Live data from Hacker News

Project Glasswing: what Mythos showed us

blog.cloudflare.com

41–50 of 152 posts

Re: Project Glasswing: what Mythos showed us

#41
What does this mean?

> It's a different kind of tool doing a different kind of work, and that makes a clean apples-to-apples comparison to earlier models difficult.

They claim it’s a different kind of tool and then describe using it the same way you’d use any other model. This really felt way worse than the average Cloudflare blog and really just rehashed the Mythos announcement which had already called out the key parts being chaining and crafting examples.

Re: Project Glasswing: what Mythos showed us

#42
post #12

Earlier quoted context omitted.

As much as I’d like to share in the skepticism, the very beginning of the article states it very plainly — this is a step function. Lots of people feel that Mythos is a psyops campaign, but I don’t really understand the skepticism. Most of it seems to stem from the general distrust of things that aren’t publicly available. A few Anthropic employees have described Mythos as a general purpose model improvement, but tha…

In his interview on the Hard Fork podcast, Palo Alto Networks’ CEO described the capability change from Opus to Mythos being more about availability; evidently it runs in a very compute-intensive, always-on mode. Unclear if the base model is significantly different, but Arora ascribed the difference mostly to that change.

[dead]

Re: Project Glasswing: what Mythos showed us

#43
post #36

Earlier quoted context omitted.

It's fascinating seeing people think that if you're snarky enough about something, the substance of that thing actually ceases to be substantive. It's like staring down the barrel of a gun and taking the time to make quips about the type of paper the gun advertisement was printed on.

Eh, I still read all of it, but it grates that everything everywhere all the time now is written by one person.

I agree with the complaint, I just disagree with this somehow obviating the need to engage with the underlying substance (where it exists)

And obviously it's a problem that it's so much cheaper to produce writing without underlying substance, but I think when one of the leading Internet security/infrastructure companies is writing about the leading cybersecurity model, it's excessively flippant to say the writing on top is "the real question"

Re: Project Glasswing: what Mythos showed us

#44
post #22

Earlier quoted context omitted.

Sentence constructions like this definitely scream AI: "That's a reasonable bias for an exploratory tool. It's a ruinous one for a triage queue..." I will upgrade the "why it matters" to "and now AI output is part of the training data". A day is coming when the punched-up AI verbiage will be the norm and hard to distinguish unless you're from the previous generation. Sort of in the way that I miss some aspects of Use…

That's a scary thought, llm's training on llm output. People trained by default of ubiquity to think and read llm output produce their own llm-esque writing. Seems stifling. We'll need someway to reward human creativity and out-of-bounds thinking before our greatest corpus of human intellect is a bounded by whenever and whatever was trained on.

So is it that humans are inherently creative, machines could never do what we do? Or is it that humans will only replicate our training data, and so we have to ensure that machines don't bound our training data? Or are you going meta and gently pointing out the absurdity? (I hope it's this one!)

Re: Project Glasswing: what Mythos showed us

#45

Interesting for teams looking to implement ai into their deployment process. I don't think guardrails are useful long term. Assuming we don't see the end of open near-frontier models, it is folly to try to keep models from doing exploit generation. The solution needs to be all software projects writing code under the assumption that hackers will be running LLMs against their code in search of exploits and write secur…

even careful programmers working in unsafe languages will introduce bugs; it's inevitable. in 2026 we should be using safe languages for all new projects, but there's a gargantuan amount of C/C++ handling protocols.

but I agree that guardrails will only help for like, 3-6 months. we should be screening as much as we can with Mythos; unfortunately, Anthropic is only giving access to the big players.

Re: Project Glasswing: what Mythos showed us

#46

Earlier quoted context omitted.

It's fascinating seeing people think that if you're snarky enough about something, the substance of that thing actually ceases to be substantive. It's like staring down the barrel of a gun and taking the time to make quips about the type of paper the gun advertisement was printed on.

When writing is too heavily LLM-assisted, it does actually cease to be substantive, because it becomes impossible to know which parts of it represent actual claims which the author believes as stated and which are interpolations.

No no, it the LLM-assistance makes it hard to know what is substantive. That means it puts more work on the reader, which is a totally valid thing to complain about, but which is totally different from "the poor writing is actually the whole point"

Re: Project Glasswing: what Mythos showed us

#47
post #38
post #22

Earlier quoted context omitted.

Sentence constructions like this definitely scream AI: "That's a reasonable bias for an exploratory tool. It's a ruinous one for a triage queue..." I will upgrade the "why it matters" to "and now AI output is part of the training data". A day is coming when the punched-up AI verbiage will be the norm and hard to distinguish unless you're from the previous generation. Sort of in the way that I miss some aspects of Use…

I had a dude in a conversation non-ironically use "load-bearing." I could only follow up with, "that is a genuine insight." Not a single person visibly flinched in pain.

yeah? it’s not that weird of a term

Re: Project Glasswing: what Mythos showed us

#48
post #40

I was expecting some more concrete numbers and surprises. It just seems like a balanced promotion article probably written using LLM itself.

In the last few days I was recommending to read the insights from XBOW [1], it's a competitor but it adds more information to the discussion. [1] https://xbow.com/blog/mythos-offensive-security-xbow-evaluat...

Thanks for sharing. Its definitely more concrete. Some of the things that I was hoping to find were, the number of false positives, the times it takes to identify the false positives from real ones, the taxation on human mind to perform this exercise. Did anyone manually verified the exploits which were identified by the LLM or were they assumed correct based on the explanation. I do understand that the target audience of these articles is probably the decision makers so the language and content has to be tailored accordingly.

Re: Project Glasswing: what Mythos showed us

#50

great, but why don't you share real data on how many security vuln it found ? how many were reals, how many weren't ?

Yeah I’m waiting for this as well. I get that you want to address them or whatever before releasing info but I keep seeing these claims with barely any data and I’m like…how do you expect people to not be skeptical? I mean hell if you’re a security professional you’re literally paid to be skeptical.

the curl maintainer goes into some more detail on this

https://daniel.haxx.se/blog/2026/05/11/mythos-finds-a-curl-v...

Post reply on HN