Tired of ads? Enjoy an ad-free experience by signing up.
👩‍🍳 How we use AI at Tech in Asia, thoughtfully and responsibly.
🧔‍♂️ A friendly human may check it before it goes live. More news here

India warns of cyber risks as Anthropic AI speeds attacks

Anthropic’s Mythos AI is compressing the gap between finding software flaws and exploiting them, prompting India’s cybersecurity agency to issue a high-severity advisory.

The agency said can turn bugs into attacks in minutes while many Indian firms take 60 to 90 days to patch systems.

Palo Alto Networks’ Unit 42 and Check Point said Mythos found tens of thousands of vulnerabilities versus about 500 in Anthropic’s earlier Opus 4.6 model.

It breached defences on the first try in 83 of 100 cases.

No Indian companies were in the program, and Nasscom has asked Anthropic to include them.

The Ministry of Electronics and Information Technology is reportedly discussing early access amid concerns over risks to banking, telecom, power, and rail systems.

🔗 Source: The Economic Times

🧠 Food for thought

Implications, context, and why it matters.

Why tech rivals are teaming up around an AI that can find software flaws and help exploit them

  • Anthropic’s Project Glasswing brings together Amazon Web Services, Apple, Google, Microsoft, and other companies 1.
  • The group centers on Claude Mythos Preview, an unreleased model that Anthropic says can spot software vulnerabilities and sometimes build exploits for them at high speed and scale 1.
  • Anthropic says the model found bugs that escaped decades of human review and millions of automated security checks 1.
  • In one case, Mythos Preview found a 27-year-old flaw in OpenBSD, an open-source operating system built with security in mind. Anthropic reported it to the maintainers, and the bug is now patched 1.
  • That mix of discovery and exploitation has led some observers to treat Project Glasswing and Mythos as urgent 2.

AI could make finding bugs cheaper while leaving fixes as the hard part

  • Some analysts argue Mythos could upend security pricing by making bug discovery far less scarce. Traditional penetration tests often cost US$20,000 to US$120,000 2.
  • That would move the pressure to remediation work such as ranking issues, fixing them safely, and rolling out patches at scale. The strain could hit open-source projects run by small volunteer teams hardest 2.
  • Forrester, a research and advisory firm, argues the Common Vulnerabilities and Exposures (CVE) system could buckle under the volume 2. CVE is a widely used catalog of public software flaws. The strain could appear as months-long enrichment backlogs 2.
  • Some analysts also expect nation-state cyber strategy to shift from stockpiling zero-days, previously unknown software flaws, to racing to use them before rivals do 2.

Recent Anthropic developments

Stay ahead in Asia’s tech landscape

You've reached your 2 free content limit for the month. Sign up for free to read the full story.

🏄 For casual readers / 👶 Free

Basic

US$0

Free forever

Get instant access to this article and more every month

0 premium content

Unlimited news briefs

5

5 articles

Ad-free reading experience

Just US$0 per day

⌛Sign up in 20s. No payment details needed.

📖 For learners / 👍 Starter

Lite

US$4.92/month

Billed annually at US$59/year

Get instant access to this article and more every month

4

4 premium content

Unlimited news briefs & articles

Ad-free reading experience

Just US$0.17 per day

Cancel anytime

Our subscriber community includes professionals from these companies:

Stay updated on the go with our mobile app.

Get latest insights with smoother, more personalized experience through TIA mobile app.