump administration has lifted the broad restrictions on Claude Fable 5, restored Mythos 5 only for government-approved U.S. organizations, and Anthropic says the trigger was an Amazon-reported bypass of Fable 5 safeguards that enabled vulnerability discovery and possible exploitation.
US lifts export controls on Anthropic’s frontier cybersecurity AI models
2026.07.01 78% relevant
This updates the same underlying Anthropic frontier-cybersecurity-model access and governance story by reporting that U.S. export controls on Fable 5 and Mythos 5 were lifted after negotiations, restoring global access to Fable 5, keeping Mythos 5 limited to vetted U.S. organizations via Project Glasswing, and adding new government review, jailbreak disclosure, and bug-bounty commitments.
In Other News: Chinese Mythos-Like AI, Tata Electronics Breach, Snyk Layoffs
SecurityWeek News 2026.06.26 41% relevant
The article references 'Chinese Mythos-like AI' and broader AI threat concerns, but in this excerpt it does not clearly establish the same concrete underlying event as the tracked Anthropic/Mythos release story beyond thematic overlap.
Chinese cybersecurity company claims it’s built a better-than-Mythos bug finder
2026.06.26 83% relevant
This article adds a direct geopolitical and industry response to the same Mythos bug-finding model story: Qihoo 360 says China's access restrictions on Mythos create a strategic imbalance, claims to have built a competing vulnerability-finding system, and says it is organizing local firms against Anthropic's Project Glasswing ecosystem.
Anthropic’s Mythos Model Found Vulnerabilities in Classified US Government Systems, Official Says
Associated Press 2026.06.24 86% relevant
This article adds a concrete example of why Mythos access has been restricted and expanded to governments: a U.S. official says the model found vulnerabilities in classified U.S. systems during Project Glasswing testing, and Sen. Warner publicly characterized the results as breaking into classified systems within hours.
French President Urges US to Share Cutting-Edge AI and Democracies to Cooperate on Regulation
Associated Press 2026.06.20 63% relevant
This article adds that France's president publicly criticized the U.S. directive restricting foreign access to Anthropic's newest models, said Fable 5 and Mythos 5 were taken offline to comply, and called for government-to-government cooperation on AI security and cybersecurity among democracies.
AI Regulation Should Be Rational, Not Retaliatory
Corynne McSherry 2026.06.18 75% relevant
This article adds that EFF is challenging the Trump administration's sanctions and export controls targeting Anthropic, arguing the measures were retaliatory and led Anthropic to shut down Mythos and Fable rather than comply. It specifically expands the policy and access implications around the same Mythos-class cybersecurity models discussed in the tracked story.
Cybersecurity Executives Urge the Trump Administration to Ease Restrictions on Anthropic AI Models
Associated Press 2026.06.16 84% relevant
This article updates the same underlying issue around Anthropic's Mythos-class cybersecurity-capable models by adding that the Trump administration issued export-control-style restrictions barring foreign nationals from access, Anthropic took Fable 5 and Mythos 5 offline to comply, and more than 100 cybersecurity leaders are urging the government to reverse the directive.
Feds freaked over Fable 5 after simple 'fix this code' prompt, not jailbreak, says researcher
2026.06.15 53% relevant
This article adds new detail on the same underlying Fable 5/Mythos model access controversy: it says the reported 'jailbreak' behind the U.S. restriction was allegedly just asking the model to 'fix this code,' and it includes criticism from Katie Moussouris and an open letter arguing the controls harm defenders.
Anthropic says US government forced it to disable cybersecurity AI models
2026.06.15 93% relevant
This updates the same underlying Anthropic Mythos/Fable cybersecurity-model access story by reporting that Anthropic abruptly disabled Fable 5 and Mythos 5 after a U.S. government export-control directive barred access by foreign nationals, including Anthropic staff, and by adding Anthropic's dispute over the claimed jailbreak risk.
US Gov asks Anthropic to ban 'foreign national' access to Fable, Mythos
Ax Sharma 2026.06.13 82% relevant
This updates the same underlying Anthropic Mythos/Fable access story with a new government-triggered restriction: Anthropic says a U.S. export-control directive forced it to suspend Fable 5 and Mythos 5 globally, including for foreign nationals and some internal staff, after concerns about a reported jailbreak.
Anthropic rolls out Claude Fable 5, but it's available for a limited time
Mayank Parmar 2026.06.10 89% relevant
This article advances the same underlying event by reporting Anthropic's public rollout of Fable 5, a guarded version of the Mythos-class model, and adds concrete details on access limits, sensitive-query downgrading to Opus 4.8, temporary availability to Pro/Max/Enterprise users, and the distinction between restricted Mythos 5 and safeguarded Fable 5.
Anthropic Launches Claude Fable 5: Mythos-Class AI With Cybersecurity Guardrails
Eduard Kovacs 2026.06.09 84% relevant
This article is a direct follow-up on that same underlying event: Anthropic has now launched Claude Fable 5 for general availability with cyber/bio fallbacks and says Project Glasswing partners are being upgraded from Mythos Preview to Mythos 5, adding concrete rollout details, guardrail design, pricing, and partner-access changes.
Claude Mythos Turns N-Days Into N-Hours With Rapid Exploit Creation
Ionut Arghire 2026.06.09 93% relevant
This is a direct follow-up on the same Mythos program, adding concrete exploit-generation results: Anthropic says Mythos Preview produced working Firefox and Windows N-day exploits within hours, showing the model can weaponize disclosed flaws rather than only find bugs.
UK banks offered access to OpenAI’s GPT-5.5 amid exclusion from Anthropic’s Glasswing expansion
2026.06.03 86% relevant
This article adds specific details on Anthropic's Project Glasswing expansion from about 50 to 200 partners across 15 countries, identifies new access dynamics affecting UK banks, and notes that ENISA will receive Mythos Preview access while CISA has not yet been selected.
Cisco sings Mythos' praises - but doesn't say how many bugs the model uncovered
2026.06.02 88% relevant
This article directly updates the same Mythos / Project Glasswing event by adding that Anthropic expanded the preview program by about 150 organizations to roughly 200 total partners, and that Cisco used Mythos Preview and OpenAI's GPT 5.5-Cyber to scan 1.8 billion lines of Cisco code in eight weeks with a reported false-positive rate under 3 percent, though Cisco did not disclose the number of flaws found or fixed.
Anthropic Expanding Mythos Access to 150 New Organizations
Eduard Kovacs 2026.06.02 96% relevant
This is a direct update on the same underlying event: Anthropic broadening Mythos availability. The new reporting adds that Project Glasswing is expanding from about 50 to roughly 200 total partner organizations, that the new cohort includes critical-infrastructure entities and reportedly Okta, Samsung, ENISA, and NATO, and that Anthropic says Mythos has found more than 23,000 potential vulnerabilities with only 75 high/critical issues patched so far.
Anthropic confirms Claude Mythos-class models will roll out to the public
Mayank Parmar 2026.05.29 95% relevant
This article directly updates the same underlying event by reporting Anthropic's confirmation that Mythos-class models are expected to roll out to all customers in the coming weeks, adding timing and reaffirming that prior restrictions were due to security risk concerns.
Anthropic’s restricted Claude Mythos model may be coming to Claude Code
Mayank Parmar 2026.05.25 93% relevant
This article adds specific evidence that Anthropic may be moving from restricted access toward product integration, citing Mythos references and a briefly exposed toggle in public Claude Code and Claude Security, plus new details on the Glasswing program and Anthropic's claim that Mythos found 10,000 high- or critical-severity vulnerabilities in its first month.
Anthropic: Mythos Detected 23,000 Potential Vulnerabilities Across 1,000 OSS Projects
Eduard Kovacs 2026.05.25 91% relevant
This is a direct update on the same underlying Mythos/Project Glasswing rollout, adding Anthropic's first large-scale outcome data: 23,000 potential flaws across 1,000+ open source projects, 1,726 externally confirmed findings, more than 1,000 high- or critical-severity issues, 75 severe issues already patched, and 65 advisories published.
Anthropic to release Mythos-class models to the public
2026.05.25 100% relevant
This article establishes a new trackable development around Anthropic’s Mythos program by adding a concrete policy shift toward wider access, naming government expansion, and quantifying validated open-source vulnerability discovery at scale.
← Back to all stories