The myth of Claude Mythos crumbles as small open models hunt the same cybersecurity bugs Anthropic showcased Anthropic has kept its Claude Mythos cybersecurity model on a short leash, pointing to capabilities it says no rival can match. But two new studies suggest that even small, openly available models can reproduce most of the vulnerability analyses Anthropic has put on display. Through Project Glasswing, Anthropic has limited access to Claude Mythos Preview to a consortium of eleven organizations, citing the model's offensive capabilities. Internal tests and an audit by the UK's AI Security Institute found that Mythos can find software bugs, build working exploits on its own, and take over entire corporate networks in simulations, as long as the network is "small, weakly defended and vulnerable." Two independent replication efforts are now poking holes in that exclusivity story, without disputing the model's overall performance. The first comes from AISLE, a company that has been running its own AI-assisted bug hunting on open source software since mid-2025. AISLE says it has reported 15 vulnerabilities in OpenSSL and five in curl. Founder Stanislav Fort fed the code snippets from Anthropic's public samples into a range of models to see how much smaller and partially open models could piece together on their own. The second study comes from Vidoc Security, which paired GPT-5.4 and Claude Opus 4.6 with the open coding agent OpenCode. Small models catch the FreeBSD bug too The FreeBSD NFS bug (CVE-2026-4747) that Anthropic spotlighted was pitched as a showcase for autonomous discovery and exploitation by Mythos. AISLE found that all eight models it tested caught the memory bug in the function in question. That included GPT-OSS-20b, a model with just 3.6 billion active parameters that runs at $0.11 per million tokens. Every model flagged the flaw as critical, though
The myth of Claude Mythos crumbles as small open models hunt the same <b>cybersecurity</b> ...
Read the original article
the-decoder.com →