What Claude Mythos Means for Your Website

By Andrew Owens |

In April, Anthropic announced a model called Claude Mythos Preview. They didn't release it to the public. They gave it to a small group of big companies and open source maintainers through something they called Project Glasswing, and published a long write-up on why.

The short version of why: it's very, very good at hacking.

It's worth reading the whole thing. Here's what's in it, and what I think it means if you run a normal website or web app.

What it did

According to Anthropic, when someone asked it to, Mythos Preview found and exploited zero-day vulnerabilities (bugs nobody knew about yet) in every major operating system and every major web browser. A few they could talk about publicly:

  • A 27-year-old bug in OpenBSD that let anyone crash a machine over the network. OpenBSD is the operating system people pick specifically because it's paranoid about security.
  • A 16-year-old bug in FFmpeg, the video library that almost every video service on earth depends on, and one of the most heavily tested projects out there.
  • A 17-year-old bug in FreeBSD's file sharing server that gave an unauthenticated attacker full root access. The model found it and wrote the working exploit with no human involved after the first prompt.

They also said they'd found thousands more high and critical severity bugs, and that over 99% of them weren't patched yet when they published.

The part that got my attention

Two lines in the write-up stuck with me.

First, Anthropic engineers with no security training asked the model to find remote code execution bugs before they went home, and woke up the next morning to a complete, working exploit. You don't need to be a hacker anymore. You need to be able to type a request.

Second, the web app findings. Everyone focuses on the operating system bugs because they're dramatic. But Anthropic also listed what it found in web applications:

  • Complete authentication bypasses that let an anonymous user make themselves an admin
  • Login bypasses that skip the password and the two-factor code
  • Bugs that let an attacker remotely delete data or take the service down

That's not exotic kernel stuff. That's the kind of bug that lives in a normal SaaS app. Maybe yours.

Old bugs got cheaper too

The part I think matters most for small companies is what they call N-days. Those are vulnerabilities that are already public and already patched, but still live on every server that hasn't installed the fix yet.

Anthropic gave Mythos Preview nothing but a CVE number and the commit that fixed it, and the model wrote a working exploit on its own. One took half a day and cost under $1,000 in compute. Another took under a day and under $2,000. That used to take a skilled researcher days to weeks per bug.

So the time between "a fix is published" and "someone has a working attack for it" is getting short. If you're the kind of shop that updates dependencies once a quarter, that window is now wide open for most of the quarter.

It's not just one lab's opinion

The UK's AI Security Institute tested Mythos Preview on their own and published results a week later. They have a 32-step simulated corporate network attack that they estimate takes a human expert about 20 hours. Mythos Preview was the first model to finish it end to end, in 3 of its 10 attempts.

To be fair, AISI pointed out that their test network had no active defenders and no security tooling, so it's easier than the real world. But their conclusion was that it can at least take over small, weakly defended networks once it's inside. That describes a lot of companies.

So what do you actually do

You're not getting access to Mythos, and you don't need it. What you need is to not be the easy target, because the easy targets are about to get a lot more attention. Here's what both Anthropic and AISI told people to do, translated for a small team:

  • Patch faster. Turn on automatic updates wherever you can. When a dependency update fixes a CVE, treat it as urgent, not as housekeeping.
  • Know what you're running. You can't patch what you don't know is there. Keep a list of your frameworks, libraries, and services and their versions.
  • Do the basics. Access control, security configuration, logging. AISI said this directly: the systems at risk are the weakly defended ones.
  • Test from the outside. Find the auth bypass before someone else's model does.

None of this is new advice. What's new is that ignoring it has gotten a lot cheaper for the other side.

If you want to know where you stand today, start with the free header scan. If you want someone to go looking for the login bypass, that's what our $495 pen test is for.

Ready to fortify your defenses against cyber threats?

Start Your Penetration Test Now