Tired of ads? Enjoy an ad-free experience by signing up.
👩‍🍳 How we use AI at Tech in Asia, thoughtfully and responsibly.
🧔‍♂️ A friendly human may check it before it goes live. More news here

Anthropic taps Big Tech to probe unreleased Mythos AI

Anthropic is forming an initiative called Project Glasswing with Amazon, Apple, Microsoft, Cisco, and other groups to give them access to its unreleased Mythos model, a general-purpose AI system designed to identify complex software vulnerabilities.

The program will give participants early access to the model to uncover security flaws and help shape safeguards before any broader rollout.

Anthropic said it does not yet plan to release Mythos publicly and will use feedback from the initiative as concerns grow that more powerful AI systems could be misused to exploit software weaknesses.

The company said Mythos has already identified long-standing vulnerabilities, including a 27-year-old bug in critical internet software and a 16-year-old issue in video game code that automated tools had missed.

Anthropic also said it has discussed the model with US officials, following an earlier leak that revealed its existence.

🔗 Source: Bloomberg

🧠 Food for thought

Implications, context, and why it matters.

### This model doesn’t just find flaws, it writes the exploits

  • Earlier AI tools mostly spotted vulnerabilities. Mythos Preview can sometimes produce working exploit code that uses a security flaw 1.
  • It built a multi-step remote code execution exploit for a 17-year-old bug in FreeBSD’s Network File System (NFS) server. It gained full administrative control without logging in first 1.
  • Anthropic’s team automated a complex Linux kernel privilege-escalation exploit chain in under a day for less than $2,000 1.
  • Anthropic says these hacking skills came as a side effect of broader coding and reasoning ability. The company did not train Mythos Preview specifically for offensive hacking 1.

### A new arms race is raising questions for cybersecurity markets and response timelines

  • After Fortune’s March report on the unreleased model, shares of several cybersecurity companies including CrowdStrike and Palo Alto Networks fell 5% to 11% 2.
  • Investors appear worried that stronger AI could reduce demand for some established cybersecurity products. It can automate advanced vulnerability research and exploit development usually done by top human researchers 2.
  • CrowdStrike’s CTO (CTO) said AI can cut the gap between discovery and active exploitation from months to minutes 3.
  • Anthropic says it has held ongoing talks with US government officials about Mythos Preview’s offensive and defensive cyber capabilities. It also warned that these capabilities could spread beyond groups committed to safe deployment 3.

Stay ahead in Asia’s tech landscape

You've reached your 2 free content limit for the month. Sign up for free to read the full story.

🏄 For casual readers / 👶 Free

Basic

US$0

Free forever

Get instant access to this article and more every month

0 premium content

Unlimited news briefs

5

5 articles

Ad-free reading experience

Just US$0 per day

⌛Sign up in 20s. No payment details needed.

📖 For learners / 👍 Starter

Lite

US$4.92/month

Billed annually at US$59/year

Get instant access to this article and more every month

4

4 premium content

Unlimited news briefs & articles

Ad-free reading experience

Just US$0.17 per day

Cancel anytime

Our subscriber community includes professionals from these companies:

Stay updated on the go with our mobile app.

Get latest insights with smoother, more personalized experience through TIA mobile app.