Live data from Hacker News

Project Glasswing: what Mythos showed us

blog.cloudflare.com

71–80 of 152 posts

Re: Project Glasswing: what Mythos showed us

#71
post #50

Earlier quoted context omitted.

Yeah I’m waiting for this as well. I get that you want to address them or whatever before releasing info but I keep seeing these claims with barely any data and I’m like…how do you expect people to not be skeptical? I mean hell if you’re a security professional you’re literally paid to be skeptical.

the curl maintainer goes into some more detail on this https://daniel.haxx.se/blog/2026/05/11/mythos-finds-a-curl-v...

Page won't open, but archive.is has it: https://archive.is/bfPZc

Re: Project Glasswing: what Mythos showed us

#72
post #3

The real question is whether it was Mythos or Opus that wrote this post. > "Why it matters" It doesn't, it's a corporate blog, they were rarely written in one-author's voice anyway, but it's interesting to see that even large organisations are outsourcing their blogs to LLMs.

It's fascinating seeing people think that if you're snarky enough about something, the substance of that thing actually ceases to be substantive. It's like staring down the barrel of a gun and taking the time to make quips about the type of paper the gun advertisement was printed on.

How do you know we haven't looked for substance, found none, and then decided to be snarky?

I can agree that snark probably isn't the type of comment that we generally value or encourage here on Hacker News, but neither is posting blatant advertisements and press releases, but here we are discussing one, so shrug ?

Re: Project Glasswing: what Mythos showed us

#73
post #38
post #22

Earlier quoted context omitted.

Sentence constructions like this definitely scream AI: "That's a reasonable bias for an exploratory tool. It's a ruinous one for a triage queue..." I will upgrade the "why it matters" to "and now AI output is part of the training data". A day is coming when the punched-up AI verbiage will be the norm and hard to distinguish unless you're from the previous generation. Sort of in the way that I miss some aspects of Use…

I had a dude in a conversation non-ironically use "load-bearing." I could only follow up with, "that is a genuine insight." Not a single person visibly flinched in pain.

Careful, you might have been talking to a Real Engineer. Perhaps even a structural variant that use this phrase pretty much daily.

Re: Project Glasswing: what Mythos showed us

#74

> The loudest reaction to Mythos Preview from other security leaders has been about speed - scan faster, patch faster, compress the response cycle. More than one team we have spoken with is now operating under a two-hour SLA from CVE release to patch in production [...] If regression testing takes a day, you cannot get to a two-hour SLA without skipping it, and the bugs you ship when you skip regression testing tend…

I don't know, but it always seems weird to me when people notice AI isn't performing super well and then they conclude that the solution to problem is to try using more AI

Re: Project Glasswing: what Mythos showed us

#75
post #11
post #3

The real question is whether it was Mythos or Opus that wrote this post. > "Why it matters" It doesn't, it's a corporate blog, they were rarely written in one-author's voice anyway, but it's interesting to see that even large organisations are outsourcing their blogs to LLMs.

Cloudflare blogs have been excellent for many years, long before transformers arrived.

Oh those Decepticons…

Re: Project Glasswing: what Mythos showed us

#76
post #12
post #2

That's great and all but how severe were the most severe vulnerabilities found? I imagine they don't want to talk about it, but that's really the most interesting and important bit.

As much as I’d like to share in the skepticism, the very beginning of the article states it very plainly — this is a step function. Lots of people feel that Mythos is a psyops campaign, but I don’t really understand the skepticism. Most of it seems to stem from the general distrust of things that aren’t publicly available. A few Anthropic employees have described Mythos as a general purpose model improvement, but tha…

A general distrust of things that aren't publicly available is very healthy. We should all do more of that!

Honest question, do you buy the narrative of everyone trying to sell you a product?

Re: Project Glasswing: what Mythos showed us

#77
post #2

That's great and all but how severe were the most severe vulnerabilities found? I imagine they don't want to talk about it, but that's really the most interesting and important bit.

I've settled in on the opinion that it's much more creative and able to run agentically for longer periods of time. So, despite it not having drastically better "hard skills", it's able to combine those together in more effective ways.

Right now, many of these vulns are identifiable by Opus, but they still require a human-in-the-loop (and often a skilled one) to guide towards complex exploits. Without a human in the loop, this means it's a lot easy for the average person to identify and leverage an exploit.

Re: Project Glasswing: what Mythos showed us

#79
> What changed with Mythos Preview is that a model can now take those low-severity bugs (which would traditionally sit invisible in a backlog) and chain them into a single, more severe exploit.

I think this statement seems to align with some of the other independent tests of Mythos[1]. It did very well on long agentic work which I expect is what they trained it for, and that requires being able to find these tangential links between loosely related topics in the context window.

[1] I'm mainly referring to https://www.aisi.gov.uk/blog/our-evaluation-of-claude-mythos...

Re: Project Glasswing: what Mythos showed us

#80
post #22

Earlier quoted context omitted.

Sentence constructions like this definitely scream AI: "That's a reasonable bias for an exploratory tool. It's a ruinous one for a triage queue..." I will upgrade the "why it matters" to "and now AI output is part of the training data". A day is coming when the punched-up AI verbiage will be the norm and hard to distinguish unless you're from the previous generation. Sort of in the way that I miss some aspects of Use…

That's a scary thought, llm's training on llm output. People trained by default of ubiquity to think and read llm output produce their own llm-esque writing. Seems stifling. We'll need someway to reward human creativity and out-of-bounds thinking before our greatest corpus of human intellect is a bounded by whenever and whatever was trained on.

I don't understand this mindset, why is it people on here think humans have some kind of magical ability machines don't or can't? Five years ago I would never have predicted this kind of human chauvinism here. It's some kind of weird romanticism almost.
Post reply on HN