/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Palo Alto Networks says Mythos found 24+ critical bugs using $1M+ in tokens; Anthropic subsidizes Mythos but some companies plan to boost their Mythos budgets

When Palo Alto Networks earlier this year began testing Anthropic's Claude Mythos to comb through its own source code, it didn't take long to see the future of cybersecurity.

The Information Aaron Holmes

Context & Ripple Effects

Anthropic positioned Mythos Preview as a restricted tool for organizations maintaining critical software after reporting that it had found high-severity vulnerabilities across widely used software. Subsequent coverage says the model can turn disclosed vulnerabilities into working exploits much faster, while CISA is using it to audit government repositories.

Palo Alto Networks' reported results add a concrete enterprise-codebase use case to that arc: Mythos is being used not only to demonstrate vulnerability discovery, but to find critical flaws in a customer's own code despite substantial inference costs.

First-order effects

  • Palo Alto Networks gains a larger queue of critical bugs to validate and remediate, while Anthropic gets a prominent production-style reference point for Mythos's security-auditing value.
  • The reported million-plus-token usage makes model cost an immediate procurement issue; Anthropic's subsidies reduce the near-term barrier, but companies planning larger budgets signal that sustained use will require dedicated spend.

Second-order effects

  • Security teams and software owners evaluating AI-assisted code review will face pressure to test comparable tools, particularly for high-value or critical code, while budgeting shifts from occasional assessments toward ongoing model-driven audits.
  • A faster vulnerability-finding workflow can expand downstream demand for human triage, patching, and remediation capacity; finding more issues does not itself resolve the operational backlog.

Third-order effects

  • If restricted access broadens and reported results prove repeatable, vulnerability discovery may become a continuous, model-assisted capability rather than a periodic specialist exercise—raising both software assurance expectations and the cost of keeping codebases current.
  • The same capability creates a dual-use governance challenge: coverage already indicates Mythos can accelerate exploit development from public disclosures, so access controls and deployment policies may become as consequential as detection performance.

The trend: Mythos is one data point in the shift from AI as a coding assistant to AI as a high-cost, tightly governed security-analysis system that can accelerate both defense and offensive exploitation.

Discussion

  • @amir Amir Efrati on x
    if you think Anthropic revenue is going good, just wait til companies start buying Mythos [image]
  • @luke_metro @luke_metro on x
    we're not ready for the layoffs that companies will do to cover their Mythos bills
  • @edsim Ed Sim on x
    Simply unsustainable to do continuous scanning as more code and code bases than ever before Huge opportunities for security harness engineering to help enterprises get SOTA but cost way less and do more continuous scanning
  • @scaling01 @scaling01 on x
    the permanent underclass is already here, but you just haven't noticed it here's what it looks like: - frontier labs keep their best models to themselves for 1-3 months to make sure it's safe - then they sell the tokens to the US government and trillion dollar companies -