惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Recent Announcements
Recent Announcements
雷峰网
雷峰网
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Hugging Face - Blog
Hugging Face - Blog
博客园 - 司徒正美
人人都是产品经理
人人都是产品经理
博客园 - 【当耐特】
量子位
有赞技术团队
有赞技术团队
博客园 - 三生石上(FineUI控件)
博客园 - Franky
M
MIT News - Artificial intelligence
U
Unit 42
Last Week in AI
Last Week in AI
酷 壳 – CoolShell
酷 壳 – CoolShell
The Cloudflare Blog
J
Java Code Geeks
V
Visual Studio Blog
Engineering at Meta
Engineering at Meta
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
MyScale Blog
MyScale Blog
T
Tailwind CSS Blog
T
The Blog of Author Tim Ferriss
V
V2EX

Security

Report: Business email compromise attacks surged dangerously in April Scope Systems confirms cyber incident, says no data loss occurred Instructure breach: ShinyHunters says ‘matter has been resolved’ Rapid7 launches Cyber GRC program to connect compliance with live risk data Australian federal budget 2026: The industry perspective Op-Ed: Microsoft May Patch Tuesday reveals 137 vulnerabilities Federal Budget 2026: The state of cyber security spending for the coming year OpenAI offers EU early access to its cyber security model Exclusive: Aussie firm Earth Systems listed by INC Ransom hacking group Op-Ed: Why Middle East tensions demand immediate action on OT security Aussie schools breach: Instructure boss “reaches agreement” with ShinyHunters to not release data Institute of Public Accountants members hit by data breach Union demands answers on Qantas AI plans 1 in 3 small businesses don't think they're a cyber target, new research finds Exclusive: Aussie toy distributor listed by M3rx ransomware Exclusive: Australian Computer Society investigating possible breach after ShinyHunters hack claims The industry speaks – part 2: World Password Day 2026 Aussie schools breach: The Instructure hack “transcends an isolated IT incident” Exclusive: Aussie car part importer Strategic Imports allegedly breached by threat actors New South Wales, other states, investigating Instructure/Canvas data breach Australian Cyber Security Centre warns of ClickFix campaign leveraging Australian infrastructure Queensland Department of Education confirms students & staff impacted by ShinyHunters data breach ACMA takes action against SpinTel & Yomojo over mobile number fraud violations The Industry Speaks, Part 1: World Password Day 2026 Qualys and Converge tie cyber insurance pricing to real-time security posture Fakeout: Iranian APT caught hiding behind Chaos ransomware activity Exclusive: Australian energy management firm allegedly breached by SafePay Real estate giant Cushman & Wakefield confirms cyber incident, Qilin and ShinyHunters claim attack CrowdStrike expands Project QuiltWorks as more partners join AI security coalition Hacked: ALS discloses cyber incident, unauthorised access to IT systems
Why Anthropic’s Project Glasswing matters, and what CISOs...
David Hollingworth · 2026-04-13 · via Security

Anthropic’s latest AI model can find vulnerabilities at speed and scale. Here’s why industry experts consider Claude Mythos to be a “watershed moment” for the industry and a wake-up call for developers.

AI firm Anthropic announced its latest AI model last week, but declined to release it to a wide audience.

Instead, Claude Mythos will be released as an exclusive preview to a select group of technology and cyber security companies as a tool to identify software vulnerabilities at scale.

You’re out of free articles for this month

To continue reading the rest of this article, please log in.

The reason? It’s too good at what it does. According to the company, the model has already found vulnerabilities in operating systems and web browsers alike, some of which have been around for decades, but had not been identified before.

In fact, 99 per cent of what Claude Mythos found had not been patched at all, making it a potentially dangerous tool in the wrong hands.

A zero-day tsunami

“The model is extremely effective at identifying software vulnerabilities that could lead to zero-day exploits,” Danny Jenkins, CEO and co-founder of cyber security firm ThreatLocker, said on LinkedIn.

“That same capability that helps defenders conduct penetration testing will also be used by attackers to find and exploit weaknesses at scale. Critical infrastructure systems are especially vulnerable, as many still rely on legacy systems the model can easily exploit.”

Jenkins, however, believes the focus on using AI to fight AI is incorrect.

“While defenders should certainly use the same penetration testing tools that attackers use, the conversation of AI stopping AI risks is distracting us from something more immediate,” Jenkins said.

“There are proven steps that organisations can deploy today that do not depend on AI, and we must do so with urgency because Anthropic won’t delay release indefinitely.”

Jenkins said that companies should instead focus on application containment to ensure that platforms can’t bypass traditional controls.

“My advice is straightforward: focus on controls that limit software behaviour, not just controls that detect what’s already happened,” Jenkins said.

“Focus on what you can do today to make yourself more secure, rather than waiting for the next innovation.”

Doug Britton, EVP and chief strategy officer of RunSafe Security, called Anthropic’s announcement a “watershed moment for AI’s runaway zero-day discovery and exploitation”.

“AI is now uncovering memory safety bugs at massive scale, including vulnerabilities that have been hiding in production code for over 25 years – the problem isn’t just that these bugs exist, it’s that they’re being found faster than organisations can fix them,” Britton told Cyber Daily.

“That means the traditional model (find, patch, repeat) can’t keep up anymore. Security has to shift from trying to eliminate every bug to protecting systems even when those bugs are still there.”

Britton added that the Claude Mythos Preview and Project Glasswing news shattered the illusion that just because software has been tested, it is therefore safe.

“OpenBSD has been audited and fuzzed an uncountable number of times over 26 years by world-class researchers,” Britton said.

“Mythos still found a remotely exploitable bug. If that’s possible there, it’s possible anywhere.”

Britton’s also concerned that this leap in technology could make traditional incident response mechanically impossible due to a “tsunami of zero-days across critical software”.

What a CISO needs to know

A more salient question for CISOs than what Anthropic’s new model may mean now, according to Douglas McKee, director of vulnerability intelligence at Rapid7, however, is a more practical and immediate one.

“CISOs do not need to decide this week whether Anthropic’s model changes the entire market,” McKee said in a blog post.

“They do need to ask a more practical question: if my environment starts surfacing materially more vulnerabilities tomorrow, what happens next?”

The answer, McKee said, is probably an uncomfortable one.

“That is where this news becomes relevant. AI-driven discovery does not reduce the need for an exposure-led security model. It increases it. The organisations that benefit most will not be the ones with the biggest pile of findings. They will be the ones that can connect those findings to business-critical assets, internet exposure, identity paths, existing detections, remediation workflows, and validation,” McKee said.

“A good board-level translation is that faster discovery only has value if the organisation can prioritise effectively, remediate quickly, and prove that the fix reduced real exposure. Otherwise, the result is more volume and more noise.”

Cyber DailyWant to see more stories from trusted news sources?
Make Cyber Daily a preferred news source on Google.

David Hollingworth

David Hollingworth has been writing about technology for over 20 years, and has worked for a range of print and online titles in his career. He is enjoying getting to grips with cyber security, especially when it lets him talk about Lego.

Tags: