Anthropic's Mythos Model Found Vulnerabilities in Classified US Systems Within Hours, NSA Confirms
A secure high-security data centre corridor with blue-lit server cabinets, representing the revelation that Anthropic's Mythos model identified vulnerabilities in classified US government systems during a Project Glasswing testing exercise

A secure high-security data centre corridor with blue-lit server cabinets, representing the revelation that Anthropic's Mythos model identified vulnerabilities in classified US government systems during a Project Glasswing testing exercise
Anthropic's Mythos model identified vulnerabilities in highly sensitive US government computer systems during a testing exercise conducted under Project Glasswing, the restricted intelligence agency programme designed to find and fix critical software vulnerabilities before adversaries could exploit them. The disclosure was confirmed publicly when Senator Mark Warner of Virginia, speaking at a congressional hearing earlier this month, revealed that NSA chief Joshua Rudd had informed him that Mythos "broke into almost all of our classified systems, not in weeks, but in hours."
The Associated Press first reported the story, citing an unidentified US official who clarified that although Mythos identified certain vulnerabilities within hours, that did not mean the model was able to exploit those vulnerabilities within the same timeframe. Anthropic, the White House, and the Department of Defense did not immediately respond to requests for comment.
What Project Glasswing Is and Why It Matters
Project Glasswing is a restricted programme in which Anthropic has partnered with Washington's intelligence agencies to test Mythos's ability to identify vulnerabilities in critical software systems, including classified government infrastructure. The programme was publicly referenced by Anthropic and by TrendAI earlier this week when the enterprise AI security company announced its own participation in the initiative as part of its UAE regional launch.
The nature of Project Glasswing is intentionally narrow: its purpose is adversarial testing under controlled conditions to find security weaknesses before external threat actors can find and use them. The classified systems that Mythos was tested against represent the most hardened computing infrastructure operated by the US government. The claim that a large language model identified entry points across almost all of those systems within hours is a significant data point in the ongoing assessment of what AI-class capabilities mean for offensive and defensive security operations. Analysis by Bain and Company following the initial Mythos Preview release found that Mythos can chain multiple small vulnerabilities into a single attack, reconstruct source code from deployed software to find exploitable weaknesses, and once inside a network, automatically map systems, move laterally, and build custom tools to extract data, all within hours.
The GCC Relevance
For GCC government entities and critical infrastructure operators, this disclosure has two immediate implications. First, it confirms that AI-powered vulnerability discovery at speed and scale is not a theoretical future risk but a demonstrated present capability. Second, it reinforces the argument that the security frameworks protecting critical national infrastructure in the UAE, Saudi Arabia, and across the Gulf must be tested and hardened against this class of capability, not just against conventional penetration testing methods.
The IMF has already warned that AI-powered cyberattacks pose systemic risk to global financial infrastructure, specifically flagging the GCC as carrying heightened exposure due to the region's deep integration between banking, energy, and government digital infrastructure. The NSA testing results reported this week provide the empirical foundation for that warning: the capability the IMF described as an emerging risk has now been demonstrated against the most hardened government systems in existence.
Anthropic's own stated position is that Mythos's capabilities in this domain are precisely why the model should be used defensively, under controlled conditions, to identify and remediate vulnerabilities before adversaries with access to comparable AI systems can do so offensively. That framing is consistent with the stated purpose of Project Glasswing and with the UAE Cyber Security Council's posture around advanced AI-assisted threat modelling, articulated most recently at the UAE Government Cybersecurity Summit in Abu Dhabi this month.
For UAE critical infrastructure operators specifically, the NESA Information Assurance Standards require mandatory proactive threat monitoring and security controls appropriate to the current threat landscape. An AI model that can identify vulnerabilities across classified government systems within hours represents a material change in that threat landscape, and NESA compliance programmes that have not yet incorporated AI-speed threat scenarios into their assessment cycles should do so now.
The Wider Context in Washington
The Mythos disclosure comes amid a broader and deeply contested set of regulatory disputes between Anthropic and the US government. The Trump administration this month ordered Anthropic to suspend access to its Mythos and Fable AI models for foreign nationals worldwide, citing national security concerns. Anthropic subsequently disabled access for all customers to ensure compliance, triggering a lawsuit from US legal technology firm Legion LegalTech, which argued the order was unlawful and that its impact was immediate and existential for its Canadian-based development team.
Separately, the New York Times reported that the NSA lost access to Mythos amid the dispute with Anthropic, an ironic development given the NSA chief's own testimony about what the model achieved during the testing exercise.
OpenAI, Google DeepMind, Microsoft, and xAI have all agreed to provide the US government early access to new models for national security evaluations. Meta remains the only major US AI developer that has not reached such an agreement, though it stated on 23 June that it hoped to sign an agreement soon.
For GCC security teams and enterprise CISOs, the operative intelligence from this story is straightforward: AI-powered vulnerability discovery is now a confirmed reality at the level of the most hardened classified systems in existence. TechRadar's analysis of Mythos's offensive security capabilities documents a Zero Day Clock project finding that time-to-exploit has fallen from 2.3 years in 2018 to roughly 20 hours in 2026. The defensive response is to ensure that AI-assisted security assessment is part of your own organisation's evaluation cycle, not just a capability held by adversaries or state intelligence services.
Layla Haddad
Cyber Policy & Digital Risk CorrespondentLayla Haddad covers cybersecurity regulations, data protection laws, and digital transformation initiatives across GCC and North Africa. She has worked closely with compliance teams, fintech startups, and government advisory groups. Her articles explore how cyber policy, AI governance, and privacy frameworks shape the region’s digital future.