Live data from Hacker News

New serious vulnerabilities spiked around release of Claude Mythos Preview

epoch.ai

61–70 of 82 posts

Re: New serious vulnerabilities spiked around release of Claude Mythos Preview

#61
post #4

How are these reports verified to be valid? If there are too many some could be hallucinations too.

We (Project Glasswing users) follow a proof-of-concept approach. We create the exploit and verify that it behaves as the AI claims. Given our experience as security engineers (many of us with 10+ YoE) we don’t simply report every critical bug Mythos claims to have found. We verify each one carefully. At least, that’s what most of the high-visibility users in Project Glasswing are doing. There are bad apples everywher…

Show your work so others can reproduce it.

Or it functionally does not exist.

(No, long hashes with an equally mythic promise of reproducibility don’t count)

Re: New serious vulnerabilities spiked around release of Claude Mythos Preview

#62
post #4

How are these reports verified to be valid? If there are too many some could be hallucinations too.

The best case scenario for AI companies is, people receive those bug reports, look at the model that produced it and not even look at the details, just apply the fix mindlessly This gives Anthropic a staggering amount of power. Oh it came from Mythos? We will just lose time trying to analyze it, better apply the fix ASAP

TBH, I’d reject Mythos or similar reports and require full reproduction on a publicly available model before considering them valid.

Re: New serious vulnerabilities spiked around release of Claude Mythos Preview

#63
post #31

I do maintain dozens of C/C++/Perl projects. I got massive amounts of new good vulnerability reports, more than with the latest fuzzing waves. Fuzzing is still the majority overall, but Opus dominates now. Haven't got any Mythos/Fable vuln yet. And with the help of Sonnet/DeepSeek I can finally get around and weed out all the still existing fuzzing bugs. It has nothing to do with Mythos for me, just people getting An…

On my hobby coding with C++ I also cross check with CoPilot, alongside the usual VS analysis tools.

Which was certainly an improvement, given that Github is in no hurry to add modules support to CodeQL.

Re: New serious vulnerabilities spiked around release of Claude Mythos Preview

#64
post #58

One of the major differences between Amodei’s and Hagseth’s views is that Hagseth said that in their world they don’t distinguish between “defensive” and “offensive” capabilities. In other words, a weapons missle defense system is equivalent to an attack one. I think that applying this thinking to software is a mistake. A lot of commercial software uses open source libraries under the hood, and and while the large co…

If we take the noise about Mythos' capabilities as read, then releasing it freely into the world could result in chaos, as attackers find myriad new vulnerabilities and use them, and code owners frantically hunt for them and fix any that are exploited. (Noting, of course, how legendarily quick and agile large corporations aren't , compared to motivated individuals or small groups.). Eventually, given unfettered acces…

[deleted]

Re: New serious vulnerabilities spiked around release of Claude Mythos Preview

#65

One of the major differences between Amodei’s and Hagseth’s views is that Hagseth said that in their world they don’t distinguish between “defensive” and “offensive” capabilities. In other words, a weapons missle defense system is equivalent to an attack one. I think that applying this thinking to software is a mistake. A lot of commercial software uses open source libraries under the hood, and and while the large co…

Wouldn't open source enable review from people with access to the scanners prior to release?

Seems like there is a fair chance that it will mostly be an actual spike, where's a bunch of existing vulnerabilities get cleaned up and then published software mostly has less vulnerabilities going forward.

Re: New serious vulnerabilities spiked around release of Claude Mythos Preview

#66

One of the major differences between Amodei’s and Hagseth’s views is that Hagseth said that in their world they don’t distinguish between “defensive” and “offensive” capabilities. In other words, a weapons missle defense system is equivalent to an attack one. I think that applying this thinking to software is a mistake. A lot of commercial software uses open source libraries under the hood, and and while the large co…

OpenAI gives access to cyber models for open source maintainers

https://openai.com/index/patch-the-planet/

Re: New serious vulnerabilities spiked around release of Claude Mythos Preview

#67

This is hardly news? We've known for months that a flood of AI-assisted vulnerabilities was coming; I posted on Twitter in March calling 2026 the year of a million CVEs: https://x.com/i/status/2035045573116789002

In pretty much every single HN post on this topic, there are a number of commenters claiming it’s false. Continued quantifiable data like this seems very important at hopefully resolving the ongoing disagreement about the facts.

AI has driven many people into denial. It's excruciating to watch otherwise smart individuals embrace terrible thinking, over and over and over.

Re: New serious vulnerabilities spiked around release of Claude Mythos Preview

#68

One of the major differences between Amodei’s and Hagseth’s views is that Hagseth said that in their world they don’t distinguish between “defensive” and “offensive” capabilities. In other words, a weapons missle defense system is equivalent to an attack one. I think that applying this thinking to software is a mistake. A lot of commercial software uses open source libraries under the hood, and and while the large co…

You're right on that, https://www.hurstpublishers.com/book/full-stack-spies/ goes over it in much more lucid detail.

Hegseth is to blindisded by macho-ism to value anything that requires patience and planning (see iran) If Fable is able to cheaply (ie less than $40k) find serious CVEs in common software, then it costs america much more to defend against it. especially as they are keeping the price of zero days artificially high.

Post reply on HN