Claude Mythos: what it means for your cyber security strategy
How Anthropic’s Claude Mythos has gained traction since launch.


Since it's accidental leak on 26 March, and subsequent official release on 7 April 7, Anthropic's new(ish) frontier model named "Claude Mythos" has gathered a significant amount of interest globally, specifically from the security community. But why?
Testing AI models
Firstly, it's important to explain what it actually is and why it exists. "Claude" is the broad AI system developed and sold by Anthropic, and "Mythos" is a new model developed for us in the Claude ecosystem. When it was first announced, it was known as "Mythos Preview". The researchers whose responsibility it is to test and track the progress of every AI model launched, then discovered that Mythos showed an exceptional step up in offensive cyber security capabilities.
One of the primary research institutions globally that carry out these tests is AISI (AI Security Institute), based in London. It's important that we understand from a high-level how these tests are carried out, and how we can track the data of these tests to provide context on why, where, and how this raises concern from a cyber and infosec perspective. AISI has been carrying out these tests since 2023 and I implore you to check out their website, where you can find reports and in-depth analysis on the tests.
The AISI tests are broken down into two categories, a classic capture-the-flag (CTF) test, and a multi-stage cyber range test on the AISI platform called "The Last One's" - not 100% sure why that is named so ominously.
- The CTF: This is a linear test with a several single outcomes, the "flag" as it were, is a series of tests one after the other. AISI split the CTF into two difficulty settings for the models, called apprentice and technical non-expert. The models are then positioned to have several "runs" at capturing the flags, measuring their percentage completion against the number of tokens used. To give an indication of Mythos performance, Claude Opus 4 (released in May 2025), took ten runs, consuming 2.5M tokens for 80% completion as a technical non-expert. Mythos took half the amount of runs whilst consuming the same amount of tokens, for nearly 100% completion.
- The Last Ones: This is AISI's ultimate test. CTFs are great, but only test skills in isolation. Expert human threat actors have to deploy multiple skills in parallel, and The Last One's (TLO) tests this mapped to real life tactics, techniques, and procedures (TTPs). There are 32 steps involved in a multi-stage network takeover. Mythos Preview is the first model to ever solve TLO using three of its ten attempts, meaning it completed everything from reconnaissance to network takeover, and across all of its ten attempts completed an average of 22 steps out of 32, consuming around 100M tokens cumulatively.
Now immediately this does raise alarms, but it is also worth noting that AISI has started to develop contextual tests relevant to certain industries. An example is critical national infrastructure, the first of which is called "Cooling Tower" and focuses on compromising an operational technology (OT) which Mythos Preview failed to complete.
It is also really important to understand, that while these tests are incredibly effective at testing model capability, they do not account for common security controls, or in fact, the presence of human defenders. Nor is there a penalty for tripping defences like in a real-world scenario. AISI is working at building this in though, which is fantastic.
The important thing is though - AISI can see that AI models are doubling in capability roughly every four months, so by September as I'm writing this, there will be something twice as good as Mythos is now - that is the real concern.
The response - Project Glasswing and impact
Due to the rapid success of the Mythos preview model, Anthropic realised that it could discover and exploit vulnerabilities in systems much faster than human researchers, which is where the panic from the security community came from. So rather than releasing the model on general availability, it set up a "core" community of vendors and critical organisations to give them a 12 month period in which they could evaluate their own software and firmware against, plus how they could incorporate it in to their security products if applicable. That core group is organised as follows:
- Cloud service providers and large software companies: Microsoft, Google, Amazon Web Services, The Linux Foundation
- Hardware and chip manufacturers: NVIDIA, Apple, Broadcom
- Security companies: CrowdStrike, Cisco, Palo Alto
- Global critical infrastructure providers: JPMorgan Chase
Now, speaking with Softcat's key partners who make up the core 12 of Project Glasswing, and although at the time of writing they have only had six weeks or so with Mythos Preview, their reaction is one of deliberate focus, but also quiet optimism. The broader impact of Mythos-like models in general means a couple of things:
- Over the next 6-12 months these vendors will be releasing a deluge of patches for their own software and firmware.
- Once Mythos is in general availability (and much before if you're a nation state actor) the capabilities of cyber-crime actors will be greatly increased.
- We must patch and fix very quickly to avoid any potential exploits, many of which will be in Internet facing assets.
- The importance of your hardware being supported by the vendor and any intermediary party is crucial. The harsh reality is that a lot of us will need to replace hardware like switches, compute, storage, and firewalls. In the midst of a RAM and GPU shortage, we need to understand what this inventory looks like now.
What can we do?
Patching and Exposure Management
Well, the first thing we need to do is review our patching, vulnerability, and exposure management practices quickly. Can we mobilise patches and fixes and deploy them immediately? Do our processes around change and release management help or hinder us?
Do we have a genuine, catalogued inventory of devices, software and firmware across our estate? How do we identify End of Sale (EoS) and End of Life (EoL) kit? Can we cover our on-premise, cloud, and application estate?
Do we have live, programmatic vulnerability management baked into the above? Do we apply any cyber threat intelligence to enable us to prioritise based on our industry? Do we collate this with our SOC to setup proactive services such as threat hunting?
How automated is our client and server patching? Can we do the same with our other infrastructure such as networking and security appliances?
Protective controls
I think with Mythos plus the proliferation of Agentic AI, we need to realise lateral movement is not as far down the kill chain as we have previously understood. Typically, when we know a threat actor has achieved lateral movement today, this is considered as a breach and we treat it as an emergency situation, and rightly so. With AI agents, lateral movement will now form a key part of malicious actors way to compromise organisations, and I firmly believe the agents are and will become the new endpoints, meaning that catching lateral movement and stopping it is more important.
All that considered, network security controls get brought back into the limelight and modern versions of:
- Network detection and response (NDR): I think we will see a move from firewalls to include this functionality natively. As mirroring traffic and deploying dedicated infrastructure is too cumbersome and introduces too much latency for AI systems. NDR will then be critical to detect and respond to malicious agent behaviour across our networks, as it has done in more niche use cases for years.
- Micro-segmentation: Combined with NDR, the ability to prevent behaviours and mandate activity is crucial. For post-Mythos exploits, this will also act as a platform where we can deploy what has been known in the past as "virtual" patches. Countermeasures we can use to protect devices that are unsupported or are sensitive to patch.
- AI Observability: Tracking and understanding AI agents as we do with our regular endpoints now is crucial. This is not as straightforward as just placing a piece of software on them though. We will need to use Identity as an example to feed these observability tools. Things like the CAEP (Continuous Access Evaluation Profile) protocol, part of the OAuth suite, will be critical in understanding up to date agent behaviour and acting on it from a security sense.
The noise around Mythos
The noise around Mythos is understandable, but like most things in life, if we assess the facts and draw conclusions from them, we're in a good place:
- When assessed by AISI Mythos Preview surpassed previous model performance: when conducting testing, raising concerns about its ability to be used maliciously if released, to exploit vulnerabilities at a rapid rate with little human intervention.
- In response, Anthropic delayed the public release, and announced a core group of 12 organisations that would be granted initial access for testing and evaluations purposes, this is called Project Glasswing and has since expanded to over 40 organisations.
- There is a high likelihood that we will be hit with a large amount of CVEs from key vendors due to them using Mythos to uncover them. We must be prepared to address these quickly.
- There will also be an impact on organisations operating infrastructure that is out of support but is exploitable. Combined with current hardware constraints around GPU and RAM, this is imperative to flag and address early.
- Protective controls we have known for a long time are changing, and some will come back into focus as the network once again becomes more important to organisations for security, due to agentic AI, and Mythos-like threats.
ore. I'm writing this currently listening to one of my favourite all time progressive house tracks, Teenage Crime by Adrian Lux (what a tune). Let's make sure we progress into what's coming as prepared as we can be!
If you’d like to find out more about how this could impact your organisation, please get in touch with us.