Use of AI model Mythos finds over 10,000 vulnerabilities, urgent fixes needed
Over 10,000 defects found in high-performance AI
Anthropic said on the 22nd that companies using its high-performance artificial intelligence (AI) model 'Mythos' had found more than 10,000 high-risk software vulnerabilities. The company said firms need to move up their patching plans before AI at the same level becomes widely used.
Testing at 50 companies shows need for swift fixes
In April, Anthropic did not make Mythos publicly available, citing its high cyberattack capabilities, and instead provided it on a priority basis to about 50 companies, mainly U.S. technology firms. When these companies tested their own software, they found several hundred vulnerabilities at each company, and more than 10,000 in total.
Vulnerabilities are flaws in software or systems that, if exploited, could lead to unauthorized access or information leaks. Because the programs that determine software design and operation are vast and updated frequently, vulnerabilities themselves are not uncommon.
Newly reported vulnerabilities reached 46,000 in 2025 alone, and an international body classifies them into four levels by severity: 'emergency', 'important', 'warning' and 'caution'. The issues pointed out this time by the companies using Mythos and by Anthropic are believed to fall into the 'emergency' and 'important' levels, which account for half of the total.
6,200 flaws also detected in open-source software
The company analyzed more than 1,000 open-source software programs that are publicly available and can be used by anyone. Mythos found 6,200 high-risk vulnerabilities in this testing. When 1,700 of them were re-evaluated, about 60% were confirmed to be genuinely high-risk vulnerabilities.
For example, in encryption software widely used around the world, Mythos created an attack method that forged certificates and enabled impersonation. The vulnerability was reported to the developer and has already been fixed, the report said.
AI is evolving quickly, and AI with performance on par with Mythos is expected to become available in the future. Even if defenders can uncover large numbers of vulnerabilities, the risk of them being exploited by attackers rises if the creation and deployment of patches cannot keep pace.
Anthropic said relying only on human labor to test and fix vulnerabilities would become a major bottleneck. It said it is necessary to promote the use of AI to save time, while also building systems such as simplifying procedures for testing patches and increasing the frequency of checks.
Mythos is currently available only on a limited basis, but Japan's three mega banks and others are expected to gain access soon. Anthropic plans to further expand availability by working with important partners, including the U.S. government and allied governments.
Enjoyed this article? Share it with your network!