Anthropic builds an AI able to hack any software — and keeps it secret
On 7 April 2026, Anthropic unveiled Claude Mythos Preview, its most powerful AI model to date. Able to discover and exploit previously unknown vulnerabilities across all major operating systems, it found a 27-year-old flaw in OpenBSD and succeeded in 181 attacks on Firefox where its predecessor succeeded in only 2. The problem: this model is deemed too dangerous to be made public. Only 40 tech giants have access to it via Project Glasswing. An industry first that raises fundamental questions about unequal access to the most advanced technologies.
The hidden opportunity
While direct access to Mythos is impossible for SMBs, this announcement reveals important trends:
Security awareness at the highest level
The fact that Anthropic locks down its own model shows just how critical cybersecurity has become. Companies that invest now in their AI security posture will be better prepared when Mythos's capabilities spread indirectly through the patches and updates of the major vendors.
The vulnerability of legacy software ecosystems
Mythos found 16- and 27-year-old flaws in software nonetheless reputed to be secure. This is a reminder that technical debt and legacy systems are sieves. SMBs that keep their software up to date and eliminate obsolete dependencies drastically reduce their attack surface.
A precedent for AI regulation
This Anthropic decision could inspire the European AI Act and regulators worldwide. SMBs that anticipate compliance requirements and document their AI uses today will have a competitive advantage tomorrow over companies caught off guard.
The major risk
An unprecedented digital divide
For the first time, an AI model of general interest — cybersecurity concerns everyone — is reserved for a club of large companies. This creates a fundamental imbalance: tech giants can discover and fix flaws before everyone else, while SMBs remain vulnerable.
The leak is inevitable
Historically, restrictive technologies eventually leak. When Mythos's capabilities spread — through theft, reverse engineering or mere rumor — malicious actors could have them before defenders do. SMBs must prepare for a world where attacks become more sophisticated without having access to the same defensive tools.
Our recommendation
In the face of this evolution, here are the priority actions for SMBs:
Strengthen your security monitoring immediately
Subscribe to the security alerts of your main software vendors. Put in place a patch management process with short deadlines: 48h for critical fixes, 1 week for important ones. Never leave a known flaw unpatched.
Audit your technical debt
Identify legacy systems, unmaintained software and obsolete dependencies in your infrastructure. Every component that is not updated is a potential target. Budget for a gradual modernization — the investment is lower than the cost of a breach.
Document and bring your AI uses into compliance
The European AI Act and the regulations that follow will require more and more transparency. Document which AI tools you use, for what purposes, and what data they process. This documentation will be your regulatory shield and a commercial asset.
In summary
Frequently asked questions
What exactly is Claude Mythos Preview?
It is the most advanced AI model ever developed by Anthropic. It excels at detecting software vulnerabilities, able to find and exploit zero-day flaws across all major operating systems and browsers. Unlike previous models, it is not available to the public.
Why does Anthropic not make this model public?
Anthropic considers the model too dangerous for broad release. Its autonomous hacking capabilities could be used by malicious actors to compromise critical systems. The company chose caution by limiting access to a consortium of large companies via Project Glasswing.
Which companies have access to Mythos?
About 40 major technology companies: AWS, Apple, Cisco, CrowdStrike, Google, JPMorgan Chase, Linux Foundation, Microsoft, NVIDIA, Palo Alto Networks, and other critical infrastructure players. Anthropic offers 100 million dollars in usage credits to the consortium.
What is the impact for an SMB without access to Mythos?
SMBs remain dependent on the patches released by the major vendors. The concern is that Mythos could discover massive vulnerabilities in widely used software, creating a window of risk between discovery and the public patch. SMBs must strengthen their security monitoring and their responsiveness.
For technical profiles
Technical performance of Claude Mythos Preview:
| Metric | Claude Opus 4.6 | Claude Mythos Preview | Improvement factor |
|---|---|---|---|
| Successful Firefox exploits | 2 out of several hundred | 181 out of several hundred | 90x |
| Control flow hijack OSS-Fuzz | 0 | 10 targets patched | Infinite |
| Oldest flaw found | N/A | 27 years — OpenBSD | N/A |
| Accessibility | Public | Consortium only | - |
Confirmed Project Glasswing members: AWS, Apple, Cisco, CrowdStrike, Google, JPMorgan Chase, Linux Foundation, Microsoft, NVIDIA, Palo Alto Networks. Anthropic commits to 100 million dollars in usage credits for the consortium.
Implications for security research: This restriction approach raises the question of disclosure responsibility — when a tool can discover vulnerabilities at industrial scale, who should have access to it? The cybersecurity community is divided between those who welcome the caution and those who fear a concentration of discovery power.