Yesterday in AI: 26 May 2026 — Mythos Flags 23K OSS Bugs, Grok Build Enters the Race
Anthropic's Mythos AI found 23,019 OSS vulnerabilities and is moving into Claude Code; xAI launched Grok Build CLI with 2M context and 8 parallel subagents; Cerebras runs Kimi K2.6 at 981 tokens/sec — 6.7× faster than any GPU cloud.
By OMC Editorial on 2026-05-27
TL;DR — Anthropic's Mythos AI flagged 23,019 security vulnerabilities across 1,000 open-source projects with Claude Code integration on the way; xAI launched Grok Build, a CLI coding agent with 2M-token context and 8 parallel subagents challenging Claude Code head-on; Cerebras posted a post-IPO benchmark running open-weight Kimi K2.6 at 981 tokens/sec — 6.7× faster than the next-best GPU cloud.
---
1️⃣ Anthropic's Mythos Surfaces 23K Security Flaws in 1,000 OSS Projects — and Is Coming to Claude Code
- What: Anthropic published Project Glasswing's first numbers: Claude Mythos Preview scanned 1,000+ open-source projects and flagged 23,019 potential vulnerabilities, with 6,202 estimated high or critical severity. One confirmed find — a cert-forging bug in wolfSSL CVE-2026-5194 — came with a working exploit built by Mythos.
- Why it matters: Mythos is being integrated into Claude Code and Claude Security, which means AI-driven vulnerability scanning is on its way into developers' daily workflow as a default, not an optional audit.
- Key number: Only 97 of the flagged vulnerabilities have been publicly patched; open-source maintainers told Anthropic to slow down its disclosure rate.
Anthropic's 50-partner Project Glasswing coalition spans major tech firms, government security agencies, and independent pen-test firms. Mozilla audited Firefox with Mythos and fixed 271 vulnerabilities. Cloudflare scanned its critical-path systems and found 2,000 bugs 400 high/critical at a false-positive rate lower than that of human testers.
Mythos briefly appeared as a selectable toggle inside Claude Code on May 25 before being pulled — a signal that a limited release is actively being tested. Anthropic says it still lacks sufficient misuse safeguards for a public launch, but the model is now filing its own CVE records and is on track to surface an estimated 3,900 confirmed high/critical flaws in open-source code.
📎 Anthropic Project Glasswinghttps://www.anthropic.com/research/gl