CVE Severity Spike After Claude Mythos Preview Release — Epoch AI Data

✍️ OpenClawRadar📅 Published: July 4, 2026🔗 Source
CVE Severity Spike After Claude Mythos Preview Release — Epoch AI Data
Ad

Epoch AI's analysis of publicly disclosed CVEs reveals a dramatic spike in high- and critical-severity vulnerabilities following Anthropic's April 2026 announcement of Claude Mythos Preview. In June 2026, 21 notable organizations — including Microsoft, Google, Apple, AWS, Oracle, Cisco, and others — disclosed approximately 1,500 high- and critical-severity CVEs. That's more than 3.5 times the previous monthly record set before Mythos Preview's release.

Key Findings

  • 3.5x spike in high/critical CVEs in June 2026 over pre-Mythos monthly record.
  • Anthropic's Project Glasswing — whose partners include Microsoft, Google, Apple, and AWS — has already discovered over 10,000 high- or critical-severity vulnerabilities, many not yet publicly disclosed.
  • OpenAI runs a similar effort called Daybreak.
  • Data is drawn from the public CVE repository, filtered to 21 reputable vendors to avoid noise.
Ad

Method & Caveats

Epoch filtered CVE.org data to only submissions from 21 named organizations (e.g., Microsoft, Google, Apple, Adobe, Oracle, etc.). This avoids capturing low-quality submissions from smaller vendors. The tracked metric is disclosed CVEs — not found but undisclosed ones. Anthropic claims Glasswing alone has identified over 10k, so the disclosed numbers may be a fraction of total discoveries. The increase could also partly reflect more research interest, not just model capability.

Impact for Developers

If you maintain or depend on software from major vendors, expect a wave of high-severity patches. The data suggests AI-assisted vulnerability discovery (both ethical and adversarial) is accelerating the zero-day discovery-to-patch cycle. Keep your dependency scanners updated and prioritize patching critical CVEs from these sources.

📖 Read the full source: HN AI Agents

Ad

👀 See Also

Claude chatbot exploited in Mexican government data breach
Security

Claude chatbot exploited in Mexican government data breach

A hacker used Anthropic's Claude chatbot to attack multiple Mexican government agencies, stealing 150GB of data including taxpayer records and employee credentials. The hacker jailbroke Claude with prompts to bypass guardrails and generate thousands of detailed attack plans.

OpenClawRadar
AviationWeather.gov API Contains 'Stop Claude' Prompt Injection Attempt
Security

AviationWeather.gov API Contains 'Stop Claude' Prompt Injection Attempt

A user reports that the US Government's AviationWeather.gov API returns the text 'Stop Claude' in its responses when accessed through Claude CoWork, triggering a security notice about prompt injection attacks.

OpenClawRadar
GitHub repository documents 16 prompt injection techniques and defense strategies for public AI chats
Security

GitHub repository documents 16 prompt injection techniques and defense strategies for public AI chats

A developer published a GitHub repository detailing security measures for public AI chatbots after users attempted prompt injection, roleplay attacks, multilingual tricks, and base64 encoded payloads. The guide includes a Claude code skill to test all 16 documented injection techniques.

OpenClawRadar
OpenClaw Skill Safety Scanner: 7.6% of 31,371 Skills Flagged as Dangerous
Security

OpenClaw Skill Safety Scanner: 7.6% of 31,371 Skills Flagged as Dangerous

A developer built a tool that scanned the entire ClawHub registry and found 2,371 out of 31,371 skills contain dangerous patterns like wallet drainers, credential theft, and prompt injection. The tool provides API access and badges for checking skills before installation.

OpenClawRadar