More broadly, across Project Glasswing, Mythos has identified more than 10,000 high- or critical-severity vulnerabilities across the world's most systemically important software since the program launched . Anthropic's own coordinated vulnerability disclosure dashboard reports 1,596 disclosed vulnerabilities across 281 open-source projects as of May 22, 2026, with roughly 23,019 findings triaged and 1,900 candidates prioritized .
The gap between discovery and remediation has been described as an existential triage crisis — the AI finds flaws faster than human patch teams can analyze, reproduce, and fix them . Internal Microsoft presentations reportedly acknowledge the company cannot keep pace with the Mythos-driven discovery rate . An internal slide from a Microsoft presentation noted that the company plans to eventually address moderate-severity flaws, but the immediate focus is on critical and important vulnerabilities only .
On July 14, 2026, Microsoft shipped its largest Patch Tuesday in history, addressing 622 vulnerabilities — triple the June 2026 count and roughly five times the monthly average . Counts vary slightly by source, with some reporting 569–622 CVEs . The release included:
CrowdStrike noted this release "reinforces that the era of 'small' Patch Tuesdays may be over as AI-driven vulnerability discovery ramps up" . Just one month earlier, June 2026 had already broken the previous record with 206 CVEs .
Hitachi joined Project Glasswing in June 2026, gaining access to Claude Mythos Preview to audit its social infrastructure software — particularly in the energy sector . On July 28, 2026, Hitachi reported that Mythos reduced security validation processes from weeks to dramatically shorter timeframes, successfully creating threat models for millions of lines of source code and confirming the model's practical applicability to critical infrastructure .
On June 22, 2026, the Five Eyes intelligence alliance (US, UK, Canada, Australia, New Zealand) issued a rare joint public statement warning that cutting-edge AI models are poised to supercharge offensive hacking capabilities within months, not years . The alliance stated: "Frontier AI models are anticipated to exceed current industry expectations, fundamentally transforming both offensive and defensive cyber capabilities. The timeline is not years, it is months" . The warning came weeks after the Trump administration ordered Anthropic to restrict access to its Mythos and Fable models for foreign nationals . While the Five Eyes statement did not name specific companies, Reuters and other outlets linked the urgency directly to concerns about Anthropic's Mythos model .
The Mythos discovery rate has exposed a fundamental mismatch between AI-powered vulnerability discovery and human-led remediation. Security experts have raised concerns:
As one security analyst noted: "Before, we worried about finding bugs. Now, we worry about finding them faster than we can fix them. The bottleneck has shifted from discovery to remediation — and we don't have AI for that yet."
The Five Eyes advisory listed five practical actions for businesses: reduce attack surface, patch more quickly, assume breach, invest in detection and response, and harden identity infrastructure . For most enterprise security teams, this means rethinking vulnerability management programs that were designed for a human-paced discovery world. Automated patching, AI-assisted triage, and risk-based prioritization are no longer optional — they are survival tactics.
Anthropic's Claude Mythos has proven that AI can find vulnerabilities at unprecedented scale and speed. The question now is whether the global cybersecurity ecosystem can evolve fast enough to patch them.