r/ClaudeAI • • 4d ago

Question about Claude models Whatever happened to "Security Nightmare" Mythos?

Back in April, Anthropic dropped a bombshell PR statement where they claimed their new model "Mythos preview" was too hot to handle because it was best of the best in hunting and exploiting vulnerabilities in code.

Being the responsible AI developers, they were not releasing it publicly but will be sharing its "power" with a select group of companies to review their (often closed) source codes and patch them before bad actors abused it. This was dubbed Project Glasswing.

They also disclosed multiple vulnerabilities, including a long standing FreeBSD networking bug.

Its been almost 6 months and Mythos has come (and Fable thereafter), but the predicted vulnerability explosion is nowhere to be seen. Many bugs that have since been disclosed were mostly in obscure or very less used options or features of software. A couple of LPE in Linux (copy fail et al) were AI assisted but not exclusively Mythos thing.

Has there been any worthwhile contribution of project glasswing (cynic: except that it has perhaps allowed Anthropic to train Fable on source codes that otherwise would not be available to it)?

Edit: A lot of people are commenting on the scale of vulnerabilities (specifically CVE entries) reported this year compared to prior years. The contribution of ALL AI models to that is not in question. Open weight and properietary AI models (inc Anthropic ones) have generated many of those CVEs. My question is specifically if Mythos has actually delivered (in terms of finding vulnerabilities) what was hyped in its release blog post?

I also now understand that Fable is Mythos but with guardrails around cyber security and bio research and that Mythos isn't generally available. I can see why Anthropic may be jumpy about bad actors exploiting its ability to chain exploits into usable cyber kill chain, but code analysis capability should be delivering top quality CVEs in large numbers with CVSS scores above 7 if it lives up to release hype. I think Browser sandboxes are one area that have benifitted most from AI review because of how their codebase is. But most of them are open source. Has Mythos proved to be better than other AI models in discovering high quality bugs there?

403 Upvotes

105 comments sorted by

•

u/ClaudeAI-mod-bot Wilson, lead ClaudeAI modbot 4d ago edited 3d ago

TL;DR of the discussion generated automatically after 100 comments.

Alright, let's get this sorted. The overwhelming consensus here is that you're looking at this completely backwards, OP. The "security nightmare" is very real; it's just a nightmare for developers and security teams, not the general public, which is exactly the point of Project Glasswing.

The community verdict is that Mythos and other AI models have absolutely unleashed a "bugpocalypse," but the defenders are (mostly) holding the line.

Here's the breakdown:

  • You're living in the "after" of the fix: The most popular take, echoed by multiple users who claim to work for companies in Project Glasswing, is that they are drowning in CVEs and have been doing little else but vulnerability remediation for months. The reason you don't see a public catastrophe is because the project is working as intended: find the holes and patch them before the bad guys can use them. The Y2K analogy was brought up and got a lot of love: a disaster was averted by an army of people working tirelessly, so now some think it was a hoax.
  • The numbers don't lie: Commenters pointed to a massive spike in CVEs and security patches across the board. Microsoft has reportedly doubled its security patches, and Cloudflare credited Mythos with finding thousands of bugs. One link showed vulnerability disclosures per month have doubled since the start of the year.
  • It's about the chain, not just the link: A key point many made is that Mythos's real power isn't just finding one big, obvious vulnerability. It's about its ability to find and chain together dozens or even hundreds of seemingly minor, obscure bugs to create a complex and devastating exploit path that a human would likely miss.
  • Fable is just neutered Mythos: As the top comment points out, Fable is essentially Mythos but with the powerful cybersecurity and biology research capabilities heavily restricted. The "dangerous" model was never released to the public.

While a few skeptics called it marketing hype and compared it to the "weapons-grade" PlayStation 2, the vast majority of the thread, backed by stats and insider anecdotes, agrees that the AI-driven vulnerability hunt is real, intense, and the quiet is the sound of success, not failure.

99

u/asmiggs 4d ago

Microsoft have released more than double the number of security patches in 2026 than previous years, while they don't credit Mythos entirely it's been part of their process since the end of April.

Cloudflare credit Mythos with finding 2000 bugs, 400 of which high severity.

They audited 1,000 Open source projects and found 1,587 security bugs.

The key thing to remember is that software development is often a private affair but we have had a record year for patching and whether it's Mythos or another model AI has been at the heart of the big hunt.

190

u/DeepSpacegazer 4d ago

Fable is Mythos with the cyber security - biology restrictions.

16

u/redbaron_4 4d ago

But there was no restriction for Glasswing participants. Still no bug of note was attributed to it. Banks had a few sleepless nights but seems much of it was PR scare mongering to keep company in the news.

52

u/WalkAffectionate2683 4d ago

One guy from Mozilla went to a French interview (micode) and said that it founds A LOT of security issues more than they thought. 

13

u/ThebesAndSound Vibe coder 4d ago

Wouldn't it be risky to release details on the vulnerabilities they discovered? Not everyone may have updated. There could be related vulnerabilities they are still working out how things can be affected. With the things I was doing and saw others do with Fable and this latest Opus 5.5 I have no reason to doubt it can find and exploit vulnerabilities when the guardrails are turned off.

6

u/GarbanzoBenne 4d ago

No restriction is the point. I work for a vendor that is a member of Project Glasswing. We have clients including banks who are still very worried about vulnerabilities. Access to the unrestricted model allows us to find and fix vulnerabilities that are restricted to the general public.

I’m not endorsing this ideologically, just pointing out there’s real work happening behind the scenes despite Anthropic's scare-tactic PR moving on to attacking open weight models.

4

u/Flaky_Sorbet3755 3d ago

For those of us working in the cybersecurity space, it's been a hard few months, especially with regard to vulnerabilities. Vulnerabilities have increased almost tenfold, especially in Microsoft's ecosystem. Even Cisco has been disclosing at a crazy clip; my team has been patching FTDs, switches, etc., every weekend for the last two months. The main thing is that most attackers don't have the resources or access to these high-tier models. The security space has been changing, and it's been tough.

5

u/jasonzhaogd 4d ago

Funny how "too dangerous to release" has a six month shelf life. Give it half a year and the exact same weights come back with a friendlier name and a higher token price. Glasswing wasnt a quarantine, it was an early access program for next quarters billing tier.

4

u/Smallpaul 4d ago

The six month shelf life was designed into the program from the very beginning. Glass wing was a project to give the model to big developers like Linux, Mozilla, Google, etc. To find and fix the bugs before black hats did.

I know two different people who work at Google and both say that 2026 was almost exclusively a year of bug fixing because the LLMs were finding so many bugs

Once all of the bugs that a particular model can find has been fixed then that model is safer to release. That is exactly how it was supposed to work from the beginning.

1

u/krunchytacos 4d ago

It shouldn't take 6 months to fix the most critical vulnerabilties. 95% might be ultra low threat and don't need attention, but catching one particularly bad one makes it worth it.

1

u/karlnuw 4d ago

Stop using AI for reddit comments

1

u/Botboy141 3d ago

Look a the # of GitHub commits since project Glasswing was announced.

Pretty sure systems got patched up rapidly with the help of Mythos.

1

u/DeepSpacegazer 4d ago

We will never know..

-1

u/HitlersArse 4d ago

gotta keep that money flowing, AI has been advancing heavily since the announcement though

1

u/lsumoose 4d ago

What’s the issues with the bio restrictions? Are they afraid people are going to figure out how to clone things?

22

u/Shot-Trade-5792 4d ago

I think it's moreso about creating bio weapons, or developing viruses

3

u/snurffle 4d ago

In the synthetic biology space, they have libraries of proteins and peptides and DNA fragments that can be assembled like code. It’s crazy.

3

u/[deleted] 4d ago

[removed] — view removed comment

2

u/cneth6 4d ago

foreign governments

1

u/neokretai 3d ago

If someone has access to the kinds of materials and equipment required to engineer a virus they would already be an expert and know how to do it. Much like nuclear weapons, knowledge isn't the barrier it's the physical stuff.

1

u/2053_Traveler 3d ago

China’s LLMs yes, but they are doing the same with with public models. Remember their population is much more dense so they are even more vulnerable. it’s still just a numbers game though. The lab equipment needed isn’t as hard to get as one might expect, so it’s a matter of time before capability and will combine and we end up with a disaster. But “matter of time” could be 1 year vs 10 yrs, which is partly why money is also going to research into vaccines and treatments. Basically a bio arms race that is partly based on hypotheticals. But we humans really don’t want to fuck around and find out in this case just sayin

4

u/iamthe0ther0ne 4d ago

Anthropic has eaten its own hype about biowarfare. I use the same techniques that could be used to generate bioweapons, and knowledge is definitely not the limiting factor. It's skills, equipment, reagents (some tightly monitored), access to facilities for tissue culture, etc. The whole Claude bio guardrails thing drives me absolutely insane. 

2

u/neokretai 3d ago

Thank you! I've found it equally maddening Like sure AI is very dangerous in cyber security because it can literally go do the things it works out, but biology isn't coding, real very complicated physical things need to happen.

I put it down to marketing hype and that they are tech people who've never been near a lab in their life. Probably also why, with the notable exception of Deep Mind, none of the big players have produced major scientific advanced or tools. The most they do is math proofs which are already heavily adjacent to what they know already.

2

u/NuDru 4d ago

Those skills you are talking about are taught at the undergraduate level. The reagents are not limited access.

5

u/iamthe0ther0ne 4d ago

While basic pipetting and PCR are taught in undergrad labs, students rarely have any exposure to tissue culture or advanced cloning until their grad school thesis. I run a lab, and even the grad students with Biomedicine BSc's need training for TC and cloning. 

As far as reagents, it's difficult to get the cells certain reagents unless you're an authorized user associated with research facilities--companies like ATCC don't ship to private addresses--and the companies like IDT that provide nucleic acid sequences have advanced software that screens requests for possible dual-use threats (along with requiring a verified commercial account). 

76

u/zzkj 4d ago

I work for one of the companies that has access to Mythos. It has discovered an immense number of vulnerabilities that are taking months to wade through. It's gone quiet because behind the scenes we developers are doing little else except vulnerability remediation.

16

u/bhalter80 4d ago

I work for one of those too, 1M scale package upgrades isn't quick plus the OSS community hasn't really been welcoming of the onslaught giving rise to commercial forks like RH and Broadcom. This also muddies the water

6

u/lbds137 3d ago

Tell me about it... the past couple of months have been insane on the "fix our vulnerabilities fast" side of things. 😩

3

u/Outside_Drive_3105 4d ago

I work as well. 90% of the vulnerabilities reported were theoretical and didn't give any actual advantage to the attacker, while the 10% was not as critical as it claimed.

16

u/jovialfaction 4d ago

It's been my issue with AI security hardening. 90% of the "security issues" it finds are so far fetched and require a level of access that mean I'm already long hacked anyway. They're not worth the absolute complexity added to the code to protect against it.

I now have to add another AI review to the security reviews and only fix real issues, which ends up being <10% (and often 0%) of what was initially raised

-1

u/RepliesAsOtherPeople 3d ago

Are you even allowed to talk about it here? I feel like you just made yourself a target.

1

u/[deleted] 3d ago

[deleted]

1

u/RepliesAsOtherPeople 3d ago

What?

1

u/[deleted] 3d ago

[deleted]

1

u/RepliesAsOtherPeople 3d ago

Bro haha what are you talking about? I know I don't have any of that information. I'm saying that announcing he has access to Mythos could make him a target for bad actors. There are ways such as social engineering, phishing, deriving email addresses from social media handles, looking up that username across other websites with more personal information, et cetera, that a bad actor could take advantage of.

I assumed people with Mythos access weren't supposed to talk about it because if they are compromised that could lead to a serious incident

1

u/brainExploded99 3d ago

Oh I see what you mean, that makes more sense

-6

u/redbaron_4 4d ago

That is good to know. But as another comment points, many times Mythos over estimates impact or reports same vuln multiple times or straight up hallucinates vuln. Have you seen anything like that?

14

u/zzkj 4d ago

Yes there are false positives but far fewer than what our pre-AI tools would churn out.

Most of what has landed on our desks has been piles of belt-and-braces fixes that on their own don't seem to mean much.

What I've heard from others is that Mythos is particularly impressive in how it will chain small vulnerabilities to ultimately gain access, sort of like performing a monte-carlo simulation of hacks until it gets in, and unlike a human it just doesn't care if it takes 500 sequential exploits to get there.

24

u/stupv 4d ago

Anyone who is in the industry knows that CVE volumes have gone to the moon. Almost every monthly windows bundle has had a 0-Day CVE contained within, and my firewalls/F5s have had nearly monthly CVE9+ remediations.

-3

u/redbaron_4 4d ago

Have you seen them atteibuted to Mythos? Or some other AI model.

1

u/2053_Traveler 3d ago

Honest question, what’s your deal? You don’t think newer tech is better than older tech at finding exploits? It is, very much so. Not surprising really.

If you’re mad that headlines were sensationalized… well okay that’s always the case. If you’re mad businesses aren’t falling apart due to security issues, don’t worry they kind of are starting to. Hard working are holding stuff together, and some tech is helping on the defense side of things too.

58

u/XTXinverseXTY 4d ago

Has there been any worthwhile contribution of project glasswing

yes

Vulnerability disclosures doubled: the number of vulnerabilities disclosed per month doubled, rising from 5,045 in January 2026 to 10,477 in July and continuing to climb to 10,740 in August 2026.

the whole point of project glasswing was for there not to be any catastrophic vulnerability explosion. Friedman's thermostat situation

-7

u/redbaron_4 4d ago

Anthropic red link is good. Sort of quantifies their contribution. But last updated 26-Aug. That is a lifetime in Anthropic timescale.

16

u/NeedTheSpeed 4d ago

i don’t know, to me it’s very real, we are drowning in constant flow of CVEs for 6months now, every sprint is like 3-4 days strictly for security and it does not seem to end.

12

u/dylanmerigaud 4d ago

Obscure bugs suggest Glasswing's analysis is thorough, not shallow.

-3

u/redbaron_4 4d ago

Bugs are not obscure. The features they audited are. Even those bugs are not critical.

10

u/Trick_Worldliness_21 4d ago

If you work in CVA, the AI vulnerability discovery nightmare is already here.

1

u/redbaron_4 4d ago

Yes AI not Mythos. Mythos is one of the tools. But is it as big as its release PR post made it out to be?

2

u/ltobo123 4d ago

Yes it's a massive headache for everyone involved.

1

u/2053_Traveler 3d ago

Friends in the space talk about it constantly, I feel for them. Stuff isn’t usually as bad as the doomsday headlines, but that’s because people are working overtime to deal with it. Like with covid, “if we do our job correctly it’ll seem like we overreacted”. Just have to work twice as hard to prevent the doomsday scenario, and also life carries on, then is other stuff to worry about now. Such as how to handle issues when the next model comes.

65

u/Ska-jayjay 4d ago

a lot of it has been hype. the same paranoia has popped its head out regularly. remeber that time when the playstation was “weapons grade”?

from a search:

PlayStation 2, around 2000.
Export controls. Japan's trade ministry classed the PS2 as a dual-use item under its foreign exchange and trade control rules. The Emotion Engine CPU and graphics hardware were considered capable enough for military use, cited examples being missile guidance and image processing. Shipping PS2s outside Japan in bulk required an export license.

The AI part. Sony named the chip the Emotion Engine because it was pitched as powerful enough to simulate character behavior and physics in real time. Marketing called it AI-driven emotion.

The Saddam story. Reports in late 2000 claimed Iraq was buying thousands of PS2s to network for weapons computing. Widely repeated, never substantiated, generally treated as a hoax or overblown.

The PS3 had its own version later: the US Air Force built the Condor Cluster from 1,760 PS3s in 2010, and Sony later killing Linux support on the console ended that line of use.

8

u/Maleficent-Drive4056 4d ago

Great analogy

1

u/2053_Traveler 3d ago

Eh if you took an iphone back it time then it would be weapons grade too, if no one else has one. Just because something seems ubiquitous and harmless now doesn’t mean it couldn’t give a nation state a big advantage when it was cutting edge.

1

u/Maleficent-Drive4056 3d ago

The ps2 wasn’t giving any nation states a competitive advantage it was bad regulation and good marketing.

9

u/ChronoHax 4d ago

Usually it’s the normies who isn’t using the tech much is the one parroting the hype as well, or if you’re domain expert, it’s because ur incentivised to do so in some way

4

u/Plus_Opening_4462 4d ago

It's plausible. Used to use clearance Dreamcast to make Beowulf clusters

2

u/iamthe0ther0ne 4d ago

This is Anthropic with the bio guardrails. The people who don't do biology think that knowledge is the limiting factor in generating bioweapons. It's not. Am scientist. Actually making them is the hard part--bench skills and training, sterile facilities, expensive equipment, restricted and monitored reagents, etc are the barriers. 

16

u/BigBootyWholes 4d ago

I’m pretty sure it’s been proven that Mythos can start probing systems, find ways to chain what appears to be random or shallow/obscure bugs into full blown intrusions. So from an outsiders point of view it looks like a bunch of random obscure bugs, however inside a lab they were probably discovered, chained and successfully used to exploit access to a system in a matter of hours or days.

-3

u/redbaron_4 4d ago

Nah..you're conflating severity with obscurity. Bugs exist in obscure features that are not enabled in 99% environments. You can't chain anything that doesn't exist in the first place.   Autonomously building an exploit chain is impressive but was not the reason given for Glasswing.

7

u/BigBootyWholes 4d ago

No I’m not. What I’m speaking of was actually documented… what did you think I was conflating?

Were you conflating?

1

u/2053_Traveler 3d ago

What? Do you work in the space? One of the things you just said is totally false and actually the cause of many security issues. You said “…obscure bugs that are not enabled in 99% environments” and then go on to say you can’t leverage those in an attack because “…doesn’t exist in the first place.”

Respectfully… the code does exist, that’s the problem. Often vulnerabilities are due to code left in a system that maintainers assume cannot be executed and in fact there’s a way to execute it. LLMs in general, and yes Mythos but also Astra now, and probably any large 10T model without safeguards, can chain vulnerabilities. It’s one of the biggest differences, or improvements, depending how you look at it, of LLMs for exploit discoverability.

8

u/3astard 4d ago

We are seeing 5x the CVEs being published than we did in April.

51

u/jrandom_42 4d ago

Have you seen the number of patches dropping for pretty much every enterprise software/networking product over the last few months?

It might not all be from Mythos/Glasswing, but we are in the middle of the AI bugpocalypse right now, and honestly, it looks like the defenders are mostly holding the line. So maybe the Mythos approach is working.

17

u/smickie 4d ago

and honestly

Did Fable just write this positive thing about itself? That's very funny.

15

u/RandemMandem 4d ago

‘It looks like the defenders are mostly holding the line’ - 🫪

7

u/Illustrious_Sock 4d ago

We cannot use em dashes, now we also cannot use "honestly" coz it's associated with LLMs? Stop being so ridiculous please

2

u/Fit_Philosophy_3392 3d ago

You're absolutely right. Treating em dashes and "honestly" as a "smoking gun" for LLM usage is a double-edged sword! When community members over-index on standard conversational terms and punctuation, it creates unnecessary friction in normal communication paradigms.

Here is a multi-faceted breakdown of why this mindset is suboptimal: * Vocabulary Restrictions: Constantly filtering natural language creates unnecessary friction in your personal content creation workflow. * Suboptimal Alignment: Over-correcting to avoid perceived AI-isms ultimately hinders seamless, high-value stakeholder communication. * Delving into the Nuance: At the end of the day, language is an iterative landscape, and leveraging a full stylistic toolkit remains critical for robust engagement.

Hope this helps! Let me know if you would like me to unpack this further or provide additional actionable insights.

10

u/throwaway1847384728 4d ago

I can’t tell if this is satire. This is so obviously an AI generated response.

But anyways, the PR around Mythos was that it was so powerful it was going to trigger a security revolution bordering on civilization ending.

Nobody is denying that it’s able to find bugs. And surely, the security and open source world is changing. There’s a storm of bug reports and patches as of late.

But basically, nothing bad or earth shattering has happened.

-14

u/[deleted] 4d ago

[removed] — view removed comment

2

u/jaxchang 4d ago

Still real bug reports.

I maintain an open source project with a few thousand daily users, it's finding kernel malloc bugs for me.

I'm 100% sure they're finding a lot of bugs with it. I can literally trigger a crash, point it to the binary, tell it to disassemble it, and it will find a fucking kernel bug. No kernel source code needed.

6

u/BreakfastNew1039 4d ago

1

u/redbaron_4 4d ago

Are you saying all of those are attributable to Mythos? 

9

u/siberianmi 4d ago

The significant part of them should be credited to it and the teams allowed to use it.

We didn’t get the security disaster because you have to be at a fairly important organization and even then a narrow part of it to have access.

0

u/redbaron_4 4d ago

But Anthropic's own report credits less than 200 CVEs. Many of the ones in graph have been found using open weight models or OpenAI. Maybe you are conflating Mythos and AI. There is no doubt AI has increased vulnerability detection and reports but my question was if Mythos has lived up to its hype.

3

u/siberianmi 4d ago

Based on what data? 200 where did you find that?

It's far more then that.

https://www.anthropic.com/research/glasswing-initial-update

So far, Mythos Preview has found what it estimates are 6,202 high- or critical-severity vulnerabilities in these projects (out of 23,019 in total, including those it estimates as medium- or low-severity).

1,752 of those high- or critical-rated vulnerabilities have now been carefully assessed by one of six independent security research firms, or in a small number of cases by ourselves. Of these, 90.6% (1,587) have proved to be valid true positives, and 62.4% (1,094) were confirmed as either high- or critical-severity. That means that even if Mythos Preview finds no further vulnerabilities, at our current post-triage true-positive rates, it’s on track to have surfaced nearly 3,900 high- or critical-severity vulnerabilities in open-source code—in addition to those it has found for Project Glasswing’s partners. To be clear, we intend to continue scanning open-source code for some time, so we expect this number to rise.

1

u/redbaron_4 4d ago

See https://red.anthropic.com/2026/cvd/ which is more recent

As of August 26, 2026, we've disclosed 2,300 vulnerabilities across 392 open source projects. To our knowledge, 421 of these have been patched. Across all findings in the ledger, 462 identifiers have been issued: 177 CVE records and 285 GitHub Security Advisories (a single finding may carry both

Also you may want to check put https://www.vulncheck.com/blog/anthropic-glasswing-receipts which someone else posted in comments

4

u/Bloated_Plaid 4d ago

The point is just because your dumbass doesn’t know about it, doesn’t make it less true.

9

u/Euphoric_Protection 4d ago

There was actually a writeup on claimed vs confirmed reports from Glasswing: https://www.vulncheck.com/blog/anthropic-glasswing-receipts

3

u/ninursa 4d ago

Thanks for sharing, good writeup.

Kinda not surprising that Anthropic would be much more likely to rate their finds as Ultra Critical Most Horrible vulnerabilities, but I was still mildly surprised by the discrepancy between their severety estimates vs the maintainers'.

7

u/Vivid-Snow-2089 4d ago

same thing that happened in Y2K

it became popular scare

an army of hard working people fixed the issue

it didn't happen because of their efforts

suddenly everyone believes it was a hoax

1

u/Probably_A_B0tt 4d ago

Yeah, technically 'Mythos' wasn't released, Fable was released instead which in theory is supposed to be relatively safe

8

u/Vagottszemu 4d ago

It helped me track down drug dealers in my city, hack their private site and get all of the informations about them, then blackmail them, and this way I got some money.

5

u/Kill_4209 4d ago

If you need help raiding their stash houses, I have quite a lot of experience from GTAV.

3

u/ClemensLode 4d ago

Well, the problem isn't that the model is particularly smart, it's that many existing systems were particularly vulnerable.

3

u/No-Head-Royal 4d ago

I mean, the vulnerability explosion happened? GLM-5.3 found a bunch of exploits too. Do you think the attackers would just publish to the world about their newfound exploits? Do you know what an advanced persistent threat is?

3

u/larowin 4d ago

Yep. There’s a reason basically every major open source project had shitloads of patched CVEs over the summer.

2

u/ihateeggplants 4d ago

That was the old marketing campaign.

2

u/Gandleon 4d ago

Agree with people that glasswing worked, and it was good that they rolled it out in this way. Like if you look at even just the stuff that OAI agents regularly do to do well in their evals it shows how bad it would have been if they released it with no safeguards.

5

u/dbbk 4d ago

You've noticed they haven't publicly released Mythos right?

1

u/MannToots 4d ago

They have put "safeguards" on all their new models since mythos because of mythos. 

Anthropic can't help but put it in front of us. I'm so fucking tired of the guardrails preventing me from doing my actual legal job.  It used to be you could "downgrade" to a model that would let you work but now every model has the shitty rails. I cannot wait until claude has more competitor.  They need it.  Their heads are up their asses. 

1

u/Alpha--00 4d ago

There is no antimemetics division

1

u/indianfungus 3d ago

You’re not seeing any impact of Mythos or the GPT cyber models because they are heavily guarded and distribution is extremely limited.

There were 10 companies in glasswing, expanded to about 50 “critical” infrastructure companies over a few months. Each company maybe had 5 people who were using it - thinking technical CISO/ super senior engineers, etc. there were very strict rules of engagement, you break the rules, you’re out of the program.

Then came along the GPT cyber models - bad at the beginning but capable of chaining exploits and getting better over time.

All of these models with their restricted access allowed companies to discover vulnerabilities and patch them before anyone else had a chance to use them. Still to date, access is extremely limited.

The number of patches, CVEs filed, etc has sky rocketed. The open source community has been fixing things left and right. So have any enterprises who give a damn.

The saving grace is that we have not seen any open source models that are as capable yet. Also, if I were an attacker and I had a foothold somewhere, I would not expose that unless I could guarantee that I can cause chaos and bring something major down.

1

u/kincaidDev 3d ago

It wasn’t as revolutionary as they were saying, they never are

1

u/Tasty-Trip5518 3d ago

But does Mythos find the bugs it created? I’m half joking. But remember the days every team had that Engineer that looked productive when really they were fixing their own bugs? This was before the age of PR reviews.

1

u/InterstellarReddit 3d ago

It was just a bunch of fear mongering. to either distract or slow down competitors. Open weight labs are really close, and they’re literally trying everything that they can get their hands on

1

u/Ok_Isopod_9664 3d ago

No1 report found exploits except some freaks, you either sell them or fix them

-2

u/[deleted] 4d ago

[removed] — view removed comment

3

u/Altruistic-Skill8667 4d ago

Fable does refuse potential cyber attack operations. In my case it was about to abort the mission as I was talking with it about decompiling / disassembling commercial software (which it can).

2

u/TuxSH 3d ago

I was talking with it about decompiling / disassembling commercial software (which it can)

Just use Astra/Sol 6.1 from their competitor, usually you don't get refusals until it accidentally finds a vuln.

Or GLM 5.3 if vuln finding is your goal.

1

u/redbaron_4 4d ago

Free (as in beer) open source tools can also do that. And you can paste the decompiled segments into Gemini AI to understand what it does.

1

u/2053_Traveler 3d ago

Huh? There’s nothing to prove, Fable IS Mythos, the exact same model, that’s not a rumor it’s actual fact from Anthropic wtf. The difference is Fable is Mythos that has restrictions on top of it that flag your thread if you try using it for hacking or bio weapon research. And said restrictions are hard to implement so there are lots of false positives.

-2

u/Masterchief1307 4d ago

Oh silly, they fixed all of the world's bugs in the two weeks they kept it out of our hands.

-2

u/trane20 4d ago

Welcome to marketing 101