Project Glasswing: what Mythos showed us
Quick Answer
Cloudflare's Project Glasswing tested Anthropic's Mythos Preview, revealing its advanced capabilities in exploit chain construction and proof generation, significantly outperforming previous models in vulnerability research despite inconsistent model refusals.
Key Points
- Mythos Preview excels in chaining low-severity bugs into significant exploits.
- It generates and tests code to prove exploitability of identified vulnerabilities.
- The model's organic refusals are inconsistent, affecting its reliability in security research.
- Programming languages like C/C++ yield more false positives compared to memory-safe languages.
- Future models must include additional safeguards for broader security applications.
Source Excerpt
In recent weeks, we pointed Mythos and other security-focused at live code across critical parts of our infrastructure. We share what we observed, the models’ strengths and weaknesses, and what the work around them needs to look like before any of it can scale.
Want this in your inbox every morning?
Daily brief at your local 8am — bilingual EN/中文, free.
More from Cloudflare AI
See more →
Temporary Cloudflare Accounts for AI agents
Cloudflare introduces Temporary Accounts on Cloudflare Workers, enabling AI agents to deploy live Workers instantly using 'wrangler deploy --temporary'. This feature removes barriers for AI agents, allowing them to operate more efficiently in real-time environments.

