Brief IA

Anthropic and Mythos: The AI That Concerns Global Cybersecurity

🤖 Models & LLM·Tom Levy·

Anthropic and Mythos: The AI That Concerns Global Cybersecurity

Anthropic and Mythos: The AI That Concerns Global Cybersecurity
Key Takeaways
1Anthropic has unveiled Claude Mythos Preview, an AI model deemed too dangerous for the public due to its advanced capabilities.
2The Project Glasswing, launched with 40 tech giants, aims to address critical vulnerabilities detected by Mythos.
3Anthropic has discovered major flaws in OpenBSD and FFmpeg, which have gone undetected for years.
💡Why it mattersThe security of critical infrastructures is threatened by AIs capable of exploiting vulnerabilities on a large scale.
Le brief IA que lisent les pros

Le brief IA que les pros lisent chaque soir

Les 7 actus IA du jour, décryptées en 5 min. Gratuit.

Inclus dès l'inscription : notre sélection des meilleurs guides & comparatifs IA.

Choisis ton rythme

Gratuit · Pas de spam · Désabonnement en 1 clic

📄
Full Analysis

Two weeks ago, an unexpected revelation shook the cybersecurity world. Anthropic, a leading company in artificial intelligence, accidentally leaked information about its most powerful AI model to date: Claude Mythos Preview. This model, described as a "radical shift" in AI performance, was unveiled following a human error and a misconfiguration of a content management system. According to a leaked blog post, Mythos poses serious cybersecurity risks, heralding a new era of models capable of exploiting vulnerabilities in a far more sophisticated manner than current efforts by defenders.

The following Tuesday, Anthropic officially announced the launch of Mythos, accompanied by Project Glasswing. This ambitious project brings together more than 40 of the world's largest tech companies, including Apple, Google, Microsoft, Cisco, and Broadcom. The goal is to provide early access to the model to identify and fix vulnerabilities in numerous critical systems. Participating companies are tasked with scanning and correcting their own systems as well as critical open-source systems that underpin modern digital infrastructure. To encourage this collaboration, Anthropic is offering $100 million in usage credits for Mythos and donating $4 million to open-source security efforts.

However, this technological advancement raises major concerns. Anthropic, one of the three leading AI labs in the world, has created a model it considers too dangerous to be released to the public. The dangers associated with Mythos do not stem from specialized cybersecurity training, but from the same general improvements that all other labs are currently pursuing. This means that models with similar capabilities could soon be accessible to criminals, hackers, and nation-states, or even more broadly through open-source models.

Anthropic has already found that its Mythos model has discovered thousands of high-severity vulnerabilities in every major operating system and web browser, and in many cases, has developed associated exploits. Among the most notable discoveries is a vulnerability in OpenBSD, a security-focused open-source operating system, which had gone undetected for 27 years. Additionally, a flaw in the FFmpeg video encoder, which had escaped detection during 5 million previous automated tests, was identified. Finally, several vulnerabilities in the Linux kernel were discovered, which could be exploited to gain complete control over a user's machine.

In a statement, Anthropic emphasized that "given the pace of AI advancements, it won't be long before such capabilities spread, potentially beyond actors committed to deploying them safely." The consequences could be severe for economies, public safety, and national security. Project Glasswing is an urgent attempt to put these capabilities to the service of defense.

A video accompanying the announcement shows Anthropic researchers explaining that Mythos is particularly dangerous due to its advanced reasoning capabilities. Unlike current models that can identify high-severity vulnerabilities, Mythos is capable of identifying multiple distinct vulnerabilities in a single piece of software and chaining them together to create a new, particularly dangerous attack. Coupled with the growing ability of models to operate unsupervised for extended periods, Anthropic stated that we have reached a tipping point in cybersecurity risks.

AI labs have often been criticized for making alarming statements about the dangers posed by their own work, which can seem like a strange new form of marketing. For this reason, as well as the fact that my fiancé works at Anthropic, I wanted to know what other cybersecurity experts thought about the announcement of Mythos.

Alex Stamos, product director at the cybersecurity company Corridor, stated that Glasswing is "a big deal, and really necessary." Stamos, who previously led security at Facebook and Yahoo, added: "We have about six months before open-weight models catch up to baseline models in bug detection. At that point, every ransomware actor will be able to find and exploit bugs without leaving traces for law enforcement to track (and at minimal cost)."

Stamos's sentiments were widely shared by participants in Glasswing. Anthony Grieco, head of security and trust at Cisco, stated in a statement accompanying the announcement that "AI capabilities have crossed a threshold that fundamentally changes the urgency required to protect critical infrastructure from cyber threats, and there is no turning back."

If critical infrastructure is indeed at risk, as Grieco suggests, one would hope that the U.S. government pays attention. Unfortunately, the U.S. government attempted to declare Anthropic a supply chain risk after the company refused to modify its contract with the Pentagon to allow for mass domestic surveillance and fully autonomous weapons. A judge blocked this designation while the case is being litigated.

Anthropic informed U.S. government officials about the offensive and defensive capabilities of Mythos before launching Project Glasswing. This includes the Cybersecurity and Infrastructure Security Agency and the Center for AI Standards and Innovation, which works with industry to test new models and assess them for security risks. However, it is unclear whether the government is accepting Anthropic's offer to help evaluate Mythos.

A functional government should closely monitor what Anthropic is doing here, if only out of self-preservation. We simply do not know if Project Glasswing will be sufficient to protect critical systems from breaches — and for how long.

Alex Stamos outlined two possible scenarios: "The optimistic timeline is that we are one step beyond human capabilities, and that means there is a huge but finite reservoir of defects that can be found and fixed." In contrast, "the pessimistic timeline is that with each new release, there will be new classes of defects that we have never even imagined. It is hard to predict, as we are trying to model superhuman thought."

For now, one could argue that Project Glasswing represents the application of Anthropic's founding thesis. The reason the company set out to build cutting-edge AI models was that a safety-focused lab would be the first to encounter the most dangerous capabilities — and could pave the way for their mitigation. With Mythos, this seems to be exactly what is happening.

At the same time, Glasswing rests on a deeply uncomfortable principle — that the only way to protect ourselves from dangerous AI models is to build them first. And Anthropic is doing this in a barely regulated environment, almost at the insistence of the Trump administration.

One effect of this is to centralize power. Kelsey Piper observed today about Mythos: "a private company now possesses incredibly powerful zero-day exploits from almost every software project you've heard of." Another effect is to centralize risk: among other things, the incentives to steal Anthropic's model weights have just increased significantly.

All of this is unlikely to make AI more popular in a country that seems to be turning against it. Surveys show that people are demanding more control over the use of AI and stronger guarantees regarding it. As the story of Project Glasswing unfolds, we may regret not having started this work much earlier.

Brief IA — L'actualité IA en français

L'essentiel de l'actualité de l'intelligence artificielle, décrypté et expliqué chaque jour.