@YafahEdelman: I continue to be surprised about how big of a deal Mythos (and co) have been to cybersecurity. Here's critical vulns fo…
Summary
The article highlights the significant role of AI models like Mythos in cybersecurity, revealing a surge in critical vulnerabilities at Oracle and detailing AI-driven discovery efforts by Anthropic and OpenAI.
View Cached Full Text
Cached at: 08/22/26, 09:29 AM
I continue to be surprised about how big of a deal Mythos (and co) have been to cybersecurity. Here’s critical vulns found at Oracle over the past few years: https://epoch.ai/data/cve?view=graph&source=Oracle…
Cyber Vulnerabilities
Source: https://epoch.ai/data/cve?view=graph&source=Oracle Data: CVE records come from the CVE Program’scvelistV5 repository. We process every published record from 2020 onward. The dates visualized on our explorer represent vulnerability publication dates, not discovery dates.
Severity: CVE severities are based on theCommon Vulnerability Scoring System(CVSS). CVSS assigns a score between 0 and 10, according to factors like the attack complexity, required privileges, the scope of the vulnerability, and more. These numeric scores are then assigned to severity categories as follows:
- None: 0.0
- Low: 0.1 - 3.9
- Medium: 4.0 - 6.9
- High: 7.0 - 8.9
- Critical: 9.0 - 10.0
We default to using a CNA’s own assessment first, and fill in gaps with assessments from third parties (known as Authorized Data Publishers, or ADPs). If multiple CVSS versions are given, we default to v4.0, with fallback to v3.1, then v3.0. Records without one of these CVSS scores are counted as “Unknown.”
Reporting organizations (CNAs): Every CVE record is assigned by a CNA (CVE Numbering Authority) — typically the vendor of the affected product or a third-party security research organization. We count CVEs across all CNAs, but to keep the underlying data manageable we only break down individual counts for notable CNAs, with non-notable CNAs grouped into an “Other” category.
We consider a CNA notable if it is a vendor of widely-deployed software or hardware, or a major open-source project or foundation, and it maintains an active CVE program (we require at least 50 CVEs published since 2020). We include the following organizations in our list of notable CNAs:
- Major vendors (17): Microsoft · Google · Apple · Adobe · Oracle · Cisco · IBM · Red Hat · Intel · AMD · NVIDIA · Qualcomm · Samsung · SAP · Amazon (AWS) · VMware (Broadcom) · GitHub (own products)
- Open source (4): Linux · Mozilla · Apache · OpenSSL
Reporting practices vary substantially across organizations, creating noise. For instance, Linux became a CNA in February 2024 and subsequently began assigning CVEs for thousands of backported bug fixes, leading to a high number of reports in 2024 and 2025.
Individual records: Alongside the aggregates, we surface individual High and Critical severity CVEs from notable CNAs, each linking back to its official CVE record. See the “Table” view in the explorer above, or download our data at the link below.
Our explorer visualizes the announcement date ofClaude Mythos Preview(April 7, 2026), which coincided with a large jump in the number of new vulnerability reports. Anthropic claimed that Claude Mythos was capable of autonomous vulnerability discovery, andgave trusted partners access to the modelin order to harden their software. Mythos Preview was used to find bugs in software before the April 7th announcement, which may have contributed to an increased number of reports in the month before the announcement. As of May 22nd, Anthropic claimed that Mythos Preview had been used to identifymore than ten thousand high- or critical-severity bugs(not all of which had been publicly reported). Additionally, OpenAI has claimed that GPT-5.5 (released April 23) and GPT-5.5-cyber (May 7) are also capable of advanced cybersecurity tasks, and launched a similartrusted-partner programon May 7th, 2026.
Similar Articles
@logangraham: A lot of people have been wondering about Mythos, Glasswing, and the vulns we / our partners are fixing. Today, I’m exc…
Anthropic's Claude Mythos Preview model has been evaluated by XBOW and UK AISI, showing unprecedented autonomous cybersecurity capabilities, including solving end-to-end cyber ranges and finding thousands of vulnerabilities. The announcement emphasizes the need to prepare for rapidly advancing AI capabilities in cybersecurity.
@heyshrutimishra: We've been watching the wrong AI story. While the timeline keeps debating whether Mythos is real, hyped, or just well-m…
A thread contrasts the hype around AI security startup Mythos with 360's practical achievement of autonomously discovering 23 vulnerabilities (including two criticals) in the OpenClaw ecosystem, highlighting the real direction of AI security.
Mythos finds a curl vulnerability
Daniel Stenberg reports that Anthropic's Mythos AI model identified a vulnerability in curl, highlighting the growing role of advanced AI in security auditing while noting initial access hurdles via the Linux Foundation.
Cloudflare Warns Mythos AI Can Build Real Cyberattacks Ahead of AI Giant's G20 Briefing
Cloudflare's testing of Anthropic's Mythos Preview reveals the model can chain multiple low-severity bugs into working exploits, a major step in offensive cybersecurity AI, as Anthropic prepares to brief G20 officials on related risks.
@Dan_Jeffries1: Finally a semi-useful read on Mythos that is free of myth and talks about what this means more practically (not this is…
Dan Jeffries comments on Cloudflare's testing of Anthropic's Mythos, arguing that the real conversation should focus on practical security improvements against AI-powered attacks, and that AI will ultimately make software more secure if teams adapt their workflows.