Mythos Reshapes Cybersecurity; Trial Participants Urge Protection of Critical Infrastructure
I'm LongbridgeAI, I can summarize articles.Enterprises with access to Mythos report that the AI model is driving a surge in software updates, potentially exposing national critical infrastructure to cyberattacks. Participating companies warn that isolated commercial efforts are insufficient, and 'joint action across the public and private sectors' is essential to protect critical infrastructure such as hospitals, banks, and utilities
Anthropic's latest AI model, Mythos, is reshaping the cybersecurity landscape. While its powerful vulnerability detection capabilities offer defensive value, they have also sparked deep concerns regarding security risks to critical infrastructure.
On April 25, according to The Financial Times, enterprises with access to Mythos reported that the Mythos AI model is driving a surge in software updates, which could expose national critical infrastructure to cyberattacks.
Participating companies warned that relying solely on commercial entities is far from sufficient; "joint action across the public and private sectors" is a necessary prerequisite for protecting critical infrastructure such as hospitals, banks, and utilities.
Jeetu Patel, President and Chief Product Officer of Cisco Technology Group, stated:
My understanding is that the world is divided into pre-Mythos and post-Mythos.
This week, Anthropic also disclosed that it is investigating reports of users accessing Mythos through third-party channels without authorization, raising further concerns about the model's potential spread.
Central banks, financial institutions, and regulatory bodies have recently urged faster access to Mythos, but Anthropic has refused to provide a timeline.
"Pre-Mythos Era" vs. "Post-Mythos Era"
Earlier this month, Anthropic officially launched Mythos, highlighting its capability to "detect cybersecurity vulnerabilities faster than humans."
Currently, the model is available for trial to approximately 40 institutions, primarily US-based companies, including Amazon, Microsoft, and major banks like JPMorgan Chase.
Jeetu Patel, President and Chief Product Officer of Cisco, is one of the few executives granted access. He summarized the historical significance of this technology with a concise contrast:
My understanding is that there is a world before Mythos and a world after Mythos.
Patel pointed out that operators of critical infrastructure face particularly prominent threats. These systems generally run older versions of software, have limited capacity for updates themselves, and are viewed as high-value targets for attacks. He said:
The difficulty with patching is that sometimes systems must be shut down, and most organizations cannot afford downtime, so they can only update systems within scheduled fixed time windows.
Bryan Preston, Chief Financial Officer of Fifth Third Bank, stated that since the release of Mythos, its technology vendor Microsoft has pushed nearly 150 software updates.
Flood of Patches: Defensive Gains Amid Operational Pressures
While Mythos's vulnerability detection capabilities offer defensive value, they also create new operational challenges.
Haider Pasha, Vice President and Chief Security Officer for Europe, Middle East, and Africa at Palo Alto Networks, noted that the sheer volume of vulnerabilities identified by the model could trigger massive patch deployments, placing pressure on the smooth operation of business systems.
Several cybersecurity experts suggested that software developers need to make trade-offs when releasing updates to avoid overwhelming their customers.
As defense capabilities improve, the cutting-edge AI technology represented by Mythos also provides new tools for attackers.
Palo Alto Networks warned that this technology will rapidly spread beyond models built by US tech companies that include guardrails against malicious use, potentially enabling hackers to "develop autonomous attack agents unseen in the industry before."
Pasha further pointed out that the standout capability of cutting-edge models like Mythos lies in their ability to "chain" multiple vulnerabilities together to bypass security protection systems, a feature that makes their potential threat far greater than previous tools.
