Commentary: Anthropic’s Mythos AI marks a cybersecurity moment Singapore cannot ignore Even if Anthropic’s claims about its new AI model are overstated, the deeper challenge Mythos represents is very real, say NCS cybersecurity chief Foo Siang-tse and strategic adviser Shashi Jayakumar. SINGAPORE: Cybersecurity researchers tend to be a hard-bitten lot. Yet even the most jaded took notice when Anthropic announced Claude Mythos Preview on Apr 7. Here was a frontier AI lab withholding its most powerful model for being too dangerous to release to the general public. Independent verification remains limited. But if Anthropic’s claims hold up under scrutiny, Mythos has, in days, surfaced more “zero-day” vulnerabilities than the world's adversaries collectively deployed in a decade. Mythos reportedly discovered thousands of software flaws - called zero-days because they were unknown to developers and could be immediately exploited - across every major operating system and browser, including flaws dating back decades. The claims were startling, compared to what the industry had seen so far. Google's threat intelligence team, drawing on one of the most comprehensive industry datasets, tracked 75 zero-days exploited in the wild across the global software ecosystem in 2024, and 90 in 2025. The broader research community has not had the chance to fully assess what Mythos can do, beyond Anthropic’s handpicked coalition of 12 launch partners. Early signals suggest some of the headline findings may be less unique than advertised. Even if marketing hype runs ahead of reality, Mythos’ capabilities are almost certainly real, directionally. HISTORY RHYMES WITH MYTHOS Anthropic cannot indefinitely contain a capability this valuable. There have already been credible reports of unauthorised users gaining access to Mythos on the very day of its limited release, reportedly via a vulnerability in a third-party vendor's environment. We have seen where this leads. In 2017, EternalBlue, a Microsoft