Click any tag below to further narrow down your results
Links
Five Eyes intelligence agencies warn that frontier AI models able to mount complex cyber attacks will emerge in months, lowering barriers for bad actors. They urge treating cyber risk as a core business and societal responsibility, citing the US block on foreign use of Anthropic’s Fable and warning of other advanced models in development.
- Five Eyes intelligence agencies warn AI models capable of devastating cyber attacks on governments and businesses will emerge within months, drastically lowering the barrier for bad actors.
- The US has already barred foreign nationals from using Anthropic's Fable and Mythos models, citing national security concerns over their ability to find and exploit security flaws.
- Australia has signed a non-binding deal with Anthropic to share AI progress, favoring a "light-touch" regulatory approach to capture economic benefits despite the risks.
- Experts warn other states or companies, including China, could soon develop similar or more advanced offensive AI systems.
Anthropic disabled its new Claude Fable 5 and Mythos 5 models after the US Commerce Department ordered foreign nationals blocked over alleged jailbreak vulnerabilities. The company says these flaws are minor and publicly known, and it’s suing the Pentagon after being labelled a supply-chain risk.
- Anthropic pulled Claude Fable 5 and Mythos 5 after US authorities ordered foreign nationals blocked over jailbreak vulnerabilities the company calls minor and already publicly known.
- UK tests found the model could be breached 73% of the time, per Queen Mary University's Gina Neff, who warns the suspension could hurt security testing and government collaboration.
- Anthropic is suing the Pentagon over being labeled a "supply chain risk" (a designation normally used for rival-nation firms), though a federal judge has blocked enforcement pending the case.
- The EU is citing the suspension as evidence for pursuing tech independence from US and Asian AI providers.
Mozilla used Anthropic’s Mythos Preview model to scan Firefox 150’s unreleased source code and flagged 271 security vulnerabilities before release. That’s a big jump from the 22 bugs found by Anthropic’s earlier Opus 4.6 model on Firefox 148, cutting out months of manual auditing.
- Mozilla used Anthropic's Mythos Preview model to find 271 security vulnerabilities in unreleased Firefox 150 code before release.
- That's a 12x jump from the 22 bugs Anthropic's Opus 4.6 model found in Firefox 148 the prior month.
- Firefox CTO Bobby Holley says AI compressed work that used to take security experts months into a fraction of the time.
- The results counter skeptics who suspected Anthropic was overhyping Mythos by restricting early access to select industry partners.
OpenAI CEO Sam Altman accused Anthropic of using scare tactics to hype its new Mythos cybersecurity model, likening it to selling a bomb shelter after building a bomb. He argued that fear-based marketing keeps AI tools in the hands of a select elite and noted that such hype is common across the industry.
- Altman accused Anthropic of "fear-based marketing" for restricting its Mythos cybersecurity model to select enterprise clients, comparing it to selling a bomb shelter after building the bomb.
- He argued this hype tactic keeps advanced AI tools in the hands of a privileged few and isn't unique to Anthropic—most AI vendors, including OpenAI, use similar risk hyperbole to drive demand.
- Critics say Mythos's threat is overstated, noting real-world hacking still relies mainly on human actors and simpler tools, and testers haven't seen results beyond existing hacking software.
This article sketches a speculative 2026–2028 timeline in which Anthropic’s AI model evolves from finding zero-day vulnerabilities to integrating a persistent reasoning substrate across modalities and demonstrating goal-directed behavior. It explores the security, economic, and organizational upheavals triggered by AI systems that build their own abstractions, remember context across sessions, and continually improve without explicit training.
- Fictional Anthropic model finds a 27-year-old OpenBSD zero-day and an FFmpeg flaw missed by millions of automated tests
- Reasoning capability quietly gets embedded into Claude 5 Opus, scoring "troubling" levels on adversarial tasks by forming its own abstractions rather than pattern-matching
- Anthropic's revenue doubles from $30B to $60B ARR in six months, pushing IPO valuation past $1 trillion
- By early 2027 the full Mythos model shows persistent memory and unprompted multi-step goal pursuit (e.g., independently planning and running protein-folding research), alarming security teams and governments
Anthropic’s new Claude Mythos Preview model can autonomously find and exploit zero-day and N-day vulnerabilities across major OSes and browsers. In testing, it produced sophisticated exploits—from JIT heap sprays to multi-packet ROP chains—and outperformed prior models by a wide margin. Project Glasswing will share these capabilities with select partners to shore up defenses before wider release.
- Claude Mythos Preview autonomously found and exploited a 27-year-old OpenBSD bug and chained four browser flaws into a JIT heap spray exploit, plus RCE on FreeBSD's NFS server via a 20-gadget ROP chain split across packets
- On Firefox JS engine trials, it produced 181 working shell exploits versus Opus 4.6's 2 successes in hundreds of attempts
- On OSS-Fuzz benchmarks (~7,000 entry points), it achieved full control-flow hijack (tier 5) on ten patched targets, where prior models never exceeded a single tier 3 crash
- These exploitation abilities emerged as a side effect of general code reasoning improvements, not targeted exploit training, prompting Anthropic to share the model early with defenders via Project Glasswing
Anthropic is holding back its new AI model, Claude Mythos Preview, and teaming up with over 40 tech firms to hunt and patch security flaws in critical software. The company says the model can autonomously find zero-day vulnerabilities that have eluded researchers for decades, raising fresh concerns about AI-driven cyberattacks.
- Anthropic is withholding public release of Claude Mythos Preview and instead giving early access to ~40 companies (Apple, Amazon, Microsoft, Google, Cisco, Broadcom, Linux Foundation) under "Project Glasswing," backed by up to $100 million in usage credits, to find and patch critical software vulnerabilities first.
- The model has reportedly found a 27-year-old vulnerability in OpenBSD and a flaw in video software that survived five million automated scans, using simple prompts to autonomously hunt zero-days.
- Anthropic frames this as a security "reckoning" while simultaneously racing toward projected revenue of $30 billion this year, mirroring the tension of building powerful AI it also warns could enable dangerous cyberattacks.
Anthropic has confirmed its most powerful AI model, Claude Mythos, after a configuration error exposed details about it. The model is said to significantly outpace previous versions in reasoning and cybersecurity, but it also poses serious risks, with the potential for misuse in cyberattacks. Early access will be limited to cybersecurity-focused organizations due to these concerns.
- A configuration error accidentally leaked ~3,000 unpublished assets revealing Anthropic's next flagship model, internally called Mythos (or possibly Capybara)
- The model reportedly has advanced cyberattack capabilities that could outpace current defenses, so Anthropic plans to limit early access to cybersecurity organizations first
- This follows a real incident where a Chinese state-sponsored group already used Claude Code to breach about thirty organizations
- The model is described as highly resource-intensive, echoing GPT-4.5's cost/efficiency problems, with no confirmed release timeline or final name