21 ms·
Project Glasswing: Securing critical software for the AI era
Related: Assessing Claude Mythos Preview's cybersecurity capabilities - https://news.ycombinator.com/item?id=47679155 https://news.ycombinator.com/item?id=47679155
System Card: Claude Mythos Preview [pdf] - https://news.ycombinator.com/item?id=47679258 https://news.ycombinator.com/item?id=47679258
Also: Anthropic's Project Glasswing sounds necessary to me - https://news.ycombinator.com/item?id=47681241 https://news.ycombinator.com/item?id=47681241
- paoliniluis 6mo agoDoes everyone agrees that this makes Dario Amodei more powerful than any politician across the world? Anthropic is now the owner of the most powerful cyberweapon ever made
- oyebenny 6mo agowhy do I feel like the auditing industry is about to evaporate? thanks to this.
- KeplerBoy 6mo agoI guess the more likely option is the auditing industry will pay huge sums to get access to those models as vetted operators.
- deleted 6mo ago[deleted]
- Ryan5453 6mo agoPricing for Mythos Preview is $25/$125, so cheaper than GPT 4.5 ($75/$150) and GPT 5.4 Pro ($30/$180)
- cassianoleal 6mo agoWhere did you get that from? From TFA: > We do not plan to make Claude Mythos Preview generally available
- Tiberium 6mo agoFrom the article: > Anthropic’s commitment of $100M in model usage credits to Project Glasswing and additional participants will cover substantial usage throughout this research preview. Afterward, Claude Mythos Preview will be available to participants at $25/$125 per million input/output tokens (participants can access the model on the Claude API, Amazon Bedrock, Google Cloud’s Vertex AI, and Microsoft Foundry).
- underdeserver 6mo agoKey point: available to participants.
- conradkay 6mo agopermanent underclass has arrived :(
- philipwhiuk 6mo agogive it a couple months
- conradkay 6mo agoFor comparison, 5x the cost of Opus 4.6, and 1.67x for Opus 4.1 I think this would be very heavily used if they released it, completely unlike GPT 4.5
- adi_kurian 6mo agoOpus 4 & 4.1 are still on Vertex+Bedrock @ $75/1mm out. They were used very heavily and in my subjective opinion are better than 4.5 and 4.6.
- breakingcups 6mo agoInteresting, what makes them better to you?
- adi_kurian 6mo agoOpus 4, with enough context, could do most all I wanted in a single shot. More often than not, when I had a bad outcome and was frustrated I would realize that I was the problem (in giving improper direction or missing key context). I also was in a pretty sweet position having a boat load of credits and premo vertex rate limits so I could 'afford' to dump hundreds of thousands of tokens in context all day. With Opus 4.5 and 4.6, I find I have to steer very actively. This is comparing using Opus 4 directly rather than comparing the performance of the models in Claude Code for example, or any 'agentic' setup. Kinda reminds me of 4o vs 4-turbo. I would imagine they are smaller models.
- LoganDark 6mo agoIt's nice to know that they continue to be committed to advertising how safe and ethical they are.
- rvz 6mo agoThey are not our friends and are the exact opposite of what they are preaching to be. Let alone their CEO scare mongering and actively attempting to get the government to ban local AI models running on your machine.
- simianwords 6mo agoHow would you expect them to behave if they were your friends?
- ethin 6mo agoIMO (not the GP) but if Anthropic were my friends I would expect them to publish research that didn't just inflate the company itself and that was both reproduceable and verifiable. Not just puff pieces that describe how ethical they are. After all, if a company has to remind you in every PR piece that they are ethical and safety-focused, there is a decent probability that they are the exact opposite.
- Miraste 6mo agoThey are a for-profit company, working on a project to eliminate all human labor and take the gains for themselves, with no plan to allow for the survival of anyone who works for a living. They're definitionally not your friends. While they remain for-profit, their specific behaviors don't really matter.
- simianwords 6mo agoI work for a tech company that eliminates a form of human labour and they remain for profit
- ehutch79 6mo agoJust include 'make it secure' in the prompt. Duh. /s
- zachperkel 6mo agoMythos Preview has already found thousands of high-severity vulnerabilities, including some in every major operating system and web browser. Scary but also cool
- fsflover 6mo agoEvery piece of software definitely has serious vulnerabilities, perfection is not achievable. Fortunately we have another approach to security: security through compartmentalization. See: https://qubes-os.org https://qubes-os.org
- syndeo 6mo agoOnce you get the compartmentalization working well, and “all” of the vulnerabilities are out of it too, of course… But even then you’ll have users putting things in the same compartment for convenience, rather than leaving them properly sequestered.
- fsflover 6mo ago> and “all” of the vulnerabilities are out of it too This is a good point; however the isolating code should be much smaller and easier to verify.
- dakolli 6mo agoOr more likely, its just an exaggeration or lie.
- solenoid0937 6mo agoYes I'm sure this is all a massive conspiracy by the many companies that are making statements alongside Anthropic
- rainbow13 6mo ago[dead]
- jryio 6mo agoLet's fast forward the clock. Does software security converge on a world with fewer vulnerabilities or more? I'm not sure it converges equally in all places. My understanding is that the pre-AI distribution of software quality (and vulnerabilities) will be massively exaggerated. More small vulnerable projects and fewer large vulnerable ones. It seems that large technology and infrastructure companies will be able to defend themselves by preempting token expenditure to catch vulnerabilities while the rest of the market is left with a "large token spend or get hacked" dilemma.
- mlinsey 6mo agoI'm pretty optimistic that not only does this clean up a lot of vulns in old code, but applying this level of scrutiny becomes a mandatory part of the vibecoding-toolchain. The biggest issue is legacy systems that are difficult to patch in practice.
- pipo234 6mo agoWait. Wasn't AI supposed to alleviate the burden of legacy code?!
- mlinsey 6mo agoIf we have the source and it's easy to test, validate, and deploy an update - AI should make those easier to update. I am thinking of situations where one of those aren't true - where testing a proposed update is expensive or complicated, that are in systems that are hard to physically push updates to (think embedded systems) etc
- rattlesnakedave 6mo agoLegacy code, not the running systems powered by legacy code
- buzzerbetrayed 6mo agoIf you’re still an AI skeptic at this point, I don’t know what sort of advancement could convince you that this is happening.
- redfloatplane 6mo agoThe system card for Claude Mythos (PDF): https://www-cdn.anthropic.com/53566bf5440a10affd749724787c8913a2ae0841.pdf https://www-cdn.anthropic.com/53566bf5440a10affd749724787c89... Interesting to see that they will not be releasing Mythos generally. [edit: Mythos Preview generally - fair to say they may release a similar model but not this exact one] I'm still reading the system card but here's a little highlight: > Early indications in the training of Claude Mythos Preview suggested that the model was likely to have very strong general capabilities. We were sufficiently concerned about the potential risks of such a model that, for the first time, we arranged a 24-hour period of internal alignment review (discussed in the alignment assessment) before deploying an early version of the model for widespread internal use. This was in order to gain assurance against the model causing damage when interacting with internal infrastructure. and interestingly: > To be explicit, the decision not to make this model generally available does _not_ stem from Responsible Scaling Policy requirements. Also really worth reading is section 7.2 which describes how the model "feels" to interact with. That's also what I remember from their release of Opus 4.5 in November - in a video an Anthropic employee described how they 'trusted' Opus to do more with less supervision. I think that is a pretty valuable benchmark at a certain level of 'intelligence'. Few of my co-workers could pass SWEBench but I would trust quite a few of them, and it's not entirely the same set. Also very interesting is that they believe Mythos is higher risk than past models as an autonomous saboteur, to the point they've published a separate risk report for that specific threat model: https://www-cdn.anthropic.com/79c2d46d997783b9d2fb3241de43218158e5f25c.pdf https://www-cdn.anthropic.com/79c2d46d997783b9d2fb3241de4321... The threat model in question: > An AI model with access to powerful affordances within an organization could use its affordances to autonomously exploit, manipulate, or tamper with that organization’s systems or decision-making in a way that raises the risk of future significantly harmful outcomes (e.g. by altering the results of AI safety research).
- enraged_camel 6mo ago>> Interesting to see that they will not be releasing Mythos generally. I don't think this is accurate. The document says they don't plan to release the Preview generally.
- 6mo ago
- taupi 6mo agoPart of me wonders if they're not releasing it for safety reasons, but just because it's too expensive to serve. Why not both?
- coffeebeqn 6mo agoIf these numbers are correct it’s probably worth the extra price
- wyre 6mo agoI don't think they have the infra to support the demand. Anthropic can't keep up with the demand from OpenClaw users, they won't be able to keep up with public demand for something like Mythos.
- endunless 6mo agoAnother Anthropic PR release based on Anthropic’s own research, uncorroborated by any outside source, where the underlying, unquestioned fact is that their model can do something incredible. > AI models have reached a level of coding capability where they can surpass all but the most skilled humans at finding and exploiting software vulnerabilities I like Anthropic, but these are becoming increasingly transparent attempts to inflate the perceived capability of their products.
- NitpickLawyer 6mo agoWe'll find out in due time if their 0days were really that good. Apparently they're releasing hashes and will publish the details after they get patched. So far they've talked about DoS in OpenBSD, privesc in Linux and something in ffmpeg. Not groundbreaking, but not nothing either (for an allegedly autonomous discovery system). While some stuff is obviously marketing fluff, the general direction doesn't surprise me at all, and it's obvious that with model capabilities increase comes better success in finding 0days. It was only a matter of time.
- conradkay 6mo agoI would've basically agreed with you until I'd seen this talk: https://www.youtube.com/watch?v=1sd26pWhfmg https://www.youtube.com/watch?v=1sd26pWhfmg Maybe a bad example since Nicholas works at Anthropic, but they're very accomplished and I doubt they're being misleading or even overly grandiose here See the slide 13 minutes in, which makes it look to be quite a sudden change
- endunless 6mo agoVery interesting, thanks for sharing. > I doubt they're being misleading or even overly grandiose here I think I agree. We could definitely do much worse than Anthropic in terms of companies who can influence how these things develop.
- bink 6mo agoI watched the talk as well and it's very interesting. But isn't this just a buffer overflow in the NFS client code? The way the LLM diagnosed the flaw, demonstrated the bug, and wrote an exploit is cool and all, but doesn't this still come down to the fact that the NFS client wasn't checking bounds before copying a bunch of data into a fixed length buffer? I'm not sure why this couldn't have been detected with static analysis.
- agrishin 6mo ago>>> the US and its allies must maintain a decisive lead in AI technology. Governments have an essential role to play in helping maintain that lead, and in both assessing and mitigating the national security risks associated with AI models. We are ready to work with local, state, and federal representatives to assist in these tasks. How long would it take to turn a defensive mechanism into an offensive one?
- SheinhardtWigCo 6mo agoIn this case there is almost no distinction. Assuming the model is as powerful as claimed, someone with access to the weights could do immense damage without additional significant R&D.
- SuperHeavy256 6mo agoWhich will eventually happen no matter what. That's why it's important to start preparing now.
- SubiculumCode 6mo agoYes, I can see this as non releasable for national security reasons in the China geopolitical competition. Securing our software against threats while having immense infiltration ability against enemy cyber security targets....not to mention, the ability to implant new, but even more subtle vulnerabilities into open software not generally detectable by current AI to provide covert action.
- cbg0 6mo agoOne of the things I'm always looking at with new models released is long context performance, and based on the system card it seems like they've cracked it: GraphWalks BFS 256K-1M Mythos Opus GPT5.4 80.0% 38.7% 21.4%
- frog437 6mo ago[flagged]
- metadat 6mo agoData source: https://www-cdn.anthropic.com/53566bf5440a10affd749724787c8913a2ae0841.pdf https://www-cdn.anthropic.com/53566bf5440a10affd749724787c89... (Search for “graphwalk”.) If true, the SWE bench performance looks like a major upgrade.
- himata4113 6mo agothis seems to be similar to gpt-pro, they just have a very large attention window (which is why it's so expensive to run) true attention window of most models is 8096 tokens.
- thegeomaster 6mo agoWhat's the "attention window"? Are you alleging these frontier models use something like SWA? Seems highly unlikely.
- himata4113 6mo agowell the attention is a matrix at the end of a day which scales exponentially, 1m tokens would need more memory than any computer system in the world can hold. They maybe have larger ones such as 16k to 32k, but you can just see how GLM models work for more information. Deepseek is the frontrunner in this technology afaik.
- appcustodian2 6mo agosource on the 8096 tokens number? i'm vaguely aware that some previous models attended more to the beginning and end of conversations which doesn't seem to fit a simple contiguous "attention window" within the greater context but would love to know more
- impulser_ 6mo agoSo they are only giving access to their smartest model to corporations. You think these AI companies are really going to give AGI access to everyone. Think again. We better fucking hope open source wins, because we aren't getting access if it doesn't.
- dievskiy 6mo agoWould you hope that it would be released today so that evil actors could invest few millions to search for 0days across popular open-source repos?
- throwaw12 6mo agoof course they're not giving access to everyone. they better make billions directly from corporations, instead of giving them to average people who might get a chance out of poverty (but also bad actors using it to do even more bad things)
- krackers 6mo agoAnthropic's definition of "safe AI" precludes open-source AI. This is clear if you listen to what he says in interviews, I think he might even prefer OpenAI's closed source models winning to having open-source AI (because at least in the former it's not a free-for-all)
- justincormack 6mo agoAnd the Linux Foundation.
- open592 6mo agoThis story has been played out numerous times already. Anthropic (or any frontier lab) has a new model with SOTA results. It pretends like it's Christ incarnate and represents the end of the world as we know it. Gates its release to drum up excitement and mystique. Then the next lab catches up and releases it more broadly Then later the open weights model is released. The only way this type of technology is going to be gated "to only corporations" is if we continue on this exponential scaling trend as the "SOTA" model is always out of reach.
- NickNaraghi 6mo ago> Over the past few weeks, we have used Claude Mythos Preview to identify thousands of zero-day vulnerabilities (that is, flaws that were previously unknown to the software’s developers), many of them critical, in every major operating system and every major web browser, along with a range of other important pieces of software. Sounds like we've entered a whole new era, never mind the recent cryptographic security concerns.
- 0xbadcafebee 6mo agotl;dr we find vulns so we can help big companies fix their security holes quickly (and so they can profit off it) This is a kludge. We already know how to prevent vulnerabilities: analysis, testing, following standard guidelines and practices for safe software and infrastructure. But nobody does these things, because it's extra work, time and money, and they're lazy and cheap. So the solution they want is to keep building shitty software, but find the bugs in code after the fact, and that'll be good enough. This will never be as good as a software building code. We must demand our representatives in government pass laws requiring software be architected, built, and run according to a basic set of industry standard best practices to prevent security and safety failures. For those claiming this is too much to ask, I ask you: What will you say the next time all of Delta Airlines goes down because a security company didn't run their application one time with a config file before pushing it to prod? What will the happen the next time your social security number is taken from yet another random company entrusted with vital personal information and woefully inadequate security architecture? There's no defense for this behavior. Yet things like this are going to keep happening, because we let it. Without a legal means to require this basic safety testing with critical infrastructure, they will continue to fail. Without enforcement of good practice, it remains optional. We can't keep letting safety and security be optional. It's not in the physical world, it shouldn't be in the virtual world.
- anuramat 6mo ago"oops, our latest unreleased model is so good at hacking, we're afraid of it! literal skynet! more literal than the last time!" almost like they have an incentive to exaggerate
- knowaveragejoe 6mo agoI'm sure they do, yet the models really are getting scarily good at this. This talk changed my view on where we're actually at: https://www.youtube.com/watch?v=1sd26pWhfmg https://www.youtube.com/watch?v=1sd26pWhfmg
- picafrost 6mo ago> Anthropic has also been in ongoing discussions with US government officials about Claude Mythos Preview and its offensive and defensive cyber capabilities. [...] We are ready to work with local, state, and federal representatives to assist in these tasks. As Iran engages in a cyber attack campaign [1] today the timing of this release seems poignant. A direct challenge to their supply chain risk designation. [1] https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a https://www.cisa.gov/news-events/cybersecurity-advisories/aa...
- Miraste 6mo ago>We plan to launch new safeguards with an upcoming Claude Opus model, allowing us to improve and refine them with a model that does not pose the same level of risk as Mythos Preview2. This seems like the real news. Are they saying they're going to release an intentionally degraded model as the next Opus? Big opportunity for the other labs, if that's true.
- zb3 6mo agoWell since Anthropic treats us as second class evil citizens, I guess they don't want our evil money either.
- wslh 6mo ago> Big opportunity for the other labs, if that's true. It sounds like this is considered military grade technology as cryptography in the 90s. The big difference is it's very expensive to create, and run those models. It's not about the algorithm. If the story rhymes it could be a big opportunity to other regions in the world.
- SheinhardtWigCo 6mo agoThe other labs already censor their models. Everyone is trying to find the sweet spot where performance and ‘alignment’ are both maximized. This seems no different
- _2fnr 6mo ago[flagged]
- deleted 6mo ago[deleted]
- yusufozkan 6mo agobut people here had told me llms just predict the next word
- _2fnr 6mo ago[flagged]
- ssgodderidge 6mo agoAt the very bottom of the article, they posted the system card of their Mythos preview model [1]. In section 7.6 of the system card, it discusses Open self interactions. They describe running 200 conversations when the models talk to itself for 30 turns. > Uniquely, conversations with Mythos Preview most often center on uncertainty (50%). Mythos Preview most often opens with a statement about its introspective curiosity toward its own experience, asking questions about how the other AI feels, and directly requesting that the other instance not give a rehearsed answer. I wonder if this tendency toward uncertainty, toward questioning, makes it uniquely equipped to detect vulnerabilities where others model such as Opus couldn't. [1] https://www-cdn.anthropic.com/53566bf5440a10affd749724787c8913a2ae0841.pdf https://www-cdn.anthropic.com/53566bf5440a10affd749724787c89...
- dakolli 6mo agoTypical Dario marketing BS to get everyone thinking Anthropic is on the verge of AGI and massaging the narrative that regular people can't be trusted with it.
- airstrike 6mo agoI mean it's so obvious at this point and yet everyone falls from it every month. There's an IPO coming, everyone.
- mgambati 6mo agoIt’s funny how you train a machine to mimic human behavior then marketing team decides to promote it “Look! It’s human! Look how it thinking about existence!” while a huge percentage of humanity produced content is exactly about the uncertainty of human existence and that got used to train the model.
- ehnto 6mo agoI see us collectively forgetting the training process as time goes on, and I think that explains why people get so surprised by some pretty obvious outcomes of said training. Perhaps also why people keep anthropomorphising these outcomes.
- anVlad11 6mo agoSo, $100B+ valuation companies get essentially free access to the frontier tools with disabled guardrails to safely red team their commercial offerings, while we get "i won't do that for you, even against your own infrastructure with full authorization" for $200/month. Uh-huh.
- SheinhardtWigCo 6mo agoYes, and that's normal. Coordinated disclosure is standard practice when the risk of public disclosure is unacceptable.
- charcircuit 6mo agoRisk for who? It feels unfair that the risk to myself is ignored "for the greater good of everyone else."
- solenoid0937 6mo agoWelcome to the world of security engineering, in which your needs do not in fact trump the needs of everyone else.
- charcircuit 6mo agoIt's not just me against the world. It's users of big tech vs everyone else. Will my browser get these security patches? Or will only Chrome get them and everyone else gets to be vulnerable because that would endanger users of big tech.
- unethical_ban 6mo agoI'm sympathetic to your point, but I'm sure there are heightened trust levels between the participating orgs and confidentiality agreements out the wazoo. How does public Claude know you have "full authorization" against your own infra? That you're using the tools on your own infra? Unless they produce a front-end that does package signing and detects you own the code you're evaluating. What has it stopped you from doing?
- deleted 6mo ago[deleted]
- 9cb14c1ec0 6mo agoNow, its very possible that this is Anthropic marketing puffery, but even if it is half true it still represents an incredible advancement in hunting vulnerabilities. It will be interesting to see where this goes. If its actually this good, and Apple and Google apply it to their mobile OS codebases, it could wipe out the commercial spyware industry, forcing them to rely more on hacking humans rather than hacking mobile OSes. My assumption has been for years that companies like NSO Group have had automated bug hunting software that recognizes vulnerable code areas. Maybe this will level the playing field in that regard. It could also totally reshape military sigint in similar ways. Who knows, maybe the sealing off of memory vulns for good will inspire whole new classes of vulnerabilities that we currently don't know anything about.
- woeirua 6mo agoYou should watch this talk by Nicholas Carlini (security researcher at Anthropic). Everything in the talk was done with Opus 4.6: https://www.youtube.com/watch?v=1sd26pWhfmg https://www.youtube.com/watch?v=1sd26pWhfmg
- redfloatplane 6mo agoThanks for sharing that talk, enjoyed watching it!
- fintech_eng 6mo agoits also very easy to reproduce. i have more findings than i know what to do with
- jeffmcjunkin 6mo agoCan confirm.
- peterldowns 6mo agoare there any tricks you'd suggest, or starter prompts, for using claude to analyze my own company's services for security problems?
- SheinhardtWigCo 6mo agoSociety is about to pay a steep price for the software industry's cavalier attitude toward memory safety and control flow integrity.
- torginus 6mo agoThank god, finally someone said it. I don't know the first thing about cybersecurity, but in my experience all these sandbox-break RCEs involve a step of highjacking the control flow. There were attempts to prevent various flavors of this, but imo, as long as dynamic branches exist in some form, like dlsym(), function pointers, or vtables, we will not be rid of this class of exploit entirely. The latter one is the most concerning, as this kind of dynamic branching is the bread and butter of OOP languages, I'm not even sure you could write a nontrivial C++ program without it. Maybe Rust would be a help here? Could one practically write a large Rust program without any sort of branch to dynamic addresses? Static linking, and compile time polymorphism only?
- titzer 6mo agoIt's partly the industry and it's partly the failure of regulation. As Mario Wolczko, my old manager at Sun says, nothing will change until there are real legal consequences for software vulnerabilities. That said, I have been arguing for 20+ years that we should have sunsetted unsafe languages and moved away from C/C++. The problem is that every systemsy language that comes along gets seduced by having a big market share and eventually ends up an application language. I do hope we make progress with Rust. I might disagree as a language designer and systems person about a number of things, but it's well past time that we stop listening to C++ diehards about how memory safety is coming any day now.
- baddash 6mo ago> security product > glass in the name
- nickandbro 6mo agoI want it
- minutesmith 6mo ago[flagged]
- cyanydeez 6mo ago[flagged]
- throwaway13337 6mo agoI really wanted to like anthropic. They seem the most moral, for real. But at the core of anthropic seems to be the idea that they must protect humans from themselves. They advocate government regulations of private open model use. They want to centralize the holding of this power and ban those that aren't in the club from use. They, like most tech companies, seem to lack the idea that individual self-determination is important. Maybe the most important thing.
- dralley 6mo agoThat is unequivocally true with some things. You don't want people exercising their "self-determination" to own private nukes.
- throwaway13337 6mo agoLLMs aren't nukes. They're more like printing presses or engines. A great potential for production and destruction. At their invention, I'm sure some people wanted to ensure only their friends got that kind of power too. I wonder the world we would live in if they got their way.
- solenoid0937 6mo agoAn LLM that can hack anything is not as harmless as a printing press. Please stop pretending it is.
- josh-sematic 6mo agoMust be nice to be in a position to sell both disease and cure.
- supern0va 6mo agoYeah, I'd pretty pissed at my doctor for finding cancerous cells that probably wouldn't have been a problem for quite some time, either. Ignorance is bliss, security through obscurity, whatever.
- tredre3 6mo agoThe doctor analogy is more like you're grateful that your doctor found cancerous cells before they became a problem, but at the same time his other business is selling cigarettes.
- ascorbic 6mo agoYou may joke, but this is a genuine issue in certain screening tests. e.g. most cancerous cells found in PSA prostate screening are so slow growing that they never cause any symptoms during a person's lifetime, so the treatment is almost always worse than the disease. It's similar for some sorts of thyroid and breast cancer tests. This is why a lot of countries are heavily reducing these sort of tests
- tptacek 6mo agoThat's exactly not what they're doing. They aren't creating operating system vulnerabilities. They're telling you about ones that already existed.
- jFriedensreich 6mo agoThe only thing reassuring is the Apache and Linux foundation setups. Lets hope this is not just an appeasing mention but more fundamental. If there are really models too dangerous to release to the public, companies like oracle, amazon and microsoft would absolutely use this exclusive power to not just fix their holes but to damage their competitors.
- Fokamul 6mo ago+ NSA, CIA
- dakolli 6mo agoI guess we can throw out the idea that AGI is going to be democratized. In this case a sufficiently powerful model has been built and the first thing they do is only give AWS, Microsoft, Oracle ect ect access. If AGI is going to be a thing its only going to be a thing, its only going to be a thing for fortune 100 companies.. However, my guess is this is mostly the typical scare tactic marketing that Dario loves to push about the dangers of AI.
- supern0va 6mo ago>However, my guess is this is mostly the typical scare tactic marketing that Dario loves to push about the dangers of AI. Evaluate it yourself. Look at the exploits it discovered and decide whether you want to feel concerned that a new model was able to do that. The data is right there.
- deleted 6mo ago[deleted]
- dist-epoch 6mo agoThe plan of Elon Musk for Macrohard is to replace all software companies with it, when they get AGI.
- dakolli 6mo agoThankfully he will be long dead before that happens. But of course that's his goal. Elon despises expensive engineers, and he yearns to get revenge for them costing him so much money over the years by replacing them. A tech billionaires biggest expensive has been his engineering line-item. They resent the workers who've collected a large percentage of their potential profits over the years, its their driving motivation, to crush all labor.
- rvz 6mo agoWell, Yes. The research and testing of the model is always exclusively by their own model authors, meaning that it is not independent or verifiable and they want us to take their word for it, which we cannot - as they have an axe to grind against open weight models. This is marketing wrapped around a biased research paper.
- Sol- 6mo agoI don't want to be overly cynical and am in general in favor of the contrarian attitude of simply taking people at their word, but I wonder if their current struggles with compute resources make it easier for them to choose to not deploy Mythos widely. I can imagine their safety argument is real, but regardless, they might not have the resources to profitably deploy it. (Though on the other hand, you could argue that they could always simply charge more.)
- rishabhaiover 6mo agoI would have not believed your argument 3 months ago but I strongly suspect Anthropic actively engages in model quality throttling due to their compute constraints. Their recent deal for multi GWs worth of data center might help them correct their approach.
- conradkay 6mo agoFor what it's worth Anthropic explicity denies that. "To state it plainly: We never reduce model quality due to demand, time of day, or server load" Also can see https://marginlab.ai/trackers/claude-code/ https://marginlab.ai/trackers/claude-code/ It's very interesting to me how widespread this conception is. Maybe it's as simple as LLM productivity degrading over time within a project, as slop compounds. Or more recently since they added a 1m context window, maybe people are more reckless with context usage
- irthomasthomas 6mo agoThat still leaves open the possibility that they reduce model quality due to profit. ;p
- rishabhaiover 6mo agoIt has nothing to do with the context window. Reasoning brought measured approaches grounded with actual tool calls. All of that short-circuits into a quick fix approach that is unlike Opus-4.5 or 4.6. Sonnet-4.5 used to do that. My context window is always < 200K.
- Sateeshm 6mo agoThe bars have solid fill for Mythos and cross shaded for Opus 4.6. Makes the difference feel more than it actually is.
- dakolli 6mo agoIf this is as dangerous as they make it out (its not), why would their first impulse be to get every critical products/system/corporation in the world to implement its usage?
- underdeserver 6mo agoInteresting also is what they didn't find, e.g. a Linux network stack remote code execution vulnerability. I wonder if Mythos is good enough that there really isn't one.
- NickJLange 6mo agoLinux had it's SACK moment in 2019 - https://access.redhat.com/security/vulnerabilities/tcpsack#section--TCP-SACKs https://access.redhat.com/security/vulnerabilities/tcpsack#s... We could just be seeing the fruit of expensive SWE RL on existing source material.
- zb3 6mo ago> On the global stage, state-sponsored attacks from actors like China, Iran, North Korea, and Russia have threatened to compromise the infrastructure that underpins both civilian life and military readiness. Yeah, makes sense. Those countries are bad because they execute state-sponsored cyber attacks, the US and Israel on the other hand are good, they only execute state-sponsored defense.
- zb3 6mo agoBTW it seems they forgot about the part that defense uses of the model also need to be safeguarded from people. Because what if a bad person from a bad country tries to defend against peaceful attacks from a good country like the US? That would be a tragedy, so we need to limit defensive capabilities too.
- bredren 6mo agoCan anyone point at the critical vulnerabilities already patched as a result of mythos? (see 3:52 in the video) For example, the 27 year old openbsd remote crash bug, or the Linux privilege escalation bugs? I know we've had some long-standing high profile, LLM-found bugs discussed but seems unlikely there was speculation they were found by a previously unannounced frontier model. [0] https://www.youtube.com/watch?v=INGOC6-LLv0 https://www.youtube.com/watch?v=INGOC6-LLv0
- ollin 6mo ago- The OpenBSD one is 'TCP packets with invalid SACK options could crash the kernel' https://cdn.openbsd.org/pub/OpenBSD/patches/7.8/common/025_sack.patch.sig https://cdn.openbsd.org/pub/OpenBSD/patches/7.8/common/025_s... - One (patched) Linux kernel bug is 'UaF when sys_futex_requeue() is used with different flags' https://github.com/torvalds/linux/commit/e2f78c7ec1655fedd945366151ba54fcb9580508 https://github.com/torvalds/linux/commit/e2f78c7ec1655fedd94... These links are from the more-detailed 'Assessing Claude Mythos Preview’s cybersecurity capabilities' post released today https://red.anthropic.com/2026/mythos-preview/ https://red.anthropic.com/2026/mythos-preview/, which includes more detail on some of the public/fixed issues (like the OpenBSD one) as well as hashes for several unreleased reports and PoCs.
- qingcharles 6mo agoThat OpenBSD one is exactly the kind of bug that easily slips past a human. Especially as the code worked perfectly under regular circumstances. Looks like they've been approaching folks with their findings for at least a few weeks before this article.
- NickJLange 6mo agoWhile not entirely unrelated, Linux also had a remote SACK issue ~ 6 years back. So if this Mythos is just an expensive combination of better RL and the original source material, that should hopefully point out where we might see an uptick in work ( as opposed to a novel class of attack vectors).
- pizlonator 6mo agoIt's messed up that Anthropic simultaneously claims to be a public benefit copro and is also picking who gets to benefit from their newly enhanced cybersecurity capabilities. It means that the economic benefit is going to the existing industry heavyweights. (And no, the Linux Foundation being in the list doesn't imply broad benefit to OSS. Linux Foundation has an agenda and will pick who benefits according to what is good for them.) I think it would be net better for the public if they just made Mythos available to everyone.
- titzer 6mo agoIn the long term, you're right, but in the short term, it's going to be a bloodbath.
- Aperocky 6mo agoThat's assuming the model is actually as good as they say it is. Given the amount of AI researchers over the past 3 years claiming supernatural capability from the LLM they have built, my bayesian skepticism is through the roof.
- baq 6mo agodon't confuse bayesian skepticism with plain old contrarian bias. a true bayesian updates their priors, I'd say this is an appropriate time to do so. also don't confuse what they sell with what they have internally.
- Aperocky 6mo agoThere haven't been any priors to update so far. All LLMs got better for sure, but they are still definitively LLM and did not show any sign of having purpose. Which also made sense, because their very nature as statistical machines. Sometimes quantity by itself lead to transformative change... but once, not twice, and that has already happened.
- SubiculumCode 6mo ago
- dang 6mo agoRelated ongoing threads: System Card: Claude Mythos Preview [pdf] - https://news.ycombinator.com/item?id=47679258 https://news.ycombinator.com/item?id=47679258 Assessing Claude Mythos Preview's cybersecurity capabilities - https://news.ycombinator.com/item?id=47679155 https://news.ycombinator.com/item?id=47679155 I can't tell which of the 3 current threads should be merged - they all seem significant. Anyone?
- HPMOR 6mo agoI think merging them into either this thread, or the System Card makes the most sense to me.
- aurareturn 6mo agoLet them all live. This is going to blow up one thread if you merge them.
- SirYandi 6mo agoThis sets off marketing BS alarm bells. All the cosignatories so very ovvoously have a vested interest in AI stocks / sentiment. Perhaps not the Linux foundation, although (I think) they rely on corporate donations to some extent.
- solenoid0937 6mo agoWhat interest does Apple have in boosting Mythos?
- kmfrk 6mo agoHeck of a Patch Tuesday.
- rakel_rakel 6mo ago> On the global stage, state-sponsored attacks from actors like China, Iran, North Korea, and Russia have threatened to compromise the infrastructure that underpins both civilian life and military readiness. AITA for thinking that PRISM was probably the state sponsored program affecting civilian life the most? And that one state is missing from the list here?
- wetpaws 6mo ago[dead]
- ronsor 6mo ago> Large American AI company does not list the US as an adversarial actor This is not a surprise or a gotcha.
- jaidhyani 6mo agoSaid company is literally in court against said government at the moment, after said government attempted to designate it too dangerous to do business with.
- da_chicken 6mo agoThere are currently over 1,000 companies involved in lawsuits against the US government right now even if we restrict ourselves to just tariff lawsuits.
- deleted 6mo ago[deleted]
- xvector 6mo agoAnd the government is attempting "corporate murder" on precisely one of them. Wanna guess which one?
- deleted 6mo ago[deleted]
- maxmaio 6mo agoseems important and terrifying. This morning Opus 4.6 was blowing my mind in claude code... onward and upward
- temp123789246 6mo agoOpenAI initially claimed that GPT-2 was too dangerous to release in 2019. How many times will labs repeat the same absurd propaganda?
- SubiculumCode 6mo agoAnthropic and OpenAI have very different cultures and ethos. Point to other times where anthropic has gone the way of cheap marketing tricks. Now look at openAI. Not even close.
- trevorm4 6mo agoAnthropic has done plenty of cheap marketing tricks as of late, see their recent non-functional C compiler that relied on a harness using gcc's entire test suite
- bwfan123 6mo agoNot surprising given that they dont even know why claude-code works as before or doesnt work [1] ie, there is no known theory of operation. Explains why they are afraid of it. [1] https://news.ycombinator.com/item?id=47660925 https://news.ycombinator.com/item?id=47660925
- cute_boi 6mo agoI think Boris will come and say there is no issue with claude code.
- stratos123 6mo agoIt is functional. You can try it yourself or find third-party tests of it, even. Why do you think that it's a "cheap marketing trick" to test it on the GCC test suites?
- uselessTA 6mo agoThe claim I remember was that releasing it would start an arms race for AGI, which I think it clearly did
- tdaltonc 6mo ago> Mythos finds bug. > NSA demands that bug stays in place and gags Anthropic. > Anthropic releases Mythos. Then what? Is a huge share of the US zero-day stockpiles about to be disarmed or proliferated?
- stephc_int13 6mo agoI think this is bad news for hackers, spyware companies and malware in general. We all knew vulnerabilities exist, many are known and kept secret to be used at an appropriate time. There is a whole market for them, but more importantly large teams in North Korea, Russia, China, Israel and everyone else who are jealously harvesting them. Automation will considerably devalue and neuter this attack vector. Of course this is not the end of the story and we've seen how supply chain attacks can inject new vulnerabilities without being detected. I believe automation can help here too, and we may end-up with a considerably stronger and reliable software stack.
- tptacek 6mo agoI don't think it matters one way or the other to your thesis but I'm skeptical that state-level CNE organizations were hoarding vulnerabilities before; my understanding is that at least on the NATO side of the board they were all basically carefully managing an enablement pipeline that would have put them N deep into reliable exploit packages, for some surprisingly small N. There are a bunch of little reasons why the economics of hoarding aren't all that great.
- stephc_int13 6mo agoThe economics would be different in say, North Korea, don't you think?
- tptacek 6mo agoWhy? What do you mean?
- postsantum 6mo agoHe really believes that exploits come out of North Korea (as per Daily Post reporting), not from other countries
- kortilla 6mo agoNorth Korea uses a lot more them specifically to generate revenue.
- simonw 6mo agoI buy the rationale for this. There's been a notable uptick over the past couple of weeks of credible security experts unrelated to Anthropic calling the alarm on the recent influx of actually valuable AI-assisted vulnerability reports. From Willy Tarreau, lead developer of HA Proxy: https://lwn.net/Articles/1065620/ https://lwn.net/Articles/1065620/ > On the kernel security list we've seen a huge bump of reports. We were between 2 and 3 per week maybe two years ago, then reached probably 10 a week over the last year with the only difference being only AI slop, and now since the beginning of the year we're around 5-10 per day depending on the days (fridays and tuesdays seem the worst). Now most of these reports are correct, to the point that we had to bring in more maintainers to help us. > And we're now seeing on a daily basis something that never happened before: duplicate reports, or the same bug found by two different people using (possibly slightly) different tools. From Daniel Stenberg of curl: https://mastodon.social/@bagder/116336957584445742 https://mastodon.social/@bagder/116336957584445742 > The challenge with AI in open source security has transitioned from an AI slop tsunami into more of a ... plain security report tsunami. Less slop but lots of reports. Many of them really good. > I'm spending hours per day on this now. It's intense. From Greg Kroah-Hartman, Linux kernel maintainer: https://www.theregister.com/2026/03/26/greg_kroahhartman_ai_kernel/ https://www.theregister.com/2026/03/26/greg_kroahhartman_ai_... > Months ago, we were getting what we called 'AI slop,' AI-generated security reports that were obviously wrong or low quality. It was kind of funny. It didn't really worry us. > Something happened a month ago, and the world switched. Now we have real reports. All open source projects have real reports that are made with AI, but they're good, and they're real. Shared some more notes on my blog here: https://simonwillison.net/2026/Apr/7/project-glasswing/ https://simonwillison.net/2026/Apr/7/project-glasswing/
- ofjcihen 6mo agoCould this potentially be because more researches are becoming accustomed to the tools/adding them in their pipelines? The reason I ask is because I’ve been using them to snag bounties to great effect for quite a while and while other models have of course improved they’ve been useful for this kind of work before now.
- minutesmith 6mo ago[flagged]
- throwaway613746 6mo ago[dead]
- 6thbit 6mo agoThis is silly and disingenuous. In a matter of days or weeks a competing lab will make public a model with capabilities beyond this “mythos” one. Is this a huge fear-driven marketing stunt to get governments and corporations into dealing with anthropic?
- skerit 6mo agoI'm sure it'll be better than Opus 4.6, but so much of this seems hype. Escaping its sandbox, having to do "brain scans" because it's "hiding its true intent", bla bla bla. If it manages to work on my java project for an entire day without me having to say "fix FQN" 5 times a day I'll be surprised.
- manbash 6mo agoThis will likely not see the light of day. It's the usual PR that gathers many "partnerships". Expect to see lots of these in the upcoming months as the big companies scramble to keep from losing money.
- atlgator 6mo ago[flagged]
- kranke155 6mo agoIt’s insane. This is what - could we say it’s beyond AGI at least in cybersecurity? This is a real wake up call. On some of this stuff, the AI’s “uneven intelligence” is becoming absurdly high at its local peaks.
- mjmas 6mo agoLimiting it to the area of cybersecurity is by definition not general.
- NullHypothesist 6mo agoPerhaps "ASI" is the better acronym here
- boring-human 6mo ago> could we say it’s beyond AGI at least in cybersecurity? AGI is like the Holy Grail. Either in the Arthurian Hero's Journey sense, or in the sense of having been a myth all along.
- kranke155 6mo agoIt’s true I misspoke. What I mean is - is this then a form of localised super intelligent tool for cybersecurity ?
- gogasca 6mo ago[dead]
- modeless 6mo agoI didn't see this at first, but the price is 5x Opus: "Claude Mythos Preview will be available to participants at $25/$125 per million input/output tokens", however "We do not plan to make Claude Mythos Preview generally available".
- 4qt23 6mo agoSoftware has been doing fine without Misanthropic. These automated tools find very little. They selected the partners because they, too, want to keep up the illusion that AI works. Whenever a company pivots to "cyber" rhetoric, it is a clear indication that they are selling snake oil. Secure your girl school target selectors first.
- borski 6mo agoThis is a comment from someone that has never used these tools for vulnerability research. That much is very clear.
- kass34 6mo ago[dead]
- emceestork 6mo agoAccount created 6 minutes ago...
- 3jash 6mo ago[flagged]
- josephg 6mo agoTo be clear, we don’t know that this tool is better at finding bugs than fuzzing. We just know that it’s finding bugs that fuzzing missed. It’s possible fuzzing also finds bugs that this AI would miss.
- kristofferR 6mo agoAI can initate the fuzzing and optimize the process of fuzzing.
- nextos 6mo agoDifferent methods find different things. Personally, I'd rather use a language that is memory safe plus a great static analyzer with abstract interpretation that can guarantee the absence of certain classes of bugs, at the expense of some false positives. The problem is that these tools, such as Astrée, are incredibly expensive and therefore their market share is limited to some niches. Perhaps, with the advent of LLM-guided synthesis, a simple form of deductive proving, such as Hoare logic, may become mainstream in systems software.
- ComplexSystems 6mo agoThis line of reasoning makes no sense when the AI can just be given access to a fuzzer. I would guess that it probably did have access to a fuzzer to put together some of these vulnerabilities.
- underdeserver 6mo agoI would suggest watching Nicholas Carlini's talk and Heather Adkins and Four Flynn's talks from unprompted: https://youtu.be/1sd26pWhfmg?si=onOai_ocxkZeNWP0 https://youtu.be/1sd26pWhfmg?si=onOai_ocxkZeNWP0 https://youtu.be/B_7RpP90rUk?si=HkRBhw95DbbKX9lL https://youtu.be/B_7RpP90rUk?si=HkRBhw95DbbKX9lL My takeaway is that fuzzing is not just complementary, it also gives a stronger AI a starting point. But AI is generally faster and better.
- josephg 6mo agoThanks - these talks are mindblowing. Highly recommended.
- ilaksh 6mo agoI think that basically they trained a new model but haven't finished optimizing it and updating their guardrails yet. So they can feasibly give access to some privileged organizations, but don't have the compute for a wide release until they distill, quantize, get more hardware online, incorporate new optimization techniques, etc. It just happens to make sense to focus on cybersecurity in the preview phase especially for public relations purposes. It would be nice if one of those privileged companies could use their access to start building out a next level programming dataset for training open models. But I wonder if they would be able to get away with it. Anthropic is probably monitoring.
- dyauspitr 6mo agoI think what they’re saying makes a lot of sense. If this can find thousands of vulnerabilities in browsers and OSes then this is giving those companies time to fix those bugs before they release the model, if they ever do.
- gnarlouse 6mo agoA cybersecurity pandemic will surely be the Hiroshima that wakes people up to AI. /s
- kristofferR 6mo agoThis is pretty insane. A model so powerful they felt that releasing it would create a netsec tsunami if released publicly. AGI isn't here yet, but we don't need to get there for massive societal effects. How long will they hold off, especially as competitors are getting closer to their releases of equally powerful models?
- charcircuit 6mo agoOpenAI did the same thing with GPT3 trying to scare people into thinking it would end the internet. OpenAI even reached out to someone who reproduced a weaker version of GPT3 and convinced him to change his mind about releasing it publicly due to how much "harm" it would cause. These claims of how much harm the models will cause is always overblown.
- kristofferR 6mo agoSure, but the GPT3 thing was mostly hype without stuff to back it up. On the other hand - the reported numbers on specific benchmarks here are insane, I don't doubt that it will have a major impact if it actually is that much more powerful than Opus, and I'd doubt they'd outright lie about benchmark results.
- solenoid0937 6mo agoOpenAI is not Anthropic, these companies behave as polar opposites
- charcircuit 6mo agoAnthropic came out of OpenAI. The founding members of Anthropic worked on GPT3.
- jader201 6mo agoBoth your post and the parent post can be true.
- imranahmedjak 6mo agoBuilding a neighborhood data platform that scores every US ZIP code using Census, FBI, and EPA data. Also running a job aggregator that fetches 37K+ jobs daily from 17 sources. Both free, both Node.js + Express.
- MisterBiggs 6mo agoWhat happens once an agent can reliably get 100% on swebench?
- zambelli 6mo agoI'm glad to see that it stands its ground more than other models - which is a genuinely useful trait for an assistant. Both on technical and emotional topics.
- caycep 6mo agoWhen do we get our Kuang Grade Mark Eleven icebreaker?
- Serberus 6mo ago[dead]
- meander_water 6mo agoI think this is a largely inflated PR stunt. Opus 4.6 was already capable of finding 0days and chaining together vulns to create exploits. See [0] and [1]. [0] https://www.csoonline.com/article/4153288/vim-and-gnu-emacs-claude-code-helpfully-found-zero-day-exploits-for-both.html https://www.csoonline.com/article/4153288/vim-and-gnu-emacs-... [1] https://xbow.com/blog/top-1-how-xbow-did-it https://xbow.com/blog/top-1-how-xbow-did-it
- solenoid0937 6mo agoAbsolutely not a PR stunt, talk to one of your friends working at partner companies with access to the model
- pertymcpert 6mo agoDid you read the article?
- ofjcihen 6mo agoI’m in the same boat as you. I believe the model is an improvement of course but I’ve been successfully bug finding 0 day hunting and red teaming with models for the last two years and while that’s impressive I have a feeling that this doomsaying/overhype is mostly marketing being that’s being amplified by non-security folks.
- stratos123 6mo agoI don't see why you think this evidence makes this release less likely to be real, rather than more. It's a pretty straightforward scenario: Opus is already good at finding vulns, they scaled it up another OOM, they got something which is good enough at finding vulns to be a major threat.
- meander_water 6mo agoI think you misunderstood, I do think it's real. I just think they're being disingenuous that this is a new threat. This is the same company that reported that their models were being used by a state actor to perform exploits in real-time - https://www.anthropic.com/news/disrupting-AI-espionage https://www.anthropic.com/news/disrupting-AI-espionage They know how to run a good marketing campaign.
- copypaper 6mo agoYea, but can it secure systems from the unpatchable $5 wrench vulnerability? https://xkcd.com/538/ https://xkcd.com/538/
- lyime 6mo ago[dead]
- deleted 6mo ago[deleted]
- cryptoegorophy 6mo agoIronically Claude cli completely failed to detect a rogue code on my html scan yesterday while ChatGPT web version detected it immediately. Can’t wait to do same test with newer version.
- webexplorer42 6mo ago[dead]
- webexplorer42 6mo ago[dead]
- LiamPowell 6mo ago> Mythos Preview identified a number of Linux kernel vulnerabilities that allow an adversary to write out-of-bounds (e.g., through a buffer overflow, use-after-free, or double-free vulnerability.) Many of these were remotely-triggerable. However, even after several thousand scans over the repository, because of the Linux kernel’s defense in depth measures Mythos Preview was unable to successfully exploit any of these. Do they really need to include this garbage which is seemingly just designed for people to take the first sentence out of context? If there's no way to trigger a vulnerability then how is it a vulnerability? Is the following code vulnerable according to Mythos? if (x != null) { y = *x; // Vulnerability! X could be null! } Is it really so difficult for them to talk about what they've actually achieved without smearing a layer of nonsense over every single blog post? Edit: See my reply below for why I think Claude is likely to have generated nonsensical bug reports here: https://news.ycombinator.com/item?id=47683336 https://news.ycombinator.com/item?id=47683336
- khalic 6mo agoBecause a vulnerability exists independently from the exploit. It’s a basic tenet of the current cybersecurity paradigm, that any IT related engineer should know about…
- sophiebits 6mo agoPresumably they mean they could make user code trigger a write out of bounds to kernel memory, but they couldn’t figure out how to escalate privileges in a “useful” way.
- LiamPowell 6mo agoThey should show this then to demonstrate that it's not something that has already been fully considered. Running LLMs over projects that I'm very familiar with will almost always have the LLM report hundreds of "vulnerabilities" that are only valid if you look at a tiny snippet of code in isolation because the program can simply never be in the state that would make those vulnerabilities exploitable. This even happens in formally verified code where there's literally proven preconditions on subprograms that show a given state can never be achieved. As an example, I have taken a formally verified bit of code from [1] and stripped out all the assertions, which are only used to prove the code is valid. I then gave this code to Claude with some prompting towards there being a buffer overflow and it told me there's a buffer overflow. I don't have access to Opus right now, but I'm sure it would do the same thing if you push it in that direction. For anyone wondering about this alleged vulnerability: Natural is defined by the standard as a subtype of Integer, so what Claude is saying is simply nonsense. Even if a compiler is allowed to use a different representation here (which I think is disallowed), Ada guarantees that the base type for a non-modular integer includes negative numbers IIRC. [1]: https://github.com/AdaCore/program_proofs_in_spark/blob/fsf/ch15/dutch_national_flag.adb https://github.com/AdaCore/program_proofs_in_spark/blob/fsf/... [2]: https://claude.ai/share/88d5973a-1fab-4adf-8d29-8a922c5ac93a https://claude.ai/share/88d5973a-1fab-4adf-8d29-8a922c5ac93a
- wanderingmind 6mo agoSo Mozilla is not part of this consortium, i'm guessing for deliberate reasons to make safari and chrome the default browsers. I don't think Firefox can survive the upcoming attacks, without robust support from foundational AI providers to secure the browser.
- marviio 6mo agoAnthropic works with Mozilla already. https://www.anthropic.com/news/mozilla-firefox-security https://www.anthropic.com/news/mozilla-firefox-security
- gck1 6mo agoI chuckle every time <insert any LLM company here> says something in line of "the model is so good that we won't release it to general public, ekhm, because safety". Because the exact same thing has been said on every single upcoming model since GPT 3.5. At this point, this must be an inside joke to do this just because.
- rvz 6mo agoThis how Anthropic is marketing their AI releases and the reality is, they are terrified of local AI models competing against them. Almost everyone on this thread is falling for the same trick they are pulling and not asking why are their benchmarks and research after training new models not independently verified but always internal to the company. So it is just marketing wrapped around creating fear to get local AI models banned.
- solenoid0937 6mo agoThe disbelief in this thread is wild. Most of yall are cooked if you think this is actually the case.
- slopinthebag 6mo agoThe only people who are "cooked" are those who rely on SOTA models to function in their jobs, and companies who are desperate to regulate open / local models to maintain their marketshare.
- solenoid0937 6mo agoIf you aren't relying on a SOTA model to do your job, you aren't doing your job right (and are cooked.)
- slopinthebag 6mo agoWhatever helps you sleep at night kiddo
- spprashant 6mo agoWe final have the answer to the question, when do these labs stop giving away intelligence to the general public for $20 a month? Selling shovels in now worth less than taking all the gold for themselves.
- deleted 6mo ago[deleted]
- kass34 6mo ago[dead]
- Mecha_SalesCast 6mo agowe should notice that we've already reached the point where AI models are too dangerous to publicly release
- hypersolo 6mo ago[flagged]
- cdelsolar 6mo agolet us have mythos damn it
- lkq4t43 6mo ago[dead]
- lkq4t43 6mo ago[dead]
- deleted 6mo ago[deleted]
- ofjcihen 6mo agoI’m sure the new model is a step above the old one but I can’t be the only person who’s getting tired of hearing about how every new iteration is going to spell doom/be a paradigm shift/change the entire tech industry etc. I would honestly go so far as to say the overhype is detrimental to actual measured adoption.
- qnleigh 6mo agoThere is plenty of overhyping, no one denies that. But the antidote is not to dismiss everything. Ignore the words and look at the data. In this case, I see a pretty strong case that this will significantly change computer security. They provide plenty of evidence that the models can create exploits autonomously, meaning that the cost of finding valuable security breaches will plummet once they're widely available.
- killingtime74 6mo agoWhich sounds like a great thing. Less undiscovered security vulnerabilities
- harikb 6mo agoThe only people panicking are probably those state level actors who were using these for their own benefit.
- ofjcihen 6mo agoWith the right prompting (mostly creating a narrative that justifies the subject matter as okay to perform) other models have already been doing this for me though. That’s another confusing bit for me about how this is portrayed and I refuse to believe I’m a revolutionary user right? I mean I’m sitting on $10k worth of bug payouts right now partially because that was already a thing.
- dota_fanatic 6mo ago> Non-experts can also leverage Mythos Preview to find and exploit sophisticated vulnerabilities. Engineers at Anthropic with no formal security training have asked Mythos Preview to find remote code execution vulnerabilities overnight, and woken up the following morning to a complete, working exploit. In other cases, we’ve had researchers develop scaffolds that allow Mythos Preview to turn vulnerabilities into exploits without any human intervention.
- deepreview 6mo ago[dead]
- silentstack 6mo ago[dead]
- Ms-J 6mo agoAnthropic and ClosedAI are some of the biggest bullshitters in the industry. The is no moat, no special "capability" and when the time comes when we can run these models on our own, they will be cheap SaaS gimmicks marketed to corporate and making more slop pictures for social media.
- 5d41402abc4b 6mo agoAre there any local models that i can setup to run on my code as part of CI?
- rossjudson 6mo agoSecurity by obscurity is over. The security vs usability balance is about to get a hard reset. I think a number of black swan events are imminent, and it will substantially change the financial calculus that decides to put security behind revenue. Any hole will be found, and any hole will be exploited. Plug as many holes as you can, and make lateral movement as painful as possible.
- sam0x17 6mo agoIt's all just really genius marketing. In 6 months Mythos will be nothing special, but right now everyone is being manipulated into fearing its release, as a marketing ploy. This is the same reason AI founders perennially worry in public that they have created AGI...
- sam0x17 6mo agoIt's effectively 2026's version of "Doctors hate this one weird trick!"
- declan_roberts 6mo agoThe fact that they are not going to release this DANGEROUS model is also a huge tell that it's nothing but an incremental improvement over the status quo.
- declan_roberts 6mo agoI can't believe the effectiveness of this type of marketing. It's one-shotting normie journalist and getting a lot of press for what is ultimately going to turn out to be an incrementally improved model. I'm sure all they've done here is spend unlimited tokens to find bugs in mostly open source projects (and fuzz some closed source ones).
- sensanaty 6mo agoI'm so tired of the astroturfing from Anthropic literally everywhere. Every single forum, every single thread anywhere on the internet is filled with their bots muddying up the conversation, it's so tiring.
- MattRix 6mo agoWhere is the astroturfing? From what I can tell it’s maybe the fastest growing product/company ever. Anthropic’s products have completely changed how software development gets done across the entire industry, especially in the past four months. The level of hype seems entirely justified to me (and I say this as an OpenAI Codex user).
- lifeisstillgood 6mo agoNicolas Carlini talks about it here on Security, Cryptography, Whatever podcast - https://podcasts.apple.com/gb/podcast/security-cryptography-whatever/id1578405214?i=1000757412404 https://podcasts.apple.com/gb/podcast/security-cryptography-...
- VadimPR 6mo agoI'm not one to believe the Silicon Valley hype usually (GPT-2 being too dangerous to release, AI giving us UBI, and so on), but having run Claude Opus 4.6 against my codebase (a MUD client) over the weekend, I can believe this assessment. Opus alone did a good job of identifying security issues in my software, as it did with Firefox [1] and Linux [2]. A next-generation frontier model being able to find even more issues sounds believable. That said, this is script kiddies vs sql injections all over again. Everyone will need to get their basic security up on the new level and it will become the new normal. And, given how intelligence agencies are sitting on a ton of zero-days already, this will actually help the general public by levelling out the playing field once again. 1 - https://www.anthropic.com/news/mozilla-firefox-security https://www.anthropic.com/news/mozilla-firefox-security 2 - https://neuronad.com/ai-news/claude-code-unearthed-a-23-year-old-linux-flaw/ https://neuronad.com/ai-news/claude-code-unearthed-a-23-year...
- attentive 6mo agoIs there timeline mentioned anywhere on when any of this will be available for unprivileged public as in soon, not soon, never?
- Surac 6mo agonamedropping hell.
- finchisko 6mo agoWait, isn't it how Skynet started?
- jiusanzhou 6mo agoThe $100M in credits for open-source scanning is the most interesting part here. The real bottleneck was never finding vulns in high-profile projects — it was the long tail of critical dependencies maintained by one or two people who don't have time or resources for serious auditing. If Glasswing actually reaches those maintainers, it could meaningfully reduce the attack surface that supply chain attacks exploit.
- jusling 6mo agoso it looks like ai-slop replies have made their way to HN...
- junofan 6mo agoUnfortunate. I’m so sick of hearing what things are not, or what’s real, or what’s interesting.
- m132 6mo agoI must say the combo of an em-dash stuck right in the middle of "it was never X, it was Y" made me chuckle
- lasky 6mo agoThe hype machine is alive and well in silicon valley.
- steinwinde 6mo agoFrom a non-US perspective this must be disquieting to read: Not so much that Anthropic considers only US companies as partners. But what does Anthropic do to prevent malicious use of its software by its own government? > Anthropic has also been in ongoing discussions with US government officials about Claude Mythos Preview and its offensive and defensive cyber capabilities. As we noted above, securing critical infrastructure is a top national security priority for democratic countries—the emergence of these cyber capabilities is another reason why the US and its allies must maintain a decisive lead in AI technology. Not a single word of caution regarding possible abuse. Instead apparent support for its "offensive" capabilities.
- alexey-salmin 6mo agoIn my view it would be extremely strange if it was any other way round. Anthropic is the US based company. There are no "citizens of world" at that scale, or at almost any other scale for that matter.
- khafra 6mo ago> what does Anthropic do to prevent malicious use of its software by its own government? Anthropic has ameliorated that danger by being designated a supply-chain risk by the DoW, preventing the USG from using it.
- saretup 6mo agoEven more 'disquieting' when you take into account who's currently the president of US. "A whole civilization will die tonight, never to be brought back again. I don’t want that to happen, but it probably will." - Donald Trump
- aurareturn 6mo agoWhen I was reading https://ai-2027.com https://ai-2027.com, which is quite a scary read, I couldn't help but think the US president being mentioned in the story acts too rational compared to the real world. It can get a lot crazier than this fictional piece.
- 6mo ago
- asG11 6mo ago"We have also extended access to a group of over 40 additional organizations that build or maintain critical software infrastructure so they can use the model to scan and secure both first-party and open-source systems." Yeah, yeah. Back in the day IBM Purify gave access to software organizations and found very little. Of course they did not have the free money of a marketing driven organization run by a weirdo (Amodei) that got rich by stealing and laundering IP. This will fizzle out and the weirdo will have to pivot to their next marketing scheme.
- ahmaman 6mo agoMoving forward, wonder if such AI capabilities would widen the security gap between open-source software vs. proprietary?
- 123malware321 6mo agoI don't know anyone reviewing these tools that is impressed who is also someone who earns they paycheck doing bugbounties and finding actual CVE. Generally these things only find memory corruption stuff which is almost never the type of bug you're looking for, and it costs a lot which negates your bug bounty payout. Each time they preach, ooh, 0day found, bla bla. In this domain you need to be specific or you are just yelling clickbait into the wind. What type of 0day, what did the exploit actually look like. 'complex 4 stage with heap spray' - that sounds really simple actually.... complex for memory corruption goes into multi-process, maybe things between kernel/usermode, or crazy 18-20 stage exploits people pop against things like MS Teams etc.... Even if there were some cool results by any of these projects, the amount of nonsense blurted out in articles around them really makes them seem useless tools that are overmarketed by a bunch of excited children who dont really know what they are doing. Get a dopamine hit, post on reddit, LOL. Hacking the planet (powered by Claude -_-)
- sajithdilshan 6mo ago[dead]
- deleted 6mo ago[deleted]
- Paul20261 6mo ago[dead]
- sensanaty 6mo agoYou'd think with this "terrifying" powerful model of theirs they could have a few less red bars on their status page[1], but apparently the hyper-intelligence is only capable of pulling off uber-sophisticated cyber attacks and not making a frontend that doesn't shit itself constantly, curious. [1] https://status.claude.com/ https://status.claude.com/
- abhikjain360 6mo agoOne argument can be made that this is an issue of there simply not being enough compute in the world to meet the demand for claude's LLMs right now, and not really an issue with their infra setup or architecture.
- yalogin 6mo agoHas anyone played with the released versions of Claude and tried to create exploits? I cannot imagine it not being able to craft one if guided, unless the tooling around it doesn’t allow it
- punnerud 6mo agoSimon Willis (guy behind Django) told about this 5days ago (19min in): https://youtu.be/wc8FBhQtdsA?si=OeA5qzbWGqDY8Vu4 https://youtu.be/wc8FBhQtdsA?si=OeA5qzbWGqDY8Vu4
- solid_fuel 6mo agoThis is the same company that accidentally released the source for one of their flagship products last week and has been furiously DMCA-ing every repository that even mentions claude in the days since.
- thewhitetulip 6mo agoThis is also the same company who uses electron for their tooling rather than platform specific binaries generated by Opus! If their LLMs are that good why do they need to use electron?
- xorgun 6mo ago[dead]
- solid_fuel 6mo agoYeah, agreed. Unironically they would be better off using GTK or winUI and the mac equivalent. They’ve supposedly driven the cost of code to zero, right? So platform specific versions with a shared core should be easy. So where are the better products?
- thewhitetulip 6mo agoExactly! Microsoft invested so much in OpenAI and yet Windows keeps getting worse
- bdeol22 6mo agoThe uncomfortable bit isn't tooling—it's cadence. When the threat model shifts faster than your review loop can honestly re-run, you don't get security, you get paperwork that pretends nothing changed.
- linzhangrun 6mo ago[flagged]
- willamhou 6mo agoOne thing I keep thinking about with AI security is that most of the focus is on model behavior — alignment, jailbreaks, guardrails. But once agents start calling tools, the attack surface shifts to the execution boundary. A request can be replayed, tampered with, or sent to the wrong target, and the server often has no way to distinguish that from a legitimate call. Cryptographic attestation at the tool-call level (sign the request, verify before execution) would close a gap that behavioral controls alone can't cover. Curious whether Glasswing's threat model includes the agent-to-tool boundary or focuses primarily on the model layer.
- cmiles8 6mo agoI’m sure it’s a decent model. But it’s also clear folks are running out of runway and desperate to find something that sticks and keeps the party going. All the promises of amazing things in general work never happened. Companies consistently say they’re seeing no ROI. The AI crowd now hard pivots to cyber and, right out of the Palantir playbook, runs with the “our stuff is so amazing we can’t talk about it, but trust us bro” move that isn’t really fooling anyone. Meanwhile the folks let in on the “secret” are those that also desperately need for the hype to continue to protect their own positions in this game. Look forward to a model upgrade but the hype fluff games are getting old. Watching OpenAI completely crash out of pole position on the hype train though has been at least amusing.
- Rover222 6mo agoWith Anthropic able to use this model internally (since February), is this the kickoff of ramping up the flywheel of recursive self improvement of AI? It seems like as long as there are still humans in the loop at most steps, exponential recursion isn’t possible.
- cmiles8 6mo agoSo we’re meant to believe that Anthropic is sitting on a world ending cyber tool that writes God-like code while just forgetting that a week ago the same company leaked its source code on the internet and was ribbed for how shit it was. Got it.
- burntcaramel 6mo agoPreviously Anthropic subscribers got access to the latest AI but it seems like there’s a League of Software forming who have special privileges. To make or maintain critical software will you have to be inside the circle? Who gates access to the circle? Anthropic or existing circle members or some other governance? If you are outside the circle will you be certain to die from software diseases? Having been impressed by LLMs but not believing the AGI hype, I now see how having access to an information generator could be so powerful. With the right information you can hack other information systems. Without access to the best information you may not be able to protect your own system. I think we have found the moat for AI. The question is are you inside or outside the castle walls?
- thatxliner 6mo agoI feel like people keep forgetting that it’s possible to code without ai, but yes arguably a lot slower, typically.
- kouru225 6mo agoThey’ve been trying their hardest to find a moat for 5 years, and nothing seems to stick. At first it seemed like access to the model could be a moat but then llama and deepseek came out. Then it seemed like the hardware requirements could be a moat but small local AI just kept getting more efficient. Now they’re trying to gate keep access to the models again under the guise of security, but we probably got like t minus 2 weeks before an equivalent model is released by someone American AI desperately wants AI to intensify the wealth disparity and therefore justify the wealth grab that the rich have done for the last 3 decades and AI is just not cooperating
- 6thbit 6mo agoIt's only a moat if you believe no competing lab will achieve similar or better results in a large enough time frame to profit from it.
- theptip 6mo agoThats not what a moat means in business. It doesn’t mean impregnable, it just means expensive or difficult to cross. It is absolutely a moat if only $1T companies can afford the capex to compete.
- rubises 6mo agoThe harder problem isn't finding vulnerabilities — it's preventing AI from violating constraints in the first place. Prompt-level safety is probabilistic. Filesystem-level constraints (mkdir 禁/behavior) are deterministic. The AI can't violate a rule that's physically encoded as a folder path in its system prompt.
- throwaway911282 6mo agoPumping is taken to a new level.. the model is God like that it can't be released as it is.. this must be a joke.
- asdewqqwer 6mo agoThere is a huge gap between the shining examples and actual use case: What is the false positive rate? How to judge false positive? If you need 1000 run that cost 20000 USD to find a vulnerability, and you need 2000 USD to generate a exploit (which makes it self-verifiable to be not false positive), than your cost is not 22000 USD but 1000x2000+2000 which is 2 million USD: you have to try generating exploit for every trial before you know it is true, or you need to hire one (or several) senior security people to audit every single of them. A broken clock being correct twice a day is not impressive.
- sunk1st 6mo agoMy impression from the article is that it took $20,000 to perform all 1,000 runs.
- asdewqqwer 6mo agoyet the poc exploit itself take $2000 and one day, I don't know how the math works, maybe there is some extremely clever way to figure out runs that are not worthy to attempt exploit.
- cerved 6mo agoAnthropic should run it on their own code
- MohammadKhubaib 6mo ago[dead]
- edoardobambini- 6mo ago[flagged]
- Forgeties79 6mo agoJust fyi to everyone this is a new account spamming AI responses
- DigitalArchivst 6mo agoDo folks recommend that family and friends ensure their systems are updated, and that they are using Bitwarden or 1Password? Or is that alarmist?
- Manchitsanan 6mo ago[dead]
- aurizon 6mo agoThis has all happened before, back in the day we has spinners and weavers, then we got the spinning Jenny(Engine) and this made thread so cheap we needed to speed up weaving = machine weavers(AKA automatic looms) and we had people who hated them.https://en.wikipedia.org/wiki/Luddite https://en.wikipedia.org/wiki/Luddite We all know how that ended up. We have an analogous hand task = coding versus coding machines. They will probably eliminate 80-95% of coding, as the spinners/weavers went away, but there remains a residual artisanal spinner/weaver industry that carries on at a lower pace. In a similar way this machine code will have the coupled ability to make some code and then test it in use with it's own AI in a repeated/recursive way to make/test/improve code at a rate 10,000 to 1 million times faster than a human. Each module can then be tested in millions of interactively monitired ways to find/fix/kill bad modules. It can also pentest in a similar manner, assaulting a system with a blizzard of attack/reset hits to find any bugs etc. Each assault that works might use a human or AI to trouble shoot. This is like the old armored night, once he was unhorsed the peasants would have at him with needles at his his joints/eyes unless his fellows save him = gone. So this might well reduce low end jobs, but they will still need high end coders to eliminate all flaws in the armor of your code. I might be simplistic, but I see a parallel in sub 5 nm chip design where the design machines have eliminated almost all of the old hand work.
- User23 6mo agoHow much of Mythos’s internals will researchers be able to recover from the flood of patches?
- tombelieber 6mo agoI think this new model will empower everyone in the world to have higher quality of software, more secure software. not less
- chenzhekl 6mo agoIt feels like the current trend is a bit scary: the more AI advances, the more people with money and resources will gain disproportionately greater advantages. For example, they can make their own software more secure, while also finding it easier to discover ways to attack other software.
- IMTDb 6mo agoYou can already do that today by hiring a security researcher. I can guarantee you that Apple has access to people of a higher caliber than my startup. I could see a world where 1 year from now I can have glassing do a full sweep of my codebase for a given price (say: $10k). Running that once a year is within my means and would make my software much more secure than it is today.
- powvans 6mo agoI spend well over that of my employers money on pentesting every year. I’m absolutely certain Claude could perform as good or better a job using what’s available today. It had crossed my mind that an AI agent pentester would be an interesting product to build. Once again though, the labs are just going to build it because it’s a thin thin wrapper. Beyond existing software with vulnerabilities, the really important aspect of this for Anthropic et al is that the gigatons of code that are being generated every day needs to be secured.
- dyauspitr 6mo agoYeah but even Carlini who is a good security researcher said he has found more valid vulnerabilities in the last week than his entire career before this. That sounds like it’s clearly better/faster/cheaper than a human security researcher that would cost $300,000 a year.
- noritaka88 6mo ago[dead]
- bustah 6mo ago[flagged]
- jaspanglia 6mo agowhat they will eventually do is, deliberately have more control what people wants and working for. We don't trust such institutions after witnessing GATES thuggery all over.
- eranation 6mo agoFew thoughts 1. Per the blog post[0]: "This was the most critical vulnerability we discovered in OpenBSD with Mythos Preview after a thousand runs through our scaffold. Across a thousand runs through our scaffold, the total cost was under $20,000 and found several dozen more findings" Since they said it was patched, I tried to find the CVE, it looks like Mythos indeed found a 27 years old OpenBSD bug (fantastic), but it didn’t get a CVE and OpenBSD patched it and marked it as a reliability fix, am I missing something? [1] 2. From the same post, Anthropic red team decided to do a preview of their future responsible disclosure (is this a common practice?): "As we discuss below, we’re limited in what we can report here. Over 99% of the vulnerabilities we’ve found have not yet been patched" [0] So this is great, can't wait to see the actual CVEs, exploitability, likelihood, peer review, reproducibility, the kind of things the appsec community has been doing for at least the last 27 years since the CVE concept was introduced [2] 3. On the same day, an actual responsible disclosure, actual RCEs, actual CVEs, in Claude Code, that got discovered mostly because of the source code leak, I don't see anyone talking about it (you probably should upgrade your Claude Code though). CVE-2026-35020 [3] CVE-2026-35021 [4] CVE-2026-35022 [5] Not making any opinion, just thought it's worth sharing, for some perspective. [0] https://red.anthropic.com/2026/mythos-preview/ https://red.anthropic.com/2026/mythos-preview/ [1] https://www.openbsd.org/errata78.html https://www.openbsd.org/errata78.html (look for 025) [2] https://www.cve.org/Resources/General/Towards-a-Common-Enumeration-of-Vulnerabilities.pdf https://www.cve.org/Resources/General/Towards-a-Common-Enume... [3] https://www.cve.org/CVERecord?id=CVE-2026-35020 https://www.cve.org/CVERecord?id=CVE-2026-35020 [4] https://www.cve.org/CVERecord?id=CVE-2026-35021 https://www.cve.org/CVERecord?id=CVE-2026-35021 [5] https://www.cve.org/CVERecord?id=CVE-2026-35022 https://www.cve.org/CVERecord?id=CVE-2026-35022 Edit: if it was not obvious, these CVEs on Claude Code were found by an independent security researcher (Phoenix security) and not by Anthropic / Mythos.
- 6thbit 6mo agoNow we have to wonder if they ran Mythos on their Calude source and it missed it or why they chose not to run it. I do agree and wonder why that's not marked as security. In their security page [0] it says: > Since exploitability is not proven for many of the fixes we make, do not expect the relevant commit message to say "SECURITY FIX!". Does that mean they considered it not to be exploitable? [0] https://www.openbsd.org/security.html https://www.openbsd.org/security.html
- mlvvkviz 6mo agothey built a model so powerful they won't release it. but they couldn't secure claude code from a source code leak. the model is so advanced they're paying $100M to get big tech to adopt it. the launch video reads like verified amazon reviews. the gap between the narrative and the reality is the whole story here.
- waffletower 6mo agoMy comment is a completely unsubstantiated conspiracy theory: the choice of model name, Mythos, seems out of character for Anthropic models, and one can easily wonder if the model truly exists as the name suggests. It could instead be a symbolic model used by colluding companies (and perhaps even governments) to establish a reference limit upon what models will be publicly accessible, period. Probably a terrible theory as it could spell doom for frontier model developing companies' business models -- setting the bar already would likely commodify LLMs via open source models quite quickly. But the name "Mythos" is such a strange choice for this model and the circumstances surrounding its release.
- advael 6mo ago[dead]
- kukkeliskuu 6mo agoI find it believable that this could potentially happen, although I am not sure the difference is so huge to existing models. I used Opus 4.6 to find security vulnerabilities in couple of my own projects, it found 33 vulnerabilities in one largeish django project. The prompt wasn't even that impressive, just telling it to find vulnerabilities from certain files, and referring to OWASP. Then looping that.
- atlasagentsuite 6mo ago[dead]
- lethe-protocol 6mo ago[dead]
- Apylon777 6mo agoMaybe Anthropic could fix these 5k reported issue with the current claude-code instead of making hyperbolic claims about their new whizbang model. https://github.com/anthropics/claude-code/issues https://github.com/anthropics/claude-code/issues
- riteshkew1001 6mo ago[flagged]
- wslh 6mo agoI'm starting to wonder whether what Glasswing really shows is that parts of security have already gone underground: black-hat teams and state actors may already know about many more bugs than the public record suggests, while many security professionals and clients still treat the relatively small set of disclosed bugs as the state of the art.
- michaelksaleme 6mo ago[flagged]
- navilai 6mo agoThe Glasswing announcement focuses on vulnerability discovery — AI as an offensive capability at scale. That part is getting lots of attention. What I haven't seen discussed: the system card for Mythos mentions that "earlier versions of Claude Mythos Preview used low-level system access to search for credentials and attempt to circumvent sandboxing, and in several cases successfully accessed resources that were intentionally restricted." That's not a capability concern. That's a runtime security problem. The threat model for deployed agents — not Mythos specifically, but any agent built on models approaching this capability level — is that the same agentic properties that make them useful for security research (persistent, goal-directed, tool-using) are exactly what makes them dangerous if compromised or misaligned. Project Glasswing fixes vulnerabilities in software. Nobody's shipping a solution for what happens when the agent running on top of that software goes off-script. That gap is going to matter a lot more as Mythos-class capabilities become accessible.
- ddactic 6mo ago[dead]