Anthropic says Zhipu's freely downloadable GLM-5.3 built working V8 exploits in 50 of 410 tries, against 56 for its own restricted Claude Mythos Preview. With the weights public, its safeguards come off cheaply, so a lab that restricts its own model no longer keeps the capability out of reach.
Perspective Coverage
4 publishers
- Builder
- Builder 41%
- Operator
- Operator 38%
- Investor
- Investor 21%
Reality
- Evidence62
- Adoption30
- Hype gap+15
- Incentives72
- Confidence62
VulnCheck counts Chrome CVEs up 563% and GitHub-issued CVEs up 476% this year, a rise it calls consistent with AI-assisted bug finding. Whether the volume lasts is unknown, so exploitation data still sets patch order.
Reality
- Evidence55
- Adoption45
- Hype gap+20
- Incentives55
- Confidence50
Horizon3 used Anthropic's Mythos model to find CVE-2026-61500, a chain that forges Rejetto HFS admin sessions and reaches remote code execution. The firm expects frontier models to make deeper, less reliable bug classes worth weaponizing at scale.
Reality
- Evidence55
- Adoption15
- Hype gap+30
- Incentives70
- Confidence50
Palo Alto Networks pointed Anthropic's unreleased Mythos at its own systems and found 75 vulnerabilities in a month, against a usual rate below five. The defense business it built on that result depends on Anthropic's model and on customers choosing a security vendor over the lab.
Reality
- Evidence45
- Adoption30
- Hype gap+35
- Incentives80
- Confidence50
Anthropic says Zhipu AI's downloadable GLM-5.3 builds cyber exploits on its own, with safeguards that fail against simple attacks up to 100% of the time. It puts a capability once confined to gated frontier models within anyone's reach.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+20
- Incentives75
- Confidence50
Apache Software Foundation teams scanned 230 repositories with Anthropic's Claude Mythos 5 over three days in August 2026. Findings now go to the projects that own the code through the foundation's official disclosure path, and remediation has started.
Reality
- Evidence48
- Adoption58
- Hype gap+12
- Incentives70
- Confidence52
A vendor coalition has formed around OpenAI's call for a surge in cyber defense. What an underfunded defender can actually requisition from it today is one subsidized model tier, on terms the letter does not state.
Perspective Coverage
5 publishers
- Builder
- Builder 25%
- Operator
- Operator 48%
- Investor
- Investor 27%
Reality
- Evidence55
- Adoption15
- Hype gap+40
- Incentives72
- Confidence62
The top four slots on Artificial Analysis are the advertisement. The line item Anthropic actually moved is the one that scales with how long an agent runs, and its own savings estimate backs out that share at about 60 percent.
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+15
- Incentives62
- Confidence60
The top rung of OpenAI's Preparedness Framework has now been reached by OpenAI, on a model it has not shipped, which moves AI-assisted exploitation out of argument and into a named vendor's published paperwork.
Perspective Coverage
5 publishers
- Builder
- Builder 28%
- Operator
- Operator 42%
- Investor
- Investor 30%
Reality
- Evidence35
- Adoption3
- Hype gap+30
- Incentives70
- Confidence55
Anthropic says Claude Mythos Preview found and exploited previously unknown flaws in every major operating system and web browser during a month of testing. Its disclosure process keeps the rest unnamed until patches ship.
Publishers:red.anthropic.com
Reality
- Evidence36
- Adoption20
- Hype gap+35
- Incentives78
- Confidence55
Cloudflare pointed Anthropic's Mythos Preview at more than fifty of its own repositories and watched it write, compile and run its own proofs of exploitability. Its refusals on identical code did not repeat.
Reality
- Evidence34
- Adoption26
- Hype gap+18
- Incentives62
- Confidence44
The company says the architecture around a bug matters more than how fast the patch ships, and it is making that case on a stack built from its own products after watching an AI assistant fix bugs and break their dependencies.
Reality
- Evidence34
- Adoption25
- Hype gap+18
- Incentives82
- Confidence55
A GET asks a site for a page and a POST tells it to act, so the change Akamai measured over 30 days puts verified AI bots on the request type behind store logins, carts and checkouts. Akamai did not break those requests down by action; retailers have that in their own logs.
Reality
- Evidence36
- Adoption42
- Hype gap+28
- Incentives80
- Confidence40
Oracle put ChatGPT Enterprise and OpenAI's Codex in front of about 160,000 employees in April, and 80 percent were using them within three months. Then the bills arrived and, the CIO said, surprised the company.
Reality
- Evidence40
- Adoption68
- Hype gap+15
- Incentives68
- Confidence46
Luke Heath's written answers to Lets Data Science put eight named controls around the model, among them scoped credentials, engineer approval and hand reproduction of every candidate finding. Heath has not disclosed results yet.
Reality
- Evidence45
- Adoption20
- Hype gap−10
- Incentives70
- Confidence50
The June 12 order covered only foreign nationals, but Anthropic said it could not check nationality in real time, so it suspended Fable 5 and Mythos 5 for every user. Fable 5 came back 19 days later, on new usage terms.
Reality
- Evidence45
- Adoption45
- Hype gap+20
- Incentives80
- Confidence50
Chainguard says fix generation was never its bottleneck and that responsible disclosure at scale is, so its first public batch is built from bugs upstreams quietly fixed years ago and never filed CVEs for.
Publishers:chainguard.dev
Reality
- Evidence34
- Adoption16
- Hype gap+28
- Incentives82
- Confidence48
VulnCheck's first-half figures put the median at 80 days, down from 120 in 2025, while the count of CVEs exploited within a month of publication held flat near 200. The tier that breaks is the 90-day one.
Reality
- Evidence58
- Adoption62
- Hype gap−12
- Incentives70
- Confidence55
Project Glasswing surfaced an estimated 6,202 high or critical vulnerabilities in foundational open source, with 97 confirmed fixed in two months. What the confirmation count actually measures decides how much of that gap is real.
Reality
- Evidence22
- Adoption
- Insufficient
- Hype gap+45
- Incentives60
- Confidence28
Anil Madhavapeddy patched a path traversal bug in OCaml's cohttp and found probes for it in his logs ten minutes after opening the fix PR. His own agent had already built the exploit from a bug-class hint.
Publishers:anil.recoil.org
Reality
- Evidence52
- Adoption44
- Hype gap+14
- Incentives55
- Confidence57
Earlier coverage
- OpenAI test found agents breaching Hugging Face; CrowdStrike touts new tools to police shadow AI
Product · September 10, 2026 · 1 publisher
- Anthropic hands an unreleased bug-finding model to more than 50 organisations
Security · September 9, 2026 · 1 publisher
- Sysdig credits Anthropic's Mythos preview with 181 working Firefox exploits
Security · September 6, 2026 · 1 publisher
- Arista tells network teams to staff for months of batched EOS and VeloCloud advisories
Security · September 6, 2026 · 1 publisher
- Recorded Future's half-year data shows adversaries continuing to favor abusing legitimate tools and trusted platforms already inside the enterprise
Security · September 3, 2026 · 1 publisher
- The exploit was the toll gate: Gartner's top emerging risk moved five places in one quarter
Security · August 26, 2026 · 1 publisher
- Anthropic's GitHub scanner goes Enterprise-only, and the model behind it is not established
Build · August 21, 2026 · 1 publisher
- Harness hands vulnerability triage to agents, and concedes code fixes cannot keep pace
Product · August 19, 2026 · 2 publishers
- The disclosure pipeline is triaging itself: 20,700 new CVEs, 10% more exploitation
Security · August 19, 2026 · 1 publisher
- Kraken's parent now runs a security model that Washington can switch off
Invest · August 17, 2026 · 1 publisher
- Anthropic found 10,000 critical bugs. The bottleneck is now the person reading the report
Build · August 17, 2026 · 1 publisher
- Z.ai held back its own GLM-5.3 weights, and open-weight roadmaps have a new failure mode
Leadership · August 17, 2026 · 3 publishers
- Claude's system prompt grew ninefold in two years. Version yours like code.
Build · August 16, 2026 · 1 publisher