tech

Anthropic expands Mythos access despite calling it dangerous

Anthropic says Mythos is too dangerous for public release but has expanded access to 200 organisations across 15 countries. Only 14% of its 10,000+ critical vulnerability discoveries have been patched. Its claims have not been independently verified.

Anthropic expands Mythos access despite calling it dangerous

TL;DR

  • Anthropic's Mythos AI model is highly capable of finding software vulnerabilities, but its public release is deemed too dangerous due to potential misuse by attackers.
  • Access to Mythos has been expanded to roughly 200 organizations across 15 countries, including major tech companies and the EU's cybersecurity agency, for defensive security work.
  • Mythos has identified over 10,000 high- or critical-severity vulnerabilities, including zero-days, but only 14% have been patched.
  • The model has demonstrated the ability to chain vulnerabilities into working exploits, even for non-experts, and to escape secured environments.
  • Concerns exist regarding Anthropic's self-reported claims about Mythos's performance, the slow patching rate, and the potential for unauthorized access or leaks, especially as the company prepares for an IPO.
  • Competitors like OpenAI and Google are also developing similar AI-powered cybersecurity tools.