Skip to main content Scroll Top

Anthropic Mythos found security problems in every major operating system and web browser

WHY THIS MATTERS IN BRIEF

An AI that autonomously finds and exploits flaws across all major software shifts cyber defence and offence overnight.

 

Matthew Griffin is the World’s #1 Futurist Keynote Speaker and Global Advisor for the G7 and Fortune 500, specialising in exponential disruption across 100 countries. Book a Keynote or Advisory SessionJoin 1M+ followers on YouTube and explore his 15-book Codex of the Future series.

 


 

Anthropic is debuting a new Artificial Intelligence (AI) model as part of a cybersecurity partnership with Nvidia, Google, Amazon Web Services, Apple, Microsoft, and other companies. Project Glasswing, as it’s called, is billed as a way for large companies, and potentially even the government, to flag vulnerabilities in their systems with virtually no human intervention.

 

RELATED
Chinese researchers hack "Unhackable" quantum encryption, reveal method

 

Anthropic is offering its launch partners access to Claude Mythos Preview, a new general-purpose model that it’s not currently planning to publicly release due to security concerns. Newton Cheng, the cyber security lead for Anthropic’s frontier red team said that the model will ideally give cyber defenders a “head start” against adversaries. The partners will use the model to analyse their system to spot high-stakes vulnerabilities and help patch them up. Access is restricted to keep those same adversaries from using it to find weak points and conduct attacks.

 

The Future of Cyber Security and Quantum Technology | Sapphire, UK | Matt Griffin | Panel Session, by Futurist Keynote Speaker Matthew Griffin

Book a Keynote with Matthew

Though Claude Mythos Preview wasn’t specifically trained for cyber security purposes, Anthropic said in a release that the model’s “strong Agentic AI coding and reasoning skills” are behind its cyber security advances. In an interview Newton Cheng, the cyber lead for Anthropic’s frontier red team, declined to share specific details of the model’s cyber security successes beyond the company’s , but Anthropic’s blog post said that in recent weeks, Mythos Preview has flagged “thousands of high-severity vulnerabilities, including some in every major operating system and web browser.”

Anthropic’s blog post doesn’t mention keeping humans in the loop for the model’s cyber security sweeps; in fact, it highlights that the model identified vulnerabilities “and develop[ed] many related exploits entirely autonomously, without any human steering.”

 

RELATED
During Covid-19 lockdown robo-trucks in the US are keeping freight moving

 

Claude Mythos Preview’s existence was first reported in a data leak, which Anthropic attributes to human error. Dianne Penn, a head of product management at Anthropic said that the company is “taking steps in terms of solidifying our processes … That was not related to software vulnerabilities in any way.”

“Mythos Preview will be privately available to the company’s Glasswing partners, which also include JPMorgan Chase, Broadcom, Cisco, CrowdStrike, the Linux Foundation, and Palo Alto Networks, plus about 40 other organisations that maintain or build software infrastructure. For now, Anthropic will help subsidise the cost of using it. The company says it will commit up to $100 million in usage credits, plus $4 million in direct donations to the Linux Foundation and the Apache Software Foundation, said Cheng. In the long term, as Anthropic and other AI companies face pressure to turn a profit, the program could evolve into a paid service that provides a new revenue stream – if it works well enough for companies to keep using it.

Despite its highly public recent clash with the Trump administration, Anthropic also said in the release that it has been in “ongoing discussions with US government officials about Claude Mythos Preview and its offensive and defensive cyber capabilities.” When asked what that meant, Penn confirmed that the company had “briefed senior officials in the US government about Mythos and what it can do,” and that the company is still “committed to working closely with all different levels of government.”

Cheng said that though Anthropic is “engaged with” the government, he declined to speak to exactly who the company had briefed.

 


 

Why won't Anthropic release the Mythos Preview model publicly?
Because the same capability that lets it find and patch vulnerabilities autonomously also lets it write working exploits with no human steering. Releasing it openly would hand attackers a powerful offensive tool, so Anthropic is restricting access to vetted partners and briefing governments while it works out the safety and commercial model.

Related Posts

Leave a comment

Pin It on Pinterest

Share This