Anthropic's Mythos Model 'Far Ahead' in Cyber Capabilities

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Anthropic is privately warning top government officials that its unreleased model 'Mythos' makes large-scale cyberattacks much more likely in 2026, and a source briefed on coming models told Axios a major attack could hit this year.
- An unpublished Anthropic blog post obtained by Fortune says Mythos is 'currently far ahead of any other AI model in cyber capabilities' and 'presages an upcoming wave of models that can exploit vulnerabilities in ways that far outpace the efforts of defenders.'
- Mythos lets AI agents operate autonomously with high sophistication to penetrate corporate, government, and municipal systems — Axios describes the threat as 'a warehouse full of the most sophisticated criminals who never sleep.'
- Anthropic disclosed late last year that a Chinese state-sponsored group used AI agents to autonomously hack roughly 30 global targets, with the AI handling 80–90% of tactical operations independently — the first documented case of a largely AI-executed cyberattack.
- Bad actors can now scale with compute alone: a single person can run campaigns that once required entire teams, and a Dark Reading poll found 48% of cybersecurity professionals rank agentic AI as the No. 1 attack vector for 2026, above deepfakes.
- Employees connecting tools like Claude and Copilot to internal work systems — often from home — are creating what the industry calls 'shadow AI,' unknowingly opening new doors for cybercriminals to enter corporate networks.
Why it matters: Every company using agentic AI tools now faces a rapidly expanding attack surface, with 48% of cybersecurity professionals naming it the top threat vector for 2026. A single attacker with compute can run campaigns that once required whole teams, and employees experimenting with agents at home are unwittingly connecting internal systems to outside risk — Axios says this is already the biggest threat to its own operations.




