HomeSecurityAnthropic's Mythos found vulnerabilities in US government systems

Anthropic's Mythos found vulnerabilities in US government systems

Mythos , Anthropic ’s advanced artificial intelligence model , identified vulnerabilities in top-secret and classified U.S. government systems during a controlled test — and it did so in hours, not weeks. The discovery was made public on June 11, 2026 , by Democratic Senator Mark Warner of Virginia, during a hearing before the Senate Banking, Housing, and Urban Affairs Committee. The revelation sparked a heated debate between the company, the Trump administration , and the cybersecurity community.

Mythos AI model Anthropic vulnerabilities classified systems US

According to another official who spoke to the Associated Press, Anthropic worked with U.S. intelligence agencies as part of Project Glasswing — an initiative that brought together tech giants and other companies to secure critical software worldwide. In testing, the Mythos 5 found specific vulnerabilities in classified systems within hours. Senator Warner cited Gen. Joshua Rudd, head of the NSA and U.S. Cyber ​​Command, as saying that the tool “broke into almost all of our classified systems, not in weeks, but in hours.” The NSA declined to comment, and an Anthropic spokesman also declined to comment.

See also: Anthropic's Claude Mythos identified 10,000 critical vulnerabilities in one month

It is important to clarify that identifying vulnerabilities does not automatically mean exploiting them. Officials emphasized that Mythos identified the security holes, but it was not confirmed that it exploited them within the same timeframe.

Mythos 5 and Project Glasswing: What we know about the tests

Project Glasswing is an ambitious initiative by Anthropic that aims to work with government agencies and private companies to identify and address critical vulnerabilities worldwide. In this context, Mythos has already demonstrated impressive capabilities: according to Anthropic itself, the model has identified thousands of high-severity vulnerabilities in major operating systems and browsers. A typical example is the discovery of a 27-year-old vulnerability in OpenBSD, one of the most secure operating systems in the world. Also, in assessments by the UK AI Security Institute, the model breached defense systems in 73% of cases, in a controlled environment.

Among the vulnerabilities identified by AI tools in similar tests are: CVE-2026-2006 (Remote Code Execution in PostgreSQL via unauthenticated login), CVE-2026-4747 (Stack Overflow in FreeBSD via malicious network packets), and CVE-2026-5194 (signature verification bypass in wolfSSL for ECDSA/EdDSA). These examples demonstrate how quickly an advanced AI model can turn known vulnerabilities into functional exploits.

See also: Anthropic's Mythos Preview creates functional exploits

Despite recent collaboration between Anthropic and U.S. agencies to test vulnerabilities, tensions between the company and the Trump administration have increased. Anthropic has expressed concerns about how the U.S. military will use its AI, and the government has restricted the use of some of Anthropic’s models.

Earlier this month, the Trump issued a directive requiring Anthropic to restrict access to its Fable 5 and Mythos 5 to U.S. citizens only. The directive came 10 days after President Trump signed an executive order to create a framework for national security assessments of advanced AI systems before their public release.

Anthropic, unable to verify users' nationality in real time, disabled both models for all users worldwide, including allied countries and businesses.

Mythos AI system Anthropic Chinese access national security

The decision sparked a backlash from the cybersecurity community. More than 100 cybersecurity experts and executives from companies like Adobe and Nvidia sent a letter to the administration , stressing that the Mythos models are “pretty good” at identifying vulnerabilities and creating exploits , but “they are not the only ones good at these tasks.” The signatories noted that similar results can be achieved with publicly available AI systems , and that removing the best cybersecurity tools “without good reason” could benefit U.S. adversaries more than it harms them.

See also: Japanese banks gain access to Anthropic's Mythos

The incident highlights a critical contradiction in modern cybersecurity: the same tools that can be used for attack can also be the most effective defense. Mythos and similarly powerful models represent a new generation of AI-driven red-teaming tools that can identify vulnerabilities much faster than human teams. Organizations that manage critical infrastructure are urged to adopt similar approaches, monitor new CVEs detected by AI tools, and participate in collaborative initiatives like Project Glasswing. According to SecurityWeek, the case remains under investigation, with Anthropic seeking dialogue with authorities to restore access to its models.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS