8 ms·
US summons bank bosses over cyber risks from Anthropic's latest AI model
- PedroBatista 6mo agoThe more I live the more I believe people at the top operated in some sort of cult mentality. The level of gullibleness, temporary lack of critical thinking is only matched by their sociopathy and Machiavellianism. I'm sure it's a great big model, but the level of hype and dishonesty is something out of Sam Altman's book. Of course it's because of the upcoming IPO, but that's the end game, for now it's critical to get those private equity guys and bank institutions to believe the gospel and hold the bag, only then the suckers from the secondary markets will be allowed to be suckers too.
- xvector 6mo agoWill you eat your words when major vuln disclosures come out 3-4 months from now?
- ofjcihen 6mo agoWill you eat your words when you find out major vuln disclosures have been happening for decades?
- reducesuffering 6mo agoOr, you're wrong. And the smartest AI Research Scientists and the top banking officials are both correctly worried about the ramifications. That's what you'd expect if there really was an issue here. Are you aware of the deep seated bugs in critical software that were already uncovered with Mythos? Are you able to steelman the issue here at all?
- colechristensen 6mo agoTwo things can be true. Historically bad security that people just got by with matched with powerful tools that aren't any better than the best people, but now can be deployed by mediocre people.
- SpicyLemonZest 6mo agoWhich is exactly what Anthropic understands the situation to be. They state at the beginning of the Glasswing blogpost that Mythos is not better than the best vulnerability researchers. But it doesn't have to be to become a tremendously big deal.
- cestith 6mo agoThere is not just a lower barrier to entry. The best use of a tool will still be made by the most knowledgeable users. So we’re looking at lowering the bar some, but another big deal is the scale at which the top experts can work. That might actually be the longer lever. Imagine a top expert burning tokens across whole repo histories of a few dozen projects looking for likely but unconfirmed flaws, then having the model flag and rank those suspects for their own review in triaged order.
- alephnerd 6mo ago> Are you aware of the deep seated bugs in critical software that were already uncovered with Mythos This. 100% this. A large portion of the industry is under NDA right now, but most of the F500 have already already deployed or started deploying foundational models for AppSec usecases all the way back in 2023. Sev1 vulns have already been detected using "older" foundation models like Opus 4.x Of course the noise is significant, but that's something you already faced with DAST, SAST, and other products, and is why most security teams are also pairing models with experienced security professionals to adjudicate and treat foundation model results as another threat intel feed.
- colechristensen 6mo agoThere's a serious problem with being very popular/prominent/powerful and becoming surrounded by sycophants out of a sort of survival of the fittest and then developing a progressively more distorted view of reality as a result. When everything can appear to be made to work to the person at the center they start making progressively worse decisions which are consequence free because of the sway they already have. (this is a big reason why "disruptor" startups work)
- icedchai 6mo agoA good percentage of cybersecurity has always been theater. If their model helps to separate the wheat from the chaff, maybe it'll be an improvement.
- bwfan123 6mo ago> A good percentage of cybersecurity has always been theater It is great to be in a "best-effort" business where there are no consequences for bad things happening. Cybersecurity is one of those businesses. Web search, feeds and ads are another. Imagine you are selling locks to secure homes. A thief breaks the lock. The lock-maker is not held liable. In fact, they now start selling stronger locks, and lock sales actually improve with more thefts.
- SpicyLemonZest 6mo agoI'm definitely optimistic that the long-term trajectory is positive. All important software can undergo extensive penetration testing with cutting-edge vulnerability research techniques before launch? Sounds great. The problem is what goes wrong on the pathway to there.
- guzfip 6mo agoIt sounds like it’ll just kill the wheat and the chaff. Still probably a benefit depending on your philosophy.
- downrightmike 6mo agoNeed to dump the bag on retail investors and pensions before they implode
- sroussey 6mo agoPromoting the model as potentially dangerous might backfire with the government banning it from being released by executive order.
- vonneumannstan 6mo agoI think that would be a good precedent given the current lack of rules around AI Safety. These models don't seem to be plateauing yet and could be much more dangerous than Mythos in 1-2 years.
- petcat 6mo ago> the government banning it from being released by executive order. There's no legal mechanism for the president or the government at all to do that.
- rf15 6mo agoI'm sure they will find something when it really starts to bother them personally.
- empath75 6mo agoThere are ways for the government to do that sort of thing on an emergency basis, and it would take quite some time to make it's way through the courts. There are precedents from nuclear weapons technology and cryptography. I don't think it'll hold up or be particularly effective because the horse has left the barn already, but they could probably slow things down if they really wanted to.
- dist-epoch 6mo agoOf course there is. Fully automatic weapons are banned. Certain chemicals and biologics are banned. Certain hacking tools are banned (DMCA): > The “tools” prohibitions, set out in sections 1201(a)(2) and 1201(b), outlaw the manufacturing, sale, distribution, or trafficking of tools and technologies that make circumvention possible. These provisions ban both technologies that defeat access controls, and also technologies that defeat use restrictions imposed by copyright owners, such as copy controls. These provisions prohibit the distribution of software that was designed to defeat CD copy-protection technologies, for example. https://www.eff.org/pages/unintended-consequences-fifteen-years-under-dmca https://www.eff.org/pages/unintended-consequences-fifteen-ye...
- nothinkjustai 6mo agoLooks like the marketing worked at least somewhat lol. Such an obvious playbook by now I’m surprised some people here fell for it.
- skybrian 6mo agoYour cynicism doesn't prove that it's fake, though.
- nothinkjustai 6mo agoJust like their marketing campaign doesn’t mean those claims are real?
- skybrian 6mo agoI mean sure, they could be lying. It seems like a rather elaborate lie, though, considering that they got several other major companies to go along with it.
- davebren 6mo agoYou've got to admit that crying wolf about how dangerous their new model is for the hundredth time right when the biggest story about the company was a leak that made them and their internal vibe-coding look totally incompetent is a bit suspect.
- causal 6mo agoMaybe it's marketing, but I think it's regrettable that Anthropic paired project Glasswing with Mythos. It really makes it seem like Mythos is the threat, rather than the fact that tons of vulnerabilities have always been ignored throughout the software world. If Glasswing has been started years ago with the goal of applying fixes to AI-found gaps, then this would just be another model to add to that effort. But doing so in the ominous shadow of some new super model boosts panic IMO.
- skybrian 6mo agoA year ago the LLM's weren't good enough to find these security issues. They could have done other stuff. But then again, the big tech companies were already doing other stuff, with bug bounties, fuzzing, rewriting key libraries, and so on. This initiative probably could have started a few months sooner with Opus and similar models, though.
- vonneumannstan 6mo ago>This initiative probably could have started a few months sooner with Opus and similar models, though. Evidently they tried and even the most recent Opus 4.6 models couldn't find much. Theres been a step change in capabilities here.
- causal 6mo agoNo, Opus has found a lot and 112 vulnerabilities were reported to Firefox alone by Opus [0]. But Mythos is uniquely capable of exploiting vulnerabilities, not just finding them. [0] https://red.anthropic.com/2026/mythos-preview/ https://red.anthropic.com/2026/mythos-preview/
- vonneumannstan 6mo agoDoesn't even seem to be in the same ballpark of capability. https://red.anthropic.com/2026/mythos-preview/FRT-Blog-Chart-CMP-Firefox-exploit@2x.png https://red.anthropic.com/2026/mythos-preview/FRT-Blog-Chart...
- simonw 6mo ago> A recent leak of Claude’s code prompted the startup to publish a blogpost at the beginning of the month saying that AI models had surpassed “all but the most skilled humans at finding and exploiting software vulnerabilities” [...] I've seen a bunch of people conflate the Claude Code source-map leak with the Mythos story, though not quite as blatantly as here. I'm confident that they are totally unrelated.
- taytus 6mo ago[flagged]
- delis-thumbs-7e 6mo ago[flagged]
- jannyfer 6mo agoI have a pet theory that the uptick in normal cybersecurity PRs you mention as a trend in your blog were done with Claude Code’s stealth mode and Mythos.
- __natty__ 6mo agoI wonder whether this kind of release of model could become the spark that ignites a new digital "cold war" between us, europe, india and china, in which they will try to outwit their rivals and compromise their critical infrastructure using artificial intelligence. Also I’d like to believe that this really is such a huge step forward compared to Opus, but lately I’ve found it hard to believe when I look at the statements made by the CEOs of AI companies and their associates, who are fuelling the hype surrounding this topic even further. Of course, it is good that large companies and industries that are crucial to the country are the first to have access to this, but until the launch takes place, I will approach this with a degree of scepticism.
- mieubrisse 6mo agoThis invisible cyberwar is already happening; it's just that the brains powering it is getting smarter.
- alephnerd 6mo ago> ignites a new digital "cold war" Already been going on for over a decade - export controls on dual use technology like Xeon processors already began being enforced back in the Obama admin. > until the launch takes place It's already launched. Some companies had access to Mythos for months. > fuelling the hype This is true. Commercially available models from a year ago are already good enough from an offensive security perspective. Their big issue was noise, but that could be managed.
- cestith 6mo agoI was in the industry when key lengths for SSL were different between US domestic and US products for export. That’s one reason so much Open Source cryptography software expertise built up in Europe so quickly.
- alephnerd 6mo agoMuch of that muscle was already well built in Western Europe well before the SSL stuff because of KU Leuven, COSIC, and IMEC. The issue is by the late 2000s to 2010s, most European organizations didn't take advantage of that base despite being US comparable in the 1970s-90s.
- yks 6mo agoTangentially related, but how does one protect themselves against the bank account/brokerage being hacked? Can you print out a proof of funds/securities owned to take to court to be made whole?
- dist-epoch 6mo agoYour screenshot/PDF is kind of worthless since it's trivially editable. Still a good idea to have it. Banks are required by law to be able to produce account balances in a few days. In some countries the are required to submit them to account protection institution regularly so that if a bank fails they can quickly reimburse people to prevent panic spreading to other banks. You can probably request some sort of notarized proof of accounts, but it will probably cost you $100.
- jannyfer 6mo agoAside from FDIC’s insurance, nothing. And if banks get hacked and money gets wired out - maybe we’ll come up with ways to roll back the damage. Who knows - this is new territory.
- charcircuit 6mo agoI hope these banks are complaining how Anthropic is preventing them from accessing their latest model and giving preferential treatment to other businesses.
- scottyah 6mo agoAt least one of those banks is already in the partnership, and we don't know how many they reached out to.
- wankerrific 6mo agoSure. Its a meeting with major bank execs AND the fed chair to discuss Anthropics new hype model. Its definitely NOT, in any way, a meeting to discuss potential systemic risk due to insolvency/bankruptcy at some key AI-related company.
- rvz 6mo agoThey (Anthropic) really did scare the shit out of them. Didn't they.
- pieisgood 6mo agoI'm wondering whether the NSA will be granted access. It's already the largest collection of mathematicians on the planet and now they'd be given tools that could automate a lot of discovery. Or they're panicking that their "old faithful" back door will be patched soon.
- beyondscaletech 6mo ago[dead]