Anthropic's April 2026 introduction of Claude Mythos Preview and Project Glasswing is a significant development in AI-assisted security research. The company says Mythos Preview can identify vulnerabilities across major software stacks and, in some cases, autonomously exploit them. That work includes weaknesses in cryptographic libraries used for TLS, AES-GCM, and SSH.
The most important story is not a public release of two standalone academic papers on attacks called HAWK and AES. Anthropic's public materials instead describe a broader, coordinated vulnerability-disclosure effort, with selective technical disclosures while many affected issues remain under patching timelines. The distinction matters: public evidence supports the model's role in finding and building attacks against cryptographic software, but not every reported exploit or underlying technical detail is yet publicly available.
Anthropic's official Mythos Preview research announcement presents the initiative as both a security capability demonstration and a warning for defenders. The company says it has submitted high- to critical-severity reports through its disclosure program, and that most vulnerabilities it found remain unpatched in the wild.








