Anthropic’s Mythos AI finds vulnerabilities in US classified systems within hours

According to a US official who spoke to the AP, Anthropic’s Mythos model identified several security vulnerabilities in sensitive systems during a test exercise in a short period of time.

12punto


It has been reported that an artificial intelligence model named Mythos, developed by Anthropic, identified several security vulnerabilities in sensitive US government computer systems within hours during a test exercise.

A US official who spoke to the Associated Press on condition of anonymity stated that the company conducted the tests in cooperation with US intelligence agencies. The official also emphasized that the model finding the vulnerabilities in a short time does not mean it was able to exploit those vulnerabilities within the same timeframe.

The tests were reportedly conducted as part of Anthropic’s initiative called Project Glasswing. The initiative brings together technology companies aiming to protect software critical to public safety, national security, and the economy against risks that advanced AI models might pose.

Democratic Senator Mark Warner of Virginia mentioned the tests during a hearing at the Senate Committee on Banking, Housing, and Urban Affairs on June 11. Stating that he received the information from General Joshua Rudd, head of the NSA and US Cyber Command, Warner said, "This tool infiltrated almost all of our classified systems in hours, not weeks."

TENSIONS WITH THE ADMINISTRATION INCREASED

Although the tests demonstrate cooperation between US agencies and Anthropic, there is tension between the company and the Trump administration regarding the use of AI in military and national security fields. This month, the administration issued a directive requesting that the use of Anthropic’s Fable 5 and Mythos 5 models by foreign nationals be blocked.

The directive in question came 10 days after President Donald Trump’s executive order, which allows for the review of the most advanced AI systems for national security risks before they are released to the public. The executive order stated that company participation in this process would be voluntary.

Anthropic announced that it had disabled the relevant models for all customers to comply with the directive. However, the company is of the opinion that the steps taken by the government do not justify the security concerns it has raised.

Company representatives, including executives from Adobe and Nvidia, along with over 100 cybersecurity experts, sent a letter to the government requesting that the directive be lifted. The signatories argued that while Mythos models are powerful in finding software bugs and turning vulnerabilities into attack tools, they are not unique in this field.

The letter also warned that disabling powerful cyber defense tools "without a valid reason" could be dangerous at a time when the US’s rivals are advancing rapidly.