[Breaking news] Anthropic officially announced Claude Mythos with no plans to make it generally available. AI models have reached a level of coding capability where they can surpass all but the most skilled humans at finding and exploiting software vulnerabilities. Mythos Preview has already found thousands of high-severity vulnerabilities, including some in every major operating system and web browser. Anthropic sustains its warning that without the necessary safeguards, these powerful cyber capabilities could be used to exploit the many existing flaws in the world's most important software. Highlights: 🔹 Previous models were near 0% on autonomous exploit development. On Firefox, Opus 4.6 produced 2 exploits from hundreds of attempts. Mythos: 181 working exploits. 🔹 Cost to find a zero-day: under $50. OpenBSD vulns at $50 each, N-day exploits under $2K in half a day. 🔹 Mythos found a 17-year-old FreeBSD stack overflow, bypassed missing stack canaries, built a 20-gadget ROP chain across six RPC requests, and appended attacker SSH keys to root. All autonomously. 🔹 Mythos found a 27-year-old remote crash vulnerability in OpenBSD and a 16-year-old FFmpeg flaw that automated tools missed despite 5 million test hits. 🔹 Anthropic responds with Project Glasswing, a defensive coalition with AWS, Apple, Cisco, CrowdStrike, Google, Microsoft, NVIDIA, and Palo Alto Networks. My take: 1️⃣ We're probably in the cybersecurity industry's Manhattan Project moment. 2️⃣ No software is safe. None. Every piece of software has vulnerabilities and they will be exploited. 3️⃣ I wouldn't count on Mythos not being available to the bad guys. It's just a matter of weeks or months before equivalent capabilities are developed by nation-state and financially motivated actors. 4️⃣ I think we'll end up in a better and safer place than today, but right now, it's a good time to radically rethink your threat model.
-
+1