CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Most of the bugs Claude Mythos found have never been checked by a human

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 5684

As cited

Copy frozen at (site build).

research

Most of the bugs Claude Mythos found have never been checked by a human

Anthropic deployed Claude Mythos Preview to scan 281 open-source projects and identified 23,019 candidate vulnerabilities. External security firms reviewed only 1,900 of these candidates, with 1,596 reports sent to maintainers, 1,451 acknowledged, 97 fixes merged upstream, and 88 published as security advisories as of May 22, 2026. The remaining 21,119 candidates have not undergone external review, attributed by Anthropic to insufficient resources for validation.

Why it matters: Open-source maintainers and users of scanned projects need to understand that the majority of vulnerabilities identified by this automated artificial intelligence (AI) tool lack independent verification, creating uncertainty about their severity and exploitability.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary