ADVERTISEMENT

Anthropic develops AI model that smashes Google, OpenAI and is too dangerous for public release

Anthropic says its new AI model is a “striking leap,” beating all competition. But the €200 per month subscription won’t buy you into an exclusive club – it’s too risky to be publicly released. The model is only available for big tech cyber defenders.

Anthropic Claude Mythos

Image by Cybernews.

Ernestas Naprys
Ernestas Naprys Senior Journalist
April 8, 2026 Updated: April 8, 2026 4 min read
Has my data been leaked?

Major jump in capabilities

mythos results
Image by Anthropic.
ADVERTISEMENT
Jurgita Lapienyte justinasv Izabele Pukenaite vilius Ernestas Naprys Gintaras Radauskas
Don't miss our latest stories on Google News. Add us as your Preferred Source on Google
Add us as your Preferred Source on Google.

Already helped patch major vulnerabilities

  • A 27-year-old vulnerability in OpenBSD, one of the most security-hardened OSes powering firewalls and critical infrastructure. The attackers can exploit it to remotely crash any machine running the OS just by connecting to it.
  • A 16-year-old vulnerability in FFmpeg, a major software for video encoding and decoding. While it enables an attacker to write a few bytes of out-of-bounds data on the heap, Anthropic believes it would be challenging to turn this vulnerability into a functioning exploit.
  • A chain of several vulnerabilities in the Linux kernel. Attackers can use it to escalate privileges from ordinary user access to complete control of the system.
  • A memory-corruption vulnerability in a production memory-safe hypervisor (software to run virtual machines). Currently unpatched, therefore, the vendor is not disclosed.
  • JavaScript Just-In-Time (JIT) compiler vulnerabilities in every major browser, enabling cross-origin bypass and even sandbox escapes with local privilege escalation attacks.
  • Weaknesses in the world’s most popular cryptographic libraries, in algorithms and protocols like TLS, AES-GCM, and SSH, enabling attackers to forge certificates and decrypt communications. Two of the most serious bugs haven’t yet been patched.
  • “A myriad” of web application vulnerabilities, including multiple complete authentication bypasses, account login bypasses without requiring a password or two-factor authentication code, denial of service attacks, cross-site scripting, SQL injection, and other attacks.
  • “And several thousands more.”
exploitation
Image by Anthropic.

ADVERTISEMENT