Live data from Hacker News

US summons bank bosses over cyber risks from Anthropic's latest AI model

theguardian.com

21–30 of 101 posts

Re: US summons bank bosses over cyber risks from Anthropic's latest AI model

#21
post #18

Earlier quoted context omitted.

Cybersecurity is taken too lightly and it mostly boils down to recklessness of developers, they are just "praying" that no-one act on the issues they already know and it's something we must start talking about. Common recklessness obviously include devs running binaries on their work machine, not using basic isolation (why?), sticky IP addresses that straight-up identify them, even worse, using same browsers to acces…

Totally agree, though I'd argue that it's still a software failure if preventing exploits requires every user memorize and follow an onerous list of best practices.

This is where security is actually heavily intertwined with Privacy, by following good privacy principles, you automatically cover a lot of security issues.

Re: US summons bank bosses over cyber risks from Anthropic's latest AI model

#22
post #14

> A recent leak of Claude’s code prompted the startup to publish a blogpost at the beginning of the month saying that AI models had surpassed “all but the most skilled humans at finding and exploiting software vulnerabilities” [...] I've seen a bunch of people conflate the Claude Code source-map leak with the Mythos story, though not quite as blatantly as here. I'm confident that they are totally unrelated.

[flagged]

Re: US summons bank bosses over cyber risks from Anthropic's latest AI model

#23

The more I live the more I believe people at the top operated in some sort of cult mentality. The level of gullibleness, temporary lack of critical thinking is only matched by their sociopathy and Machiavellianism. I'm sure it's a great big model, but the level of hype and dishonesty is something out of Sam Altman's book. Of course it's because of the upcoming IPO, but that's the end game, for now it's critical to ge…

Or, you're wrong. And the smartest AI Research Scientists and the top banking officials are both correctly worried about the ramifications. That's what you'd expect if there really was an issue here. Are you aware of the deep seated bugs in critical software that were already uncovered with Mythos? Are you able to steelman the issue here at all?

Re: US summons bank bosses over cyber risks from Anthropic's latest AI model

#24
post #5

Looks like the marketing worked at least somewhat lol. Such an obvious playbook by now I’m surprised some people here fell for it.

Your cynicism doesn't prove that it's fake, though.

Just like their marketing campaign doesn’t mean those claims are real?

Re: US summons bank bosses over cyber risks from Anthropic's latest AI model

#25

The more I live the more I believe people at the top operated in some sort of cult mentality. The level of gullibleness, temporary lack of critical thinking is only matched by their sociopathy and Machiavellianism. I'm sure it's a great big model, but the level of hype and dishonesty is something out of Sam Altman's book. Of course it's because of the upcoming IPO, but that's the end game, for now it's critical to ge…

There's a serious problem with being very popular/prominent/powerful and becoming surrounded by sycophants out of a sort of survival of the fittest and then developing a progressively more distorted view of reality as a result. When everything can appear to be made to work to the person at the center they start making progressively worse decisions which are consequence free because of the sway they already have. (this is a big reason why "disruptor" startups work)

Re: US summons bank bosses over cyber risks from Anthropic's latest AI model

#26
post #15

Earlier quoted context omitted.

A lot of those bugs were found by seasoned developers and security professionals though. Anthropic claims that Mythos is finding vulns from people who have no security background, who just typed "hey, go find a vulnerability in X", went home for the night, and came back the next morning with a PoC ready. They could definitely be an exaggerating, but if it's true that's a very different threat category which is worth…

Yes, previous models found vulnerabilities but Mythos is uniquely capable of actually exploiting them: https://red.anthropic.com/2026/mythos-preview/

Imo that's a big deal primarily because the issue with automatically discerned vulnerabilities has long been a high volume of reports and a very bad signal-to-noise ratio. When an LLM is capable of developing PoC exploits, that means you finally have a tool that enables meaningfully triaging reports like this.

Re: US summons bank bosses over cyber risks from Anthropic's latest AI model

#27

The more I live the more I believe people at the top operated in some sort of cult mentality. The level of gullibleness, temporary lack of critical thinking is only matched by their sociopathy and Machiavellianism. I'm sure it's a great big model, but the level of hype and dishonesty is something out of Sam Altman's book. Of course it's because of the upcoming IPO, but that's the end game, for now it's critical to ge…

Or, you're wrong. And the smartest AI Research Scientists and the top banking officials are both correctly worried about the ramifications. That's what you'd expect if there really was an issue here. Are you aware of the deep seated bugs in critical software that were already uncovered with Mythos? Are you able to steelman the issue here at all?

Two things can be true.

Historically bad security that people just got by with matched with powerful tools that aren't any better than the best people, but now can be deployed by mediocre people.

Re: US summons bank bosses over cyber risks from Anthropic's latest AI model

#28

The more I live the more I believe people at the top operated in some sort of cult mentality. The level of gullibleness, temporary lack of critical thinking is only matched by their sociopathy and Machiavellianism. I'm sure it's a great big model, but the level of hype and dishonesty is something out of Sam Altman's book. Of course it's because of the upcoming IPO, but that's the end game, for now it's critical to ge…

A good percentage of cybersecurity has always been theater. If their model helps to separate the wheat from the chaff, maybe it'll be an improvement.

Re: US summons bank bosses over cyber risks from Anthropic's latest AI model

#29

The more I live the more I believe people at the top operated in some sort of cult mentality. The level of gullibleness, temporary lack of critical thinking is only matched by their sociopathy and Machiavellianism. I'm sure it's a great big model, but the level of hype and dishonesty is something out of Sam Altman's book. Of course it's because of the upcoming IPO, but that's the end game, for now it's critical to ge…

Or, you're wrong. And the smartest AI Research Scientists and the top banking officials are both correctly worried about the ramifications. That's what you'd expect if there really was an issue here. Are you aware of the deep seated bugs in critical software that were already uncovered with Mythos? Are you able to steelman the issue here at all?

> Are you aware of the deep seated bugs in critical software that were already uncovered with Mythos

This. 100% this.

A large portion of the industry is under NDA right now, but most of the F500 have already already deployed or started deploying foundational models for AppSec usecases all the way back in 2023.

Sev1 vulns have already been detected using "older" foundation models like Opus 4.x

Of course the noise is significant, but that's something you already faced with DAST, SAST, and other products, and is why most security teams are also pairing models with experienced security professionals to adjudicate and treat foundation model results as another threat intel feed.

Re: US summons bank bosses over cyber risks from Anthropic's latest AI model

#30
post #6

Maybe it's marketing, but I think it's regrettable that Anthropic paired project Glasswing with Mythos. It really makes it seem like Mythos is the threat, rather than the fact that tons of vulnerabilities have always been ignored throughout the software world. If Glasswing has been started years ago with the goal of applying fixes to AI-found gaps, then this would just be another model to add to that effort. But doin…

I guess I'm not sure why you frame this as a "rather than". What Anthropic is saying is that the norm of having tons of vulnerabilities lying around historically worked OK, but Mythos shows it will soon become catastrophically not OK, and everyone who's responsible for software security needs to know this so they can take action.
Post reply on HN