News Stay informed about the latest enterprise technology news and product updates.

Cutting through the Claude Mythos hype: What it means for CISOs

Claude Mythos entered the chat in April, and just a few short months later, it's hard to remember a time when Anthropic's frontier AI model didn't dominate cybersecurity discussions. Yet, plenty of unanswered questions about Mythos remain.

In just a single month, Mythos reportedly exposed more than 10,000 significant security flaws at major tech vendors. Anthropic granted preview access to around 50 organizations under Project Glasswing, saying the model's ability to find previously unknown vulnerabilities made it too dangerous for broad release.

As a result of frontier AI models' ability to find security weaknesses at machine speed, many experts warn that an unprecedented tsunami of vulnerabilities is rolling toward enterprises. Many argue CISOs will need to change their vulnerability management strategies to keep afloat.

In this episode of the Reporters' Notebook video series, journalists from TechTarget Cybersecurity, Dark Reading and Cybersecurity Dive discuss what else we know -- and what we still don't -- about Claude Mythos.

Watch the full discussion now, and check out the following related articles:

Alissa Irei is senior site editor of TechTarget Cybersecurity.

View All Videos
Transcript - Cutting through the Claude Mythos hype: What it means for CISOs

Editor's note: The following transcript has been transcribed and edited for length, clarity and readability by Informa TechTarget's internal AI assistant.

Dark Reading's Alex Culafi: Hello, everybody. Thank you for joining us for the latest installment of Reporters' Notebook, featuring editors and reporters from Cybersecurity Dive, TechTarget Cybersecurity and Dark Reading. I'm Alex Culafi, senior news writer at Dark Reading. I am joined here by:

Cybersecurity Dive's David Jones: David Jones at Cybersecurity Dive.

TechTarget Cybersecurity's Alissa Irei: Alissa Irei, TechTarget Cybersecurity.

Culafi: Today we are here to discuss Anthropic's Claude Mythos AI model and the intense saga that has surrounded it up until this point. Mythos was introduced in preview in April, with Anthropic claiming the large language model is so capable of finding and exploiting vulnerabilities that it could find critical exploits in popular decades-old software on its own.

Because of this supposed danger, the company launched a secondary campaign called Project Glasswing in order to give cybersecurity partners a head start and limit the potential for Mythos to be misused by threat actors. Even under Glasswing, access was restricted and monitored among organizations.

In June, Mythos Preview became Mythos 5 and was released to a larger pool of early-access partners. It was still restricted, but it was introduced alongside Claude Fable 5, a safer, publicly accessible version of Mythos that doesn't do sensitive tasks involving things like cybersecurity, biology, etc.

Soon after -- I think within a day or two of Fable and Mythos going public -- the White House restricted access to Mythos and Fable to non-U.S. nationals, including Anthropic employees, after reports that a jailbreak was able to bypass Fable's guardrails. This temporarily led Anthropic to disable Mythos and Fable access to all users, though a couple weeks later the U.S. government lifted its restriction, and things seem to be mostly back on track.

Many security experts say Mythos is capable of completely altering the security vulnerability landscape and will require organizations to rebuild their security programs from the ground up.

That brings us to our discussion today -- a check-in on how we feel about the Mythos saga to date.

My first question: I want to hear what we all think, but we'll start with you, Dave. What has your overall impression been of the Mythos saga, and what is this story to you?

Jones: Well, I think, generally, my concerns about AI from the start have been there's this tension between the interest in using AI by major companies, governments and critical infrastructure providers to accelerate their capacity to conduct their business, be productive and speed up timelines.

But the problem is that that pressure everybody seems to be under because they don't want to be left behind is getting ahead of the necessary guardrails to make sure they're doing this in a safe and thoughtful manner.

And what tends to happen is when the security guardrails are not there, the people who are tapping others on the shoulder or looking over their shoulder and saying, 'This needs to be dialed back. We need to slow this down,' may not find out until after the cat's out of the bag in terms of what the potential risks are.

Let's say you go out and you find vulnerabilities at an accelerated pace. Somebody's got to prioritize what you focus on first of all. And what do you do when you find something and you have to go out and actually remediate what you found in the first place?

Somebody's got to do the work, and somebody's got to let folks know, 'OK, we've got several thousand vulnerabilities that we found in a given time frame. Where do you start? What's the most important thing? How are you going to make sure you know what should be prioritized?'

If you don't have that thought out properly, you're just going to have a lot of people doing a lot of busy work and not really understanding what they're doing. The fire is going to start spreading, and where do you start to put it out?

Irei: I would agree with that. I think so far, the technology and the risk of AI seem to be amplifying existing problems, like, to Dave's point, vulnerability management, patch management, existing risk exposure, identity and access management, and trust.

How do we not only make sure that human users are accessing only the assets they need to do their jobs, but also now the agentic AI users?

As for the big-picture, what's-to-come angle, I think it's anybody's guess. The optimistic part of me thinks maybe this will help defenders because while there is this incoming tsunami of vulnerabilities that's already starting to arrive, it also seems possible that the same technology, deployed in a defensive capacity, could help with vulnerability management and prioritizing remediations and patches in a more strategic way than human operators have been able to do so far.

We know that security teams are so overworked, understaffed and stretched thin, and that was true before AI. So I'm hopeful. I don't know that I think this is going to happen, but best-case scenario, those teams can use AI in a way that makes enterprises safer.

Of course, the threat actors also have access to a lot of this technology, even if not the actual Mythos model yet.

Alex, what are your thoughts?

Culafi: A fundamental distrust of the B2B space makes me very skeptical any time anyone says anything about Mythos.

Because we're in the B2B space, everyone is trying to make money and push a certain agenda, which is fine. We know the space we're in. Everyone's trying to make money, but also possibly have the best security solutions.

It doesn't surprise me that AI is doing some of the things that Mythos describes because I went to DEF CON last year, and DARPA, for the last two or three years, has been building out -- or fostering younger talent and newer talent -- to basically develop AI vulnerability discovery capability. So this type of stuff has been in the works for a while.

If there's, let's say, a precipice we're going to go over, that doesn't surprise me so much, whether it's Anthropic or someone else.

The parts that I distrust or am skeptical about are that I'm still not fully clear on exactly how powerful this is, other than Anthropic's own blog posts. That's kind of interesting, right?

The other thing is, OK, let's say AI can do this stuff where it can find critical vulnerabilities through natural language prompting. Is Mythos really the only one that can do that? Are some of these Chinese models capable of doing that?

What I'm hearing is that some of these Chinese models -- some of the competitors -- are behind Mythos, but maybe six months behind Mythos. This sort of technology isn't really going to stay with Anthropic if it's only Anthropic right now.

So, I look at the White House ban and all this other stuff happening, and part of me wants to have the knee-jerk reaction that they're overselling it. They're doing their B2B thing and engaging in a little business-motivated fearmongering.

On the other hand, I'm like, if it's not there yet, I think it's going to be there soon. I don't know. Do you guys agree with me or no?

Irei: I think you make really good points because, on the one hand, we've been expecting this news from, to your point, any AI provider, not necessarily Anthropic.

On the other hand, it is sort of an interesting dynamic where they have broadcast loudly and heavily the superpowered capabilities of Mythos, but no one largely can access it. So, no one can verify it that isn't Anthropic or an Anthropic partner -- a very short list.

Cisco has come out and said they've seen really staggering results from using Mythos. But again, they're, by definition at this point, a partner, if only in the context of this project.

Anthropic is a business, and they do have PR and marketing objectives along with technological objectives. So I am with you. I go back and forth on whether this is all very convenient -- the terms of the project, the closed-door nature of it, and the short list of participants.

Another thing I've been thinking about is that they could have been quiet about this. There was a lot of announcing something that ultimately, arguably, didn't need to be publicized at the points that it was.

But I'm hearing the same things about China being hot on their heels, and OpenAI is working on similar projects.

So, I don't really know where I land, but I share your skepticism in general.

Jones: Well, I mean, if you think about it, imagine if you created a new superweapon and you keep telling people that you have this superweapon that can wipe out aircraft flying at 60,000 feet within a couple of minutes, and there's no military bomber or fighter jet that can outflank this weapon.

At a certain point, you've got to be able to roll it out and test it in the real world. You'll get that one shot to either hit the mark or miss, and there's going to be blowback.

When you have something like Anthropic, where you're testing these models in a simulated environment, at some point you've got to be able to demonstrate them in a real-world scenario where there are multiple sides, where somebody has an attempt to create a product and somebody has the ability to respond to it.

Whether or not you're going to be able to match the hype that you're bringing forth, I think at a certain point they're going to be tested. They're going to have to demonstrate that, yes, they can find these vulnerabilities and figure out a way to mitigate them.

Then the threat actors are already fairly skilled at creating vulnerabilities faster than humans can patch them right now. These models are going to have to step up to the plate at some point and demonstrate that they can actually outflank actors who are pretty skilled and pretty fast in terms of what they're capable of doing.

We're already starting to see that threat actors are taking AI outside of Mythos and creating situations where they're outpacing what we're currently capable of doing. So maybe a few months down the road -- and there have already been warnings about this -- they're going to be tested in the real world.

Irei: I think that's a great point. Just as a quick sidebar, there's already AI technology that is not Mythos and is not a frontier-model application that's weaponizing AI.

We saw the AI worm that was confined to a research lab, I believe, at the University of Toronto. But there are attacks possible already using AI that we all have access to -- open source models, and not necessarily Mythos. So, yeah, just building on Dave's point there.

Culafi: I would even go so far as to say there are a few examples of attackers doing complete front-to-back operations in preexisting, publicly available AI, from developing malware to orchestrating full attacks.

There was one example last week. I think it was maybe Cygnia that presented an example of a lone attacker who compromised an entire AWS customer, not AWS themselves but an AWS customer.

They managed to take down this whole global environment by orchestrating AI to take one set of plaintext credentials they could find, get everything they could out of it, and then gain footholds to get deeper and deeper into the organization until they were able to successfully financially extort this unnamed victim.

Even outside that, you have phishing attacks where now you can write a clean email even if, let's say, English isn't your first language, and you want to send an English-language email to someone.

If you have access to a Web browser, it's no longer difficult to get something that's perfect and plausible for the right victim, which is weird, right?

I wanted to go back to something you were saying, Dave, this idea of the superweapon. Alissa, I think you and I already talked about this a bit, but I'm curious where you stand, Dave. Do you think Mythos is the real deal based on what you're seeing out there so far? Or do you still feel a little of the skepticism that we do?

Jones: I'm a little skeptical from the standpoint that the company has a product it's trying to sell. So, they have an interest in promoting its capabilities, obviously. At the same time, they've demonstrated to a certain extent that what they've created may be a little beyond what they're capable of reining in and controlling.

What they're trying to do is set up almost sandbox environments where they can put this to the test in the most realistic scenario. They would create a model for a sophisticated, sensitive organization like a financial institution, a cybersecurity company, or other companies that are getting involved in these testing and sandbox environments. They're actually going to be able to demonstrate, "OK, we can find these vulnerabilities at this speed. We can determine how quickly we can weaponize this."

Somebody's going to have to come back and say, "OK, now that we've figured out where the vulnerability is, how much access to an environment does this product have?"

Part of the problem is there are certain products that have wide exposure to IT environments where they can access almost everything you have, and with the blink of an eye they can gain control of your systems. I think they're going to be pushed to determine, very soon -- within maybe a few months -- whether they can control how this rolls out.

For all we know, there may be companies working on an alternative version of this beyond the U.S. and beyond China, where in a few months they're going to be able to counter what Mythos does or counter what China's doing.

I'm sure the threat actors are gathering all the information they can and saying, 'Well, we have our response to the product you're putting out.'

Everybody has their own self-interest in terms of what they're putting forth. But we already know that for every technology that emerges, there's probably another unknown party that's developing a counter to whatever you're working on. And so, I think we'll learn pretty soon.

Culafi: Yeah, and the thing that I keep going back to is you've got threat actors that already use legitimate red-teaming tools like Cobalt Strike and whatnot to compromise environments. I think the threat of Mythos is that this is both better and easier to use than Cobalt Strike. If someone who isn't, let's say, technologically capable got hold of it, then they could have that superweapon capability. And I think that's the fear.

I guess the one question that sort of remains -- and we'll start with you, Alissa -- is how should organizations prepare themselves? Because maybe we don't know the exact extent that Mythos is a threat right now, or how much it'll be a threat in a few months, or when, let's say, opportunistic attackers are going to get their hands on it. But it sounds like something like this is real, or becoming real. What do you think folks should do?

Irei: So, I think the good news and the bad news is the answer is fairly boring. We've covered this quite a bit on TechTarget Cybersecurity. It's old problems that now have a new urgency: patch management, vulnerability management and making sure users are following good password practices.

I think things like zero trust, which we've been talking about for many years, are also important. A lot of organizations still have not really deployed zero trust across their environments. Identity and access management becomes hugely important if you have agentic AI in your environment, which you probably do whether you know it or not.

So, I think really doubling down on these cybersecurity fundamentals is the best place to start, and in some ways the only place to start. Because if you haven't addressed those, the outlook isn't great, whether or not Mythos turns out to be the one, or it turns out to be something a little further down the road.

It's the rare organization that really has all of those fundamentals buttoned down. I think that's what we're hearing from experts CISOs should start with, and there's plenty to work on there.

Beyond that, if you're an organization that has the resources, it's definitely a good time to be gathering information and talking to vendors about defensive AI capabilities -- not necessarily making purchasing decisions yet but monitoring what's possible and keeping abreast of how your organization can use AI defensively. That is necessary, and I think it will be necessary in the future.

Jones: I think one thing that kind of gets overlooked is the governance and the guardrails. If you're a company embracing the use of AI and you feel like you're in a race to outpace your competitors because you don't want to be left behind, do you actually know why you think you need AI? Do you know what the purpose of AI is? What is AI supposed to do to help your company?

If you're an organization and you start experimenting with frontier AI models, do you have the infrastructure set up to deal with potential outcomes that may not necessarily go your way? Do you have the personnel and the resources necessary to maintain a semblance of control over how the technology is utilized, who has access to the technology, how it's going to be implemented, and what the rules are? If, for example, a malicious actor comes back at you in response to your AI rollout, do you know who's going to be responsible for responding to that?

I'm just not sure that a lot of these secondary questions have been thoroughly thought through and game-planned for.

Everybody says, 'We have the most confidence in our security capabilities.' But if you took the CEO, the CISO and some of the lower-level employees into separate rooms, you might get a different set of answers depending on who you spoke to.

It's not necessarily clear to me that the people who need to be having these conversations are having them - or that those conversations are being listened to.

Culafi: Agreed with everything you're both saying and co-signed. The only thing I would add is there's this report that came out the weekend after Mythos and Project Glasswing were introduced from the Cloud Security Alliance.

Basically, over that weekend, a who's who of cybersecurity luminaries got together and worked on a report called "Building the AI Vulnerability Storm: Building a Mythos-Ready Security Program," which is not that long but is very helpful. April sounds like it was forever ago, but I think a lot of the advice in there is still practical and relevant because so much of Mythos, from an attacker's standpoint, is still very much theoretical.

So many of the security issues involving AI don't really evolve beyond strong security fundamentals. It's a data security program. It's keeping your authentication in check. It's a lot of the same boring stuff that you brought up, Alissa.

The idea of preparing for Mythos really hasn't changed. So, believe it or not, a report that's three months old is still perfectly viable.

On that note, thank you very much. Alissa and Dave, I really appreciate your time. For our viewers, I'm Dark Reading's Alex Culafi. I've been joined by TechTarget Cybersecurity's Alissa Irei and Cybersecurity Dive's David Jones. Thank you for watching, and we'll see you next time.

+ Show Transcript