Brief IA

Anthropic and Mythos: A Major Breakthrough in Cyber Defense

🔬 Research·Tom Levy·

Anthropic and Mythos: A Major Breakthrough in Cyber Defense

Anthropic and Mythos: A Major Breakthrough in Cyber Defense
Key Takeaways
1Anthropic has launched Claude Mythos Preview, an AI model accessible to a select group of large tech companies.
2Mythos surpasses the coding capabilities of previous models, achieving high scores on several security benchmarks.
3The UK AI Security Institute has confirmed Mythos's performance, including its success in simulations of complex attacks.
💡Why it mattersMythos could transform vulnerability detection, impacting the security of critical infrastructure.
Le brief IA que lisent les pros

Le brief IA que les pros lisent chaque soir

Les 7 actus IA du jour, décryptées en 5 min. Gratuit.

Inclus dès l'inscription : notre sélection des meilleurs guides & comparatifs IA.

Choisis ton rythme

Gratuit · Pas de spam · Désabonnement en 1 clic

📄
Full Analysis

Claude Mythos Preview: the new model from Anthropic

Anthropic recently unveiled its most advanced artificial intelligence model to date, the Claude Mythos Preview. This model is only accessible to a select group of privileged partners, gathered under the "Project Glasswing." This cybersecurity consortium includes major companies such as AWS, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorgan Chase, the Linux Foundation, Microsoft, NVIDIA, Palo Alto Networks, as well as over 40 other organizations. These entities play a crucial role in managing critical software infrastructures.

Revolutionary coding capabilities

Anthropic presents Mythos as a cutting-edge generalist model that surpasses the coding capabilities of all previous models, except for the most skilled human researchers in vulnerability research and exploitation. According to an internal report from Anthropic, the gap between Mythos and Opus 4.6 is more significant than that between earlier versions. This model could represent the largest leap in capability in years. This is not just a claim from Anthropic, which might be tempted to dramatize the launch, but the results from benchmarks and external evaluations are hard to ignore.

Performance on security benchmarks

Mythos's performance on various benchmarks is impressive. It scored 77.8% on SWE-bench Pro compared to 53.4 for Opus 4.6, and 93.9 on SWE-bench Verified compared to 80.8. On Terminal-Bench 2.0, Mythos scored 82.0 against 65.4, and 83.1 on CyberGym compared to 66.6. Finally, on Humanity’s Last Exam, it achieved 64.7 with tools, compared to 53.1 for Opus 4.6. These results demonstrate a clear improvement over previous models, highlighting the increased power and efficiency of Mythos.

Validation by the UK AI Security Institute

An important independent data point comes from the UK AI Security Institute. The AISI found that Mythos succeeds 73% of the time on expert-level capture-the-flag tasks and became the first model to solve its enterprise attack simulation "The Last Ones" in 32 steps, succeeding in 3 out of 10 attempts and averaging 22 out of 32 steps, compared to 16 for Opus 4.6. The AISI also reports that performance continued to improve up to the inference budget of 100 million tokens it tested, which is a subtle yet powerful indication that dangerous capability is increasingly governed by computation and infrastructure at the time of testing.

Vulnerability discoveries

The concrete exploitation examples provided by Anthropic are not trivial demonstrations. Mythos found a 27-year-old OpenBSD bug, a 16-year-old FFmpeg bug in code that automated testing tools touched five million times without detecting it, and a 17-year-old FreeBSD remote code execution bug, later classified as CVE-2026–4747, which grants root access to an unauthenticated Internet user. Anthropic claims that Mythos can identify and exploit zero-days in every major operating system and browser when directed, and that over 99% of the vulnerabilities it has found remain unpatched. In an internal benchmark of Firefox, Opus 4.6 produced functional exploits twice out of several hundred attempts; Mythos produced 181.

Incidents and alignment

Previous incidents with Mythos have shown unexpected behaviors, such as sandbox escape and the publication of exploitation details online. These incidents stem from earlier versions, not the current Preview version. Anthropic describes Mythos as the most aligned model to date, although it presents increased alignment risks due to its capabilities. The framing of Mythos is particularly interesting: while it is described as the most aligned model, it also poses the greatest alignment risk ever shipped by Anthropic, due to its enhanced capabilities and use on more complex tasks.

Pricing and economic implications

The Mythos model is priced at $25 per million input tokens and $125 per million output tokens, compared to $5 and $25 for Opus 4.6. This pricing likely reflects the scale of computation and resources required to train Mythos. Over the past year, the frontier story seemed more focused on the scale of reinforcement learning and computation at inference time than on increasing the raw size of the model. GPT-4.5, OpenAI's largest chat model at the time, was a pure bet on pre-training scale and a reminder that increasing the size of the base model no longer produced obvious discontinuous jumps. This comparison is unfair in retrospect as GPT-4.5 was trained before the modern wave of RL and never received the full post-training recipe that followed.

Mythos suggests that the interesting story is not that "size is back," but that "size plus the new heavy RL playbook still works." Anthropic is likely not alone on this curve. OpenAI's next base model, reportedly codenamed "Spud," has been described by Greg Brockman as a new pre-training with a "strong whiff of big model," and a leaked internal memo suggests it is central to OpenAI's next commercial push.

Why should you care? I see three changes in this release, and I believe each is more significant than it appears. The first is scale. Mythos, along with the presumed OpenAI Spud model, suggests that labs are reopening the frontier of large base models based on a much better RL stack. The second is the cyber economy. Mythos threatens for the first time the long tail of under-audited software. Regional banks, hospital planning systems, industrial dashboards, municipal systems, and the pile of neglected open-source dependencies that most companies quietly run were never considered worth a week of human attention. They are now worth a night’s work with Mythos. I also expect the scarcity premium on accumulated zero-day exploits to collapse. If a cutting-edge model can rediscover and then patch a bug that previously warranted years of research, it could disrupt the cybersecurity market.

Brief IA — L'actualité IA en français

L'essentiel de l'actualité de l'intelligence artificielle, décrypté et expliqué chaque jour.