Anthropic just announced their latest AI model Mythos under Project Glasswing that found zero-days in every major OS and browser

Reddit r/LocalLLaMA / 4/8/2026

📰 NewsSignals & Early TrendsIndustry & Market MovesModels & Research

Key Points

  • Anthropic announced Project Glasswing’s AI model “Mythos,” claiming it can identify and exploit software vulnerabilities at scale across major operating systems and browsers.
  • The announcement alleges Mythos discovered long-standing security flaws (e.g., a 27-year-old OpenBSD remote crash issue and a 16-year-old FFmpeg bug) and can chain Linux kernel vulnerabilities for privilege escalation.
  • Anthropic reports strong performance on agentic coding benchmarks (SWE-bench Verified), with Mythos reaching 93.9% versus 80.8% for Opus 4.6.
  • The project includes an unusually large coalition of major enterprises and security organizations (including AWS, Apple, Microsoft, Google, CrowdStrike, and others) that receive access before attackers, aiming to shorten patch timelines.
  • Anthropic frames the work as a sign that highly capable vulnerability-discovery/exploitation models will eventually become broadly available, making rapid defense and patching critical.

Project Glasswing is honestly one of the most alarming and exciting things at the same time.

About a week ago, when Claude Code source code was leaked, we found out about a mysterious model called Mythos and now we have official details from Anthropic:

- it's too capable at finding and exploiting software vulnerabilities (found 27-year-old vulnerability in OpenBSD that let an attacker remotely crash any machine just by connecting to it, 16-year-old bug in FFmpeg hiding in a line of code that automated tools had hit 5 million times without catching it)
- it autonomously chained Linux kernel vulnerabilities together to escalate from regular user access to full machine control
- on SWE-bench Verified (agentic coding), it hit 93.9% vs 80.8% for Opus 4.6
- an elite coalition they pulled is damn massive: AWS, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, Microsoft, NVIDIA, Palo Alto Networks, and the Linux Foundation all have access to it, before attackers do.
- they're basically admitting that models like this will eventually be available to everyone. The window to patch the world's critical software is now (that's the primary purpose of that coalition)

What are your thoughts on this? interested to hear from y'all below :)

Source: https://www.anthropic.com/glasswing

submitted by /u/OriginalInstance9803
[link] [comments]