More on the topic...
Generating detailed summary...
Failed to generate summary. Please try again.
On April 7, Anthropic unveiled Claude Mythos Preview, a general-purpose language model with a clear edge in computer security tasks. Under Project Glasswing, they’re using Mythos Preview to hunt zero-day flaws in critical software and to push the industry toward new defensive practices. In internal tests against major operating systems and web browsers, the model autonomously found and exploited vulnerabilities decades old—one 27-year-old bug in OpenBSD among them—and built multi-stage exploits, from JIT heap sprays chaining four browser flaws to remote code execution on FreeBSD’s NFS server via a 20-gadget ROP chain split over several packets.
Anthropic compared Mythos Preview’s performance to earlier models like Opus 4.6. While Opus managed successful autonomous exploits only twice out of hundreds of Firefox JavaScript engine trials, Mythos Preview produced 181 working shell exploits and achieved partial register control in 29 more. On OSS-Fuzz benchmarks covering about 7,000 entry points, previous models hit low-severity crashes (tiers 1–2) a few hundred times and saw a single tier 3 crash. Mythos Preview repeated 595 tier 1–2 crashes, added several tier 3–4 crashes, and reached full control-flow hijack (tier 5) on ten patched targets.
These offensive skills emerged without explicit exploit training; they’re a byproduct of stronger code understanding, reasoning, and autonomy. Anthropic argues that just as fuzzers evolved from attacker tools into core defensive assets, advanced language models can bolster software security—provided defenders gain early access. To that end, Project Glasswing is distributing Mythos Preview to select industry partners and open-source developers, hoping to lock down the highest-risk systems before similar models become widely available.
Questions about this article
No questions yet.