Why XEUS Platform Blog Resources ThreatLens Intel Dashboard Request a scoping call
// Frontier AI offense

No Mythos access? How to run frontier-class offensive testing without it

Claude Mythos is limited to vetted US organizations. What a security lead outside that circle can do now to attack their own estate with frontier-class AI and prove the paths that matter.

Every week since April, a security lead somewhere has been asked a version of the same question by their board: do we have access to the model that found ten thousand critical flaws in the world's software? For almost everyone, outside the United States especially, the honest answer is no, and it will stay no for a while. This post is about what to do with that answer.

The short version: you do not need Mythos to test your estate the way a frontier attacker would. You need a model that chains exposures into a demonstrated path, an operator who stands behind the result, and a cadence that keeps up with what you ship. Access to a specific restricted model is not the thing that closes the gap. Proof is.

Who actually has Mythos access today

Facts first, each from Anthropic's own pages.

Project Glasswing launched on April 7, 2026 with twelve partners: Amazon Web Services, Anthropic, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, the Linux Foundation, Microsoft, NVIDIA, and Palo Alto Networks, plus "over 40 additional organizations that build or maintain critical software infrastructure." Anthropic committed "up to $100M in usage credits for Mythos Preview" and stated plainly: "We do not plan to make Claude Mythos Preview generally available."

On June 2, 2026, Anthropic expanded the program by "approximately 150 new organizations" across "more than 15 countries," each required to meet security requirements before access. In the same update it reported that partners "have so far found more than 10,000 high- or critical-severity security flaws."

On September 1, 2026, Anthropic introduced Claude Mythos 5.1, "available to vetted cyberdefenders and life scientists through our trusted access programs." The access line is the one that matters: "Currently, we're only able to make it available to a set of US organizations, though we're working to expand access." The Cyber Verification Program is the application path, and the page says it "will include Mythos access in the near future." List pricing "starts at $10 per million input tokens and $50 per million output tokens."

So the routes, as of this writing:

Route Who qualifies Status
Project Glasswing Vendors of widely relied-on software and infrastructure, by invitation Roughly 200 organizations across two cohorts. Not generally available.
Cyber Verification Program Vetted cyberdefenders. US organizations for now. Mythos access "in the near future."
Public frontier models Anyone, through the API and cloud marketplaces Available today, with safeguards.

If you are a mid-market team in Australia, APAC, or anywhere outside that vetted US circle, the first two rows are closed to you today. The third is open. The rest of this post is about the third.

Why this matters if you are on the outside

The instinct is to treat restricted access as a moat you are stuck behind. Two things from Anthropic's own writing argue against waiting.

First, the capability is spreading. In the June update, Anthropic wrote: "within 6 to 12 months, we expect that many other AI companies will have Mythos-class models, and they could release them without safeguards that prevent misuse." Read that as a defender. The offensive capability that found ten thousand critical flaws is not going to stay scarce. Attackers do not need a trusted access program.

Second, the defenders with access are not running Mythos on everything. Anthropic described Claude Security as "a product that uses our latest public frontier models, like Claude Opus 4.8, to scan codebases and suggest patches." Public frontier models are already doing frontier defensive work inside the company that builds Mythos. The gap between a public frontier model and a restricted one is real, but it is not the gap between "can test my estate" and "cannot."

The exposure you carry does not wait for your access to catch up. New services, endpoints, and cloud resources appear between assessments and are reachable before anything tests them. That is the problem to solve now, with what is available now.

What frontier-class testing actually means

Define it by outcome, not by which model sits behind it.

A scanner produces a ranked list. Every finding stands alone, scored by CVSS, and the report is stale before anyone reads it. Frontier-class testing produces something different: it executes the exposures against authorized scope, chains the individually minor ones into a path that reaches business impact, and shows the route. What was reached, from what starting point, in how many steps.

The distinction is not academic. The compromises that matter rarely come from a single critical finding sitting in the open. They come from three or four medium and informational issues that a scanner rates and dismisses separately, and that an attacker walks through in sequence. A model that can hold the whole chain, reason about the next hop, and prove it end to end is doing frontier-class work whether or not it wears a restricted name.

The other half is accountability. An autonomous engine that reports a finding no human stands behind is a liability, not evidence. Frontier-class testing pairs machine-scale execution with a named tester of record who reviews the output and signs it. That is what makes a finding an attested result rather than a claim.

Want this run against your own estate? A technical walkthrough against your environment, with scope agreed in writing before anything runs.
Book a scoping call

What you can do with public frontier models today

Concretely, without Mythos:

Run continuous adversarial pressure on your own estate. Map the external surface, the cloud resources, and the identities, and keep the model current as the environment changes rather than freezing it at the start of a quarterly window.

Execute against authorized scope. Not an unvalidated scan: real exploitation, governed by a configurable safe mode against production and by scope agreed in writing before anything runs.

Chain the findings. The value is in the path, not the count. A finding that reads "medium" on its own but opens the door to the next hop is the one worth surfacing.

Prove and re-test. Every finding ships with a working proof of concept and the reproduction steps behind it. When the fix lands, the original attack is run again against the live surface to confirm the path is genuinely gone, and to catch it if it reopens.

XEUS runs this on public frontier models, executed by the platform and reviewed by a named tester of record. We do not have Mythos. We say so, and we say which model class we run, because the alternative, implying a capability we do not have, is exactly the kind of claim this post argues against trusting.

A worked example: three findings, one compromise

Here is the shape of it. The chain below is a representative pattern, not a specific engagement, and it carries no client detail.

Start with an asset nobody owned. An orphaned subdomain, not in the asset register, pointing at a host the team forgot. A scanner rates it informational, if it sees it at all.

Hop one to hop two: on that host, an administrative panel is exposed. On its own, a medium. There are a hundred exposed panels behind a hundred forgotten subdomains, and most of them are noise.

Hop two to hop three: a credential reused from a third-party breach works against that panel. Another medium in isolation, a well-known category, easy to wave off.

The result is not medium. Informational plus medium plus medium, walked in sequence, reaches administrative access to a system that should never have been on the perimeter. No single finding in that chain would move a remediation queue. The path is the finding. A ranked list hides it; executing the chain surfaces it.

That is the work. It does not require a restricted model. It requires executing the exposures instead of listing them, and an operator who can tell you which chain out of the thousands is the one that actually reaches you.

Five questions to ask anyone selling frontier AI pentesting

Whether you evaluate us or anyone else, these separate the real thing from the label.

  1. Is there a named tester of record who reviews and signs the report, or does raw model output reach you unreviewed?
  2. Does the report show the demonstrated attack path with a working proof of concept, or a list of CVEs ranked by severity?
  3. Which models do they actually run, and will they say so in writing? "Frontier AI" with no model named is a tell.
  4. Is remediation retesting included, so a closed ticket and a closed attack path mean the same thing, or is proving the fix a separate engagement?
  5. What does the scope and rules-of-engagement document look like, and is it agreed before anything runs?

Every one of those is a commitment on our side, which is why they double as the offer without a sales paragraph.

If you qualify, apply

If you are a US organization that builds or maintains critical infrastructure, the trusted-access route is worth pursuing on its own merits. The Cyber Verification Program is the front door, and Anthropic says Mythos access is coming to it. Applying costs you nothing and the capability is real.

For everyone else, and for the estate you have to defend between now and whenever access widens, waiting is the risk. The attackers modeling your surface are not in a trusted access program either. If the honest answer to "can we show an auditor an independent report of a demonstrated attack path against our estate" is not yet, that is the gap to close, and closing it does not require a model you cannot get.

Questions we get asked

Can I buy Claude Mythos access?

No. Anthropic's Mythos page states it is 'available to vetted cyberdefenders and life scientists through our trusted access programs,' and 'Currently, we're only able to make it available to a set of US organizations.' There is no self-serve purchase and no general availability. The Cyber Verification Program is the application route, and Anthropic says it 'will include Mythos access in the near future.'

Is Mythos available outside the United States?

Not today. The same page says access is limited to 'a set of US organizations, though we're working to expand access.' Project Glasswing's June 2026 expansion added roughly 150 organizations across more than 15 countries, but each had to meet Anthropic's security requirements first, and the program is not open to applications the way a product is.

Does XEUS use Mythos?

No. XEUS runs on public frontier models and does not have Mythos access. Every engagement is executed by the platform and reviewed and signed by a named tester of record. We say which model class we run and we do not imply a capability we do not have.

What is a Mythos-class model?

Anthropic uses the phrase to describe frontier models capable enough at cyber tasks to warrant restricted access. Its June 2026 update projected that 'within 6 to 12 months, we expect that many other AI companies will have Mythos-class models.' The useful definition for a defender is behavioral, not brand: a model that can chain findings into a demonstrated attack path, not just rank them.

How is this different from a vulnerability scan?

A scan reports issues ranked by severity. Frontier-class offensive testing executes the exposures against authorized scope, chains the minor ones into a path that reaches impact, and hands you a working proof of concept with the reproduction steps. When you fix it, the same attack is run again to confirm the path is actually closed.

Want this run against your own estate? A technical walkthrough against your environment, with scope agreed in writing before anything runs.
Book a scoping call