Live data from Hacker News

Post-Mythos Cybersecurity: Keep calm and carry on

cephalosec.com

41–50 of 83 posts

Re: Post-Mythos Cybersecurity: Keep calm and carry on

#41
post #13

it all looks suspicious: - June 1st 2026: Anthropic files S-1 paperwork with SEC to get ready for IPO - June 2nd 2026: Anthropic annouces expanding "Project Glasswing" to let people use their new model to enhance security of existing systems - June 9th 2026: Anthropic releases Mythos model - June 12th 2026: Model gets export regulations placed on it by US Gov - June 26th 2026: US gov announces they will let some comp…

Nah I spoke to a security researcher who still has access to Mythos. He says it is significantly better than their earlier models for security research. Based on my one-day use of Fable that was also a noticeable step up for coding.

There's absolutely no way Anthropic engineered this to bump their IPO price. That's lunatic conspiracy theory territory.

> I would not be surprised if the US government, the people pulling the strings who actually put the export announcements onto Anthropic, actually have purchased stock in the company to artificially pump up the stock, I would bet money on it.

The same US government that labelled Anthropic as a supply chain risk? This is the most ridiculous idea I've heard all week.

Re: Post-Mythos Cybersecurity: Keep calm and carry on

#42

I've been brewing on this topic since Mythos preview was announced. As Mythos got finally released, then banned, then released again under U.S. government control, it was time to finally flesh it out and use it as a way to exit the lurker-zone on HN !

"Released" is doing some heavy lifting here.

I hope you’re not this nice in real life!

Re: Post-Mythos Cybersecurity: Keep calm and carry on

#43
post #7

The fear porn around this all has been horrible. I work in Cybersecurity and Mythos is all the vendors will talk about because they want to sell something. It started the day of the announcement which is what told me it was all BS. They had no information about it yet would happily tell me about all their solutions for it. Anyone in my profession worth a damn will tell you the vast majority of security issues are rel…

Mythos actually does change that calculus. Going forward, with access to a mythos caliber llm actors are not tied to bad configs or lazy admins for access. I get that the bs is real. But it's important for you to not rest on your laurels having recognizing that salesmen sell. You actually have to pay attention to and understand the new developments your field. It's sad that the marketing department odd doing a better job than you in that manner

Re: Post-Mythos Cybersecurity: Keep calm and carry on

#44

The CCC talk in December showed me how good llms are at ctf. Ctf fundamentaly have to change. It also showed how critical it is to use llms now. A lot has changed in just 12 month tbh. If you still don't invest time and money into adding llms to your security you didn't hear the bang.

I'd be interested in a link to that talk if it's recorded

Re: Post-Mythos Cybersecurity: Keep calm and carry on

#45
post #16

Earlier quoted context omitted.

Forget whether it is Mythos or GPT 5.6, or any other specific model. SOTA models have tool likely have the knowledge and capability to create zero days from nearly every discovered and many undiscovered vulnerabilities. In the wrong hands can deploy and generate malware and submarine code that would go undetected behind secured systems. Add in the ability to clone voices, create mass social engineering campaigns. Yet…

You think this is not happening with open weight models?

Sure but not my point. My point is, saying that LLMs are "just another tool in the box" is a little like saying nuclear weapons are "just another bomb."

Re: Post-Mythos Cybersecurity: Keep calm and carry on

#47

I've been brewing on this topic since Mythos preview was announced. As Mythos got finally released, then banned, then released again under U.S. government control, it was time to finally flesh it out and use it as a way to exit the lurker-zone on HN !

[dead]

Re: Post-Mythos Cybersecurity: Keep calm and carry on

#48

The CCC talk in December showed me how good llms are at ctf. Ctf fundamentaly have to change. It also showed how critical it is to use llms now. A lot has changed in just 12 month tbh. If you still don't invest time and money into adding llms to your security you didn't hear the bang.

[dead]

Re: Post-Mythos Cybersecurity: Keep calm and carry on

#50

The genie is out of the bottle, folks. You can find some pretty good vulnerabilities even with models like Deepseek V4 Flash.

Find some pretty good vulnerabilities, and at a very fast speed--one or two weeks ago, mimo-v2.5-pro(some where between v4 flash and pro), released ultra-speed version with 1000 tokens/s. gpt-5.6 sol also has a nominal 750 tokens/s
Post reply on HN