{"id":36911,"date":"2026-05-13T01:23:25","date_gmt":"2026-05-13T01:23:25","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/36911\/"},"modified":"2026-05-13T01:23:25","modified_gmt":"2026-05-13T01:23:25","slug":"is-anthropics-claude-mythos-really-a-cybersecurity-risk","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/36911\/","title":{"rendered":"Is Anthropic\u2019s Claude Mythos Really a Cybersecurity Risk?"},"content":{"rendered":"<p class=\"css-ac37hb evys1bk0\">The artificial intelligence company Anthropic said last month that it would limit the release of its latest A.I. system to a small number of organizations, including a handful of big tech companies like Microsoft and Google and groups that manage important pieces of the internet.<\/p>\n<p class=\"css-ac37hb evys1bk0\">Called Claude Mythos, the new system was too powerful to share with the general public, Anthropic said, because hackers could use it to exploit security holes in computer networks with stunning speed.<\/p>\n<p class=\"css-ac37hb evys1bk0\">Executives in Silicon Valley and officials in Washington were alarmed by what Mythos could do, and its release may have helped shake the Trump administration from its defense of A.I. from government regulation.<\/p>\n<p class=\"css-ac37hb evys1bk0\">The White House is now considering <a class=\"css-yywogo\" href=\"https:\/\/www.nytimes.com\/2026\/05\/04\/technology\/trump-ai-models.html\" title=\"\" rel=\"nofollow noopener\" target=\"_blank\">government<\/a> oversight over new A.I. models, through an executive order that would create an A.I. working group of tech executives and government officials to examine potential oversight procedures. Among the possible plans is a formal government review process for new A.I. models.<\/p>\n<p class=\"css-ac37hb evys1bk0\">But more than a month after Mythos was released, cybersecurity experts still disagree on whether Anthropic made the right call. Some applaud the company for restricting who got their hands on Mythos. Others criticize Anthropic for not sharing it with a wider pool of researchers who could try it and get a handle on what it can and cannot do. So far, it seems, the only consensus is there is no consensus about Mythos.<\/p>\n<p class=\"css-ac37hb evys1bk0\">Anthropic shared the technology with about 40 organizations that maintain critical computer infrastructure, so that they could use the system to patch security vulnerabilities before hackers exploited them.<\/p>\n<p class=\"css-ac37hb evys1bk0\">Only a handful of the groups or companies that have spent time using Mythos would discuss it with The New York Times. But companies and researchers that did not have access were happy to offer their thoughts on the way that Anthropic released its new A.I.<\/p>\n<p class=\"css-ac37hb evys1bk0\">Their feedback so far has ranged from serious concern to a shrug. It could be some time before the broader tech community concludes whether Anthropic was right to limit the Mythos release \u2014 a challenge that Anthropic executives acknowledge.<\/p>\n<p class=\"css-ac37hb evys1bk0\">\u201cFor capabilities like this \u2014 or for a model as powerful as this \u2014 this is kind of an unprecedented situation where we truly do not have all the answers,\u201d Logan Graham, head of Anthropic\u2019s Frontier Red Team, which evaluates Claude for risks, said in an interview. \u201cWe don\u2019t truly know what is the best way to roll out models like this.\u201d<\/p>\n<p class=\"css-ac37hb evys1bk0\">Experts can look at the same situation and come to very different conclusions because of the inherently complex nature of cybersecurity. People can use systems like Mythos to attack computer networks, but they can also use them to defend attacks. For decades, people have argued over the best ways of handling that dual nature.<\/p>\n<p class=\"css-ac37hb evys1bk0\">Most experts agree that A.I. technologies like Mythos are fundamentally changing cybersecurity. The change gathered steam about six months ago when Anthropic and its chief rival, OpenAI, released new systems that are particularly good at writing computer code. If an A.I. system can write code, it can potentially find and exploit vulnerabilities in software applications.<\/p>\n<p class=\"css-ac37hb evys1bk0\">When Anthropic unveiled Mythos, the company said it had used the technology to find thousands of security vulnerabilities that had gone undetected in popular software systems for years. Anthropic also said that Mythos was better at identifying disparate security flaws and stringing them together into \u201cexploit chains,\u201d which are used by malicious hackers to exploit several security holes as part of a coordinated attack. In the company\u2019s words, the technology represented a \u201cstep change\u201d in what was possible with A.I.<\/p>\n<p class=\"css-ac37hb evys1bk0\">Cisco, the computer hardware and software company, is one of the companies that have used Mythos. Anthony Grieco, the company\u2019s senior vice president and chief security and trust officer, said the technology is significantly more powerful than existing systems in certain areas.<\/p>\n<p class=\"css-ac37hb evys1bk0\">Companies like Cisco, he said, should be \u201csuper aggressive about how we use this technology to identify vulnerabilities, fix them and get those fixes in the hands of our customers as rapidly as possible.\u201d<\/p>\n<p class=\"css-ac37hb evys1bk0\">He said that Mythos was indeed better at identifying exploit chains. But he added that those skills could be used to defend a computer network, not just attack it. \u201cWe are using that capability to help triage vulnerabilities and understand which ones are important to fix, so that sort of capability has a really positive connotation in the context of defense as well,\u201d he said.<\/p>\n<p class=\"css-ac37hb evys1bk0\">That is exactly why some cybersecurity researchers argue that Anthropic should release its system more widely. Like any other cybersecurity tool, it is good for both offense and defense.<\/p>\n<p class=\"css-ac37hb evys1bk0\">\u201cThe technology is not too dangerous to release,\u201d said Gary McGraw, a veteran security and A.I. researcher. \u201cIf you don\u2019t release a tool like this \u2014 or you hoard it \u2014 you are not solving the real problem.\u201d<\/p>\n<p class=\"css-ac37hb evys1bk0\">Soon after Anthropic\u2019s announcement, independent researchers showed that existing A.I. systems could find the same security holes that Mythos had found. Some cybersecurity experts argued that Anthropic had exaggerated the dangers of Mythos.<\/p>\n<p class=\"css-ac37hb evys1bk0\">For Pavel Gurvich, co-founder and chief executive of the security company Tenzai, part of the problem is that independent cybersecurity experts are unable to test the system and gain a complete understanding of its strengths and weaknesses. That understanding can help them defend against attacks from the technology.<\/p>\n<p class=\"css-ac37hb evys1bk0\">\u201cI don\u2019t think that choosing to share the model with such a small subset of companies helps us move forward,\u201d Mr. Gurvich said\u200f. \u201cThis is especially true because the announcement was accompanied by very bold claims that we can\u2019t assess.\u201d<\/p>\n<p class=\"css-ac37hb evys1bk0\">A week after Anthropic unveiled Mythos, its competitor OpenAI said that it, too, was sharing a similar technology only with a group of partners. But the company shared its model, GPT-5.4-Cyber, with a much larger group. It said it would initially share the model with hundreds of organizations, and then  release it to thousands more partners in the coming weeks.<\/p>\n<p class=\"css-ac37hb evys1bk0\">(The Times sued OpenAI and Microsoft in 2023 for copyright infringement of news content related to A.I. systems. The two companies have denied those claims.)<\/p>\n<p class=\"css-ac37hb evys1bk0\">Mr. Gurvich said that this approach \u201cmade more sense,\u201d in part because OpenAI has said that as it shares its technology, it will work to verify the identity of users in an effort to prevent misuse.<\/p>\n<p class=\"css-ac37hb evys1bk0\">Stanislav Fort, a former Anthropic researcher who now runs a security company called Aisle, said that keeping A.I. technology bottled up will not be possible in the long run, because so many tech giants, start-ups and independent developers are building powerful systems. Many of these organizations are \u201copen sourcing\u201d their A.I., allowing anyone to use and modify the underlying technology.<\/p>\n<p class=\"css-ac37hb evys1bk0\">As time goes on, he added, widely sharing these technologies will be essential to cybersecurity.<\/p>\n<p class=\"css-ac37hb evys1bk0\">\u201cSecurity by obscurity is one of the oldest bad ideas in the field,\u201d he said.<\/p>\n","protected":false},"excerpt":{"rendered":"The artificial intelligence company Anthropic said last month that it would limit the release of its latest A.I.&hellip;\n","protected":false},"author":2,"featured_media":36912,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[8],"tags":[53,1556,25,1586,1555,11248,1588],"class_list":{"0":"post-36911","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-anthropic","8":"tag-anthropic","9":"tag-anthropic-ai-llc","10":"tag-artificial-intelligence","11":"tag-computer-security","12":"tag-computers-and-the-internet","13":"tag-cyberattacks-and-hackers","14":"tag-openai-labs"},"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/36911","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=36911"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/36911\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/36912"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=36911"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=36911"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=36911"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}