Security Experts Push Back on Mythos Panic

watchTowr CEO Ben Harris put the point bluntly: teams using public models plus smart orchestration can reproduce the kinds of vulnerabilities Mythos found, with results that are very, very close. That comment, cited in a May 8 CNBC report, landed after weeks of anxiety around Anthropic's private Claude Mythos Preview. Banks, regulators and major technology companies treated the model as a new kind of cyber shock. Harris called the reaction hysteria.

Why Mythos Spooked the Market

Anthropic disclosed Claude Mythos Preview in April as a frontier model available only to 40 outside organizations, including Apple, Amazon, JPMorgan and Palo Alto Networks. In Firefox testing, it reportedly found 271 new vulnerabilities, including one that had sat unnoticed for 27 years. Anthropic's own evaluation said Mythos produced working exploits 181 times in the Firefox vulnerability set and achieved register control in another 29 cases.

Once those numbers circulated, meetings followed at the European Central Bank, Asian regulators and the White House. Jerome Powell and Scott Bessent convened Wall Street leaders, an FBI memo leaked, and Donald Trump's science adviser was drawn into the debate. Then experienced security practitioners started pushing back.

Older Models Could Already Do It

Harris' core argument is that Mythos genuinely automates the full workflow, but the underlying claim that AI can find zero-days in production code was already true last year. Anthropic itself said in a February blog post that Claude Opus 4.6, a model available to all paying users, had found more than 500 high-severity vulnerabilities in open source software. Academic and red-team work in 2025 also showed GPT-4o and Claude 3.7 paired with static-analysis frameworks finding zero-days automatically. Nation-state APT groups and mature ransomware crews, Harris argued, have already been running these workflows internally; they simply were not issuing press releases about them.

In recent meetings with banks, insurers and regulators, Harris said the questions were nearly identical: should Anthropic be blocked urgently, and have our repositories already been scanned? His answer was that adversaries were doing this three months ago, and banning Anthropic does not stop anyone else from scanning your code.

What Actually Changed

Strip away the hype and Mythos appears different in two important ways. The first is speed and accessibility. Using Opus 4.6 to find a zero-day still required a security engineer who understood exploitation, along with scripts and repeated iteration; one bug could take days or weeks. Mythos can let a junior engineer with limited exploit-development experience move from discovery to a working exploit overnight. That is a major cost reduction.

The second is scale. Opus 4.6 was more targeted. Mythos scans at broad scale across hundreds of targets in parallel. Together, those curves change the tempo of offense and defense. Defenders who once had months to patch a vulnerability may now have days or even hours. But Harris' point is that this is not a sudden break; it is the continuation of the 2025 trend line.

Why Anthropic Turned Up the Volume

Anthropic presents the release as a responsible warning. Mythos is limited to 40 companies, and the company paired it with the Project Glasswing alliance involving AWS, Apple, Microsoft, Google, CrowdStrike and Palo Alto Networks, giving defenders early access.

Some security professionals see more strategy in the narrative. One reading is that Anthropic wants to make "AI cyber weapons" its signature issue and give regulators and Wall Street a reason to treat the company as essential. Another is that Anthropic wants rivals, especially open models and companies such as DeepSeek that have faced questions about data provenance, pulled into the same tighter regulatory frame. Harris did not accuse Anthropic of hype directly. His word choice was narrower: the reaction was hysteria, putting the problem on the people reacting rather than the company releasing the model.

The Real Signal

The most important part of the episode is not Mythos itself. It is that the industry now treats AI-assisted zero-day discovery as a default assumption. This is no longer a possible future; it is happening now.

That changes the operating logic. Vulnerability disclosure windows will compress, forcing CISA and vendors to rethink response SLAs. Software suppliers can no longer assume old code is too obscure to attract attention. The red-team tools market shifts from selling labor to selling models plus orchestration. Cyber insurance pricing will need to change as AI flattens the cost curve for attackers.

The next thing to watch is how Anthropic tells the Mythos story on its third-quarter earnings call. If AI cybersecurity becomes a named business line and revenue disclosure starts leaning in that direction, the commercial intent behind the hysteria will be much harder to miss.

Sources: Anthropic's Mythos set off a cybersecurity 'hysteria.' Experts say the threat was already here (CNBC); CocoLoop; Our evaluation of Claude Mythos Preview's cyber capabilities (UK AISI)