Anthropic’s announcement this week of its new artificial intelligence model, “Claude Mythos,” which the company describes as an advanced model that successfully discovered thousands of high-severity security vulnerabilities in widely used software, has sparked a sharp division within the AI and cybersecurity communities. This disagreement among experts centers on whether this technological development represents a real and tangible leap in digital defense capabilities, or merely a strategic show aimed at generating media and marketing buzz in a crowded tech market.
A massive tech alliance and ambitious project
On April 7, Anthropic unveiled the preview version of the “Mythos” model alongside the launch of “Project Glasswing,” a massive and innovative initiative bringing together elite global tech giants under one umbrella. The launch partner list includes major companies such as Amazon, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorgan Chase, the Linux Foundation, Microsoft, Nvidia, and Palo Alto Networks. Alongside these key partners, early access to the model was granted to more than 40 additional organizations that maintain critical software infrastructures, clearly reflecting the scale of ambition behind this project aimed at securing the global digital space.
Discovering vulnerabilities that persisted for decades
Anthropic stated that its new model successfully managed to discover complex security vulnerabilities across all major operating systems and well-known web browsers. Among the model’s most prominent achievements is the discovery of a software flaw that remained hidden for 27 years in the OpenBSD system, in addition to a critical security vulnerability allowing remote code execution in FreeBSD that went undiscovered for 17 years, officially designated as CVE-2026-4747. As part of this comprehensive effort to support information security and secure internet infrastructure, the company pledged to provide up to $100 million in free model usage credits, alongside $4 million in cash donations to non-profit organizations focused on open-source software security.
The discovery of security vulnerabilities that persisted for decades in operating systems considered the backbone of many servers and infrastructures strongly highlights the fragility of the digital systems we rely on in our daily lives. A system like OpenBSD is known for its rigorous focus on security and continuous auditing, and discovering an old flaw within it highlights how adept artificial intelligence is at analyzing complex code and tracing error paths that a human programmer might overlook, no matter their experience and skill. Similarly, the existence of a vulnerability allowing attackers to execute malicious code for 17 years constitutes a catastrophic threat that could have been destructively exploited were it not for this early discovery.
A turning point in the world of programming and penetration testing
Anthropic emphasized via its project page that artificial intelligence models have now reached an unprecedented level of capability in writing and analyzing code, making them superior to all humans in discovering and exploiting vulnerabilities, with the exception of a select few of the world’s most skilled specialized experts. The company confidently pointed out that the “Mythos” model has proven its superior ability to write exploit code within mere hours—complex tasks that human penetration testing experts stated would have taken weeks of long, arduous manual development.
This astonishing development prompted cybersecurity companies that began working with the model to react with intense enthusiasm and strong positivity. Officials at Cisco and CrowdStrike described the new technology as a historical turning point, noting that analytical operations that took months in the past can now be completed in just minutes. Meanwhile, Lee Klarich, chief technology officer at Palo Alto Networks, described the achievement not only as a game-changer for finding hidden bugs, but also as a strong and clear indicator of a broader shift in strategies across the entire cybersecurity field.
Sharp criticism and questioning of motives
On the other hand, opposing and skeptical reactions were equally strong and impactful. Yann LeCun, a deep learning pioneer and executive in Meta’s AI division, sharply criticized the announcement. Writing on the X platform on April 9, LeCun stated that the drama surrounding the “Mythos” model is nothing more than nonsense born of self-deception, responding to a post by AI security firm Aisle which indicated that much smaller, significantly cheaper models could replicate much of this security analysis with similar efficiency and accuracy.
In the same context, prominent AI researcher Gary Marcus conveyed, via his personal blog, the assessment of a senior cybersecurity expert who asserted that the company’s promoted claims appear significantly exaggerated, questioning the volume of actual results attributable to the model’s independent work compared to what was achieved thanks to human intervention in guiding it. Marcus quoted his source as clearly stating that they are planting the seeds of hype and exaggeration in the garden of media illusion to draw attention.
The dilemma of security and future risks
This fierce ongoing debate over the model’s performance reflects a recurring and fundamental point of contention in the trajectory of AI development: the persistent question of whether the restricted versions of advanced models express genuine caution and ethical responsibility by companies, or if they are cleverly used as a competitive marketing strategy to spark curiosity and drive sales. As Marcus astutely noted, it is practically impossible to completely separate legitimate genuine concerns from deliberate fear-mongering campaigns used as an effective tool for marketing and promotion.
Interestingly in this context, Anthropic’s internal security assessment frankly acknowledged that while the current model is the best in terms of alignment with safe standards so far, it simultaneously carries the highest amount of alignment-related risks compared to all models previously released by the company. This leaves the door wide open to inevitable future questions about the world’s readiness to handle such dual-use technologies, which possess the capability to defend and attack with equal effectiveness.
Frequently Asked Questions
What is the Mythos model announced by Anthropic?
It is a newly developed advanced artificial intelligence model designed to discover high-severity security vulnerabilities in widely used operating systems and software, and it has sparked widespread debate among experts and specialists regarding its true effectiveness.
What are the most prominent vulnerabilities discovered by this smart model?
The model successfully discovered a hidden software flaw that lasted for 27 years in the OpenBSD system, in addition to a vulnerability allowing remote command execution that lasted for 17 years in the FreeBSD system, registered under number CVE-2026-4747.
How did tech experts react to this announcement?
Experts were divided between supporters and opponents; while major companies like Cisco and CrowdStrike considered it a historical turning point that saves considerable time and effort, other experts like Yann LeCun and Gary Marcus strongly criticized it, considering it mere media and marketing hype.