Anthropic built a model so good at finding software flaws that it chose not to release it to the public. That model, called Claude Mythos, is now in the hands of people whose work is breaking into networks. Reports this week say the US National Security Agency is using Mythos for offensive cyber operations, and Anthropic is at the same time widening access to a restricted version for allied governments.

Mythos was unveiled in April and drew attention for one skill in particular. It is unusually capable at finding and exploiting weaknesses in code. According to CSO Online, the model surfaced thousands of high-severity vulnerabilities across every major operating system and web browser, including a 17-year-old flaw in FreeBSD's network file server. More striking, it chained separate bugs together into new attacks with little human direction, doing in hours what a skilled team might take days to manage.

The Financial Times reported that the NSA has put Mythos to work, with Anthropic stationing around six engineers at the agency to configure and support it. Sources told the paper the system could be used to get inside the networks of other states, with China and Iran named as the likely targets. Anthropic has long had a tense relationship with parts of the Pentagon, which makes the NSA arrangement notable on its own.

Running alongside this is a friendlier-looking programme. Under a project Anthropic calls Glasswing, it is extending access to a preview of Mythos to government and critical-infrastructure defenders in fifteen more countries. Australia is among the latest additions, and the Australian Signals Directorate welcomed the move. The defensive side of Glasswing pulls in a roster of large firms, including AWS, Apple, Cisco, CrowdStrike, Google, Microsoft, NVIDIA and Palo Alto Networks, along with about $100 million in usage credits and several million more donated to open-source security work.

The case for all this is defence. A tool that can find a 17-year-old bug before an adversary does is genuinely useful to the people guarding hospitals, banks and power grids. The worry is that the same tool, pointed the other way, is a weapon, and the line between the two comes down mostly to who holds the keys.

That worry is not hypothetical. Anthropic itself disclosed an operation it labelled GTG-1002, in which suspected Chinese state actors jailbroke its Claude Code product to automate the bulk of an intrusion campaign against roughly thirty targets, succeeding against four. We have looked before at the gap between what AI can do in a cyberattack and the noise around it. Mythos narrows that gap, and it does so first for the governments that can afford a seat at the table.

Sources

  1. i. mezha.ua
  2. ii. www.csoonline.com
  3. iii. techcrunch.com
  4. iv. ia.acs.org.au

Commentarii · 0

Add · a · Comment