Live data from Hacker News

US summons bank bosses over cyber risks from Anthropic's latest AI model

theguardian.com

91–100 of 101 posts

Re: US summons bank bosses over cyber risks from Anthropic's latest AI model

#91
post #5

Earlier quoted context omitted.

Your cynicism doesn't prove that it's fake, though.

Just like their marketing campaign doesn’t mean those claims are real?

I mean sure, they could be lying. It seems like a rather elaborate lie, though, considering that they got several other major companies to go along with it.

Re: US summons bank bosses over cyber risks from Anthropic's latest AI model

#92

Earlier quoted context omitted.

You've got to admit that crying wolf about how dangerous their new model is for the hundredth time right when the biggest story about the company was a leak that made them and their internal vibe-coding look totally incompetent is a bit suspect.

Your cynicism doesn't prove that it's fake, though.

You got the causality backwards, the cynicism is because it's most likely to be fake.

Re: US summons bank bosses over cyber risks from Anthropic's latest AI model

#93

Earlier quoted context omitted.

I'm particularly interested if someone with relevant expertise could comment on the types of bugs Mythos found, e.g. the 27 year old OpenBSD bug. I ask because the media around Mythos is leaning into the "Mythos is a super intelligence that can find bugs that no human can" story. But in my mind it's pretty obvious that any software that is complex enough will have a lot of lurking zero days, and better tools will asy…

The OpenBSD bug was more difficult for LLMs, because it is an integer overflow bug, while out-of-bounds accesses are more common bugs that are found by most models. The OpenBSD bug was also found by GPT-OSS and by Kimi-K2: https://aisle.com/blog/ai-cybersecurity-after-mythos-the-jag... The first condition for finding a bug is to actually audit the code where bugs exist. When a human does that, this is a lot of work,…

Thank you so much. Your comment and the linked blog post is exactly the deep analysis/explanation I was looking for.

Re: US summons bank bosses over cyber risks from Anthropic's latest AI model

#94
post #6

Maybe it's marketing, but I think it's regrettable that Anthropic paired project Glasswing with Mythos. It really makes it seem like Mythos is the threat, rather than the fact that tons of vulnerabilities have always been ignored throughout the software world. If Glasswing has been started years ago with the goal of applying fixes to AI-found gaps, then this would just be another model to add to that effort. But doin…

This. I’ve been hearing panic from the non-security community about Mythos because “zomg z3r0 d4y5!!” Since the announcement but these are the same people running production servers 10 updates and 2 critical security fixes behind for years. I don’t need cutting edge AI to take you down. I need MetaSploit with a CVE list that’s been updated in the last 6 months.

I once had a freelance gig to upgrade an environment that hadn't been touched in years. One server had a 1500 day uptime and I could find no evidence of any in-place upgrades. They made me watch a bunch of IT security / process videos before starting the project, though. This was a decent sized organization with 100's of employees and 100's of millions in revenue.

My job at a "near unicorn" "we're still a startup 10 years later" was no better. Distros that were no longer updated. Obsolete python versions. Servers that hadn't been rebooted in years. All environments in a single AWS account. I could go on...

Re: US summons bank bosses over cyber risks from Anthropic's latest AI model

#95

Earlier quoted context omitted.

Your cynicism doesn't prove that it's fake, though.

You got the causality backwards, the cynicism is because it's most likely to be fake.

A lesson of the parable about "crying wolf" is that cynicism based on previous events doesn't prove that the next event is fake. The people who ignored the warning may have thought it "most likely," but they were wrong.

Re: US summons bank bosses over cyber risks from Anthropic's latest AI model

#96

Earlier quoted context omitted.

You got the causality backwards, the cynicism is because it's most likely to be fake.

A lesson of the parable about "crying wolf" is that cynicism based on previous events doesn't prove that the next event is fake. The people who ignored the warning may have thought it "most likely," but they were wrong.

Never use previous actions to predict future actions, genius advice.

Re: US summons bank bosses over cyber risks from Anthropic's latest AI model

#97
post #73

Earlier quoted context omitted.

Cybersecurity is taken too lightly and it mostly boils down to recklessness of developers, they are just "praying" that no-one act on the issues they already know and it's something we must start talking about. Common recklessness obviously include devs running binaries on their work machine, not using basic isolation (why?), sticky IP addresses that straight-up identify them, even worse, using same browsers to acces…

I read your list and all of that is normal computer use. How can it be reckless to use a computer normally?

Didn't you know running binaries on your own machine is dAnGeRoUs? Better sign up for our subscription based cloud service!

Re: US summons bank bosses over cyber risks from Anthropic's latest AI model

#98

Earlier quoted context omitted.

A lesson of the parable about "crying wolf" is that cynicism based on previous events doesn't prove that the next event is fake. The people who ignored the warning may have thought it "most likely," but they were wrong.

Never use previous actions to predict future actions, genius advice.

It’s more about when your priors are so strong that it’s not worth paying attention to a new report. Clearly not in this case.

Re: US summons bank bosses over cyber risks from Anthropic's latest AI model

#99

Earlier quoted context omitted.

You got the causality backwards, the cynicism is because it's most likely to be fake.

A lesson of the parable about "crying wolf" is that cynicism based on previous events doesn't prove that the next event is fake. The people who ignored the warning may have thought it "most likely," but they were wrong.

The point of the parable is not about the problem of induction but about how lying erodes trust.

Re: US summons bank bosses over cyber risks from Anthropic's latest AI model

#100
post #13

Earlier quoted context omitted.

>This initiative probably could have started a few months sooner with Opus and similar models, though. Evidently they tried and even the most recent Opus 4.6 models couldn't find much. Theres been a step change in capabilities here.

No, Opus has found a lot and 112 vulnerabilities were reported to Firefox alone by Opus [0]. But Mythos is uniquely capable of exploiting vulnerabilities, not just finding them. [0] https://red.anthropic.com/2026/mythos-preview/

Doesn't even seem to be in the same ballpark of capability.

https://red.anthropic.com/2026/mythos-preview/FRT-Blog-Chart...

Post reply on HN