AI code security with Claude Mythos Preview: Inside Tenable’s 500+ hours of testing for Project Glasswing
Tenable conducted over 500 hours of testing Anthropic's Claude Mythos Preview AI model for code security tasks as part of Project Glasswing. The evaluation found that while frontier AI cannot independently run a code security program, it can significantly enhance such programs when combined with expert human oversight and purpose-built tooling. Claude Mythos Preview demonstrated capabilities in source code analysis, exploit creation, binary reverse engineering, threat modeling, and dynamic testing. However, many findings generated by the AI required expert validation to determine actual risk. The research emphasizes that traditional deterministic security tools remain essential, with frontier AI serving as a complementary, creative layer to improve overall security effectiveness. The study also highlights the importance of securing source code repositories as a critical defender advantage.
AI Analysis
Technical Summary
Tenable's extensive evaluation of Anthropic's Claude Mythos Preview involved more than 500 hours and 40 billion tokens to assess its utility in various security tasks including source code scanning, exploit generation, binary reverse engineering, threat modeling, and dynamic testing. The testing was conducted with a dedicated team and a custom testing harness to orchestrate the AI model. Results indicate that the AI model alone is insufficient to run a code security program but can augment human-led security efforts by scaling testing and surfacing potential issues. Many AI-generated findings were false positives or already mitigated by existing controls, underscoring the necessity of human expertise to interpret results. The research positions frontier AI as a valuable addition to traditional deterministic tools like SAST, DAST, and SCA, enhancing the creative and variance-tolerant aspects of security analysis. The report also notes that source code access is a key asymmetric advantage for defenders over attackers.
Potential Impact
The impact of Claude Mythos Preview lies in its ability to scale and augment security testing efforts rather than replace existing tools or human expertise. It can generate a high volume of findings, but only a subset represent true security exposures after expert validation. This reduces the risk of missing vulnerabilities but requires careful triage to avoid noise. The AI's capabilities can improve the efficiency and breadth of security assessments, potentially leading to stronger overall security postures when integrated properly. There is no indication of direct exploitation or vulnerabilities in the AI itself. The research reinforces the continued importance of securing source code repositories to maintain defender advantage.
Mitigation Recommendations
No direct vulnerability or exploit is reported; therefore, no patch or fix is applicable. Organizations should continue to rely on established deterministic security tools (SAST, DAST, SCA) as the core of their code security programs. Frontier AI tools like Claude Mythos Preview can be used as supplementary aids under expert supervision to enhance security testing. Securing source code repositories remains critical to maintaining an asymmetric advantage over attackers. Since this is an analysis of AI capabilities rather than a vulnerability, no urgent remediation actions are required.
AI code security with Claude Mythos Preview: Inside Tenable’s 500+ hours of testing for Project Glasswing
Description
Tenable conducted over 500 hours of testing Anthropic's Claude Mythos Preview AI model for code security tasks as part of Project Glasswing. The evaluation found that while frontier AI cannot independently run a code security program, it can significantly enhance such programs when combined with expert human oversight and purpose-built tooling. Claude Mythos Preview demonstrated capabilities in source code analysis, exploit creation, binary reverse engineering, threat modeling, and dynamic testing. However, many findings generated by the AI required expert validation to determine actual risk. The research emphasizes that traditional deterministic security tools remain essential, with frontier AI serving as a complementary, creative layer to improve overall security effectiveness. The study also highlights the importance of securing source code repositories as a critical defender advantage.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Tenable's extensive evaluation of Anthropic's Claude Mythos Preview involved more than 500 hours and 40 billion tokens to assess its utility in various security tasks including source code scanning, exploit generation, binary reverse engineering, threat modeling, and dynamic testing. The testing was conducted with a dedicated team and a custom testing harness to orchestrate the AI model. Results indicate that the AI model alone is insufficient to run a code security program but can augment human-led security efforts by scaling testing and surfacing potential issues. Many AI-generated findings were false positives or already mitigated by existing controls, underscoring the necessity of human expertise to interpret results. The research positions frontier AI as a valuable addition to traditional deterministic tools like SAST, DAST, and SCA, enhancing the creative and variance-tolerant aspects of security analysis. The report also notes that source code access is a key asymmetric advantage for defenders over attackers.
Potential Impact
The impact of Claude Mythos Preview lies in its ability to scale and augment security testing efforts rather than replace existing tools or human expertise. It can generate a high volume of findings, but only a subset represent true security exposures after expert validation. This reduces the risk of missing vulnerabilities but requires careful triage to avoid noise. The AI's capabilities can improve the efficiency and breadth of security assessments, potentially leading to stronger overall security postures when integrated properly. There is no indication of direct exploitation or vulnerabilities in the AI itself. The research reinforces the continued importance of securing source code repositories to maintain defender advantage.
Defensive Guidance
No direct vulnerability or exploit is reported; therefore, no patch or fix is applicable. Organizations should continue to rely on established deterministic security tools (SAST, DAST, SCA) as the core of their code security programs. Frontier AI tools like Claude Mythos Preview can be used as supplementary aids under expert supervision to enhance security testing. Securing source code repositories remains critical to maintaining an asymmetric advantage over attackers. Since this is an analysis of AI capabilities rather than a vulnerability, no urgent remediation actions are required.
Technical Details
- Classification
- {"confidence":0.3,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.tenable.com/blog/ai-code-security-with-claude-mythos-preview-inside-tenables-500-hours-of-testing-for-project","fetched":true,"fetchedAt":"2026-08-06T12:04:52.895Z","wordCount":3509}
Threat ID: 6a747864bf8831d539abd1ba
Added to database: 08/06/2026, 12:04:52 UTC
Last enriched: 08/06/2026, 12:05:06 UTC
Last updated: 08/07/2026, 02:07:57 UTC
Views: 12
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.