Mythos, Myths, and Naysayers: GenAI and the Claude Mythos in Cybersecurity
Artificial Intelligence (AI) did not just parachute into the world of cybersecurity. When we read alarmist headlines today about the impact of Generative Artificial Intelligence (GenAI), it is easy to forget that this technology is the result of over four decades of maturation.
Before reaching a point where a machine can allegedly discover critical flaws without human supervision, the industry went through four distinct technological eras—all focused on classifying the past. Today, we are experiencing the fifth advent, and the rules of the game have changed irrevocably. In this first article of the series, we dive into the structural evolution of AI in cyber defence and analyse the case that recently shook governments and the financial sector: the Claude Mythos phenomenon.
The Evolution of Cyber Defence: From Rigid Systems to Deep Networks
To understand the current technological shock, we must look back at the four phases that paved the way for modern SOC (Security Operations Centre) operations:
- The Era of Rules (1980s and 90s): The first step in human simulation was based on strict deductive logic (“If X, then Y”). This was the foundation of the first antiviruses and Intrusion Detection/Prevention Systems (IDS/IPS) based on fixed signatures
- Supervised Machine Learning (2000s): With more computational power, we stopped relying exclusively on manual rules. AI began training with categorised data, which saved our email inboxes with Bayesian spam filters and enabled heuristic analysis to identify malware families by their similarities, even without the exact signature.
- Unsupervised Machine Learning and UEBA (2010s): AI started processing unlabelled information. Tools like UEBA (User and Entity Behaviour Analytics) began defining patterns of acceptable behaviour. If a user who always logs in from Lisbon at 9 AM to transfer 10MB suddenly connects at 3 AM with a foreign IP to download 5GB, the system detects the anomaly.
- Deep Learning (Late 2010s): Inspired by brain structure, Deep Learning allowed the processing of massive volumes of unstructured data. Technologies like XDR and EDR started correlating events scattered across time and space—for example, linking an email click to a hidden process generated hours later—stopping complex attacks like ransomware in real time.

The 5th Advent: The Arrival of GenAI
All four previous advents had one thing in common: they served to detect, filter, and classify events based on the past. They were, essentially, highly robust statistical filters.
GenAI ushered in the fifth advent by introducing the ability to understand context, reason, explain complex logic, and create countermeasures for future threats. AI went from being a mere detector to an engine of synthesis and autonomous action.
The Systemic Alarm of the “Claude Mythos”
This new theoretical era became frighteningly practical in April 2026. The market was shaken by Anthropic’s frontier model, named Claude Mythos, after it demonstrated unprecedented autonomous capabilities.
The model identified thousands of severe zero-day vulnerabilities in operating systems and browsers, allegedly surpassing decades of human auditing. The demonstration of power was of such magnitude that Anthropic decided to cancel the public launch of the model due to the extreme risk of complex and independent cyberattacks.
Mythos was then locked away in the so-called “Project Glasswing”, remaining accessible only to the US government and around 40 partners for strictly defensive purposes. This unprecedented restriction triggered alarms across the global financial and corporate sectors, elevating the model to a symbol of geopolitical and systemic risk, illustrating American technological dominance.

Is This the End of Human Analysts?
The narrative of a machine capable of autonomously orchestrating complex attack chains, exploiting minor flaws to overcome robust defences, naturally breeds fear.
However, at Art Resilia, we prefer to keep our feet firmly on the ground. Far from the sensationalist headlines, it is imperative to separate what is fact from what is merely marketing.
In the next article of this series, we will deconstruct the greatest media achievement of Claude Mythos—the discovery of a 27-year-old flaw in OpenBSD—and expose why this model requires human supervision now more than ever.
Authors:
- Francisco Nina Rente
- André Pinheiro
- Sérgio Alves
- Gonçalo Amaro