Live data from Hacker News

New serious vulnerabilities spiked around release of Claude Mythos Preview

epoch.ai

41–50 of 82 posts

Re: New serious vulnerabilities spiked around release of Claude Mythos Preview

#41
post #16

…are we really drawing conclusions on this starting at April? When it was released in June?

Mythos is from April, it was just limited to a small number of organizations.

It was announced in April, but it was leaked in March (CMS bug) at which point external partners were already using it, and the most common rumored date for training competition is 2026-02-07 (I think Feb is likely, but that specific date is just rumor).

Re: New serious vulnerabilities spiked around release of Claude Mythos Preview

#42

Is this because LLMs are better at finding vulnerabilities or because increased use of LLMs for coding is creating more vulnerabilities?

It's the former.

It's definitely both. Half the code my team puts into PR these days is dogshit.

Re: New serious vulnerabilities spiked around release of Claude Mythos Preview

#43

Earlier quoted context omitted.

We (Project Glasswing users) follow a proof-of-concept approach. We create the exploit and verify that it behaves as the AI claims. Given our experience as security engineers (many of us with 10+ YoE) we don’t simply report every critical bug Mythos claims to have found. We verify each one carefully. At least, that’s what most of the high-visibility users in Project Glasswing are doing. There are bad apples everywher…

Its very hard to understand what you're saying with the comment - like you have 10+ years of experience and you verify each bug because you know Mythos can provide fake positives. But other teams (which also should have people equivalent to your skill and experience level) suck at it so much that CVP level workers are having to spend time on their fake reports. Then you say Anthropic should stop theater. Then you say…

I had no trouble understanding that the quality of operators is as important as the quality of the model and the harness. new operators received access to the tool and didn't follow the operational guidelines. happens everywhere, all the time, with predictable consequences; meanwhile experienced operators who follow the manuals get good results. no idea why you are surprised at anything.

Re: New serious vulnerabilities spiked around release of Claude Mythos Preview

#44

This is hardly news? We've known for months that a flood of AI-assisted vulnerabilities was coming; I posted on Twitter in March calling 2026 the year of a million CVEs: https://x.com/i/status/2035045573116789002

In pretty much every single HN post on this topic, there are a number of commenters claiming it’s false. Continued quantifiable data like this seems very important at hopefully resolving the ongoing disagreement about the facts.

My read of the zeitgeist on HN is that these new LLMs bring with them a torrent of false or useless security reports, that whatever may be true simply drowns.

The end result is both that there are more critical CVE and that there aren’t.

Re: New serious vulnerabilities spiked around release of Claude Mythos Preview

#45
post #41
post #16

Earlier quoted context omitted.

Mythos is from April, it was just limited to a small number of organizations.

It was announced in April, but it was leaked in March (CMS bug) at which point external partners were already using it, and the most common rumored date for training competition is 2026-02-07 (I think Feb is likely, but that specific date is just rumor).

> the first early version of Claude Mythos Preview was made available for internal use on February 24. [...] Based on these findings, we decided to release the model to a small number of partners to prioritize its use for cyber defense.

https://www-cdn.anthropic.com/7624816413e9b4d2e3ba620c5a5e09... (pg. 13)

Re: New serious vulnerabilities spiked around release of Claude Mythos Preview

#47

So basically there are two plausible explanations: 1. Someone with early access to Mythos leaked it to the bad guys. 2. Cybercriminals are getting enough mileage out of alternatives to Mythos to create exploits far more quickly, even though they don't have access to Mythos. My own guess is that it's a combination of #2 plus vibe-coding degrading software quality at multiple layers, open the door to sophisticated expl…

Disclosure of a vulnerability doesnt mean a bad guy found it.

I had to cut the "disclosure" in the title from the HN submission because of the character limit...

Re: New serious vulnerabilities spiked around release of Claude Mythos Preview

#49
post #4

How are these reports verified to be valid? If there are too many some could be hallucinations too.

We (Project Glasswing users) follow a proof-of-concept approach. We create the exploit and verify that it behaves as the AI claims. Given our experience as security engineers (many of us with 10+ YoE) we don’t simply report every critical bug Mythos claims to have found. We verify each one carefully. At least, that’s what most of the high-visibility users in Project Glasswing are doing. There are bad apples everywher…

This sounds like pure propaganda. Are people actually buying this?

Re: New serious vulnerabilities spiked around release of Claude Mythos Preview

#50

Earlier quoted context omitted.

We (Project Glasswing users) follow a proof-of-concept approach. We create the exploit and verify that it behaves as the AI claims. Given our experience as security engineers (many of us with 10+ YoE) we don’t simply report every critical bug Mythos claims to have found. We verify each one carefully. At least, that’s what most of the high-visibility users in Project Glasswing are doing. There are bad apples everywher…

Its very hard to understand what you're saying with the comment - like you have 10+ years of experience and you verify each bug because you know Mythos can provide fake positives. But other teams (which also should have people equivalent to your skill and experience level) suck at it so much that CVP level workers are having to spend time on their fake reports. Then you say Anthropic should stop theater. Then you say…

"Please save us from ourselves daddy Anthropic - how will we survive without you and your incredible safety standards.

Wait, you guys had a RCE in Claude Code for nearly a year and didn't even release a disclosure about it and secretly patched it and swept it under the rug?

Well... It's okay, I still trust you."

Post reply on HN