Mythos von Anthropic und ähnliche KI-Tools können Bedrohungen und Schwachstellen schneller erkennen, als kleine Teams sie beheben können, und gefährden so das Internet.

https://www.bloomberg.com/news/articles/2026-04-17/anthropic-s-mythos-adds-strain-on-cybersecurity-teams-facing-ai-threats

4 Kommentare

  1. *Chris Stokel-Walker for Bloomberg News*

    With the unveiling of Anthropic’s latest model, Mythos, stakeholders from security experts to the US Treasury have expressed concern over whether the internet can remain secure. UK banks will get access to Mythos next week. According to Anthropic, Mythos, announced on April 7, can autonomously discover and exploit so-called “zero-day” vulnerabilities — weaknesses in code that have not yet been discovered — across every major operating system and web browser. “The fallout — for economies, public safety, and national security — could be severe,” the company wrote.

    As part of a pre-emptive effort to contain any potential impact, Anthropic decided not to release Mythos widely, instead giving access to those maintaining core code at around 40 organizations, including CrowdStrike Holdings Inc. and the Linux Foundation. It also announced $4 million of funding for a clutch of software maintainer groups. On Tuesday, OpenAI announced a model of its own, GPT-5.4-Cyber, which it says is aimed at spotting software vulnerabilities.

    Yet Anthropic’s donation — a tiny fraction of its latest $14 billion run-rate revenue — merely underscored one of the big secrets in big tech: That the sector’s current sky-high valuations depend, at least in part, on open-source software maintained by small, under-resourced teams.

    There’s a hope that Mythos, put in the right hands, could fix issues before other AI models find them. For now, though, as cyber attackers and defenders race to adopt AI, those teams are at risk of becoming a bottleneck, with their workload growing faster than their capacity to respond.

    [Read the full dispatch here.](https://www.bloomberg.com/news/articles/2026-04-17/anthropic-s-mythos-adds-strain-on-cybersecurity-teams-facing-ai-threats?accessToken=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzb3VyY2UiOiJTdWJzY3JpYmVyR2lmdGVkQXJ0aWNsZSIsImlhdCI6MTc3NjQyMDkzOSwiZXhwIjoxNzc3MDI1NzM5LCJhcnRpY2xlSWQiOiJURE1OSThLSUpIOU0wMCIsImJjb25uZWN0SWQiOiJEMzU0MUJFQjhBQUY0QkUwQkFBOUQzNkI3QjlCRjI4OCJ9.c7CRQlpYUTl-jeNegbmamAW_LkB7UXah9P6y2Kg4Cw4)

  2. sciolisticism on

    Mythos is marketing spam, and you shouldn’t let them fool you otherwise. [This article](https://www.flyingpenguin.com/the-boy-that-cried-mythos-verification-is-collapsing-trust-in-anthropic/) goes into some detail about its failure to stand up to scrutiny.

    The first example in the article here is for cURL, which received 181 bug reports in 2025. What it _doesn’t_ note is that almost all of those reports were low effort hallucinations and not actually exploitable.

    It’s true that cURL wasn’t able to keep up with the reports, but that’s not because AI was finding huge numbers of exploits, but because it made it very low effort for people to throw slop at maintainers. Many are now closing their bug bounty programs because of the flood of slop. Ultimately this is awful for actual security.

Leave A Reply