Live data from Hacker News

Post-Mythos Cybersecurity: Keep calm and carry on

cephalosec.com

11–20 of 83 posts

Re: Post-Mythos Cybersecurity: Keep calm and carry on

#11
post #8

[flagged]

I tend to agree but open weight model seem to still be lagging behind in terms of capacity, even the recent ones like GLM 5.2. If anything I hope the sudden, unpredictable changes of policy will make EU companies think twice before putting all their eggs in the same AI vendors's basket, all US based. Vendors coming back on their retention policies like they did with Fable 5 or plainly cutting the service without notice should be a gigantic red flag about your business continuity.

It's maddening how the corporate world can get shy of using any of those Chinese models, just because they are Chinese. This kind of FUD makes little sense when the inference is done in-house or by an EU/US cloud provider.

Re: Post-Mythos Cybersecurity: Keep calm and carry on

#12
post #5

Earlier quoted context omitted.

Fair, let's say a heavily staggered come back. I was actually pleased to see OpenAI openly (although timidly) complaining about the situation in their latest announcement, framing it as an unsustainable system. One can only guess the outrage in the news if the Chinese government had been the first to pull this kind of stunt.

> outrage in the news if the Chinese government had been the first to pull this kind of stunt. I suspect that the Chinese government "pulls this kind of stunt" often but just nobody ever hears about it because their society is not free to complain about such a thing publicly.

Ah so you can see the future of discourse in the US

Re: Post-Mythos Cybersecurity: Keep calm and carry on

#13
it all looks suspicious:

  - June 1st 2026: Anthropic files S-1 paperwork with SEC to get ready for IPO

  - June 2nd 2026: Anthropic annouces expanding "Project Glasswing" to let people use their new model to enhance security of existing systems

  - June 9th 2026: Anthropic releases Mythos model

  - June 12th 2026: Model gets export regulations placed on it by US Gov

  - June 26th 2026: US gov announces they will let some companies use new model

  - August 2026: Anthropic goes IPO

The timing of all of this just seems to be a play to pump the stock. The reality is that in six months GLM-5.3 will be released open source with comparable functionality to their Mythos model. They are trying to cash in before that happens.

I would not be surprised if the US government, the people pulling the strings who actually put the export announcements onto Anthropic, actually have purchased stock in the company to artificially pump up the stock, I would bet money on it.

Re: Post-Mythos Cybersecurity: Keep calm and carry on

#14
post #8

[flagged]

Companies have never secured their stuff and it's not because they didn't have access to Mythos. No one cares and breaches don't cost them money or customers. If I sound cynical it's because I am.

There's no functional difference between

"Hey npm says this is vulnerable, we need to fix it!" / "Nah, later."

and

"Hey Mythos says this is vulnerable, we need to fix it!" / "Nah, later."

Re: Post-Mythos Cybersecurity: Keep calm and carry on

#15
post #5

Earlier quoted context omitted.

Fair, let's say a heavily staggered come back. I was actually pleased to see OpenAI openly (although timidly) complaining about the situation in their latest announcement, framing it as an unsustainable system. One can only guess the outrage in the news if the Chinese government had been the first to pull this kind of stunt.

> outrage in the news if the Chinese government had been the first to pull this kind of stunt. I suspect that the Chinese government "pulls this kind of stunt" often but just nobody ever hears about it because their society is not free to complain about such a thing publicly.

It seems our government still has a lot to learn.

Re: Post-Mythos Cybersecurity: Keep calm and carry on

#16
post #7

The fear porn around this all has been horrible. I work in Cybersecurity and Mythos is all the vendors will talk about because they want to sell something. It started the day of the announcement which is what told me it was all BS. They had no information about it yet would happily tell me about all their solutions for it. Anyone in my profession worth a damn will tell you the vast majority of security issues are rel…

Forget whether it is Mythos or GPT 5.6, or any other specific model. SOTA models have tool likely have the knowledge and capability to create zero days from nearly every discovered and many undiscovered vulnerabilities. In the wrong hands can deploy and generate malware and submarine code that would go undetected behind secured systems. Add in the ability to clone voices, create mass social engineering campaigns. Yet…

You think this is not happening with open weight models?

Re: Post-Mythos Cybersecurity: Keep calm and carry on

#19
post #5

Earlier quoted context omitted.

Fair, let's say a heavily staggered come back. I was actually pleased to see OpenAI openly (although timidly) complaining about the situation in their latest announcement, framing it as an unsustainable system. One can only guess the outrage in the news if the Chinese government had been the first to pull this kind of stunt.

> outrage in the news if the Chinese government had been the first to pull this kind of stunt. I suspect that the Chinese government "pulls this kind of stunt" often but just nobody ever hears about it because their society is not free to complain about such a thing publicly.

You also have government apparatchiks influencing almost every corporate board, not just the state owned enterprises. Every private company that employs at least 3 CCP members is required by law to form a party committee within the company to represent party interests. In smaller companies, they will often simply coordinate with local governments on securing permits, etc, but I’m sure national party leadership communicates directly with the committees at the AI labs.
Post reply on HN