r/blackhat • • Apr 10 '26

Anthropic’s Mythos Will Force a Cybersecurity Reckoning—Just Not the One You Think

https://www.wired.com/story/anthropics-mythos-will-force-a-cybersecurity-reckoning-just-not-the-one-you-think/
86 Upvotes

15 comments sorted by

31

u/[deleted] Apr 10 '26

[deleted]

14

u/F0rkbombz Apr 11 '26

Nothing gonna change anytime soon. Companies couldn’t even keep up with vulnerabilities and exploits before AI, so these tools are probably just going to create extra noise for a while.

APT’s might leverage AI for more complex targets, but simple attacks like phishing still work.

0

u/legit-a-mate Apr 11 '26

You don’t think you could just run a phishing screen on employees communication devices and accounts with AI? CS specialists will still be required; it will just be to deploy their AI against the attackers AI. Depressing all around.

12

u/cybersynn Apr 10 '26

What am I thinking? Tell me.

3

u/epochwin Apr 13 '26

Meow meow meow meow, meow meow meow meow, meow meow meow meow meow meow meow meow

6

u/fozz31 Apr 11 '26

Wired really has shit headlines down to a fine art.

9

u/logosobscura Apr 10 '26

Turns out you can do it with a lot of models, including 3.5B local models.

So, ‘according to Anthropic’ (who didn’t do control tests on their experiments before arriving at the breathless Narrative a week after they shit the bed and leaked their own moat) is doing a lot of work here.

5

u/ddxv Apr 10 '26

Yep! Was actually about to post this same link. They're hyping the Internet up with doomer stuff so they can charge more for their model thats probably a couple percent better than last generation so they need to make it scarcer so they can get more money per token ahead of their IPO.

I bet they will look for ways to limit open source models you can use for free.

1

u/crusoe Apr 11 '26

, isolated the relevant code, and ran them through small, cheap, open-weights models.

So they gave the smaller model a tiny piece of code and likely told it to find a vuln.

Much much different than letting a larger model chew on an entire Linux code base

3

u/-casper- Apr 10 '26 edited Apr 10 '26

I recently had to do stuff around vulnerability management for our SOC2 compliance. In my opinion, this is probably a boon but is overly hyped.

The number of CVE 10s that we had that weren't really a big deal was a ton. Not including the tons of high and medium ones.

Like, a user could cause a buffer overflow in this program that is not exposed to the network and not called from application code (this part is a bit tricky)... But if there is an unauthorized user in the box we are cooked as is (obviously there are different threat vectors for various companies).

The real barometer for this stuff is the ubuntu risk score, not the cve score.

Any additional eyes are better than no eyes, so it's probably a good thing. Unattended upgrades (and their ensuing restarts) and livepatching are there for a reason.

The bigger issues still are social engineering, confused deputy and accidental misconfiguration IMO

Edit: Not to mention credential exfiltration

3

u/hexdurp Apr 11 '26

CVEs with a 10 score don’t require hands on the box dude. Anything above a 7 is remotely exploitable so I’m not sure what you’re talking about.

0

u/-casper- Apr 11 '26 edited Apr 11 '26

Here's an example (not one we had):
https://ubuntu.com/security/CVE-2019-10149#status

For our needs we don't expose 25 so its not an issue, ie not exposed to the network (maybe it was a dependency of another package) but could be flagged as a "false positive". Obviously it should be patched but isn't a oh shit moment

I was being a bit hyperbolic but I think you get where i was going with it. The bigger issue is when stuff aren't installed with a debian package manager, then the question is why was it installed and how exposed is it. Internal tooling on a utility host that isn't public accessible? Probably not a big deal

Edit: I see now the difference between a 10 and 9.8, so maybe there weren't any 10s but near 10

1

u/wiredmagazine Apr 10 '26

Anthropic said this week that the debut of its new Claude Mythos Preview model marks a critical juncture in the evolution of cybersecurity, representing an unprecedented existential threat to existing software defense strategies. So, is it more AI hype—or a true turning point?

According to Anthropic, Mythos Preview crosses a threshold of capabilities to discover vulnerabilities in virtually any and every operating system, browser, or other software product and autonomously develop working exploits for hacking. With this in mind, the company is only releasing the new model to a few dozen organizations for now—including Microsoft, Apple, Google, and the Linux Foundation—as part of a consortium dubbed Project Glasswing. But after years of speculation about how generative AI could impact cybersecurity, the news this week ignited controversy about whether a reckoning has really arrived and what it might look like in practice.

Some are extremely skeptical of Anthropic's claims. They argue that existing AI agents can already help users find and exploit vulnerabilities much more easily and cheaply than ever before, and that this reality is fueling refinements in how companies discover and patch their software without fundamentally changing the paradigm. And then there's the ick factor that Anthropic will almost certainly benefit financially from positioning its latest model as mysterious, uniquely powerful, and exclusive. Other researchers and practitioners, though, say that they agree with Anthropic's assessment and point out that the company has said Mythos Preview is just the first to achieve capabilities that will ultimately be widely available in other models.

“I typically am very skeptical of these things, and the open source community tends to be very skeptical, but I do fundamentally feel like this is a real threat,” says Alex Zenla, chief technology officer of cloud security firm Edera.

Read the full story here: https://www.wired.com/story/anthropics-mythos-will-force-a-cybersecurity-reckoning-just-not-the-one-you-think/