<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[I’ve had a bunch of people ask my thoughts on Anthropic’s Mythos.]]></title><description><![CDATA[<p>I’ve had a bunch of people ask my thoughts on Anthropic’s Mythos. I’ve read the research paper they released and the numbers, and basically I agree with <span><a href="https://infosec.exchange/@malwaretech">@<span>malwaretech</span></a></span>’s take. It’s marketing. The cybersecurity industry is historically very good at marketing cyber pearl harbour and the need to buy magic boxes.</p>]]></description><link>https://forum.fedi.dk/topic/949ae041-0212-4073-acf8-6b044576c352/i-ve-had-a-bunch-of-people-ask-my-thoughts-on-anthropic-s-mythos.</link><generator>RSS for Node</generator><lastBuildDate>Fri, 17 Apr 2026 14:27:13 GMT</lastBuildDate><atom:link href="https://forum.fedi.dk/topic/949ae041-0212-4073-acf8-6b044576c352.rss" rel="self" type="application/rss+xml"/><pubDate>Sun, 12 Apr 2026 09:16:31 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to I’ve had a bunch of people ask my thoughts on Anthropic’s Mythos. on Sun, 12 Apr 2026 11:13:54 GMT]]></title><description><![CDATA[<p><span><a href="/user/gossithedog%40cyberplace.social" rel="nofollow noopener">@<span>GossiTheDog</span></a></span> <span><a href="https://infosec.exchange/@malwaretech" rel="nofollow noopener">@<span>malwaretech</span></a></span> </p><p>"I heard there is some cool AI tech now that solves all cybersecurity problems."</p><p>"No, that's just a mythos."</p>]]></description><link>https://forum.fedi.dk/post/https://tech.lgbt/users/wakame/statuses/116391440164938749</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://tech.lgbt/users/wakame/statuses/116391440164938749</guid><dc:creator><![CDATA[wakame@tech.lgbt]]></dc:creator><pubDate>Sun, 12 Apr 2026 11:13:54 GMT</pubDate></item><item><title><![CDATA[Reply to I’ve had a bunch of people ask my thoughts on Anthropic’s Mythos. on Sun, 12 Apr 2026 11:02:40 GMT]]></title><description><![CDATA[<p><span><a href="/user/gossithedog%40cyberplace.social" rel="nofollow noopener">@<span>GossiTheDog</span></a></span> </p><p>Yes, we do watch videos! <img src="https://forum.fedi.dk/assets/plugins/nodebb-plugin-emoji/emoji/android/1f914.png?v=94543ec6bc6" class="not-responsive emoji emoji-android emoji--thinking_face" style="height:23px;width:auto;vertical-align:middle" title="🤔" alt="🤔" /></p>]]></description><link>https://forum.fedi.dk/post/https://infosec.exchange/users/simonzerafa/statuses/116391396026239218</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://infosec.exchange/users/simonzerafa/statuses/116391396026239218</guid><dc:creator><![CDATA[simonzerafa@infosec.exchange]]></dc:creator><pubDate>Sun, 12 Apr 2026 11:02:40 GMT</pubDate></item><item><title><![CDATA[Reply to I’ve had a bunch of people ask my thoughts on Anthropic’s Mythos. on Sun, 12 Apr 2026 10:58:48 GMT]]></title><description><![CDATA[<p><span><a href="/user/gossithedog%40cyberplace.social">@<span>GossiTheDog</span></a></span> They aren't claiming it's over, that's a strawman. But interestingly they are providing commit hashes of things they've found. Some of these are seriously scary. I've saved a copy of the webpage and will be waiting to see if the promised commits turn up. If they do check out my opinion of Anthropic will rise. If not...</p>]]></description><link>https://forum.fedi.dk/post/https://fosstodon.org/users/trademark/statuses/116391380825114601</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://fosstodon.org/users/trademark/statuses/116391380825114601</guid><dc:creator><![CDATA[trademark@fosstodon.org]]></dc:creator><pubDate>Sun, 12 Apr 2026 10:58:48 GMT</pubDate></item><item><title><![CDATA[Reply to I’ve had a bunch of people ask my thoughts on Anthropic’s Mythos. on Sun, 12 Apr 2026 10:47:28 GMT]]></title><description><![CDATA[<p><span><a href="/user/gossithedog%40cyberplace.social">@<span>GossiTheDog</span></a></span> he makes a good point about the subsidized cost. It's like in the early days when Uber was cheap AF to put the taxis out of business. Once they had market share, they cost as much as taxis.</p>]]></description><link>https://forum.fedi.dk/post/https://infosec.exchange/users/mikesiegel/statuses/116391336219876431</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://infosec.exchange/users/mikesiegel/statuses/116391336219876431</guid><dc:creator><![CDATA[mikesiegel@infosec.exchange]]></dc:creator><pubDate>Sun, 12 Apr 2026 10:47:28 GMT</pubDate></item><item><title><![CDATA[Reply to I’ve had a bunch of people ask my thoughts on Anthropic’s Mythos. on Sun, 12 Apr 2026 10:47:15 GMT]]></title><description><![CDATA[<p><span><a href="/user/bontchev%40infosec.exchange">@<span>bontchev</span></a></span> <span><a href="/user/gossithedog%40cyberplace.social">@<span>GossiTheDog</span></a></span> Agreed. Current recommendation from our end: </p><p>Keep calm, find and fix bugs, make the world a bit safer one bug at a time... </p><p>And ignore the hype train, but keep an open eye on how real and measurable things develop. Just what we did before.</p>]]></description><link>https://forum.fedi.dk/post/https://infosec.exchange/users/cure53/statuses/116391335411980405</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://infosec.exchange/users/cure53/statuses/116391335411980405</guid><dc:creator><![CDATA[cure53@infosec.exchange]]></dc:creator><pubDate>Sun, 12 Apr 2026 10:47:15 GMT</pubDate></item><item><title><![CDATA[Reply to I’ve had a bunch of people ask my thoughts on Anthropic’s Mythos. on Sun, 12 Apr 2026 10:40:46 GMT]]></title><description><![CDATA[<p><span><a href="https://infosec.exchange/@cure53">@<span>cure53</span></a></span> </p><p>I know. I've been done that. I was the only technician that talked to the compliance people so I "earned" all of the work involved in communicating and bridging both worlds.</p><p>And since then it just got worse. Nobody cares about it security. The compliance people are just writing some shit and at this point in many companies they don't even expect their technicians to actually implement it anymore either (if it is even possible at all).</p><p>It's just a work creation measure at this point…</p>]]></description><link>https://forum.fedi.dk/post/https://chaos.social/users/agowa338/statuses/116391309897378039</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://chaos.social/users/agowa338/statuses/116391309897378039</guid><dc:creator><![CDATA[agowa338@chaos.social]]></dc:creator><pubDate>Sun, 12 Apr 2026 10:40:46 GMT</pubDate></item><item><title><![CDATA[Reply to I’ve had a bunch of people ask my thoughts on Anthropic’s Mythos. on Sun, 12 Apr 2026 10:38:24 GMT]]></title><description><![CDATA[<p><span><a href="/user/gossithedog%40cyberplace.social">@<span>GossiTheDog</span></a></span> but other than that... yeah hype-marketing playbook 101.</p><p>Didn't OpenAI pull the:"oh no it's too powerful, humanity couldn't take it yet so we're not releasing it to the public", stunt with one of their earlier models as well?^^</p>]]></description><link>https://forum.fedi.dk/post/https://ioc.exchange/users/wall_e/statuses/116391300591827373</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://ioc.exchange/users/wall_e/statuses/116391300591827373</guid><dc:creator><![CDATA[wall_e@ioc.exchange]]></dc:creator><pubDate>Sun, 12 Apr 2026 10:38:24 GMT</pubDate></item><item><title><![CDATA[Reply to I’ve had a bunch of people ask my thoughts on Anthropic’s Mythos. on Sun, 12 Apr 2026 10:38:19 GMT]]></title><description><![CDATA[<p><span><a href="/user/agowa338%40chaos.social">@<span>agowa338</span></a></span> Cyber security is an insanely complex beast with some parts being technical, some being human, some being regulatory, etc., and well, finding bugs is one small component. </p><p>Emphasis on small.</p><p>We have not really been great at cyber security in the past, and improvements are needed all across the board. We won't be great at it tomorrow because magic.</p><p>Having one component potentially improve is, especially given how speculative the current situation is, is nothing to really worry about. Rather the contrary.</p><p>Time will tell, some processes might change, and that is likely all that will happen for a long time.</p><p>Most humans in cyber security will very likely notice very little impact for now. Can this all go sideways? Yes, of course. Is it time to say that cyber security is over? I don't think so. At all.</p>]]></description><link>https://forum.fedi.dk/post/https://infosec.exchange/users/cure53/statuses/116391300285664494</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://infosec.exchange/users/cure53/statuses/116391300285664494</guid><dc:creator><![CDATA[cure53@infosec.exchange]]></dc:creator><pubDate>Sun, 12 Apr 2026 10:38:19 GMT</pubDate></item><item><title><![CDATA[Reply to I’ve had a bunch of people ask my thoughts on Anthropic’s Mythos. on Sun, 12 Apr 2026 10:31:54 GMT]]></title><description><![CDATA[<p><span><a href="/user/gossithedog%40cyberplace.social">@<span>GossiTheDog</span></a></span> to be fair, the current time to poc is in many cases already down ≤ 1 day or so, but this could take some of the skill out of it and make it more broadly available</p>]]></description><link>https://forum.fedi.dk/post/https://ioc.exchange/users/wall_e/statuses/116391275016075400</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://ioc.exchange/users/wall_e/statuses/116391275016075400</guid><dc:creator><![CDATA[wall_e@ioc.exchange]]></dc:creator><pubDate>Sun, 12 Apr 2026 10:31:54 GMT</pubDate></item><item><title><![CDATA[Reply to I’ve had a bunch of people ask my thoughts on Anthropic’s Mythos. on Sun, 12 Apr 2026 10:30:39 GMT]]></title><description><![CDATA[<p><span><a href="/user/gossithedog%40cyberplace.social">@<span>GossiTheDog</span></a></span> Haven't we already been there with fuzzing?</p><p>Anyway, even if Mythos is as good as they claim, that's not really a problem as long as it is available only to a few. It's when every script kiddie gets access to it that we should start worrying.</p>]]></description><link>https://forum.fedi.dk/post/https://infosec.exchange/users/bontchev/statuses/116391270119487375</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://infosec.exchange/users/bontchev/statuses/116391270119487375</guid><dc:creator><![CDATA[bontchev@infosec.exchange]]></dc:creator><pubDate>Sun, 12 Apr 2026 10:30:39 GMT</pubDate></item><item><title><![CDATA[Reply to I’ve had a bunch of people ask my thoughts on Anthropic’s Mythos. on Sun, 12 Apr 2026 10:27:52 GMT]]></title><description><![CDATA[<p><span><a href="/user/gossithedog%40cyberplace.social">@<span>GossiTheDog</span></a></span> <span><a href="https://infosec.exchange/@malwaretech">@<span>malwaretech</span></a></span> The number of people who should know better just going "*this time* the PR blather is true, I just know it!" is pretty cringe.</p>]]></description><link>https://forum.fedi.dk/post/https://mefi.social/users/Pyrogenesis/statuses/116391259165160897</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://mefi.social/users/Pyrogenesis/statuses/116391259165160897</guid><dc:creator><![CDATA[pyrogenesis@mefi.social]]></dc:creator><pubDate>Sun, 12 Apr 2026 10:27:52 GMT</pubDate></item><item><title><![CDATA[Reply to I’ve had a bunch of people ask my thoughts on Anthropic’s Mythos. on Sun, 12 Apr 2026 10:27:30 GMT]]></title><description><![CDATA[<p><span><a href="/user/gossithedog%40cyberplace.social">@<span>GossiTheDog</span></a></span> from a practical perspective what worries me more is time to poc/working exploit for known vulns. </p><p>OSS library releases patch, model looks at diff + cve description and drops a working exploit for a couple of hundred $ of compute.</p><p>Most companies (at least this side of the pond) are not currently equipped to deal with continuously applying patches for 1-day vulns in prod.<br />Many large orgs here are proud that they've managed to get on a monthly update cycle</p>]]></description><link>https://forum.fedi.dk/post/https://ioc.exchange/users/wall_e/statuses/116391257741903511</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://ioc.exchange/users/wall_e/statuses/116391257741903511</guid><dc:creator><![CDATA[wall_e@ioc.exchange]]></dc:creator><pubDate>Sun, 12 Apr 2026 10:27:30 GMT</pubDate></item><item><title><![CDATA[Reply to I’ve had a bunch of people ask my thoughts on Anthropic’s Mythos. on Sun, 12 Apr 2026 10:22:49 GMT]]></title><description><![CDATA[<p><span><a href="/user/gossithedog%40cyberplace.social">@<span>GossiTheDog</span></a></span> </p><p>Well cybersecurity is over but not because of this but because of everyone and their mother deploying openclaw in production...</p>]]></description><link>https://forum.fedi.dk/post/https://chaos.social/users/agowa338/statuses/116391239345054570</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://chaos.social/users/agowa338/statuses/116391239345054570</guid><dc:creator><![CDATA[agowa338@chaos.social]]></dc:creator><pubDate>Sun, 12 Apr 2026 10:22:49 GMT</pubDate></item><item><title><![CDATA[Reply to I’ve had a bunch of people ask my thoughts on Anthropic’s Mythos. on Sun, 12 Apr 2026 10:17:17 GMT]]></title><description><![CDATA[<p>Anthropic set the project across open source projects and provided access and reported the vulns.  Typically, you'd expect to see NCSCs spinning up advisories to patch high impact vulns, CISA telling orgs to patch etc etc etc.</p><p>What's actually happening is... uhm...  a whole heap of nothing but people copy and pasting marketing about how cybersecurity is over.</p><p>It's not though, is it?</p>]]></description><link>https://forum.fedi.dk/post/https://cyberplace.social/users/GossiTheDog/statuses/116391217544017059</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://cyberplace.social/users/GossiTheDog/statuses/116391217544017059</guid><dc:creator><![CDATA[gossithedog@cyberplace.social]]></dc:creator><pubDate>Sun, 12 Apr 2026 10:17:17 GMT</pubDate></item><item><title><![CDATA[Reply to I’ve had a bunch of people ask my thoughts on Anthropic’s Mythos. on Sun, 12 Apr 2026 10:10:19 GMT]]></title><description><![CDATA[<p>I don't think anybody actually watches videos any more, so here's MWT's core point - </p><p>The flagship and lead vuln in the research is a BSD vuln, it cost $20k to discover with Mythos.  Anthropic only reached a crash, and the vuln class in 99%+ cases never reaches RCE, just crashes.</p><p>So.. cool.. you spent $20k of VC money to find a crash as the flagship vuln.  But... uhm...  that isn't the end of the world.</p><p>The proof is going to be if any of the open source vulns turn out to be important. So far:</p>]]></description><link>https://forum.fedi.dk/post/https://cyberplace.social/users/GossiTheDog/statuses/116391190189575518</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://cyberplace.social/users/GossiTheDog/statuses/116391190189575518</guid><dc:creator><![CDATA[gossithedog@cyberplace.social]]></dc:creator><pubDate>Sun, 12 Apr 2026 10:10:19 GMT</pubDate></item><item><title><![CDATA[Reply to I’ve had a bunch of people ask my thoughts on Anthropic’s Mythos. on Sun, 12 Apr 2026 10:08:44 GMT]]></title><description><![CDATA[<p><span><a href="/user/gossithedog%40cyberplace.social">@<span>GossiTheDog</span></a></span> <span><a href="https://infosec.exchange/@malwaretech">@<span>malwaretech</span></a></span> <span><a href="/user/steltenpower%40social.edu.nl">@<span>steltenpower</span></a></span> Well, well, well. Our old friends Fear, Uncertainty and Doubt <img src="https://forum.fedi.dk/assets/plugins/nodebb-plugin-emoji/emoji/android/1f60f.png?v=94543ec6bc6" class="not-responsive emoji emoji-android emoji--smirk" style="height:23px;width:auto;vertical-align:middle" title="😏" alt="😏" /></p>]]></description><link>https://forum.fedi.dk/post/https://mastodon.nl/users/sandorspruit/statuses/116391183950861394</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://mastodon.nl/users/sandorspruit/statuses/116391183950861394</guid><dc:creator><![CDATA[sandorspruit@mastodon.nl]]></dc:creator><pubDate>Sun, 12 Apr 2026 10:08:44 GMT</pubDate></item><item><title><![CDATA[Reply to I’ve had a bunch of people ask my thoughts on Anthropic’s Mythos. on Sun, 12 Apr 2026 09:53:55 GMT]]></title><description><![CDATA[<p><span><a href="/user/gossithedog%40cyberplace.social">@<span>GossiTheDog</span></a></span> <br />Hello, I'm Ibrahim from Gaza. I have Down syndrome and anemia. Please help me. Even small donations make a difference. Please share this pinned post to spread the word.</p>]]></description><link>https://forum.fedi.dk/post/https://mastodon.social/ap/users/116390991274314425/statuses/116391125670778780</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://mastodon.social/ap/users/116390991274314425/statuses/116391125670778780</guid><dc:creator><![CDATA[ibrahimhammad@mastodon.social]]></dc:creator><pubDate>Sun, 12 Apr 2026 09:53:55 GMT</pubDate></item><item><title><![CDATA[Reply to I’ve had a bunch of people ask my thoughts on Anthropic’s Mythos. on Sun, 12 Apr 2026 09:39:23 GMT]]></title><description><![CDATA[<p><span><a href="/user/troed%40swecyb.com" rel="nofollow noreferrer noopener">@<span>troed</span></a></span> <span><a href="/user/gossithedog%40cyberplace.social" rel="nofollow noreferrer noopener">@<span>GossiTheDog</span></a></span> <span><a href="https://infosec.exchange/@malwaretech" rel="nofollow noreferrer noopener">@<span>malwaretech</span></a></span> Everything they actually sent out went through competent human professionals that were well compensated, they prove nothing.</p>]]></description><link>https://forum.fedi.dk/post/https://gts.laalaa.land/users/jinna/statuses/01KP0GYSMJMKCPKW861AP24RZG</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://gts.laalaa.land/users/jinna/statuses/01KP0GYSMJMKCPKW861AP24RZG</guid><dc:creator><![CDATA[jinna@gts.laalaa.land]]></dc:creator><pubDate>Sun, 12 Apr 2026 09:39:23 GMT</pubDate></item><item><title><![CDATA[Reply to I’ve had a bunch of people ask my thoughts on Anthropic’s Mythos. on Sun, 12 Apr 2026 09:29:43 GMT]]></title><description><![CDATA[<p><span><a href="/user/gossithedog%40cyberplace.social">@<span>GossiTheDog</span></a></span> </p><p>I was under the impression that the open source projects they communicated their findings with have confirmed them?</p><p>Stringing together exploits and ROP-chains is what had me take it seriously. It's not that we can't do that as well, it's being able to automate it at scale that's worrying.</p><p>(And that's not a worry about _Mythos_ - we know the open models lag ~1 year behind the cloud models so these capabilities can be expected to be at nation state actors about now and with "everyone" in a year)</p><p><span><a href="https://infosec.exchange/@malwaretech">@<span>malwaretech</span></a></span></p>]]></description><link>https://forum.fedi.dk/post/https://swecyb.com/users/troed/statuses/116391030500616284</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://swecyb.com/users/troed/statuses/116391030500616284</guid><dc:creator><![CDATA[troed@swecyb.com]]></dc:creator><pubDate>Sun, 12 Apr 2026 09:29:43 GMT</pubDate></item><item><title><![CDATA[Reply to I’ve had a bunch of people ask my thoughts on Anthropic’s Mythos. on Sun, 12 Apr 2026 09:23:04 GMT]]></title><description><![CDATA[<p><span><a href="/user/gossithedog%40cyberplace.social" rel="nofollow noopener">@<span>GossiTheDog</span></a></span> <span><a href="https://infosec.exchange/@malwaretech">@<span>malwaretech</span></a></span> </p><p>Aisle (active in this space) did the research backing this up:</p><p><a href="https://aisle.com/blog/ai-cybersecurity-after-mythos-the-jagged-frontier" rel="nofollow noopener"><span>https://</span><span>aisle.com/blog/ai-cybersecurit</span><span>y-after-mythos-the-jagged-frontier</span></a></p>]]></description><link>https://forum.fedi.dk/post/https://infosec.exchange/users/avuko/statuses/116391004340749885</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://infosec.exchange/users/avuko/statuses/116391004340749885</guid><dc:creator><![CDATA[avuko@infosec.exchange]]></dc:creator><pubDate>Sun, 12 Apr 2026 09:23:04 GMT</pubDate></item><item><title><![CDATA[Reply to I’ve had a bunch of people ask my thoughts on Anthropic’s Mythos. on Sun, 12 Apr 2026 09:17:17 GMT]]></title><description><![CDATA[<p>Companion video <a href="https://youtu.be/fM7GIIylXqI" rel="nofollow noopener"><span>https://</span><span>youtu.be/fM7GIIylXqI</span><span></span></a></p>]]></description><link>https://forum.fedi.dk/post/https://cyberplace.social/users/GossiTheDog/statuses/116390981655149769</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://cyberplace.social/users/GossiTheDog/statuses/116390981655149769</guid><dc:creator><![CDATA[gossithedog@cyberplace.social]]></dc:creator><pubDate>Sun, 12 Apr 2026 09:17:17 GMT</pubDate></item></channel></rss>