What is Claude Mythos?

Claude Mythos is Anthropic's newest frontier AI cybersecurity model, designed to identify software vulnerabilities and generate working exploits autonomously. It represents a significant step beyond AI as an assistant and towards AI acting as an independent cyber operator.In late March 2026, a misconfigured content management system at Anthropic exposed thousands of unpublished documents to public search. Among them was a draft blog post describing a new AI model: Claude Mythos.

It wasn’t meant to be announced this way. But the leak was real - and so is the capability.

Anthropic formally unveiled Claude Mythos Preview on 7 April 2026, alongside Project Glasswing, a tightly controlled program that grants limited access to a small group of organisations for defensive testing.

Why is Claude Mythos different from previous AI models?

Claude Mythos isn't simply faster than earlier AI models. It can autonomously perform offensive security tasks that previously required experienced security researchers.

The cybersecurity community has tracked the evolution of AI closely over the past two years. What Claude Mythos represents is not an incremental improvement; it is a step change.

Previous models struggled with autonomous exploit development. Mythos does not. Early evaluations indicate that it can generate working exploits in a significant proportion of cases, including on complex, expert-level challenges.

More importantly, it has demonstrated the ability to identify vulnerabilities that have remained undiscovered for years, across widely used systems and platforms.

At the same time, broader threat intelligence shows that AI is already embedded across the full attack lifecycle to:

    • Automate reconnaissance

    • Generate malware

    • Identify exposed credentials

    • Chain together multiple weaknesses

    • Accelerate intrusion activity

In some cases, AI is no longer supporting the attack but running it.

AI hasn’t just accelerated cyberattacks, it has fundamentally lowered the barrier to entry.

Claude Mythos

How is AI changing modern cyber attacks?

The biggest change isn't that AI makes attacks faster. It's that AI makes them more effective.

It is tempting to frame Claude Mythos purely in terms of speed. That would be a mistake as effectiveness is becoming the real differentiator.

AI excels at identifying patterns, processing large datasets, and generating outputs at scale. But its real impact comes from how those capabilities are applied in combination.

Modern attacks are no longer defined by a single vulnerability. They are defined by how multiple weaknesses are chained together across systems.

Automation can identify thousands of potential weaknesses. But when those weaknesses are connected across identity systems, cloud environments, SaaS platforms, and human processes, they form viable attack paths that can be exploited to achieve a specific objective.

Automation finds vulnerabilities. It’s the chaining of those vulnerabilities that creates breaches.

What we’re seeing in our GSOC

At The Missing Link, we’re already seeing this shift play out directly in our own work. Now that the dust has settled and multiple AI models are delivering broadly similar levels of capability, the conversation has rightly moved on from any single model and back to security fundamentals. One of the biggest changes our GSOC team is tracking is the ability for AI to rapidly identify and chain together multiple low- and medium-severity vulnerabilities to achieve a high-impact outcome. Organisations can no longer afford to focus exclusively on critical and high-rated findings while accepting lower-risk issues as background noise.

From a GSOC perspective, this is reinforcing the importance of continuous exposure management, attack path analysis, and faster remediation cycles. We're helping organisations understand how seemingly isolated weaknesses can be combined into realistic attack scenarios, prioritising remediation based on exploitability and business impact rather than CVSS score alone.

While we haven't yet seen the level of AI-driven attack activity that some early predictions suggested, the technology is still maturing and becoming more accessible. The organisations that will be best positioned over the next few years are those investing now in mature vulnerability management programs, automation, and operational processes that allow them to identify, prioritise, and remediate exposure in hours rather than days or weeks. AI is increasing the speed at which attackers can operate, so defenders need to focus on closing security gaps at a similar pace.

Modern SOC

What AI-powered attacks already look like

AI-driven attacks are no longer theoretical. Many techniques are already being observed in real-world environments.

Attackers are increasingly using AI to automate activities that previously required significant manual effort.

In one widely reported example, AI-generated voice impersonation was used to bypass multi-factor authentication (MFA). By mimicking a senior executive and exploiting weaknesses in helpdesk processes, attackers reset credentials without triggering traditional security controls.

Elsewhere, AI has been used to analyse cloud identities, permissions and infrastructure relationships, allowing attackers to identify multiple low-risk configuration issues and combine them into a successful compromise without relying on phishing or brute-force attacks.

Organisations are also beginning to encounter new risks within AI-enabled environments themselves.

Prompt injection attacks, indirect prompt manipulation and attempts to influence AI-driven workflows are creating entirely new attack surfaces that many traditional security controls were never designed to protect.

Although the techniques differ, the underlying trend remains consistent.

AI is reducing the effort required to discover opportunities, adapt to defensive controls, and exploit weaknesses at scale.

Can AI models like Claude Mythos be contained?

Probably not for long. History suggests that advanced cyber capabilities rarely remain confined to tightly controlled environments.

Despite Anthropic’s efforts to tightly control access to Mythos, reports indicate that the model was accessed by unauthorised users shortly after its release via a third-party environment.

Anthropic has confirmed that an investigation is underway.

The details of the incident are still emerging, but it highlights a broader challenge facing the industry.

Even the most carefully managed releases are vulnerable to:

    • Supply chain exposure

    • Insider threats

    • Third-party security gaps

    • Misconfiguration

    • Credential theft

Once capabilities like this move beyond controlled environments, they don’t remain contained.

What does Claude Mythos mean for your organisation?

The arrival of autonomous offensive AI means organisations need to rethink how they manage cyber risk, not because every attacker suddenly becomes highly sophisticated, but because sophisticated capability is becoming far more accessible.

For CISOs and security leaders, Claude Mythos highlights three trends that are likely to accelerate over the next few years.

1. The window to respond is shrinking

The gap between a vulnerability being disclosed and it being exploited keeps getting smaller. Organisations that once had weeks, sometimes months, to patch a critical issue are now finding attackers can automate discovery, validation and exploitation in a matter of hours. Detection alone isn't enough anymore; how quickly you can close the gap matters just as much.

2. Sophisticated attacks are becoming more accessible

AI is chipping away at the expertise barrier that used to separate skilled attackers from everyone else. Work that once demanded years of specialist offensive security experience can now be automated or guided by AI, which doesn't remove the need for genuinely skilled attackers, but it does mean a much wider pool of people can now attempt what used to be out of reach.

3. Attacks are becoming continuous

Unlike a human attacker, AI doesn't get tired or give up after a few failed attempts; it keeps probing, adapting and testing new paths until something works. That's a problem for organisations that have historically leaned on complexity as a deterrent, because that advantage only holds up against attackers who eventually stop trying.

Modern SOC operations

The defender’s opportunity

The same AI capabilities accelerating attackers can also transform cyber defence, provided organisations adapt their operating model.

Tim Niblett, Head of Security Operations at The Missing Link, puts it clearly:

“The same capabilities that make models like Mythos dangerous are what make them valuable for defenders. The question is whether organisations are ready to use them effectively.”

The reality is that most security operations functions are not currently designed to operate at this speed.

Alert volumes are increasing. Threats are becoming more complex. And analysts are being asked to do more with the same, or fewer, resources.

Traditional, manual approaches to detection and response are reaching their limits.

Without automation and AI-driven context, no analyst can move fast enough to outpace an AI-powered attacker.

The opportunity for defenders is to use the same technologies to improve triage, investigation, threat hunting, and response activities.

AI can take on a greater share of:

    • Triage and prioritisation

    • Threat correlation

    • Proactive threat hunting

Not to replace human expertise, but to ensure it is applied where it matters most.

Five actions CISOs should take now

The release of Claude Mythos reflects a broader shift in the capabilities of frontier AI models and their application to cyber security. Organisations that begin adapting now will be better positioned to manage what comes next.

The organisations that act on that signal will be better positioned to manage what comes next.

  1. Accelerate vulnerability remediation, not simply vulnerability discovery: Infrastructure and SaaS patching can often be automated in days. Application vulnerabilities are different: code has to be re-engineered, tested and redeployed through your release pipeline, not simply patched. Treating both the same way is why remediation timelines blow out. Leading organisations are closing this gap by wiring AI coding tools like Claude Code directly into their CI/CD pipeline, so vulnerabilities are triaged and routed straight to a fix rather than sitting in a backlog, creating a continuous loop of find, fix, redeploy, revalidate, measured in hours, not months. 

  2. Commission an independent offensive security assessment: Understanding your real attack surface - how vulnerabilities can be chained and exploited- has never been more important.

  3. Reassess third-party and supply chain risk: The attack surface extends beyond your organisation. So does the risk.

  4. Modernise detection and response: Static rules and manual triage are no longer sufficient. AI-driven detection and automated response are becoming essential.

  5. Bring AI-driven cyber risk into board discussions: This is no longer a niche technical issue. It is a business risk with strategic implications.

What comes after Claude Mythos?

Claude Mythos won't be the last frontier model capable of autonomous cyber operations. It may simply mark the point where the industry recognises the shift.

Anthropic has been explicit: Mythos is not the endpoint.

Other AI providers are moving in the same direction, and competitive pressure is likely to accelerate development across the industry. As these models become more capable, organisations will need to focus not only on identifying vulnerabilities, but on their ability to prioritise and remediate them quickly.

This is why the industry is converging on Continuous Threat Exposure Management (CTEM) as the operating model going forward - not a point-in-time vulnerability scan, but an ongoing cycle of scoping, discovery, prioritisation, validation, and mobilisation. The organisations that treat exposure management as a continuous program, rather than a periodic assessment, will be the ones able to keep pace as AI compresses the time between vulnerability discovery and exploitation.

The constraint in cybersecurity is changing. Finding vulnerabilities faster only matters if organisations can fix them faster:

Diagram showing the shift in cybersecurity focus: from detection to remediation, and from awareness to execution

 The change in cybersecurity focus, from finding problems to closing them. 

Frequently asked questions

Will AI replace penetration testers?
No. AI accelerates vulnerability discovery and exploit development, but human testers still provide the judgement, creativity, and business context needed to assess real-world impact and validate findings. 
How should boards measure cyber resilience as AI attacks increase?
Vulnerability counts alone aren't enough. Boards should track Mean Time to Remediate, exposure age, percentage of exploitable vulnerabilities remediated on target, and critical attack paths eliminated. 
What is Continuous Threat Exposure Management (CTEM)?
CTEM is an ongoing cycle of identifying, validating, prioritising, and remediating cyber exposures, rather than a periodic scan; it continuously evaluates how attackers could exploit weaknesses across identities, cloud, applications, and endpoints. 
Why are medium-severity vulnerabilities becoming more important?
Attackers increasingly chain low  and medium-severity vulnerabilities together to create high-impact outcomes, so CVSS score alone no longer reflects real risk — a vulnerability's context matters as much as its rating. 
Should organisations use AI to defend against AI?
Increasingly, yes. AI helps security teams detect threats, automate investigations, and prioritise alerts faster, freeing analysts to focus on complex investigations rather than repetitive tasks. 

 

How The Missing Link can help

At The Missing Link, our offensive security, security operations, and IT operations teams work together to give you a clear, realistic view of your exposure, and a practical path to reducing it.

We help organisations:

    • Understand how attackers actually operate

    • Identify where vulnerabilities can be exploited in combination

    • Strengthen detection and response capabilities

    • Accelerate patch management across infrastructure, SaaS, and application environments

    • Prepare for the next generation of AI-driven threats

Not sure where your biggest exposure sits? Talk to our team about an offensive security assessment tailored to your environment.


Latest insights

 

Author

Louise Wallace

As a Content Marketing Specialist at The Missing Link, I turn technical insights into engaging stories that help businesses navigate the world of IT, cybersecurity, and automation. With a strong background in content strategy and digital marketing, I specialise in making complex topics accessible, relevant, and valuable to our audience. My passion for storytelling is driven by a belief that great content connects, educates, and inspires. When I’m not crafting compelling narratives, I’m exploring new cultures, diving into literature, or seeking out the next great culinary experience.