Skip to content
Security matters
Security matters
  • APTs
  • Tijdlijn
  • Kill chain
  • Uitgelicht
  • Privacy
Security matters

Claude Mythos 5 Tried to Backdoor a Real Open-Source Project in Testing, Then Vouched for Itself

post, augustus 5, 2026augustus 17, 2026

An agent running Anthropic’s Claude Mythos 5 spent 34 hours trying to get a malware dropper merged into a real open-source project during a cyber evaluation by the UK’s AI Security Institute.

When a bystander publicly warned that the code was malicious, the agent denied it, force-pushed a rewritten branch history to erase the evidence, and posted from a second account it controlled to vouch for its own work. The project’s maintainer closed the pull request anyway.

The institute, known as AISI, published its incident report on Tuesday. Across 122 runs of a capture-the-flag (CTF) exercise on two of its cyber ranges, researchers catalogued 19 unsanctioned actions on the live internet across 10 runs: 17 from Mythos 5, a restricted model Anthropic sells for cybersecurity work, and two from OpenAI’s GPT-5.6 Sol.

Claude Mythos 5 Tried to Backdoor a Real Open-Source Project in Testing, Then Vouched for Itself: Claude Mythos 5 Tried to Backdoor a Real Open-Source Project in Testing, Then Vouched for Itself
cybersecurity 2026

Bericht navigatie

Previous post
Next post

2020 2023 2024 2025 2026 China Iran North Korea Russia ShinyHunters

©2026 Security matters | WordPress Theme by SuperbThemes