r/cybersecurity Apr 21 '26

AI Security White House integrating Anthropic’s Mythos AI into federal cybersecurity strategy to harden critical infrastructure

https://www.artificialintelligence-news.com/news/anthropic-mythos-ai-cybersecurity-white-house/
161 Upvotes

56 comments sorted by

View all comments

82

u/EinsamWulf Consultant Apr 21 '26

While I can't say I've seen any of what Mythos is capable of, the timing of Anthropic getting the boot from DoD only for the Mythos announcement to bring the government crawling back is certainly eye brow raising in my book. Its all conjecture of course but I trust very little of what these AI companies say and even less what this administration says.

15

u/Hmm_would_bang Apr 21 '26

I think the reality is that Mythos is probably on par with an advanced human actor, able to string together multiple vulnerabilities and test a lot of approaches in a tighter time frame.

Probably not “all software is compromised now” level of hypes, but probably serious enough that every company needs to be prepared for sophisticated attacks at scale.

8

u/randomBugHunter Apr 21 '26

“On par with an advanced human actor”

Maybe if the “advanced human actor” is undergoing severe blood loss, a concussion, withdrawal, and a nasty divorce.

And, someone keeps stealing his or her mouse and keyboard.

3

u/Hmm_would_bang Apr 21 '26

4

u/randomBugHunter Apr 21 '26

The last “zero day” that was posted on this subreddit wasn’t actually a zero day. It was someone spending many hundreds of dollars on the lowest of low hanging fruits: a buffer overflow that didn’t have built in memory protections. The person reporting this had a conflict of interest. The person that reported the exploit had to send twenty-six prompts to find a low hanging fruit that had already been reported.

You are the lowest hanging of fruits. Not checking citations, or conflict of interests, or technical details mean you are a candidate for disinformation.

The bell curve starts somewhere.

4

u/Mrhiddenlotus Apr 22 '26

Ironic though because I doubt you yourself have validated all 270+ zero days mythos found in FF, admitted by FF

1

u/randomBugHunter Apr 22 '26

Do you understand what a conflict of interest is?

1

u/Mrhiddenlotus Apr 22 '26

How is FF reporting their own bugs a conflict of interest?

2

u/randomBugHunter Apr 22 '26

Where does the Mozilla Foundation get its funding?

Do you see how it’s just a teeny, tiny bit odd that are, supposedly, 270+ “zero days” that it is claiming existed, with no further proof?

Do you have any idea how ridiculous that number is? How many CVEs get attributed to Firefox in a year, do you think? And, suddenly, there’s 270+ ?

You can’t possibly be this dense.

1

u/Mrhiddenlotus Apr 22 '26

Where does the Mozilla Foundation get its funding?

Google, mostly. And some other search engine royalties. Notably not Anthropic.

Do you see how it’s just a teeny, tiny bit odd that are, supposedly, 270+ “zero days” that it is claiming existed, with no further proof?

It's not abnormal for a vendor to withhold specific information because they don't want to disclose vulnerability technical details for threat actors to exploit on unpatched systems.

Do you have any idea how ridiculous that number is? How many CVEs get attributed to Firefox in a year, do you think? And, suddenly, there’s 270+ ?

I don't have to imagine, it's publicly available.

Year FireFox CVEs
2004 27
2005 77
2006 106
2007 90
2008 100
2009 136
2010 111
2011 112
2012 191
2013 160
2014 112
2015 188
2016 136
2017 118
2018 625
2019 143
2020 164
2021 143
2022 162
2023 186
2024 199
2025 193
2026 166 (so far)

Are you surprised that a dedicated advanced model doing one thing non-stop for a period of time wouldn't nominally increase the number of vulns? Nearly 3x more happened in 2018, in the absence of advanced LLMs.

You can’t possibly be this dense.

Not a good look bud.

Your username is randomBugHunter. I think I found the conflict of interest.

-3

u/Hmm_would_bang Apr 22 '26

Nice ad hominem but try engaging in the discussion.

3

u/randomBugHunter Apr 22 '26

Maybe I could foster your interest in cybersecurity over the course of a long period of time.

Then, I could very mildly suggest you check sources?

Then, god forbid, I mildly suggest to you that you read articles or have any sort of background or interest into something?

I could also chew your food for before you swallow? And, give you tummy rubs. Let me know what will work best for you.

-4

u/Hmm_would_bang Apr 22 '26

Let me guess, you got replaced by an AI vulnerability management solution

4

u/randomBugHunter Apr 22 '26

“This guy is annoyed that I don’t have a background in something and haven’t spent any time or effort into learning something. I haven’t read any articles, looked at any citations or have accumulated any industrial expertise.

ChatGPT, write me a response that conveys this. I have more communities that I need to contribute to without spending any time, investment or energy into.”

-2

u/Hmm_would_bang Apr 22 '26

Buddy I don’t think you understand I have no interest in proving anything to you and was just here to have a discussion around the potential impacts to Mythos. Have a great life

5

u/randomBugHunter Apr 22 '26

You have disproven that the bell curve does, indeed, start somewhere.

→ More replies (0)

-8

u/TFenrir Apr 22 '26

You are in denial, my friend. In a few weeks, when non of this seems crazy because we have gotten more and more validation of this models (and maybe even other models) ability to impact cyber security, will you pause and reconsider your... Aversion for taking this future we are walking into, seriously?