The Cybercriminal’s Cookbook
Put yourself, if you will, in the shoes of a cybercriminal. You have just gained access to one of the most advanced AI models of its time – astonishingly proficient in advanced cybersecurity, and capable of not only discovering, but also reasoning through, chaining, and exploiting vulnerabilities in virtually any software.
What do you, as a nefarious cybercriminal, do with this superlative new power?
Congratulations – you’ve just hit upon the reason why access to Claude Mythos is so heavily restricted.
Mythos is a gamechanger in the world of cybersecurity, helping defenders to analyse vulnerabilities, model adversary behaviour, and test defences more efficiently than ever. But what can be exposed can also be exploited, and when the technology behind the attacker is this advanced, the smallest gap might as well be an open door. That little integer overflow vulnerability that’s been floating around unnoticed and unchecked for 27 years? That becomes infinitely more problematic once Mythos has unearthed it and pointed it out to the wrong person. The wrong person doesn’t even need to be particularly competent – Mythos could potentially turn even a mediocre attacker into a very real threat.
Project Glasswing
The Project Glasswing initiative is Anthropic’s response to this threat, restricting Claude Mythos access to a select group of partners for whom a successful cyber-attack could have major ramifications for both global and national security. The aim is to support defenders and accelerate triaging and patching of critical zero-day software vulnerabilities before other AI models catch up, while empowering organisations towards security practices that reflect this new reality. But the clock is ticking – Anthropic predicts that:
within 6 to 12 months, we expect that many other AI companies will have Mythos-class models, and they could release them without safeguards that prevent misuse. In that world, cyberattacks could occur much more often, and in much more unpredictable forms.[1]
To sum up: Anthropic has developed an AI agent that’s too powerful to safely release to the public and has the capability to turn the whole cybersecurity landscape on its head, for better or for very much worse. For the time being, it’s tightly contained, but other AI companies almost certainly will not be far behind Anthropic, and there’s no guarantee that they’ll all be quite so public-minded.
By accident or by design, the genie will eventually escape from the bottle.
The Solution
When AI can identify even the most well-hidden gap in your security and – ever eager to please – advise on the most efficient means to exploit it, the keystone of your cybersecurity strategy must be resilience: the ability to adapt to and withstand the next attack before it happens.
Cymulate helps organisations to become Mythos-ready by providing autonomous, proactive exposure validation – powered by agentic AI – to manage newly discovered vulnerabilities. The platform leverages Cymulate’s own Vero AI, alongside a comprehensive and constantly updated attack library to continuously test and validate your security controls against advanced threats. The goal is not just to run simulations, but to give security teams evidence of what is exploitable today and what they should fix first.
Better still, Cymulate recently joined the Anthropic Cyber Verification Program, part of the Project Glasswing initiative. The program is designed to give vetted cybersecurity organisations access to advanced frontier AI models, such as Mythos, for approved defensive research. Participation in this program further strengthens Cymulate’s ability to stay ahead of evolving attacker behaviour and supply continuous, AI-powered cyber defence engineering to customers.
Learn more about the program and what it means for customers here:
Cymulate Joins Anthropic Cyber Verification Program
If you’d like to find out more and see for yourself what Cymulate can do, be sure to book a call or a demo here: