Don't Panic: Muse on Mythos
Mythos is Anthropic's most capable model yet. What makes it different isn't that it can find vulnerabilities - AI has been doing that for a while. What's new is that it can chain attack steps together autonomously: reconnaissance, discovery, exploitation, in sequence, without a human guiding each move.
Anthropic took the unusual step of not releasing it publicly. Instead, they launched Project Glasswing - giving vetted vendors access to use Mythos to find and fix vulnerabilities before it potentially falls into the wrong hands.
That's a responsible move. It's also, frankly, a smart PR one. However, the underlying capability is real.
The UK's AI Security Institute didn't just take Anthropic's word for it. They ran their own evaluations.
They built a 32-step corporate network attack simulation - the kind of operation a skilled human attacker needs around 20 hours to complete end-to-end.
Here's what Mythos managed:
Completed the full scenario in 3 out of 10 attempts; Averaged 22 of 32 steps across all attempts; Tested with no active defenders, no endpoint detection, no penalties for triggering alerts.
That last point is the one I keep coming back to. AISI said explicitly they "cannot say for sure" whether Mythos would succeed against a well-defended system.
This is significant. Not because it makes Mythos harmless - it doesn't - but because it tells you exactly where the risk sits: in organisations with weak security posture and limited detection capability.
If that's not you, this is a warning to heed, not a crisis to manage.
The trend line is the real story: I want to be clear about something, because I think it gets lost in the noise around specific models.
18 months ago, the best AI models completed fewer than 2 steps of this same attack simulation. Today's best completes over 15. A full attack attempt now costs around £65.
Meanwhile, separate from Mythos entirely, the Zero Day Clock project shows that 72% of exploited vulnerabilities in 2026 were zero-days, up from 16% in 2018. The 30-day patch window that the industry built its vulnerability management processes around is, for practical purposes, gone.
Mythos didn't cause this shift. It's a product of it.
What we're doing about it at Muse Cyber
I reached out to our partners at Aikido Security this week, specifically to understand how their platform maps to what Mythos is doing. Their response was direct: this isn't a surprise to us, and we built for it.
Aikido's platform already operates across the entire software development lifecycle, not just point-in-time scans. It chains across code, APIs, dependencies, and cloud because chaining is where the real risk lives. Their pipeline works in three stages: find, validate, fix. Not just surface issues and hand them over but actually confirm exploitability and support remediation.
Most importantly: they're not theorising. Aikido has run over 1,000 of these AI-driven tests in live production environments in under six months. The types of chained, complex vulnerabilities Mythos made headlines for finding? Their stack has been finding them already.
They don't have formal Glasswing participation yet but they're following events closely, and confident their offer to the market is on point for targeted use iin a company.
The bottom line for Muse clients: you don't need to wait for frontier AI models to become widely available before your defences catch up. That work is already happening.