Mythos Storm is Coming – be prepared

Articles Cybersecurity
8 min read
Share to

In early April 2026, Anthropic, the company behind Claude, launched Project Glasswing, an initiative that uses the Claude Mythos Preview model to identify vulnerabilities in critical software before attackers can exploit them.

The programme initially involved around 50 organisations, including AWS, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorgan Chase, the Linux Foundation, Microsoft, NVIDIA, and Palo Alto Networks. By early June, it had expanded to approximately 150 organisations across more than 15 countries, and the ecosystem has since grown to around 200 partners.

During the first month alone, participating organisations identified more than 10,000 high-severity and critical vulnerabilities within their own software environments.

Anthropic has also used Mythos to analyse more than 1,000 open-source projects. According to the company, these projects form a significant part of the infrastructure that powers the modern Internet. In a report published in May, Anthropic disclosed that it had identified 23,019 potential vulnerabilities, of which 6,202 were assessed as high-severity or critical. At that time, 1,752 findings had undergone additional validation, primarily by independent cybersecurity firms. Of these, 90.6% were confirmed to be genuine vulnerabilities.

According to Anthropic’s public vulnerability disclosure tracker, by 2 October 2026 the company had reported 6,157 vulnerabilities across 591 open-source projects. Of these, only 516 had reportedly been remediated. These figures include vulnerabilities across all severity levels.

The Real Challenge Behind the Mythos Storm

This is where the real problem begins.

Artificial intelligence has made vulnerability discovery faster and more scalable than ever before. However, the processes that follow, such as validation, disclosure, remediation, testing, and patch deployment, do not scale at the same pace.

Early Signs Are Already Visible

There are already indications that software patch volumes are increasing significantly. While a direct link to Mythos has not been publicly confirmed in the examples below, the trend is clear:

Microsoft: September’s Patch Tuesday was the largest in the company’s history. Microsoft released fixes for approximately 975 CVEs, of which around 964 required customer action. Two vulnerabilities were already being actively exploited. For comparison, Microsoft addressed 1,139 CVEs during the entire year of 2025. The company has publicly stated that patch volumes are expected to continue increasing for some time.

Linux Kernel: On 29 September, Debian released security update DSA-6528-1 for its stable Trixie release. The advisory referenced 1,313 CVEs. This number does not directly indicate severity, as the current Linux kernel CVE policy assigns CVE identifiers to a much broader range of security-related fixes than many commercial vendors. Nevertheless, the scale of the update illustrates the volume of vulnerabilities organisations may soon need to manage.

Mozilla: Firefox 150 addressed 271 vulnerabilities, more than ten times the number fixed in Firefox 148, which was tested using Anthropic’s earlier Opus 4.6 model.

Cloudflare: Cloudflare reported finding approximately 2,000 bugs within its own systems, around 400 of which were classified as high-severity or critical.

Open-source components now underpin almost every modern IT environment. As a result, vulnerabilities found within them can impact a wide range of systems, including network infrastructure, servers, storage platforms, applications, endpoints, industrial systems, and embedded devices.

Everything connected to the Internet is continuously exposed to automated scanning and attack attempts. AI is now increasing the ability of both defenders and attackers to identify exploitable weaknesses.

The Pace Is Not Slowing Down

Mythos Preview was the first model of this capability level that Anthropic made available only to carefully selected defenders. Newer versions, such as Mythos 5.1, remain restricted to approved organisations.

Most publicly accessible AI models today include safeguards intended to limit their use for offensive cyber activities. The challenge, however, lies with open-weight models.

At the end of September, Anthropic published a separate analysis of the Chinese Z.ai model GLM-5.3. According to Anthropic, the model’s exploit development capabilities are approaching those of Mythos Preview. In ExploitBench testing against Google’s Chrome V8 engine, GLM-5.3 successfully generated working exploits in 50 out of 410 attempts, compared with 56 achieved by Mythos Preview. The difference is that GLM-5.3 includes significantly weaker safeguards against misuse.

While Anthropic has a clear stake in the discussion, the U.S. NIST CAISI centre has reached a broadly similar conclusion. According to its assessment, GLM-5.3 is currently the most capable open-weight cyber-focused model available and trails the leading U.S. models by approximately four months.

In practice, this means that Mythos-level offensive and defensive capabilities are no longer limited to a controlled group of trusted defenders. Comparable capabilities are now available in models that can be used to discover vulnerabilities, build exploit chains, and automate attack workflows.

Nor does access require nation-state resources any longer. Running such models on privately owned GPU infrastructure typically requires an investment of a few hundred thousand euros, while equivalent cloud capacity can often be rented for tens of euros per hour.

The barrier to entry for advanced offensive cyber capabilities has therefore dropped dramatically.

Why Does This Matter to Me?

Responsible vulnerability disclosure generally relies on agreed disclosure windows. The best-known example is the 90-day disclosure policy, although practices vary between vendors and industries.

The volume of findings generated by systems like Mythos is now large enough to place significant pressure on traditional vulnerability management processes. Validating findings, notifying vendors, developing fixes, testing patches, and releasing updates all take considerably longer than identifying vulnerabilities in the first place.

In practical terms, organisations should expect larger and more frequent security advisories and patch releases from infrastructure and software vendors.

Based on non-public information we have received from vendors, this trend is expected to become more visible in security bulletins and software updates released during October. This is no longer merely a future scenario.

Every organisation should ensure that appropriate preparation and protection measures are in place for Internet-connected systems and devices.

The first step is understanding exactly what exists within the environment. Organisations should maintain an up-to-date inventory of devices, systems, and software, as well as identify which assets are Internet-facing and which are business-critical. Only then can a risk-based vulnerability management process be established.

Organisations Should At Minimum:

  • Continuously monitor vulnerability intelligence and vendor security advisories.
  • Maintain an accurate inventory of devices, systems, and software, including identification of Internet-facing and business-critical assets.
  • Prioritise remediation based on risk. Not every vulnerability can be fixed immediately. Focus on those that represent a realistic threat within your own environment.
  • Apply security updates rapidly to Internet-facing systems whenever the vulnerability represents a genuine risk.
  • Automate patching processes wherever possible. Organisations should also maintain dedicated emergency procedures for urgent security changes, including internal and external communications.
  • Use virtual patching and other compensating controls within firewalls, IPS platforms, WAF solutions, and other security controls whenever official software fixes cannot be applied immediately.
  • Harden systems appropriately. For routers, switches, firewalls, servers, and storage systems, this includes removing unnecessary services, restricting management access, using centralised identity management, and enforcing multi-factor authentication (MFA).

Additional Layers of Protection Are Essential

Technical patching alone is not enough.

Organisations should also:

  1. Segment internal networks to prevent unrestricted lateral movement if a system becomes compromised.
  2. Collect sufficient logging and telemetry and continuously analyse it through capabilities such as a Security Operations Centre (SOC). Unnecessary services, user accounts, management interfaces, and external connections should be removed.
  3. Accept that not all attacks can be prevented in advance and prepare accordingly.
  4. Ensure backups are isolated from production environments and, where possible, immutable. Backup integrity and recovery procedures should be tested regularly.
  5. Be capable of restoring operations to a state prior to compromise if necessary.

Some Systems Will Be Patched. Others Will Not.

Technology vendors define product lifecycles that include End-of-Sales milestones followed by separate support, software maintenance, and security maintenance end dates. These timelines vary significantly between products and vendors.

From a security perspective, the most important date is not necessarily End-of-Sales, but the point at which the vendor stops providing security updates.

The challenge lies in systems that are already beyond support.

The Internet and enterprise networks still contain vast numbers of devices whose support and security update lifecycles have already expired. Vendors generally do not develop fixes for newly discovered vulnerabilities in these products.

This is where the Mythos storm may have its greatest impact.

If new critical vulnerabilities are found in unsupported systems, organisations are typically left with only two options: deploy compensating controls or replace the system entirely.

For this reason, identifying end-of-life systems and planning their replacement before a critical vulnerability emerges is far preferable to reacting under pressure after exposure becomes public.

The storm is beginning now. Preparing early makes it more likely that replacement systems will be operational before the worst impacts arrive.

Support Is Available

NetNordic helps organisations transform an increasing flood of vulnerability disclosures into actionable and manageable security plans.

As we receive information from vendors regarding newly discovered vulnerabilities and available fixes, we proactively engage with our customers whenever appropriate.

We can help map environments, identify Internet-facing and business-critical systems, correlate vulnerability information against existing assets, and establish a risk-based prioritisation strategy for remediation and protection.

Where required, we can also assist with system hardening, compensating controls, software updates, and broader preparedness measures. Through our security services, we can further monitor environments for intrusions, anomalies, and attack activity.

The Mythos storm does not mean every system is at immediate risk.

It means that vulnerabilities will be discovered faster than ever before.

And that means organisations must be prepared to respond faster than ever before.

Author

Mika Kähärä

Network and Infrastructure Architect
About Mika Kähärä

Mika Kähärä is NetNordicäs Network and Infrastructure Architect, who works with secure networks and infrastructure.

Get in touch

Fill in the form and we will get back to you as soon as possible! Thanks!