Post-Mythos Cybersecurity: Keep calm and carry on
cephalosec.com
cephalosec.com
It's one thing to forget an Authorize attribute. That's a coaching event and procedure update. It's another altogether to not be able to see a dormant use-after-free bug because your brain can't hold the entire codebase and product roadmap at once. You can't coach a human developer on that. We all miss things this deep in the rabbit hole. The 2nd best option is to avoid this space of possibilities altogether.
I was actually pleased to see OpenAI openly (although timidly) complaining about the situation in their latest announcement, framing it as an unsustainable system.
One can only guess the outrage in the news if the Chinese government had been the first to pull this kind of stunt.
I suspect that the Chinese government "pulls this kind of stunt" often but just nobody ever hears about it because their society is not free to complain about such a thing publicly.
The old "cathedral-style" democracy is dying. People are seeing that the "regular" politicians are just ineffective and kinda boring. The old party-based structures are stifling and prevent changes. People want more direct participation in the governance.
So people are voting for a "new wave" of candidates that promise to work around the old institutions. Right-wingers were the first to harness this, initially with the Tea Party takeover and then Trump came in and crushed the entire Republican Party into his personal fiefdom.
Mamdani is doing the same with the Democratic Party now. After the recent primary victories, he's well-poised to become the left-wing Trump.
If you want historical analogies, the situation is similar to the start of the 20-th century when the wide masses first became politically active. Literacy spread, then radio broadcasts and daily nation-wide newspapers gave people the impression that they're a part of the same entity.
It ended well, with democracy winning over authoritarianism. But the middle part contained a couple of world wars and mass genocides.
Mamdani is NOT doing the same nor like Trump. For all the scaremongering, he is pragmatic politic with policies full of compromises.
There ia no symmetry between what those parties do.
Remember, democracy doesn't mean that "good" people win.
> Mamdani is NOT doing the same nor like Trump. For all the scaremongering, he is pragmatic politic with policies full of compromises.
Just wait. He's well poised to fail upwards with his policies. They can't and won't work long term, but they'll create a lot of buzz by the time he aims for a higher office. But anyway, that's beside the point.
> There ia no symmetry between what those parties do.
The horseshoe theory works: the extremes are very much alike. And that's why Republicans were taken over by Tea Party radicals, and Democrats are now getting taken over by Mamdani radicals.
Both are the result of the same sentiment: "the current elites are not representing us, and we need to destroy the political system".
They do now.
Top AI researchers in China are barred from getting an exit visa [0] (the PRC has done this for other employees as well such as Foxconn China employees who were working on shifting Apple supply chains to India [1]), and "AI Safety" from a national security perspective has been codified as party policy now [2].
The leading Chinese AI labs are also shifing away from open-source AI for commercial reasons, as can be seen with the org changes at Alibaba with the axing of the Qwen team [3][4].
That said, these are called out but it's all in Putonghua and no one on HN actively reads or follows what happens within China. I've noticed most HNers now source information from Reddit which has been dealing with DRAGONBRIDGE deluge for a couple years now, and I've noticed similar tactics being applied on HN as well.
In all honesty, I've found HN's noise to signal ratio to have tanked severely since 2022. Silver lining is that less people that matter are using it as much, so the IW impact is limited.
[0] - https://www.bloomberg.com/news/articles/2026-05-26/china-exp...
[1] - https://www.bloomberg.com/news/articles/2025-01-17/china-mov...
[2] - http://theory.people.com.cn/n1/2026/0616/c40531-40741238.htm...
[3] - https://m.guancha.cn/economy/2026_06_12_820253.shtml
[4] - https://www.ft.com/content/b39da303-3188-447b-8b65-3dd8dad8b...
Posts questionable info, gets called out or downvoted -- throws a fit, doesn't reply with anything concrete. Rinse and repeat.
wuh?
> Since then, Mythos and it’s safeguard-heavy equivalent
The simple "it's" vs. "its" rule is this:
If you can replace it with "it is" and it sounds weird, it's "its", otherwise it's "it's". In other words, "it's" is 100% of the time an abbreviation of "it is" (or, rarely, "it has"); it's not a possessive form.
Which is of course internally-inconsistent; I say "Peter's toys", not "Peters toys", but we say "its toys" to mean the same thing. /shrug
I only tell you this because I screwed it up for years before looking up the rule and going "... Oh. Duh. But also... Fucking hell, English!" ;)
Anyone in my profession worth a damn will tell you the vast majority of security issues are related to bad configurations and bad practices + accidents and bad luck. Vulnerable software is a problem but basic defense in depth will either mitigate or drastically reduce attack surface. Mythos does nothing to change that.
The technical debt at companies is the largest security threat. That, and layer 8 which is the people factor. The amount of silliness I've seen from people and companies as a whole is truly hard to verbalize. I've seen banks that gave every employee from the janitor up to the CEO domain admin access due to a crappy application that was written in 2004 that they never updated. I've seen a fortune 250 company write its own internal routing protocol that was basically clear text traffic that dated back to the 1990's and was never retired because, why not. I've seen contractors infect entire fab's in the chip industry because they plugged an infected USB stick into a 30 year old tool that hadn't seen an update in over 20. Then when the fab came back up, they did it again the next day.
Ultimately, Mythos is just another tool in the toolbox. It's great to find new vulns but it is incredibly short sighted to think it will move the needle in any meaningful way in the security industry.
Yet "Just another tool in the toolbox." I mean, that's not wrong!
AI itself is a security risk: https://www.404media.co/hackers-simply-asked-meta-ai-to-give...
I keep seeing screen shots of random AI chat bots who have been prompt injected to write code. That car dealership is now paying for the tokens for some script kiddie to pump out python.
Your open source dependencies may need to be version bumped quickly, but most companies are not going to be immediately exploitable without a large scale source code leak, and an attacker motivated to spend large amounts of money/compute on finding lucrative exploits (not just any exploits).
To me the reaction has been way overblown, though again, very real for large scale open source projects.
And going forward there's not going to be as many issues due to using models defensively, e.g. this vulnerability spike is likely a one time event.
So the fear porn is a bit much.
Me: LLMs are like any other machine. They're either a benefit or a hazard. If they're a benefit, it's not my problem.
- June 1st 2026: Anthropic files S-1 paperwork with SEC to get ready for IPO
- June 2nd 2026: Anthropic annouces expanding "Project Glasswing" to let people use their new model to enhance security of existing systems
- June 9th 2026: Anthropic releases Mythos model
- June 12th 2026: Model gets export regulations placed on it by US Gov
- June 26th 2026: US gov announces they will let some companies use new model
- August 2026: Anthropic goes IPO
The timing of all of this just seems to be a play to pump the stock. The reality is that in six months GLM-5.3 will be released open source with comparable functionality to their Mythos model. They are trying to cash in before that happens.I would not be surprised if the US government, the people pulling the strings who actually put the export announcements onto Anthropic, actually have purchased stock in the company to artificially pump up the stock, I would bet money on it.
There's absolutely no way Anthropic engineered this to bump their IPO price. That's lunatic conspiracy theory territory.
> I would not be surprised if the US government, the people pulling the strings who actually put the export announcements onto Anthropic, actually have purchased stock in the company to artificially pump up the stock, I would bet money on it.
The same US government that labelled Anthropic as a supply chain risk? This is the most ridiculous idea I've heard all week.
Just look at the consumer side: the current attitude of most people is they'd rather not pay the actual cost of the LLM they're using. Therefore the big money is probably in an IPO by boosting your product to be so unfathomably potent, it must be ridiculously valuable to own and control.
It also helps to pretend it's actually too dangerous for the general public: high-paying government contracts only please.
That could only be true if serving inference to customers was the least profitable part of the business, and that the training side of the business was the more profitable side of the business? Otherwise unless their huge fixed training costs get cheaper if they lose customers, it's only going to be worse?
Ctf fundamentaly have to change.
It also showed how critical it is to use llms now.
A lot has changed in just 12 month tbh.
If you still don't invest time and money into adding llms to your security you didn't hear the bang.
Hoping op will confirm.
:)
The consent want us to know that so we stay dependent.
Also known the cloud is made up of the same equipment that many can get access to similar or equivalent at their level of need.
The origin story of the cloud was that there were networking bottlenecks. Those were long since solved but the cloud kept carrying on like it wasn’t.
The cloud provides incredible convenience. It’s still some one else’s computer.
Self hosting is extremely more streamlined and secure than it was 5,10,20 years ago.
Because it’s the same gear.
Or an Opus 9.0
Will Cybersecurity ever start to be an issue?