Glasswing Month One: UK AISI Confirms Mythos Solves Both Cyber Ranges End-to-End, 2,100 Vulnerabilities Patched — Public Release Still Blocked
Anthropic published the first Glasswing progress update on May 22. The numbers confirm what the lab has been calibrating its model release posture around: Mythos Preview is operating in a capability tier that no published defensive framework has yet caught up to.
What the UK AI Security Institute Confirmed
The UK’s AI Security Institute assessed Mythos Preview against two separate cyber ranges — structured simulations of multistep corporate cyberattacks. Mythos Preview is the first model to complete both ranges end-to-end. No prior model had solved either in full.
XBOW, an independent security platform that benchmarks models on web exploit development, rated Mythos Preview a “significant step up over all existing models” and reported “absolutely unprecedented precision” on a token-for-token basis.
Two academic benchmarks released specifically to measure AI exploit development — ExploitBench and ExploitGym — both show Mythos Preview as the strongest performer in their respective datasets. Anthropic states it supported the development of both benchmarks and is committing to expand the academic evaluation infrastructure for frontier cyber AI.
Mozilla: 271 Firefox Vulnerabilities, 10x the Rate
Mozilla tested Mythos Preview against Firefox 150 and found 271 vulnerabilities, all now fixed. For comparison, the same team found a fraction of that count when testing Firefox 148 with Claude Opus 4.6 — Mythos Preview produced more than ten times the output. Zero false positives were reported.
The improvement is not marginal. It changes the economics of vulnerability research: one model run at frontier cost is now producing what previously required substantial manual security engineering effort.
Claude Security Beta: 2,100 Patches in Three Weeks
Claude Security launched in public beta three weeks ago for Claude Enterprise customers. It scans codebases for vulnerabilities and generates proposed fixes. In the three weeks since launch, Claude Opus 4.7 has been used to patch 2,100 vulnerabilities across enterprise customer codebases.
The pace is faster than the open-source patching described in the Mozilla case because enterprises are fixing their own code rather than coordinating with volunteer maintainers through disclosure pipelines. Anthropic has also formed a partnership with the Open Source Security Foundation’s Alpha-Omega project to support maintainers processing and triaging bug reports at scale.
Why Mythos Is Not Shipping to the Public
Anthropic’s position is now formally on the record: no Mythos-class model will be released publicly until the lab has developed safeguards strong enough to prevent misuse that could cause severe harm. The update states directly that “no company — including Anthropic — has developed safeguards strong enough” at present.
The practical consequence is that models as capable as Mythos Preview will be developed by other labs on their own timelines. Anthropic’s bet with Glasswing is that building defensive infrastructure now, before that capability spreads, changes the asymmetry. The 271-Firefox-bug number is the clearest expression of that bet: the same capability that makes Mythos dangerous to deploy is being used to find and fix the vulnerabilities it would otherwise be used to exploit.
The next phase of Glasswing involves expanding access to additional government and critical infrastructure partners. A general release follows once the safeguards exist.
Key Numbers
- UK AISI: Mythos Preview first model to complete both multistep corporate cyberattack range simulations end-to-end
- Mozilla: 271 Firefox 150 vulnerabilities found with Mythos Preview — 10x+ the rate with Claude Opus 4.6
- Claude Security beta: 2,100 patches applied across enterprise codebases in first 3 weeks
- XBOW: “absolutely unprecedented precision” — rated Mythos a significant step up on web exploit benchmarks
- ExploitBench, ExploitGym: Mythos Preview leads both academic exploit-development benchmarks
- Glasswing partnership: Alpha-Omega project (Open Source Security Foundation) for open-source triage
- Current partner count: described as US and allied governments plus select private sector; White House held access at 50 orgs, not yet expanded to the 120 Anthropic requested
- Mythos public release: contingent on safeguard development; no timeline given