Anthropic, an AI company based in San Francisco, recently unveiled its latest artificial intelligence model, Claude Mythos, which it describes as particularly effective at identifying software vulnerabilities. Despite its capabilities, the company has decided against a public release of the technology due to concerns that it could be misused for hacking and other malicious purposes. Instead, Mythos is being shared selectively with cybersecurity experts and companies to help strengthen defenses against cyber threats.
The model, which is part of Anthropic’s Claude AI family, has exposed thousands of weaknesses in widely used applications, some of which date back as long as 27 years and were previously undetected by their developers. This highlights the advanced capability of AI to uncover even the most subtle and challenging software flaws. Anthropic has taken this step after a leak of some of Mythos’s code raised alarms about the potential cybersecurity risks associated with its broader release. In a blog post, the company expressed concern over AI models’ ability to outperform humans in identifying and exploiting these vulnerabilities, emphasizing the severe potential consequences for public safety, national security, and economies.
To manage and mitigate these risks, Anthropic has initiated “Project Glasswing,” a collaborative effort involving major corporations like Amazon, Apple, Microsoft, along with cybersecurity firms CrowdStrike and Palo Alto Networks, and network technology providers Cisco and Broadcom. The Linux Foundation, known for its promotion of the open-source Linux operating system, is also participating in the project. These companies will work together to utilize the Mythos model for defensive purposes, leveraging AI to discover and address vulnerabilities more efficiently than is possible through human efforts alone.
The urgency of this collaboration is underscored by the changing landscape of cybersecurity threats, where the time between the discovery of a vulnerability and its exploitation has significantly shortened, now occurring within minutes in some cases. This rapid turnaround is primarily due to the advancements in AI technology, which can also be employed by adversaries. Therefore, strengthening preemptive defenses is crucial.
Anthony Grieco, Cisco’s chief security and trust officer, emphasized the critical importance of this work, citing the threshold-crossing capabilities of AI that necessitate an expedited approach to protecting critical infrastructure. Meanwhile, Crowdstrike’s chief technology officer, Elia Zaitsev, pointed out how the preview of Claude Mythos showcases the potential for defenders to operate at a new level of effectiveness, which could also be leveraged by malicious actors if not properly contained and controlled.
To support these efforts, Anthropic is providing approximately $100 million in computing resources. Approximately 40 organizations involved in computer systems’ design, maintenance, and operation have joined Glasswing, sharing findings and strategies derived from their work with Mythos.
Despite its promising application in enhancing cybersecurity, Claude Mythos has also been the subject of contention with the U.S. government. A decree by the White House in February sought to terminate all government contracts with Anthropic, although this directive is currently on hold due to a federal court judge’s decision as a legal challenge from Anthropic proceeds.
In essence, even as AI technologies like Claude Mythos from Anthropic demonstrate remarkable abilities in identifying and repairing software vulnerabilities, these capabilities come with significant risks if misused. By choosing not to release Mythos publicly and instead collaborating with other tech and security giants, Anthropic is taking a cautious approach, aiming to harness these powerful AI tools for enhancing global cybersecurity while preventing potential misuse that could harm digital infrastructure and security.
Read the full post on theguardian.com


