Return to Threats

Anthropic Expanding Mythos Access to 150 New Organizations

securityweek.com 2026-06-02 AI supply chain High

What Happened

Only approximately 50 companies have had access to Mythos until now and they have found thousands of vulnerabilities in their products. The post Anthropic Expanding Mythos Access to 150 New Organizations appeared first on SecurityWeek .

Why It Matters

According to the report, Anthropic is expanding access to its Claude Mythos Preview model under Project Glasswing from roughly 50 to about 200 total organizations, adding around 150 new participants that meet Anthropic’s security standards.[1][2] Mythos has already identified over 23,000 potential vulnerabilities and thousands of severe issues across products and open source projects, demonstrating its power as a defensive cybersecurity tool.[1][3] CyberSE.AI analysis: Broadening access to a powerful, unreleased frontier model through a partner program introduces AI supply chain risk, because organizations are now dependent on Anthropic’s security controls, access governance, and third-party integration hygiene for a critical security capability. Security teams should treat Mythos as a high-value, dual-use component in their AI supply chain, requiring SBOM-level visibility, strict access control, continuous red teaming of how it is integrated into their environments, and readiness assessments to ensure policies and monitoring align with the model’s elevated attack and misuse potential.

Healthcare Fintech SaaS SMB AI startups

CyberSE Analysis

This signal maps to AI supply chain. Organizations using AI agents, LLM APIs, SaaS integrations, or sensitive data workflows should review whether this class of issue could create unauthorized tool execution, data leakage, weak approval gates, or unmanaged supply-chain exposure.

Recommended Actions

  • Restrict AI agent tool permissions and production write paths.
  • Review sensitive data access across prompts, logs, embeddings, memory, and SaaS integrations.
  • Add human approval workflows for high-impact or state-changing actions.
  • Run prompt injection and indirect prompt injection tests against affected workflows.
  • Document the owner, control gap, and remediation deadline for this risk class.

Source

https://www.securityweek.com/anthropic-expanding-mythos-access-to-150-new-organizations/

Talk to AI CISO