



How Anthropic’s Mythos AI has exposed India to a cybersecurity worry with sovereignty implications
Subscribe to enjoy similar stories.Last week, Anthropic announced that its latest artificial intelligence (AI) model, Claude Mythos, was too dangerous to release. In testing, the company discovered that the model could unearth thousands of hitherto unknown security vulnerabilities in many of the software applications, operating systems and web browsers that the world depends on.
Until it could be sure that these capabilities of the model would not be misused, said Anthropic, it believed it was too risky to let the model loose on the world.What was particularly disconcerting was that since some of the bugs had been around for decades, they are deeply embedded in many of the critical systems we rely on. This includes a 27-year-old vulnerability in OpenBSD, an operating system believed to be unhackable, and a 16-year-old flaw in FFmpeg, a video library used by billions of devices and that has passed millions of security tests.
The model also demonstrated how attackers could assume complete control of a machine by chaining together vulnerabilities in the Linux kernel; when asked to try to escape a sandbox and contact a researcher, the model succeeded effortlessly, posting details of its actions on public-facing websites without being asked. These are just the bugs Anthropic was willing to talk about.
Over 99% of the vulnerabilities the AI firm discovered are yet to be patched and so details about them have been withheld. The question is not whether these bugs will be fixed, but who gets to decide when, and for whom.Given the “substantial leap” in the model’s cybersecurity capabilities, the company has granted a small number of organizations (several of the world’s top tech companies) access to its capabilities so they can
. Read on livemint.com