New serious vulnerabilities spiked around release of Claude Mythos Preview
摘要
Epoch AI 分析显示,2026 年 4 月 Anthropic 宣布其最新内部模型 Claude Mythos Preview 具备自主发现与利用网络安全漏洞的能力,随后 Anthropic 与 OpenAI 均启动使用前沿模型对关键软件进行加固的举措。数据来自 cve.org,由 21 家知名组织(含 Microsoft、Google、Apple、Adobe 等)报告的高危和严重严重度 CVEs 记录显示,较 Mythos Preview 宣布前的上一个月记录,6 月份数量增加超过 3.5 倍。文章附带每月图表、CSV 下载链接,并讨论数据来源假设、局限性,以及可能由发现可行性提升和发现兴趣增加共同导致的观测增幅。
荐读理由
AI / 系统 / 工程领域的真实技术变化:Anthropic 宣称 Project Glasswing 发现并报告了 10000+ 高危和关键级别漏洞(2026 年 4 月起),使 CVEs 激增 3.5 倍,引发了双方在安全加固上的新方向
原文
Epoch's work is free to use, distribute, and reproduce provided the source and authors are credited under the Creative Commons BY license.
Learn more about this graph
In April 2026, Anthropic announced that its latest internal model (Claude Mythos Preview) was capable of autonomous cybersecurity vulnerability discovery and exploitation. Since then, both Anthropic and OpenAI have launched efforts to use frontier models to harden critical software before malicious actors are able to use the same models for harm.
We show that the number of Common Vulnerabilities and Exposures (CVEs) jumped significantly following these announcements. Compared to the previous monthly record before the Mythos Preview announcement, the number of high- and critical-severity vulnerabilities increased more than 3.5x in June.
Data
Our Cyber Vulnerability Reports hub visualizes data from cve.org, a public repository of CVE reports from software companies and third-party security researchers. We focus our analysis on CVEs reported by 21 notable organizations to avoid capturing noisy submissions from less reputable sources. These notable organizations include:
Microsoft · Google · Apple · Adobe · Oracle · Cisco · IBM · Red Hat · Intel · AMD · NVIDIA · Qualcomm · Samsung · SAP · Amazon (AWS) · VMware (Broadcom) · GitHub (own products) · Linux · Mozilla · Apache · OpenSSL
Assumptions and limitations
Our figures come from publicly disclosed vulnerabilities, which do not include discovered but not publicly disclosed vulnerabilities. Anthropic claims that their Project Glasswing alone has identified over 10,000 high- and critical-severity vulnerabilities.
While some of the increase in observed vulnerability disclosure is almost certainly due to increased feasibility of discovery, the spike may also be caused in part by an increase in the amount of interest in discovering bugs.
Download this data
Monthly high- and critical-severity CVEs from 21 notable organizations
CSV, Updated Jul. 2, 2026
这条对你有帮助吗?