{"id":51545,"date":"2026-04-10T15:37:58","date_gmt":"2026-04-10T19:37:58","guid":{"rendered":"https:\/\/mjtsai.com\/blog\/?p=51545"},"modified":"2026-04-10T15:37:58","modified_gmt":"2026-04-10T19:37:58","slug":"mythos-and-glasswing","status":"publish","type":"post","link":"https:\/\/mjtsai.com\/blog\/2026\/04\/10\/mythos-and-glasswing\/","title":{"rendered":"Mythos and Glasswing"},"content":{"rendered":"<p><a href=\"https:\/\/tidbits.com\/2026\/04\/09\/what-anthropics-mythos-and-project-glasswing-mean-for-your-apple-devices\/\">Rich Mogull<\/a>:<\/p>\n<blockquote cite=\"https:\/\/tidbits.com\/2026\/04\/09\/what-anthropics-mythos-and-project-glasswing-mean-for-your-apple-devices\/\">\n<p>Anthropic, the company behind the Claude AI chatbot, made two security announcements that were shocking for many but seen as inevitable by those of us working in AI security. First, it announced <a href=\"https:\/\/red.anthropic.com\/2026\/mythos-preview\/\">Mythos Preview<\/a>, a new, non-public AI model that turns out to be startlingly good at finding security flaws in software. The second was <a href=\"https:\/\/www.anthropic.com\/glasswing\">Project Glasswing<\/a>, Anthropic&rsquo;s program for getting that capability into the hands of the companies best positioned to fix those flaws before anyone else can exploit them. Apple is one of those companies.<\/p>\n<p>As much as I&rsquo;d like to downplay the announcements, Mythos and Project Glasswing are very big deals on their own, and harbingers for the future of digital security. Mythos was able to find and exploit new vulnerabilities in every major operating system, including a bug in OpenBSD, an operating system famous for its security, that had been sitting there unnoticed for 27 years.<\/p>\n<p>[&#8230;]<\/p>\n<p>We are at the start of a period in which finding software flaws that affect everyday users will become dramatically easier for both attackers and defenders. [&#8230;] However, over the long run, I believe using AI to identify security vulnerabilities favors defenders, because developers can find and fix many more bugs before shipping software to the public.<\/p>\n<\/blockquote>\n\n<p>Anthropic has a habit of making wild and scary public statements that seem designed to generate headlines and funding but sort of fall apart upon scrutiny. I initially dismissed this as more of the same, but people seem to be <a href=\"https:\/\/daringfireball.net\/linked\/2026\/04\/08\/claude-mythos-exploits\">taking it seriously<\/a>.<\/p>\n\n<p><a href=\"https:\/\/tapbots.social\/@paul\/116372420608659953\">Paul Haddad<\/a>:<\/p>\n<blockquote cite=\"https:\/\/tapbots.social\/@paul\/116372420608659953\">\n<p>Our model is so good, it&rsquo;s not safe to release, yet. Has to be one of the greatest AI marketing stunts ever.<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/stratechery.com\/2026\/myth-and-mythos\/\">Ben Thompson<\/a>:<\/p>\n<blockquote cite=\"https:\/\/stratechery.com\/2026\/myth-and-mythos\/\">\n<p>There&rsquo;s reason for cynicism, given Anthropic&rsquo;s history, but <a href=\"https:\/\/stratechery.com\/2026\/anthropics-new-model-the-mythos-wolf-glasswing-and-alignment\/\">the part of the &ldquo;Boy Cries Wolf&rdquo; myth everyone forgets<\/a> is that the wolf did come in the end.<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/mastodon.social\/@danielpunkass\/116376377017659450\">Daniel Jalkut<\/a>:<\/p>\n<blockquote cite=\"https:\/\/mastodon.social\/@danielpunkass\/116376377017659450\">\n<p>If Anthropic has really developed an LLM that can suss out security weaknesses better than any other AI, the US government would be foolish to continue shunning them.<\/p>\n<\/blockquote>\n\n<p>Or, rather, if the government believes the marketing, it may want to take control of the company and its technology, like how it restricted restricted civilian nuclear research.<\/p>\n\n<p><a href=\"https:\/\/stratechery.com\/2026\/anthropic-and-alignment\/\">Ben Thompson<\/a>:<\/p>\n<blockquote cite=\"https:\/\/stratechery.com\/2026\/anthropic-and-alignment\/\">\n<p>In fact, Amodei already answered the question: if nuclear weapons were developed by a private company, and that private company sought to dictate terms to the U.S. military, the U.S. would absolutely be incentivized to destroy that company.<\/p>\n<\/blockquote>\n\n<p>Previously:<\/p>\n<ul>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2026\/04\/02\/ios-18-7-7-and-ipados-18-7-7\/\">iOS 18.7.7 and iPadOS 18.7.7<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2026\/02\/06\/llms-and-software-development-roundup\/\">LLMs and Software Development Roundup<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2026\/01\/27\/curl-removes-bug-bounties\/\">curl Removes Bug Bounties<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2025\/07\/04\/common-vulnerabilities-and-exposures-cve-funding\/\">Common Vulnerabilities and Exposures (CVE) Funding<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2025\/05\/08\/curl-takes-action-against-ai-bug-reports\/\">curl Takes Action Against AI Bug Reports<\/a><\/li>\n<\/ul>","protected":false},"excerpt":{"rendered":"<p>Rich Mogull: Anthropic, the company behind the Claude AI chatbot, made two security announcements that were shocking for many but seen as inevitable by those of us working in AI security. First, it announced Mythos Preview, a new, non-public AI model that turns out to be startlingly good at finding security flaws in software. The [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"apple_news_api_created_at":"2026-04-10T19:38:04Z","apple_news_api_id":"597d5214-9a8e-45eb-ad91-31347ceb4d3b","apple_news_api_modified_at":"2026-04-10T19:38:04Z","apple_news_api_revision":"AAAAAAAAAAD\/\/\/\/\/\/\/\/\/\/w==","apple_news_api_share_url":"https:\/\/apple.news\/AWX1SFJqOReutkTE0fOtNOw","apple_news_coverimage":0,"apple_news_coverimage_caption":"","apple_news_is_hidden":false,"apple_news_is_paid":false,"apple_news_is_preview":false,"apple_news_is_sponsored":false,"apple_news_maturity_rating":"","apple_news_metadata":"\"\"","apple_news_pullquote":"","apple_news_pullquote_position":"","apple_news_slug":"","apple_news_sections":"\"\"","apple_news_suppress_video_url":false,"apple_news_use_image_component":false,"footnotes":""},"categories":[2],"tags":[2615,1351,31,2741,30,2742,663,991,2359,48],"class_list":["post-51545","post","type-post","status-publish","format-standard","hentry","category-technology","tag-anthropic","tag-artificial-intelligence","tag-ios","tag-ios-26","tag-mac","tag-macos-tahoe-26","tag-marketing","tag-open-source-software","tag-openbsd","tag-security"],"apple_news_notices":[],"_links":{"self":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/51545","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/comments?post=51545"}],"version-history":[{"count":1,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/51545\/revisions"}],"predecessor-version":[{"id":51546,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/51545\/revisions\/51546"}],"wp:attachment":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/media?parent=51545"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/categories?post=51545"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/tags?post=51545"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}