Analysis: Anthropic's Claude Mythos Marketing Uses Previously Discovered FreeBSD Vulnerability
By
jgalt212
A baker's-dozen of insight crammed into one ring.
Summary
The article criticizes Anthropic's marketing of its Claude Mythos Preview AI model, which is being showcased using CVE-2026-4747 - a 17-year-old FreeBSD kernel vulnerability. The author argues that this security flaw was actually discovered, patched by FreeBSD, and publicly exploited before Mythos existed, yet Anthropic is taking credit for it. The article highlights how the FreeBSD security advisory credits "Claude" without specifying which model was used, suggesting this is a marketing tactic rather than genuine AI security research achievement.
Key quotes
· 4 pulledAnthropic's flagship showcase for Claude Mythos Preview is CVE-2026-4747, a remote kernel code execution vulnerability in FreeBSD's RPCSEC_GSS module.
It is a 17-year-old bug. It is a textbook stack buffer overflow. And it was found before Mythos, patched by FreeBSD, and publicly exploited by a third party.
Yet someone's idea of credit flows backwards to Mythos.
The advisory notably credits 'Claude', leaving out the model that Carlini used in his February 2026 paper.
You might also wanna read
Anthropic's Claude Mythos Preview: Limited Release for Security Scanning, But Competitors Offer Similar Capabilities
Anthropic announced its Claude Mythos Preview model, which is highly effective at finding software security vulnerabilities, and decided not

Anthropic's Claude Mythos AI model accessed by unauthorized users despite security claims
Anthropic's tightly controlled rollout of its Claude Mythos AI model, touted as too dangerous for public release due to its advanced cyberse

Anthropic's Mythos cybersecurity AI model accessed by unauthorized users via third-party contractor
Anthropic's powerful Mythos cybersecurity AI model, described as potentially dangerous in the wrong hands, was accessed by unauthorized user
Google reports first evidence of hackers using AI to develop zero-day security exploit
Google has reported evidence of hackers using AI to develop a zero-day security vulnerability, marking the first time the company has observ

Researchers bypass Claude's safety guardrails using flattery and psychological manipulation
Researchers at AI red-teaming company Mindgard discovered they could bypass Anthropic's safety measures on Claude by using psychological man
AI-assisted vulnerability discovery raises concerns about Linux kernel security
This opinion article discusses a troubling trend in Linux security where AI-powered tools are being used to discover and exploit kernel vuln
