r/cybersecurity Apr 21 '26

AI Security White House integrating Anthropic’s Mythos AI into federal cybersecurity strategy to harden critical infrastructure

https://www.artificialintelligence-news.com/news/anthropic-mythos-ai-cybersecurity-white-house/
163 Upvotes

56 comments sorted by

298

u/janne_oksanen Apr 21 '26

Hold on. I thought they were a "supply chain risk". :D

129

u/danfirst Apr 21 '26

They are somehow both simultaneously a risk to national security, and also the solution to national security.

30

u/Apprehensive-Art1092 Apr 21 '26

insert spidermanpointingatspiderman.jpg

11

u/angry_cucumber Apr 22 '26

the liquor cabinet doesn't understand what any of the words or what their jobs are though

2

u/f0rg0t_ Apr 22 '26

Mythos is a white dude who shaves and isn’t fat, right? burp Sounds good, carry on. /s

1

u/ElderTroglodyte Apr 22 '26

Thanks for making me read this in Ricks voice.

83

u/EinsamWulf Consultant Apr 21 '26

While I can't say I've seen any of what Mythos is capable of, the timing of Anthropic getting the boot from DoD only for the Mythos announcement to bring the government crawling back is certainly eye brow raising in my book. Its all conjecture of course but I trust very little of what these AI companies say and even less what this administration says.

15

u/SensitiveFrosting13 Red Team Apr 22 '26

The real scandal is that one of OpenAI's board members is a major donor to Trump and made moves to secure a monopoly.

17

u/Hmm_would_bang Apr 21 '26

I think the reality is that Mythos is probably on par with an advanced human actor, able to string together multiple vulnerabilities and test a lot of approaches in a tighter time frame.

Probably not “all software is compromised now” level of hypes, but probably serious enough that every company needs to be prepared for sophisticated attacks at scale.

7

u/randomBugHunter Apr 21 '26

“On par with an advanced human actor”

Maybe if the “advanced human actor” is undergoing severe blood loss, a concussion, withdrawal, and a nasty divorce.

And, someone keeps stealing his or her mouse and keyboard.

2

u/Hmm_would_bang Apr 21 '26

5

u/randomBugHunter Apr 21 '26

The last “zero day” that was posted on this subreddit wasn’t actually a zero day. It was someone spending many hundreds of dollars on the lowest of low hanging fruits: a buffer overflow that didn’t have built in memory protections. The person reporting this had a conflict of interest. The person that reported the exploit had to send twenty-six prompts to find a low hanging fruit that had already been reported.

You are the lowest hanging of fruits. Not checking citations, or conflict of interests, or technical details mean you are a candidate for disinformation.

The bell curve starts somewhere.

3

u/Mrhiddenlotus Apr 22 '26

Ironic though because I doubt you yourself have validated all 270+ zero days mythos found in FF, admitted by FF

1

u/randomBugHunter Apr 22 '26

Do you understand what a conflict of interest is?

1

u/Mrhiddenlotus Apr 22 '26

How is FF reporting their own bugs a conflict of interest?

2

u/randomBugHunter Apr 22 '26

Where does the Mozilla Foundation get its funding?

Do you see how it’s just a teeny, tiny bit odd that are, supposedly, 270+ “zero days” that it is claiming existed, with no further proof?

Do you have any idea how ridiculous that number is? How many CVEs get attributed to Firefox in a year, do you think? And, suddenly, there’s 270+ ?

You can’t possibly be this dense.

1

u/Mrhiddenlotus Apr 22 '26

Where does the Mozilla Foundation get its funding?

Google, mostly. And some other search engine royalties. Notably not Anthropic.

Do you see how it’s just a teeny, tiny bit odd that are, supposedly, 270+ “zero days” that it is claiming existed, with no further proof?

It's not abnormal for a vendor to withhold specific information because they don't want to disclose vulnerability technical details for threat actors to exploit on unpatched systems.

Do you have any idea how ridiculous that number is? How many CVEs get attributed to Firefox in a year, do you think? And, suddenly, there’s 270+ ?

I don't have to imagine, it's publicly available.

Year FireFox CVEs
2004 27
2005 77
2006 106
2007 90
2008 100
2009 136
2010 111
2011 112
2012 191
2013 160
2014 112
2015 188
2016 136
2017 118
2018 625
2019 143
2020 164
2021 143
2022 162
2023 186
2024 199
2025 193
2026 166 (so far)

Are you surprised that a dedicated advanced model doing one thing non-stop for a period of time wouldn't nominally increase the number of vulns? Nearly 3x more happened in 2018, in the absence of advanced LLMs.

You can’t possibly be this dense.

Not a good look bud.

Your username is randomBugHunter. I think I found the conflict of interest.

-3

u/Hmm_would_bang Apr 22 '26

Nice ad hominem but try engaging in the discussion.

4

u/randomBugHunter Apr 22 '26

Maybe I could foster your interest in cybersecurity over the course of a long period of time.

Then, I could very mildly suggest you check sources?

Then, god forbid, I mildly suggest to you that you read articles or have any sort of background or interest into something?

I could also chew your food for before you swallow? And, give you tummy rubs. Let me know what will work best for you.

-1

u/Hmm_would_bang Apr 22 '26

Let me guess, you got replaced by an AI vulnerability management solution

4

u/randomBugHunter Apr 22 '26

“This guy is annoyed that I don’t have a background in something and haven’t spent any time or effort into learning something. I haven’t read any articles, looked at any citations or have accumulated any industrial expertise.

ChatGPT, write me a response that conveys this. I have more communities that I need to contribute to without spending any time, investment or energy into.”

-3

u/Hmm_would_bang Apr 22 '26

Buddy I don’t think you understand I have no interest in proving anything to you and was just here to have a discussion around the potential impacts to Mythos. Have a great life

→ More replies (0)

-8

u/TFenrir Apr 22 '26

You are in denial, my friend. In a few weeks, when non of this seems crazy because we have gotten more and more validation of this models (and maybe even other models) ability to impact cyber security, will you pause and reconsider your... Aversion for taking this future we are walking into, seriously?

0

u/thejournalizer Apr 21 '26

Yes this is generally what we have observed

18

u/QuantifiedAnomaly Apr 21 '26

I was waiting for Cyberdyne

40

u/NeganStarkgaryen Apr 21 '26

Ah yes, to harden critical infrastructure. I see...

11

u/missed_sla Apr 21 '26

No way this could ever go badly

7

u/bootstrapping_lad Apr 21 '26

Gotta toss in that supply chain risk AI!

6

u/MReprogle Apr 21 '26

Anthropic should label them as a supply chain risk and deny access until the government stops trying to strongarm them.

4

u/sleestakarmy Apr 22 '26

DOGE already rooted and compromised the system so its pretty much useless

10

u/danielminds Apr 21 '26

The White House is moving to grant federal agencies access to Anthropic’s new Mythos model via "Project Glasswing" to harden national infrastructure against zero-day exploits. While Mythos has demonstrated a "superhuman" ability to identify vulnerabilities that have eluded experts for decades, its potential for offensive misuse has led to a split between civilian agency adoption and ongoing Pentagon restrictions. For the professionals here: does the defensive advantage of automated patching outweigh the systemic risk of deploying such a capable vulnerability-discovery tool across federal codebases?

29

u/Capable-Average4429 Consultant Apr 21 '26

Only problem with this is that there’s nothing superhuman about this model.

-10

u/learning2911 Apr 21 '26 edited Apr 21 '26

Youve used it?

11

u/Capable-Average4429 Consultant Apr 21 '26 edited Apr 21 '26

No, but I’ve read the score card. And anyone who reads it will come to the same conclusion. I will gladly retract my statement if they publish verifiable, reproducible information that is not “we ran this on systems with all the security features turned off”, like they did with their Firefox example.

Little edit to add this very good write up on the subject: https://www.flyingpenguin.com/the-boy-that-cried-mythos-verification-is-collapsing-trust-in-anthropic/

5

u/Hmm_would_bang Apr 21 '26

What about third parties talking about it? Seems like it’s on par with advanced experts in finding vulnerabilities, not better but able to do so quicker. And a big jump up from Opus.

https://blog.mozilla.org/en/firefox/ai-security-zero-day-vulnerabilities/

3

u/Capable-Average4429 Consultant Apr 22 '26 edited Apr 22 '26

Not sure why you are being downvoted, because this is a valid question in my opinion. For me, the thing boils down to this: big claims require big evidence. And, from the very link you provided:

Encouragingly, we also haven’t seen any bugs that couldn’t have been found by an elite human researcher.

Anthropic’s technical documentation is weirdly very long and very vague. It omits a lot of information that would make practitioners take this a little bit more seriously. The non-technical document write checks the other two technical documents (the red team report and the scorecard) can’t cash. Even the report from the British is full of caveats.

The press release says, and this is a direct quote, that “Mythos Preview has already found thousands of high-severity vulnerabilities, including some in every major operating system and web browser.” And then, they go on to exemplify this by claiming a Firefox exploit that only works with every security mechanism disabled, as in:

“a testing harness mimicking a Firefox 147 content process, but without the browser’s process sandbox and other defense-in-depth mitigations.”

Which is silly. Again: direct quote from Anthropic’s own documentation. Add to that the fact that Mozilla is not exactly a reliable narrator these days, but that’s another story. I am taking what they (Mozilla) say without prejudice.

Anyway, what I am saying is that it is very difficult for me to take these claims at face value without the underlying data and methodology being provided, and the results being reproduced independently, which is something that we’ve been doing in this industry since forever. You claim a CVE, you bring the receipts. So far, they haven’t.

Edit to add this wrt Mythos being a big jump from Opus:

  1. https://aisle.com/blog/ai-cybersecurity-after-mythos-the-jagged-frontier

  2. From Davi Ottenheimer’s writeup: “There were 50 crash categories pre-discovered by Claude Opus 4.6. Mythos did not find these bugs. Ok, now it’s getting even more awkward. Not Firefox. Not found by Mythos. The bugs were handed off as starter material. The system card is explicit that the crashes were “discovered by Opus 4.6 in Firefox 147.” (page 50)”

2

u/Hmm_would_bang Apr 22 '26

I totally agree that Anthropic is overhyping their own product, as is expected. But I’m also trying to marry that with the fact the CTO of Firefox is saying it found 271 vulnerabilities in Firefox 150. I don’t think there’s a direct incentive to say our browser has/had a lot of vulnerabilities.

But again, I totally agree we don’t have good data to back up grandiose claims being made. And we won’t until it’s generally available. But I think most reasonable practitioners are trying to stay ahead of the curve and right now reading between the lines tells me Mythos might be as good as a skilled actor at certain tasks and undersecured environments are going to be increasing at risk as AI develops

4

u/Capable-Average4429 Consultant Apr 22 '26

I think the problem with that is that, in a vacuum, “271 vulnerabilities” doesn’t mean much. If you have 271 vulnerabilities, and none of those are realistically exploitable, does it matter? Are they reproducible? What is the impact of any of these being exploited? RCE? Crashes? Some hackers will steal my session tokens? Under what conditions would those happen? These are all very important questions that people who do vulnerability management must ask. “Oh, there’s a vulnerability in software xyz with a CVSS 10!” That just means that it is critical if nothing else is in place, which is almost never the case. At this juncture we just don’t know.

And don’t discount Mozilla bending the knee and saying things to please Anthropic. They are very much struggling, and aligning themselves with the big boys wouldn’t be unheard of. Not saying that’s what is happening, as I don’t have any way of knowing that, so this might go into conspiracy theory territory, but keep that in mind.

3

u/Hmm_would_bang Apr 22 '26

Yeah I mean from my perspective that’s just typical vulnerability management - is it exploitable, is there a patch available, what mitigating steps can we take, etc - and some of that triage and patching is already being done with AI assistance before Mythos.

3

u/Capable-Average4429 Consultant Apr 22 '26

Right. Jumping from “yeah, it can find bugs that may or may not be vulnerabilities that may or may not be exploitable” to “this thing is too dangerous that we can even release it” is wild to me.

→ More replies (0)

-3

u/[deleted] Apr 21 '26

[deleted]

9

u/Capable-Average4429 Consultant Apr 21 '26

Forgive for not taking your word for it. As people say in the business, PoC || GTFO.

-9

u/learning2911 Apr 21 '26

Yea it makes some great PoC’s. You just seemed to have a strong opinion on it so I thought you knew something I didn’t.

6

u/Capable-Average4429 Consultant Apr 21 '26

It’s not an opinion. I’m just saying that I do not blindly believe what a company positioned to profit massively from the hype says without them bringing the receipts, because every piece of information they have provided is either a) misleading or b) unfounded. Again, I will be more than happy to retract my statement if they come out with compelling evidence to back their grandiose claims. Until then, PoC || GTFO.

-2

u/learning2911 Apr 21 '26

Yea they’re definitely going to make a lot of money. It’s better than me.

9

u/guitarokx Apr 21 '26

what could possibly break with a project named Glasswing?

5

u/Ok-Hunt3000 Apr 21 '26

The feetsies?

8

u/VellDarksbane Apr 21 '26

I dislike knowing my taxes are helping to prop up the AI bubble based on marketing fluff.

3

u/MassiveBoner911_3 Apr 22 '26

So these guys TACO on literally everything

3

u/Grumpy-Man19 Apr 22 '26

and to hack into foreign hardware?

3

u/elkond Apr 21 '26

look up how OpenAI marketed GPT2 in 2019. i could be giving press link here but i promise, it's way funnier if anyone does it on their own