Anthropic Is Gating the Cyber-Capable Model It Disclosed Last Week

Anthropic launched Project Glasswing, restricting access to Mythos Preview. The "thousands of zero-days" figure is Anthropic's own and covers identification, with working exploits a separate bar.

Anthropic Is Gating the Cyber-Capable Model It Disclosed Last Week

Anthropic launched Project Glasswing on May 8, providing a small group of vetted organizations with restricted access to Claude Mythos Preview, the same capability evaluation that drove the Trump administration to reverse course on AI oversight last week. In Anthropic's internal testing, Mythos identified thousands of zero-day vulnerabilities across major operating systems and web browsers. The company stated there are no plans for public release, citing dual-use cybersecurity risk.

The "thousands of zero-days" figure is Anthropic's own characterization. Nobody has independently verified it. The claim covers identification of potentially exploitable conditions. Working exploits are a higher bar, and most coverage blurs the two. The Glasswing vetting framework is voluntary and runs under Anthropic's internal policy, with no federal certification regime behind it, which is the same gap that triggered last week's draft administration response. Security teams need two answers: which organizations get access (the "select" pool is undisclosed), and what visibility affected vendors get into the vulnerabilities Mythos identifies. The second answer determines whether Glasswing becomes a coordinated-disclosure pipeline or a separate stockpile of unfixed vulnerabilities.

If you run a security operations team, treat any model-discovered vulnerability disclosure cycle as a parallel pipeline to your existing vendor-disclosure tracking. The cadence and confidentiality terms are different, and your incident-response runbook should account for both.