GPT-5.5 found on par with Mythos, with OpenAI to limit access to Cyber version

It took about three weeks for a competing model to hit parity with Mythos. (Picture: Adobe)
After a major research paper by the UK’s AI Security Institute found GPT-5.5 a little better than Mythos, Sam Altman moved to limit access to the Cyber version of the model.

The paper probes «vulnerability research and exploitation against realistic targets and modern mitigations» through rigorous tests, and found GPT-5.5 had a pass rate of 71.4%, compared to Mythos’ 68.6% on the most advanced evaluations.

According to the AISI, their test suite proves that Mythos is not a one-off act of brilliance, but part of a wider trend for frontier models. They say «we should expect further increases in cyber capability from models in the near future, potentially in quick succession.»

At the same time, Sam Altman posted on x.com that OpenAI will indeed follow Anthropic’s lead on limiting access to GPT-5.5-Cyber to «critical cyber defenders:»

— We will work with the entire ecosystem and the government to figure out trusted access for cyber; we want to rapidly help secure companies/infrastructure, Altman wrote.

Read more: The AI Security Institute, Altman’s x post, TechCrunch. Discussion on r/Singularity.

Private Discord group gains access to Mythos — to «play around» with it

The unnamed group has not run any cybersecurity prompts for fear of losing access. (Picture: adobe)
Bloomberg (paywalled) is reporting that a «private online forum» has managed to get access to Anthropic’s heralded Mythos model — said to be so advanced, it would be too dangerous to release.

— We’re investigating a report claiming unauthorized access to Claude Mythos Preview through one of our third-party vendor environments, Anthropic tells TechCrunch.

The group is part of a Discord channel focused on finding information on unreleased models, and made some educated guesses as to where the model would be located. They also had some help from a member whose job gave him access.

As for the warnings of dangerous fallout from public access to the model, the group says they are only interested in «playing around with new models,» not «wreaking havoc,» Gizmodo says, but the «hack» itself will raise concern in the security sector.

Read more: Bloomberg (paywalled), TechCrunch, and Gizmodo.

Mozilla uses Mythos to fix 271 bugs in latest Firefox, claims «vertigo»

The Mythos model is only available to select organizations for defensive cybersecurity. (Picture: generated)
The browser developer has been working with Anthropic since February, and got their hands on an early version of Claude Mythos Preview to scan for vulnerabilities.

— For a hardened target, just one such bug would have been red-alert in 2025, and so many at once makes you stop to wonder whether it’s even possible to keep up, Mozilla writes in their blog.

The upshot is that the 271 bugs mean that the company can approach security «much better than just keeping up», and that «defenders finally have a chance to win, decisively.»

— We have many years of experience picking apart the work of the world’s best security researchers, and Mythos Preview is every bit as capable, Mozilla continues.

They used Claude Opus 4.6 to find 22 bugs back in March, but this Mythos-powered bug hunt was so large it left them with a feeling akin to vertigo, they say.

Read more: Mozilla’s blog, interview on Wired, writeups on Ars Technica and Engadget.

In spite of government ban, the US NSA is actively using Anthropic’s Mythos

With compelling technology from Mythos, other agencies might not be far behind. (Picture: Shutterstock)
Sources in contact with Axios claim the National Security Agency, the premier digital spying agency, is widely using Anthropic’s Mythos

The model was deemed too dangerous to be released, but is available to about 40 select organizations through Project Glasswing, which uses its advanced cyber capabilities to scan for exploits and vulnerabilities — before the rest of the world catches up.

This is in spite of a Trump government ban on Anthropic and it being labeled a national security threat by the DoD this February after refusing to comply with Pentagon demands.

Anthropic held a meeting with the White House this Friday, said to be «productive and constructive,» Reuters reports.

Read more: Axios, Engadget, and Reuters

Anthropic launches Project Glasswing, greatly advancing cybersecurity

Project Glasswing pokes holes in almost any software, and if it isn’t used defensively now — attackers might soon. (Picture: Anthropic)
Anthropic has been cooking up the Mythos model lately, that internal documents had put as «a sea-change in capabilities,» and was too dangerous to release publicly.

Instead, they are releasing Project Glasswing, having found it to be especially suited for «an effort to secure the world’s most critical software.» It won’t take long for others to catch up, Anthropic says, and this is «an urgent attempt to put these capabilities to work» defensively.

Launch partners include a who’s who of Silicon Valley giants, and Anthropic claims it has already found thousands of vulnerabilities across every major operating system and browser.

The Mythos Preview model scores 93.9% on SWE-bench Verified compared to Opus 4.6 with 80.8%, and on SWE-bench Pro it is 77.8% vs 53.4%.

Smaller actors maintaining critical software will enjoy $100 million in usage credit donations from Anthropic — but for others it will cost a whopping $25/125 per million input/output tokens.

Read more: Anthropic’s announcement, Venturebeat, TechCrunch, CNBC