Anthropic Mythos: The AI Model That Found Thousands of Vulnerabilities and Is Changing Cybersecurity

Dan Patiño

AI Strategy & Innovation at Coderhouse

Artificial Intelligence

Anthropic Mythos: The AI Model That Found Thousands of Vulnerabilities and Is Changing Cybersecurity

Published on

On April 7, Anthropic announced Mythos, its most powerful AI model to date, but with an unprecedented twist: it did not release it to the public. Mythos was developed within the framework of Project Glasswing, an initiative with 12 global technology partners that include Apple, Amazon, Microsoft, and Cisco, and its most disruptive capability is also the most unsettling: it identified thousands of critical vulnerabilities in decades-old operating systems and browsers, without constant human supervision. For tech and cybersecurity teams in LATAM, this opens an urgent debate: AI is already an industrial-grade cybersecurity tool. The question is no longer whether to adopt it, but how to do so responsibly.

What Project Glasswing is and why Anthropic chose not to release Mythos publicly

Project Glasswing is Anthropic's initiative to develop high-risk AI models in a controlled environment, with strategic partners who can absorb and mitigate the risks before any massive deployment. With Mythos, Anthropic made the unprecedented decision not to publish the model on its API or on Claude.ai, even though it is already operational and being used by the project's partners in controlled environments.

The reasons stated by Anthropic according to reports from TechCrunch are three:

  • The model has offensive capabilities so advanced that open access to it would represent a national and corporate security risk on a global scale

  • It requires a responsible-use framework still in the process of being jointly defined with the Project Glasswing partners

  • It is the first model to trigger the "critical capability level" in Anthropic's internal evaluation system (ASL-4), the highest level on its risk scale

This marks a turning point in the industry: for the first time, a frontier AI company publicly acknowledges that it has a model too powerful to release. It is a precedent that will define how the next frontier models are governed.

What Mythos found: critical vulnerabilities and their real scope

According to reports from 9to5Mac and CNN Business on April 7, Mythos was able to do the following in a controlled environment:

  • Identify more than 4,000 unreported vulnerabilities in Linux and Windows kernels prior to 2020

  • Detect attack vectors in Chrome, Firefox, and Safari not previously identified by conventional security teams

  • Generate functional exploits to demonstrate the exploitability of the vulnerabilities found

  • Complete this analysis in a fraction of the time an equivalent human penetration testing team would require

The magnitude of the finding forces organizations to rethink their security auditing processes. If an AI model can find thousands of vulnerabilities in weeks, annual pentesting cycles are no longer sufficient as the only layer of defense.

What it means for cybersecurity in LATAM companies

The Mythos announcement has concrete implications for tech teams in the region, both in terms of opportunities and risks that must be managed.

Opportunities already available

  • Similar (though less powerful) models are already available in tools like GitHub Copilot for Security and Snyk Code, integrable into CI/CD pipelines to detect vulnerabilities in real time during development

  • AI can automate repetitive security auditing tasks, freeing analysts for higher-complexity vulnerabilities that require human judgment

  • Companies that adopt AI in security will have a competitive advantage in contracts with multinationals that demand higher cybersecurity standards as a supplier requirement

Risks that must be managed

  • The same models that detect vulnerabilities can be used to exploit them. Not all organizations that have access to these tools use them ethically.

  • The gap between organizations that adopt AI in security and those that don't will grow exponentially in the coming years, creating a structural inequality in the LATAM tech ecosystem

  • IT teams in the region need urgent upskilling to audit, understand, and work with AI-based security systems effectively

The debate about double-edged AI and the Anthropic precedent

Anthropic's decision not to release Mythos raises a broader debate about the governance of high-risk AI models. It is the first documented case of a frontier company restricting a model for security reasons, and it probably won't be the last.

The question that remains open for the industry: who decides when a model is "too dangerous" to release? For now, that decision is made by the developing companies themselves without a binding international regulatory framework. The debate is already on the agenda of the United States Congress and the European Parliament, and LATAM needs a voice in that conversation.

For tech professionals, the message is concrete: AI has already entered the cybersecurity battlefield. Mastery of AI tools applied to information security becomes a critical differentiating skill in the region's tech job market.

If you're interested in exploring this topic further, you can also read automation with Make and ChatGPT to create intelligent no-code workflows.

Recommended Coderhouse courses

To understand the technological context of AI and prepare for the changes it generates in the tech industry and in cybersecurity:

  • AI Engineering Course: tools to work with AI models at a technical level, including API integration, model evaluation, and use cases in security and automation.

  • Introduction to Artificial Intelligence Course: an ideal entry point to understand what people are talking about when they talk about models like Mythos, their real capabilities, and their limitations.

  • AI Automation Course: for teams that want to implement automated workflows with AI, including use cases in auditing, monitoring, and incident management.

Frequently asked questions

When will Mythos be available publicly?

Anthropic did not give concrete dates. The Project Glasswing roadmap foresees a gradual evaluation process with the partners before any public release decision, which could take months or never happen if the risks cannot be adequately mitigated with existing security frameworks.

Are there AI models for cybersecurity that can already be used today?

Yes. Tools like GitHub Copilot for Security, Snyk Code, Veracode AI, and CrowdStrike Charlotte AI already use language models to detect vulnerabilities, analyze code, and respond to incidents. They don't have Mythos's power, but they are accessible, available on the market, and integrate with existing development pipelines.

Could Mythos be used maliciously if someone obtained access?

That is exactly the reason Anthropic decided not to release it. The model has the ability to generate functional exploits, which in the wrong hands would represent a critical risk for corporate and government infrastructure. Anthropic internally describes it as the first model to trigger its ASL-4 (Advanced Safety Level 4), the highest on its risk evaluation scale.

What should LATAM companies do in this scenario?

Three concrete and prioritizable actions: first, invest in updating systems (especially outdated kernels and browsers, which are the most exploited vectors). Second, adopt AI tools for continuous security auditing instead of relying only on annual pentesting cycles. Third, train their IT teams in AI applied to cybersecurity before the gap with the most advanced companies becomes irreversible.

Does the development of Mythos change the competitive landscape between Anthropic, OpenAI, and Google?

Yes, although in a complex way. The fact that Anthropic has a model it decided not to release positions the company as the most conservative in terms of security within the trio of frontier companies, which can be an advantage or a disadvantage depending on the market segment. For corporate clients with strict compliance requirements, Anthropic's stance can be a positive differentiator. For the mass consumer market, the pace of OpenAI and Google remains more aggressive.

About the author

Dan Patiño

I'm Dan Patiño, head of AI Strategy & Innovation at Coderhouse. My day-to-day work involves merging the tactical management of e-commerce (CRO, Email Marketing and SEO) with the development of disruptive solutions. I specialize in building internal AI-powered apps to automate tasks and boost innovation within the team. I firmly believe that technology is strategy's best ally. To dive deeper into my professional journey, I'll be waiting for you on my LinkedIn profile.

English

© 2026 Coderhouse. All rights reserved.

English

© 2026 Coderhouse. All rights reserved.

English

© 2026 Coderhouse. All rights reserved.

English

© 2026 Coderhouse. All rights reserved.