What Is Mythos: The Nature of AI Attacks and How to Respond
Anthropic's Claude Mythos Preview and Project Glasswing have recently drawn significant attention across the global security industry. Some see them as evidence of a new class of AI-driven attacks, but that view does not fully capture what this case represents.
This case is better understood not as the arrival of a new attack technique, but as evidence that AI can significantly increase the speed and automation involved in vulnerability discovery, exploitation, and attack scenario execution.
In other words, the nature of attacks has not changed. What is changing is the speed and scale at which attacks can be carried out.

What Is Mythos and Glasswing?
On April 7, 2026, Anthropic announced Claude Mythos Preview, its latest frontier model, along with Project Glasswing.
Claude Mythos Preview
- An LLM-based model for security analysis
- Specialized in discovering vulnerabilities and generating exploits
- Demonstrated the potential to generate highly automated attack scenarios in restricted environments
What makes the model notable is its ability to move from vulnerability discovery to working exploit generation.
Project Glasswing
- A partnership involving major companies, including AWS(Amazon Web Services), Microsoft, Google, Cisco, and CrowdStrike
- A security research initiative aimed at proactively identifying and remediating vulnerabilities in critical software and infrastructure
- Operated through a restricted partner-based model, not as a publicly available program
In this sense, the project should be understood not as the spread of an attack tool, but as an effort to use AI-based vulnerability discovery capabilities for defensive purposes.
Same attacks, greater speed and automation
AI is not changing the attack flow. Instead, it is changing how quickly and automatically that flow can be executed.
AI-driven attacks still follow the conventional attack flow.
- Exploitation of vulnerabilities
- Malware execution
- Privilege escalation
- Lateral movement
However, the adoption of AI is creating the following changes.
- A sharp increase in the speed of vulnerability discovery
- Automation of repeated attacks
- More sophisticated attack scenarios
- Lower barriers to entry for attacks
Gartner describes this as a structural shift in which the time gap between vulnerability discovery and exploitation is rapidly shrinking. Bain & Company also points out that AI-based attacks have already become a reality.
Why Prevention-Only Security Has Reached Its Limits
Traditional security strategies have been designed around prevention. However, as attacks become faster and more automated, this approach is increasingly showing its limits.
Three major shifts are becoming more apparent.
First, more attacks are exploiting the gap between vulnerability disclosure and patch deployment.
Second, automation enables attackers to repeat and scale the same attack rapidly.
Third, AI is significantly increasing the number of vulnerabilities being discovered.
Together, these changes are fundamentally shifting the focus of security.
Security Criteria Are Shifting Toward Exposure Management
The way organizations measure security effectiveness is changing. In the past, organizations often measured vulnerability response by MTTR (mean time to remediate, or how quickly they could apply patches.)
Now, the focus is expanding beyond patch speed. Security teams are also looking at the exposure window, meaning how long a vulnerability remains exposed, as well as how quickly they can detect threats and respond.
Gartner defines this as a shift to exposure management and emphasizes that security KPIs are changing as well.
Our Perspective: A Shift in Defense Models
We do not view the Mythos issue simply as a crisis. Rather, we see it as a turning point in the way security operations are conducted.
The most important changes are:
- Limits of human-centered security operations: Security teams can no longer rely on manual analysis and response for every alert.
- The need for AI-based security operations: Organizations need to apply AI across detection, analysis, and response.
- Recognition of AI as an actor: AI is no longer just a tool. Organizations must also identify, monitor, and control AI as an active participant in the security environment.
Security strategies will need to evolve in two directions: using AI to strengthen defense, and building controls to identify, monitor, and govern AI itself.
How Enterprises Should Prepare for AI-Driven Attacks
Enterprises need to move beyond a prevention-centered model and build security operations around visibility, detection, analysis, and response. This starts with maintaining clear asset visibility and strengthening vulnerability management.
Behavior-based detection helps organizations proactively detect suspicious behavior. XDR (extended detection and response) then correlates security signals across systems to support integrated analysis and response.
In addition, they can further improve operational response speed by connecting response automation with threat intelligence.
Our Approach: Connected Security Operations
To address these changes, we are building a security operations framework that connects detection, analysis, control, and response.
- AhnLab EDR: Provides a proprietary behavior-based analysis engine, custom detection, detailed threat intelligence based on MITRE ATT&CK, and expert analysis and guidance through MDR(managed detection and response).
- AhnLab XDR: Serves as a security operations platform that collects and correlates threat data from multiple systems, analyzes and detects threats, identifies assets and risks, and supports coordinated response
- AhnLab TIP: A threat intelligence platform that delivers threat intelligence across malware, security incidents, threat actors, vulnerabilities, IoCs, and security news. When integrated with EDR and XDR, AhnLab TIP helps organizations quickly assess the impact of emerging threats and vulnerabilities.
- AhnLab XTG's ZTNA(zero trust network access): Continuously verifies users, devices, security posture, and access conditions based on zero trust principles. It controls access to applications and network resources and helps limit the spread of damage after initial intrusion or lateral movement.
Together, these capabilities are designed not just to block individual attacks, but to connect detection, analysis, control, and response across security operations.
Conclusion: The Security Shift Highlighted by Mythos
Mythos matters not because it introduces a completely new attack method, but because it makes the limits of existing security models harder to ignore. As AI becomes part of the attack process, attackers can accelerate multiple stages of the workflow, automate repetitive tasks, and exploit more vulnerabilities at the same time. Still, the underlying attack chain has not changed. Exploitation, execution, and lateral movement remain central to how attacks unfold.
What has changed is what enterprises need to prioritize. The goal is no longer to assume that every attack can be blocked, but to answer a more practical question:
How quickly can they detect a threat, analyze it accurately, and respond?
Ultimately, an organization's security competitiveness will depend on three capabilities.
- Detection speed
- Analysis accuracy
- Response capability
The most important message left by Mythos is clear
Security is no longer just about prevention. It is becoming an operating model that connects detection, analysis, and response.
FAQ: Key Questions About Mythos and AI-Driven Attacks
Q1. What are Anthropic's Mythos and Project Glasswing, and what do they mean?
On April 7, 2026, Anthropic announced Claude Mythos Preview and Project Glasswing. Claude Mythos Preview is not a commercial model available to the public. It is part of a restricted research program for selected partners and participating organizations working on defensive security.
The program is designed to help identify and remediate vulnerabilities in critical software and infrastructure more quickly. Anthropic has also stated that it does not plan to make the model available to the public.
This makes Mythos less a case of a new attack tool spreading in the wild, and more a sign that AI can accelerate vulnerability discovery and response.
Q2. Is Mythos a real threat, or is the concern overstated?
Mythos is currently a research model operating in a restricted environment. Even so, it matters from a security strategy perspective because it shows how AI could accelerate vulnerability discovery, exploit generation, and attack execution.
Q3. Will AI systems like Mythos make existing security products ineffective?
No. The basic principles of security have not changed. However, as attacks become faster and more automated, asset visibility, vulnerability management, behavior-based detection, integrated analysis, and response automation become even more important.
Anthropic is also operating Mythos Preview as a restricted research program for defensive security, rather than making it publicly available.
Q4. Can AI-driven attacks be fully prevented?
Not entirely. No organization should assume it can block every attack. What matters is reducing exposure and improving the speed and accuracy of detection, analysis, and response.
Q5. Can AhnLab’s products help organizations respond to AI-driven attacks?
AI-driven attacks ultimately show up through endpoint behavior, network activity, command execution, and other observable signals. We help organizations strengthen their response capabilities through EDR, XDR, threat intelligence, and response automation.
Q6. How does AhnLab keep their products secure against AI-driven threats?
We manage product reliability across the entire product lifecycle, from development and release to operation, based on supply chain security and vulnerability management.
The key is how systematically and quickly an organization can identify, assess, and address newly discovered vulnerabilities, whether they are found by AI or by humans.
To support this, we embed security validation throughout the development process.
This includes open source management based on global standards, vulnerability identification and impact analysis, fix verification, continuous inspection, secure coding, static and dynamic analysis, vulnerability scanning, and SBOM-based component management.
Through these measures, we reduce vulnerability response lead time.
We also continue to strengthen our security validation and response framework so that customers can use our products with confidence, even as AI accelerates vulnerability discovery and exploitation.
Q7. What is the most important element of security in the AI era?
Security in the AI era requires more than a prevention-centered approach. Organizations need an operating model that connects detection, analysis, and response, with response speed and automation becoming especially important.
Q8. How will security change going forward?
Security will likely evolve in two directions at the same time: using AI to strengthen defense, and building security controls to identify, track, and govern AI itself.
- AhnLab