Anthropic says last week it began letting Mythos users responsibly share cybersecurity threats with others who face similar vulnerabilities, changing its stance
How to restrict access while still allowing users to share threat information is a major challenge facing AI companies
Wall Street JournalAmrith Ramkumar
Context & Ripple Effects
Related coverage shows Anthropic has been managing Mythos access cautiously: a wider release was reportedly delayed by serving reliability concerns, while unauthorized access through a private Discord channel raised control questions. The new sharing policy changes how information can move among authorized users, not simply who can use the model.
That matters because Mythos is also associated with increased bug-report volume for open-source maintainers. Anthropic is therefore navigating a trade-off between restricting a security-capable system and enabling defenders to distribute actionable threat information.
First-order effects
Mythos users can now pass relevant cybersecurity threats to peers facing similar vulnerabilities, accelerating coordination among affected defenders.
Anthropic assumes a more active role in setting the rules and safeguards for threat-information sharing after previously limiting that pathway.
Second-order effects
Organizations using Mythos may receive more reports and remediation work as shared findings reach additional affected projects and maintainers.
The policy raises the operational importance of access controls, recipient matching, and abuse monitoring, particularly given prior reports of unauthorized Mythos access.
Third-order effects
If other AI providers adopt similar controlled-sharing models, cybersecurity AI deployment may increasingly be governed by differentiated access and disclosure rules rather than a simple open-versus-closed choice.
The pattern could sharpen pressure for AI-safety frameworks that account for both misuse prevention and the defensive value of rapid vulnerability disclosure.
The trend: This is one data point in the shift from blanket restrictions on advanced AI security capabilities toward tightly managed use cases that preserve defensive coordination.
This, 1M% this: “The principle is to make exploitation harder for an attacker even when a bug exists, so that the gap between when a vulnerability is disclosed and when it is patched matters less. That means defenses that sit in front of the application and block the bug from
i read it and thought these 2 main points were interesting: 1. Mythos vs other frontier models - Frontier models could find a lot of the individual bugs, but a lot of cyber attacks use multiple small bugs chained together. Frontier models weren't that good at piecing these smal…
“Well, the great researchers are submitting world class reports assisted by AI at an even greater pace, and the less skilled researchers are polluting the triage queue with genuinely unimportant vulnerability reports”😉
This is the kind of conversation we need, not idiotic ones about the end of all software... it can't just be patching the 100 or so projects that got access to Project Glasswing. That is not gonna help the world... In the long run, AI will make software more secure, not less. B…
Reading this, the bun rewrite to rust makes much more sense. My guess: Mythos looked at bun and had a shit fit - generated a deluge of vulnerabilities and memory bugs so vast and profound that they would be effectively impossible to fix in zig. Anthropic looked at the report an…
I'm preaching you need to sprint to do the basics and do them well to help defend against AIs like Mythos. This is crap we should have done 20 years ago, but ran to the “next-gen” products thinking it would save us.
Great write-up from @cloudflare on how they chain Mythos agents together into a useful harness. A lot of lessons in there apply well beyond just vulnerability scanning. The adversarial review by other agents (and models) works great on code investigations and reviews too.
Nice write up from the Cloudflare team, but the post here is misleading. Patch faster is not the wrong answer, because most teams are patching on the order of weeks or months. You must patch faster than that right now. But I will agree that 2 hours is infeasible beyond the
It's really funny watching companies learn things like patching at high velocity isn't a cybersecurity silver bullet The state of cybersecurity is so bad in tech today, they're recreating defense in depth from first principles
Amazing post. Giving LLM's narrow tasks, and composing those as lego blocks gives much better results than “just ask the model”. great example of what the lego blocks & composition look like for a security scanner.
A must read. One thought: Does AI flip the OSS security tradeoff? OSS was pitched as more “good eyeballs” on your code, catching bugs before “bad eyeballs” do. But now devs get eyeballs from AI. Maybe closed source makes sense, to starve the bad eyeballs. @thegrugq @ImposeCost
Mythos and other frontier models, pointed at live code across critical Cloudflare infrastructure. An honest read on what's working and what comes next. https://blog.cloudflare.com/ ...
“Mythos Preview is a real step forward, and it's worth saying that plainly before getting into anything else. We've been running models against our code for a while now, and the jump from what was possible with previous general-purpose frontier models to what Mythos Preview does
Cloudflare is right about this. You're not going to be able to patch fast enough, but you can build your systems so that the vast majority of vulnerabilities don't matter. If you've not done that, you're going to have a bad time. [image]
Cloudflare's security team spent the last few weeks testing Anthropic's Mythos against fifty of our own repositories. What we learned about offensive AI, why faster patching is the wrong reaction, and what the architecture around vulnerabilities has to look like next.
AI has officially entered its “Senior Security Researcher” era. Cloudflare's security team recently spent weeks testing Anthropic's new Mythos Preview against 50+ of their own code repositories. …
“Anthropic has agreed to brief leading finance ministries and central banks on vulnerabilities in the global financial system's cyber defences identified by the US technology company's latest AI model.”