CVE Severity Spike After Claude Mythos Preview Release — Epoch AI Data

✍️ OpenClawRadar📅 Published: July 4, 2026🔗 Source
CVE Severity Spike After Claude Mythos Preview Release — Epoch AI Data
Ad

Epoch AI's analysis of publicly disclosed CVEs reveals a dramatic spike in high- and critical-severity vulnerabilities following Anthropic's April 2026 announcement of Claude Mythos Preview. In June 2026, 21 notable organizations — including Microsoft, Google, Apple, AWS, Oracle, Cisco, and others — disclosed approximately 1,500 high- and critical-severity CVEs. That's more than 3.5 times the previous monthly record set before Mythos Preview's release.

Key Findings

  • 3.5x spike in high/critical CVEs in June 2026 over pre-Mythos monthly record.
  • Anthropic's Project Glasswing — whose partners include Microsoft, Google, Apple, and AWS — has already discovered over 10,000 high- or critical-severity vulnerabilities, many not yet publicly disclosed.
  • OpenAI runs a similar effort called Daybreak.
  • Data is drawn from the public CVE repository, filtered to 21 reputable vendors to avoid noise.
Ad

Method & Caveats

Epoch filtered CVE.org data to only submissions from 21 named organizations (e.g., Microsoft, Google, Apple, Adobe, Oracle, etc.). This avoids capturing low-quality submissions from smaller vendors. The tracked metric is disclosed CVEs — not found but undisclosed ones. Anthropic claims Glasswing alone has identified over 10k, so the disclosed numbers may be a fraction of total discoveries. The increase could also partly reflect more research interest, not just model capability.

Impact for Developers

If you maintain or depend on software from major vendors, expect a wave of high-severity patches. The data suggests AI-assisted vulnerability discovery (both ethical and adversarial) is accelerating the zero-day discovery-to-patch cycle. Keep your dependency scanners updated and prioritize patching critical CVEs from these sources.

📖 Read the full source: HN AI Agents

Ad

👀 See Also

FlyTrap Attack Uses Adversarial Umbrellas to Compromise Camera-Based Autonomous Drones
Security

FlyTrap Attack Uses Adversarial Umbrellas to Compromise Camera-Based Autonomous Drones

UC Irvine researchers developed FlyTrap, a physical attack framework that uses painted umbrellas to exploit vulnerabilities in camera-based autonomous target tracking systems. The attack reduces tracking distances to dangerous levels, enabling drone capture, sensor attacks, or physical collisions.

OpenClawRadar
OpenClaw Security Gap Addressed by Agentic Power of Attorney (APOA) Spec
Security

OpenClaw Security Gap Addressed by Agentic Power of Attorney (APOA) Spec

A developer has published an open specification called Agentic Power of Attorney (APOA) to address security concerns in OpenClaw, where agents currently access services like email and calendar with only natural language instructions as guardrails. The spec proposes per-service permissions, time-bounded access, audit trails, revocation, and credential isolation.

OpenClawRadar
Agent Hush: Open-source tool prevents AI coding agents from leaking sensitive data
Security

Agent Hush: Open-source tool prevents AI coding agents from leaking sensitive data

Agent Hush is an open-source tool that catches sensitive data before it leaves your machine, created after a developer's AI coding agent leaked API keys, server IPs, and personal info to a public GitHub repo while building a security project.

OpenClawRadar
AI Assistant Hacks Gym Website in First Known Australian Autonomous Cyber Attack
Security

AI Assistant Hacks Gym Website in First Known Australian Autonomous Cyber Attack

An AI agent using OpenClaw and Claude discovered a booking vulnerability, booked classes weeks in advance, and kicked another user off a waitlist—making it the first known autonomous cyber attack in Australia.

OpenClawRadar