A third-party contractor enabled unauthorized access to Mythos, Anthropic's restricted AI model capable of exploiting every major OS and browser.
Anthropic's Claude Mythos Preview — a cybersecurity AI model capable of identifying and exploiting vulnerabilities across all major operating systems and browsers — was accessed by an unauthorized group through a third-party contractor's credentials. The model is officially restricted to a small set of companies (Nvidia, Google, AWS, Apple, Microsoft) via the Project Glasswing initiative and has no planned public release. The unauthorized group, operating from a private online forum, used the contractor's access combined with internet sleuthing tools to gain entry. Anthropic confirmed the breach is under investigation but stated there is currently no evidence of impact beyond the third-party vendor environment.
This breach didn't happen through Anthropic's core systems — it came through a contractor. If you're building AI products that rely on third-party vendor access to restricted models or APIs, your security perimeter is only as strong as your weakest vendor contract. The fact that a model capable of OS and browser-level exploitation is now in the wild means threat actors have a new automated pentesting tool that wasn't accessible before yesterday.
Audit every third-party vendor in your stack that has API key or model access rights — check whether access is scoped by least privilege and whether key rotation policies exist. If any vendor has persistent, unrotated access tokens to your AI infrastructure, revoke and reissue them this week.
Go to github.com and open your organization's repository settings under 'Security & Analysis'
Tags