Anthropic Mythos AI discovers thousands of zero-day vulnerabilities while the Federal Reserve and Treasury gather bank CEOs to discuss cyber risks.

Anthropic Mythos AI discovers thousands of zero-day vulnerabilities while the Federal Reserve and Treasury gather bank CEOs to discuss cyber risks.

      TL;DR: Anthropic's Claude Mythos Preview has identified thousands of zero-day vulnerabilities in major operating systems and browsers, prompting the Federal Reserve chair and Treasury secretary to meet with bank executives. The company warns there is a six-to-twelve month window for addressing these weaknesses before adversaries can replicate the technology.

      Anthropic has developed an AI model that uncovered thousands of zero-day vulnerabilities in all major operating systems and web browsers. In response, the chairs of the Federal Reserve and Treasury held discussions with bank CEOs regarding the implications. The company cautions that there is a six-to-twelve month timeframe to rectify these issues before adversaries create models capable of similar discoveries. The cybersecurity sector has suggested that this threat has been present for a while, making both perspectives valid.

      The model in question, Claude Mythos Preview, has not been made public yet. During controlled tests, it outperformed nearly all but the most proficient humans in detecting and exploiting software vulnerabilities, uncovering flaws that had been unidentified for years, such as a 27-year-old bug in OpenBSD and a 17-year-old remote code execution vulnerability in FreeBSD. Anthropic CEO Dario Amodei referred to this period as a "moment of danger," warning of a significant increase in vulnerabilities, breaches, and the financial damages from ransomware affecting not only banks but also schools and hospitals.

      The discovery: Mozilla launched Firefox 150, addressing 271 security vulnerabilities flagged by Mythos in a single assessment. This number is notable not due to Firefox's inherent insecurity but because a human team had not previously uncovered these issues, which accumulated over years of development and serve as potential entry points for attackers equipped with the right tools. Mythos identified all 271 vulnerabilities in just one scan.

      The capabilities of the model raise a vital question that the cybersecurity industry must now tackle: what occurs when the cost of discovering vulnerabilities approaches zero? The fundamental economics of cybersecurity rely on the imbalance between attackers, who need to find just one flaw, and defenders, who must secure all vulnerabilities. Mythos diminishes costs on both fronts; defenders can scan their entire codebase for previously unknown flaws, while attackers can replicate this process once they construct or acquire similar models.

      The response: Anthropic opted for a controlled rollout, termed Project Glasswing, giving around 40 tech companies and institutions initial access to Mythos to enhance their systems. Central banks and governments are notably absent from this list, deliberately creating an asymmetry to provide defenders a head start before this capability becomes broadly accessible.

      Financial regulators reacted promptly. Federal Reserve Chairman Jerome Powell and Treasury Secretary Scott Bessent convened a meeting with CEOs of major US banks to address the cyber threats presented by Mythos. The IMF warned about AI-driven cyber risks to the global banking sector. The concern lies not in the potential use of Mythos for direct attacks on banks, but in the ability of adversaries to replicate the superhuman speed of automated vulnerability discovery that Mythos showcases, outside of Anthropic’s responsible disclosure framework.

      Anthropic also delivered financial services agents on the heels of announcing a $1.5 billion partnership on Wall Street, reflecting its dual role as both a warning entity about AI-related cyber threats and a provider of AI products to banks. The partnership with Blackstone and Hellman & Friedman involves around $300 million from Anthropic, aimed at integrating AI into private equity operations.

      The race: Amodei's six-to-twelve month estimate predicts how long it might take Chinese AI companies to create models with similar vulnerability-discovery capabilities. This timeframe is not about whether adversaries will achieve analogous capabilities, but rather when. The controlled distribution of Mythos allows early access companies sufficient time to fix their most critical vulnerabilities ahead of the closing window.

      OpenAI has released GPT-5.4-Cyber for approved security teams, expanding its Trusted Access initiative in direct response to Mythos's findings. The competitive landscape between Anthropic and OpenAI has extended from commercial AI ventures to the realm of cybersecurity, with both companies positioning themselves as guardians of the software infrastructure that they could potentially compromise.

      Researchers have already shown that AI agents developed by Anthropic, Google, and Microsoft can be exploited through prompt injection to extract API keys and tokens, resulting in all three companies paying bounties without making public disclosures. The irony is clear: the AI agents designed to bolster security may themselves be susceptible to attacks that could undermine the very systems they are intended to protect.

      The tension: The cybersecurity community's reaction to the Mythos announcement has ranged from alarm to skepticism. Security researchers highlight that AI-assisted vulnerability discovery has been evolving for years, suggesting that the capabilities exhibited by Mythos, while impressive, represent an acceleration of established trends rather than a radical shift. The risk of AI-driven cyberattacks was flagged by the UK’s National Cyber Security Centre over a year ago. What changes with Mythos is not the existence of the threat, but the clarity of the evidence.

      Anthropic's position is

Other articles

Amazon introduces vertical videos suitable for doomscrolling in the Prime Video app. Amazon introduces vertical videos suitable for doomscrolling in the Prime Video app. Discovering content on Prime Video might soon resemble scrolling through Shorts rather than navigating a traditional streaming menu. Akamai's shares jump 27% following a $1.8 billion cloud agreement with Anthropic as the CDN firm shifts towards AI infrastructure. Akamai's shares jump 27% following a $1.8 billion cloud agreement with Anthropic as the CDN firm shifts towards AI infrastructure. Akamai announced a seven-year cloud agreement worth $1.8 billion with Anthropic, marking its largest contract to date. The stock jumped 27% as the CDN pioneer's shift towards AI infrastructure receives validation. Intruder introduces AI-powered pentesting agents as a startup supported by GCHQ automates $50,000 worth of manual security assessments. Intruder, supported by GCHQ, has introduced AI-powered penetration testing agents that can mimic manual pen testing in just a few minutes. CEO Chris Wallis showcases this technology at KnowBe4's KB4-CON 2026. Apple might return to using Intel chips, but not in the way you might anticipate (or fear). Apple might return to using Intel chips, but not in the way you might anticipate (or fear). Apple and Intel are said to be considering a manufacturing partnership that could transform the production process of future Apple chips. However, contrary to the initial impression, this does not indicate that Apple is moving away from Apple Silicon or reverting to Macs with Intel processors. A recent report from the Wall Street Journal suggests that Apple and Intel have established a preliminary agreement for Intel to […] What is the most effective method for monitoring income and expenses in an expanding business? What is the most effective method for monitoring income and expenses in an expanding business? Automated financial tracking assists expanding businesses in managing their income and expenses with greater precision. By substituting spreadsheets with integrated systems, companies achieve real-time insights, minimize mistakes, and enhance reporting efficiency as transaction amounts rise and financial processes grow more intricate. Apple requires you to confirm your identity before you can access the Education discount on products. Apple requires you to confirm your identity before you can access the Education discount on products. Students can verify their status through the school portal or by uploading their ID; homeschool teachers are required to provide a government ID along with a homeschooling document. Most verifications are done instantly, while manual reviews are finished within 24 hours.

Anthropic Mythos AI discovers thousands of zero-day vulnerabilities while the Federal Reserve and Treasury gather bank CEOs to discuss cyber risks.

The preview of Anthropic's Claude Mythos revealed thousands of zero-day vulnerabilities in major software. The chair of the Federal Reserve and the Treasury secretary contacted bank executives to talk about the potential threat.