Anthropic launches Mythos, a new cybersecurity model so powerful it is tightly restricted

Anthropic launches Mythos, a new cybersecurity model so powerful it is tightly restricted

Anthropic has introduced Mythos, a new frontier AI model focused on cybersecurity, as part of its Project Glasswing initiative. The company describes it as a “step change” in capabilities, and while the preview is not generally available due to security concerns, it is being offered to 12 partners, including Amazon, Apple, Broadcom, Cisco, CrowdStrike, the Linux Foundation, Microsoft, and Palo Alto Networks, along with 40 additional organizations that are using the model to help find and fix vulnerabilities across Anthropic’s own systems and open source software.

Anthropic says the model has already found thousands of high severity zero day vulnerabilities in recent weeks, with many of the flaws dating back more than a decade. The company says that although Mythos was not specifically trained for cybersecurity, its coding and reasoning capabilities make it effective for real world software analysis, while internally it has been described as more capable than the Opus line in areas such as coding, reasoning, and academic tasks. Ironically, leaked documents also raised concerns about how it could be misused by hackers if deployed offensively, which helps explain why it is not currently available to the general public.

Speaking of those recent leaks, it was actually through them that Mythos was first revealed under the name "Capybara", after a draft blog post was exposed in an unsecured cache, something the company later attributed to human error. More recently, Anthropic also exposed Claude Code source files through a packaging mistake, which triggered a messy cleanup effort and accidental GitHub repository takedowns.

by Mauricio B. Holguin

justarandomKaitan-IDalternativeto-dingo898
justarandom found this interesting
Claude iconClaude
  127
  • ...

Claude is an AI chatbot developed by Anthropic, leveraging advanced research to ensure it is helpful, honest, and harmless. Accessible via a chat interface and API, Claude excels in diverse conversational and text processing tasks. Key features include AI-powered capabilities, dark mode, and a chatbot interface. Rated 3.2, Claude's alternatives include other AI-powered chatbots and text processing tools.

Comments

RDF0909
0

I have a more advanced model I personally made. It does really cool stuff. Starting bid is $10 million.

akselaeration
0

Mythos is not NEW NEWS, the funny part of Anthropic workforce use WRONG LLMs to send sensitive info is NOT new, and is not something that is written in statements, but that doesn`t make it less correct.. Fighting Trump, Pentagon, Open AI, the works can make you use "enter" at the worst time...

Hendrikus Gregory
0

If this is the case, what can we expect from future models — and what does this mean for the security posture of SMB stakeholders? They need to accelerate their efforts to secure their infrastructure.

UserPower
1

Mythos, in ancient Greek, means "fiction", certainly because automatic finding vulnerabilities is all fiction.

Google has a whole team of experienced security analyzers dedicated to track vulnerabilities (and seems to only be part of Glasswing because it's offering it on its cloud) and the best automatic tool is still fuzzy-testing.

Now is thousands severe 0-day vulnerabilities a lot? In Linux, yes, it's enormous. In Windows, about how much are introduced in any update.

2 replies
BorisF

Great catch on the "fiction" part. I do believe it will catch some vulnerabilities that humans miss, but it will also miss plenty of vulnerabilities that people catch. It is not the ultimate tool, just one of the tools. The rest is hype to increase the stock price. All AI companies do it.

Darlene Sonalder

While there is probably more marketing hype than reality I honestly wouldn't be surprise than an expensive heavy model is able to catch batch of huge vulnerabilities in any code. LLM are getting impressively efficient at writing code. Of course having experienced developers using them as juniors is important for getting good results but we are here, in a world were machine can push working code, find vulnerabilities all of this without sleeping and consuming tons of water.

Gu