Artificial intelligence firm Anthropic has unveiled 'Project Glasswing,' a major cybersecurity initiative centered around its unreleased frontier AI model, 'Claude Mythos Preview.' The model has demonstrated an unprecedented ability to autonomously discover and exploit thousands of high-severity zero-day vulnerabilities across critical software, including major operating systems and web browsers. Due to the profound national security and public safety implications of such a powerful offensive tool, Anthropic has decided against a public release. Instead, it has formed a defensive coalition with leading technology companies—including Amazon Web Services, Apple, Google, and Microsoft—to use the model's capabilities to find and fix flaws before they can be exploited by malicious actors. This development marks a significant inflection point in cybersecurity, where advanced AI is now a primary force in both vulnerability discovery and defense.
On April 7, 2026, Anthropic announced that its Claude Mythos Preview model, without explicit training for the task, had developed emergent capabilities for vulnerability research that surpass most human experts. The AI has already identified a vast number of critical flaws, some of which have lain dormant for decades.
Notable discoveries include:
Project Glasswing provides partners with access to the model to scan their own software for vulnerabilities. Anthropic is committing up to $100 million in model usage credits and donating $4 million to open-source security organizations like the Apache Software Foundation and OpenSSF to bolster the security of the open-source ecosystem.
The capabilities of Claude Mythos represent a paradigm shift from traditional, human-driven vulnerability research. The model's success implies a mastery of multiple complex techniques at machine speed.
While the internal workings are proprietary, the model's ability to find such a diverse range of flaws suggests it can perform automated actions equivalent to the following MITRE ATT&CK techniques:
T1599 - Vulnerability Scanning.T1595.001 - Active Scanning: Scanning IP Blocks.T1210 - Exploitation of Remote Services.This is a 'gray goo' scenario for vulnerabilities. An AI that can find and weaponize exploits at this scale could theoretically cripple global digital infrastructure if it fell into the wrong hands or was replicated by adversaries.
The emergence of AI-driven vulnerability discovery has dual-use implications:
While the AI model itself is not an observable, defenders can hunt for the types of vulnerabilities it found. For the specifically mentioned CVE-2026-4747 in FreeBSD's NFS server, security teams should monitor for:
rpc.statd or rpc.lockd errorsnfsd) spawning a shell or other unexpected child process.Detecting exploitation of AI-found vulnerabilities relies on robust, layered security monitoring.
nfsd process for suspicious behavior like spawning shells (/bin/sh), downloading files, or establishing outbound network connections.D3FEND Reference: Defensive strategies should include D3-NTA - Network Traffic Analysis to spot anomalous connections and D3-PA - Process Analysis on endpoints to detect exploit payloads executing.
The existence of tools like Claude Mythos makes proactive and rapid security measures more critical than ever.
M1051 - Update Software.M1016 - Application Developer Guidance.M1030 - Network Segmentation.D3FEND Reference: Hardening measures like D3-PH - Platform Hardening and isolation techniques are paramount. The most relevant D3FEND countermeasure is D3-SU - Software Update, which is the primary defense against newly discovered vulnerabilities.
Cybersecurity stocks plummeted by nearly $1 trillion on April 9, 2026, due to investor fears over Anthropic's Claude Mythos AI disrupting the industry.
A massive selloff in software and cybersecurity stocks occurred on April 9, 2026, wiping out nearly $1 trillion in market value. This was directly triggered by Anthropic's announcement regarding its Claude Mythos AI's ability to discover thousands of zero-day vulnerabilities. Investors fear that advanced AI could automate and commoditize vulnerability discovery, fundamentally disrupting the business models of established cybersecurity and software companies. Major players like Qualys, Cloudflare, Tenable, Zscaler, CrowdStrike, and Okta experienced sharp declines, indicating a significant economic consequence of the AI's capabilities and raising concerns about the future of the cybersecurity industry.
Financial regulators in the UK and US are urgently assessing the systemic cybersecurity risks posed by Anthropic's 'Claude Mythos' AI, holding meetings with major banks to address potential disruption to global financial IT infrastructure.
Top financial regulators in the UK (Bank of England, FCA, NCSC) and US (Treasury, Federal Reserve) are urgently assessing the systemic cybersecurity risks posed by Anthropic's 'Claude Mythos' AI. High-level meetings with major banks are underway to address potential widespread disruption to global financial IT infrastructure. This development highlights the dual-use nature of the AI, raising alarms about its potential weaponization and the need for new regulatory frameworks and defensive strategies to counter AI-powered cyber threats. The perceived threat has escalated to a point where it is considered a systemic risk to the global financial system.
Unit 42 research confirms frontier AI models autonomously find zero-days, posing immediate, large-scale threat to OSS and accelerating exploitation to N-hours.
Palo Alto Networks' Unit 42 independently validated that frontier AI models can autonomously discover zero-day vulnerabilities and complex exploit chains. Their research highlights a critical risk to open-source software (OSS) due to AI's ability to analyze source code, accelerating the vulnerability-to-exploitation timeline from N-days to N-hours. This lowers the barrier for attackers, predicting a surge in AI-driven supply chain attacks. Unit 42 details a hypothetical AI attack path, emphasizing the need for prevention-first security to counter machine-speed threats.
Anthropic announces Project Glasswing and the capabilities of its Claude Mythos Preview AI model.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.