Palo Alto Networks tests Anthropicās Claude Mythos to enhance cybersecurity
The AI model found 75 vulnerabilities in one month, a task that would normally take years using traditional methods
Palo Alto Networks CEO Nikesh Arora decided to stress-test his own company’s defenses using one of the most powerful AI models ever built. The results were both impressive and a little terrifying.
In April, Arora’s team turned Anthropic’s unreleased Claude Mythos 5 model loose on Palo Alto Networks’ internal infrastructure with a single directive: find vulnerabilities. Over the course of roughly one month, the model uncovered 75 vulnerabilities across more than 130 products. For context, the company’s typical discovery rate was fewer than five per month.
Arora said the testing surfaced security gaps that would have taken five to seven years to find manually.
A model so effective the government stepped in
Claude Mythos 5 is Anthropic’s frontier AI model purpose-built for advanced coding and cybersecurity work. During Palo Alto Networks’ internal evaluations, the model successfully generated working exploits more than 70% of the time.
That capability caught Washington’s attention. Around June 12, the US government imposed export controls on both Mythos and a related model called Fable, temporarily forcing Anthropic to disable access for all users. The controls were partially lifted around June 26 for approved entities, allowing trusted organizations to resume access under tighter guardrails.
AI, tech, and the markets they move—in one daily briefing.
Daily. Free. Join 34,000+ readers across crypto, finance, and policy.
Anthropic had already been cautious about distribution. Rather than making Mythos broadly available, the company channeled access through something called Project Glasswing, a consortium that provided the Mythos Preview to roughly 40 or more organizations starting around April 7. Palo Alto Networks and CrowdStrike were among the selected partners.
From experiment to enterprise product
Palo Alto Networks’ Unit 42 threat intelligence team used the findings to implement 26 CVE fixes directly in response to the vulnerabilities Mythos surfaced.
By September 22, Palo Alto Networks formalized the relationship by launching its Unit 42 Continuous Frontier AI Defense service. The offering integrates Claude Mythos 5’s capabilities with Palo Alto’s proprietary threat intelligence to deliver continuous exposure management for enterprise clients.