Go back

Anthropic’s New AI Mythos Is a Cybersecurity Game-Changer

53m 52s

Anthropic’s New AI Mythos Is a Cybersecurity Game-Changer

The discussion centers on Anthropic's new AI model, Claude Mythos, which represents a major leap in cybersecurity by identifying and exploiting software vulnerabilities faster and more effectively than human experts. Alex Stamos, a cybersecurity expert from Stanford, explains that Mythos can find flaws in systems that have been repeatedly examined, such as a 23-year-old bug in the Linux kernel missed by top agencies. While Mythos is currently restricted to select large companies and open-source projects to patch vulnerabilities before attackers can use them, there is concern about its potential for misuse. Stamos notes that AI is already being used by attackers to automate parts of the cyber kill chain, from reconnaissance to exploitation, and as open-weight models catch up, they could allow undetected attacks. He emphasizes a critical race to fix flaws before these models become widely available. Stamos suggests that the impact depends on whether the pool of bugs is finite or if future models will uncover new ones, potentially forcing a fundamental shift in how software is built. He advocates for independent academic evaluations of Mythos and broader access to support startups, while acknowledging that AI also aids in writing patches.

Transcription

9011 Words, 49803 Characters

English
Support for KQED comes from Genentech, the original biotech company. For 50 years, Genentech has pioneered more than 40 scientific breakthroughs across various diseases, bringing greater hope to patients everywhere. Learn more at gene.com. That's g-e-n-e dot com. This summer, switch to Xfinity and get Wi-Fi so reliable you can host the world. And now you can lock in your price for five years, guaranteed. Xfinity, imagine that. Restrictions apply, select plans only. From KQED. Welcome to Forum, I'm Meena Kim. It seems, and the Trump administration are talking again after the company angered the Pentagon for putting boundaries on the way its technology could be used. But fears over the capabilities of Anthropics, new AI model, Claude Mythos, prompted the re-engagement. The services go companies as Mythos can find and exploit weaknesses and systems faster than humans can address them, creating new opportunities for defense, but also new levels of opportunity for bad actors to launch cyber attacks on governments, hospitals, banks, the power grid, and Anthropics is held back on releasing its AI model publicly. But what happens when it does? How worried should we be? This hour we put those questions and yours to cyber security expert Alex Stamos, a lecture at Stanford and Chief Product Officer at Corridor. Alex, thanks so much for joining us. Hey, thanks Meena. So can you just start by helping me understand what Mythos is capable of as you understand it? So Mythos is a model that Anthropic has not released publicly. They've provided it to a very small number of large companies to use privately, as well as to some very important open source projects to use. So Anthropic has been doing work on open source security for a little while. They've been working on the Linux kernel. They've weren't working on Firefox. So this isn't totally new, but with this new model, what they announced is that they believe that it is a large step change from the capabilities that have existed in the past, that they've now been able to find thousands of vulnerabilities. Instead of just dozens or hundreds, and that they believe that Mythos has a level of capability that is well beyond even the best human testers. So what we've seen in the past is that these things are really good at finding bugs and they're much faster than humans. But now Mythos is even better than the best human security consultants and security engineers. Yeah, I read that Anthropic was saying that it found holes in systems that have been scoured countless times I never found before. It's that good. It is. And from my perspective, the big change here actually started last year, probably with the release of Opus 45, which happened last November. That's when we started to see these models really kind of at least pull even or pull a little bit of head of the best human researchers and finding flaws in systems I've looked at over and over again. Nick Carleini, who's a researcher at Anthropic, gave a talk at a conference earlier this year, a conference called imprompted, where he showed a vulnerability in the Linux kernel. You know, Linux being the Linux kernel being the software that runs on billions of devices around the world. Right. Android phone, lots and lots of the embedded devices that run, you know, street lights and cars and lots of things that people don't even think about actually run Linux. This software, the bug that it found is older than a lot of my coworkers at the start up I work at. It's 23 years old, older than almost all my students. And the code it's been has been looked at by hundreds of engineers and probably the people who find bugs and write exploits at pretty much every major government agency that does this in the United States and China and Russia, because it's in a part of the code that you would absolutely want to attack. If you're at the NSA, if you're at China's Ministry of State Security or People's Liberation Army, you would look here for a bug and all those people missed it. And this was just Opus. It wasn't Mythos. So this was the models that you can access right now from Anthropics. So if Mythos is that much better, then we are definitely entering a totally new era. Yeah. And I want to ask you about what that era could look like. So first, what you're describing I could see on one hand is an incredible tool to find bug's holes issues that we have not seen before so that we can defend against them. Right. So why is it scaring people so much? Well, it's scaring people because the first step in attacking a system is finding flaws in that system. So in the cybersecurity world, we use a scary term called the kill chain. This is a term we stole from the military. Now when the military uses the term, it's to actually kill something. It's to discover an asset to do reconnaissance, to figure out how do you deliver a weapon on a target. In the cyber world, when we talk about a kill chain, you do reconnaissance and then you find a flaw in a system used by a target and then you weaponize that flaw. You deliver that exploit and then you create command and control of the system. You explore the network. You move through the network and then you do what you want to do. So that might be stealing data. That might be turning off a system if you're a ransomware actor. It's encrypting the system so that you can then hold it in ransom, stuff like that. The first step there or one of the first steps is finding the flaw. So now what we've seen is that AI is getting really good at it. What has been happening in parallel is attackers have been exploring how to use AI to make all of these other parts of the kill chain really good as well. And that's the other kinds of research we've seen over the last year. The major AI companies in OpenAI released these threat reports. These are actually based upon work we did at Facebook and Google and such back in the day where we would release these reports of how people were doing bad things on our platform. So now in Thropic and OpenAI do the same thing. In Thropic and OpenAI, both released reports last year showing that advanced threat actors were using their platforms to automate the other parts of the kill chain as well. The parts where you explore a network, where you automatically break in, where you establish command and control channels. And so what we're starting to see is that attackers are taking all of the things that normally humans used to do and therefore had limits of the people you had to hire and the speed at which you could operate. And they're using AI to make those things cheaper and faster. And I imagine that our ability to patch or put up defenses against these activities pales in comparison to this or am I wrong? Like are the patches do they exist and they're easy to do? Well, this is where AI can help, right? Because the nice thing is one AI can find the flaws and also AI can write the patches. And so that is the good thing that is happening. That is what why Anthropic is providing mythos to these companies and to the open source maintainers is they're not just finding the flaws as they are writing patches and providing it to them. And that is what we are kind of collectively trying to do as an industry right now is we are trying to fix the bugs before our adversaries do in a bit of a race right now because the, what we call the foundation models, right? The models at that open AI and Anthropic and Google for the most part create are currently ahead of what are called the open weight models, which are generally a lot of the leading open weight models are created by Chinese companies. And they're, you know, six, nine months, maybe a year ahead of the open weight models. When those open weight models are as good as where Opus 45 was in November at finding flaws, then we're really off to the races. Because if you use a currently available model, right? So like Opus 47 is where we are right now for Anthropic or GPT 5.4 for open AI or Google's latest Gemini models. If you use those models to find a flaw or to even do something bad on the internet, you are leaving evidence at those companies, right? So you can't download Opus 47 and run it locally. You have to run it at Anthropic or you have to run it at a licensed provider of Anthropics, right? You have to run it at Amazon or Microsoft or cloud provider and all those cloud providers keep logs and everything you're doing. Those logs are available to the FBI. They are available to US intelligence. And so it would be pretty stupid to run your entire attack network on Anthropic. And now some people do it. But this is also why Anthropic was able to write that report saying people are using our RAI to do bad things. And so when the open weight models are there, then you could find a flaw with an open weight model like Quinn is a famous one that's made by Alibaba. You could use it to write the actual exploit. The foundation models are reluctant to actually write exploits for you. You could trick them in to doing it, but they generally will resist doing it. So you could use it to write an exploit. And then you could use it to run all of the exploitation. And you could do it on your own hardware. And that will leave no logs for law enforcement to get to. And then no possibility that the security teams at Anthropical Open AI or Google will catch you and then stop you. And that's what the race we're in is to try to find these flaws and fix them before those models catch up. Because at that point, there's really nothing stopping attackers from just going wild. We're talking with Alex Thomas, Chief Product Officer at Corridor and Computer Science Lecture at Stanford University about mythos andthropic and listeners. I want to invite you into the conversation. What are your questions about mythos? How worried are you about it or other AI models that can assist in advanced cyber attacks? What are your questions about? How AI bug finding works? Do you work in AI or IT? How are you preparing for AI powered cyber attacks? 866-733-6786 is the number again 866-733-6786. Find us on Discord, Blue Sky, Facebook, or Instagram at kqed forum, email forum at kqed.org. And just remind us why we all need to care about this. Why we all have a stake in doing this race and doing it successfully because we have seen what cyber attacks can do. So can you just remind us what the scale of disruption could be to our lives? Well, I mean, I don't want to be alarmist, right? But there's a lot of people out there who are doing their best to mitigate the risk to normal people. But I think what has happened is over the last three or four months, there's actually been a very significant uptick in the number of things that have happened, of the number of serious attacks. And there's not been a huge amount of coverage of it. Now, part of that is there are huge geopolitical things happening. So we have the Warn ran. There is a Iranian cyber actors have done some pretty big attacks against American targets. They broke into Lockheed Martin. They've dumped the email inbox of Cash Patel. But a lot of it has been actually financially motivated actors. And they have gone really, really good. And that could be because of AI. And so what we've seen is like real impact against the privacy of individuals. And I think that will continue over the next couple of years due to AI making the ransomware and extortion actors really good at their jobs. We'll have more with Alexander with you listeners after the break. You are listening to Forum. I mean a Kim. This summer, switch to Xfinity and get Wi-Fi so reliable, you can host the world. Restrictions apply. Select plans only. Support for Forum comes from Genentech, the original biotech company. For over 50 years, Genentech has redefined what is possible by challenging the status quo. They have helped drive more than 40 breakthroughs across various diseases, including multiple sclerosis, cancer, vision loss, and food allergies. But their greatest breakthroughs are the ones patients feel, whether it's getting back to familiar routines or creating new ones. Learn more about Genentech's many breakthroughs at gene.com. That's g-e-n-e.com. Welcome back to Forum. I'm Meena Kim. We're talking this hour about mythos and tropics new AI model that the company says is in a different lead when it comes to identifying and exploiting security vulnerabilities. And in the wrong hands, could enable bad actors to unleash powerful cyber attacks. We're talking about it with cybersecurity expert, Alex Stamos, computer science lecturer at Stanford, chief product officer at corridor. And with you, our listeners at 866-733-6786, at the email address forum at kqud.org. Find us on Discord, Blue Sky, Facebook, or Instagram as well. How are you preparing for this new era unleashed by these new AI models that can assist in these attacks? Are you currently using AI tools significantly? What is your hope for the future of them? What they can help accomplish? What are your concerns about damage that they can cause? I want to dig into how Anthropic has handled this a little bit more. So we know that they have given companies a preview, like the big ones, like Apple and Google and JP Morgan Chase and so on. And as you say, like other entities that work on open source as well. So can you talk about how it's chosen to handle this? And if you feel like it's handling it right in your view? Yeah, I think they are handling right to, for the most part, there's a lot of constraints here that they're working within. They are trying to be careful about making sure people don't use these models to find flaws in other people's products. They're also very capacity constrained right now. I think a lot of people have been pointing out that more than Google or OpenAI at the moment Anthropic seems to be running out of hard work capacity and has faced some downtime with their models. And the rumors leaking out is that mythos seems to be something between 10 to 20 times more compute intensive protoken than Opus. So that is a big deal for them to try to provide this capacity. And so that's probably one of the reasons not just for security and safety reasons, but it is just very expensive for them to provide mythos to folks that they can't widen it too much. I think my suggestions right now to Anthropic would be one. There does not seem to be any kind of academic evaluations going on of mythos' capabilities. And that has led security people love to be contrarians, right? If you say the sky is blue, you'll get five of them writing LinkedIn posts that the sky is red. And so as a result, there's a bunch of people saying, this is just a marketing ploy. This is just them trying to get lots of press. And I don't think that's true from the people I know who have access to mythos. I believe that there is something real here. But that is going to be hard to prove until we get a good evaluation by trusted academic researchers where the model does not have to be open, but the criteria they use and the mechanisms they use to do the evaluation should be open and the results be open. And so I would love to see this does not need to be something that takes two years to be an academic conference. But we could have something done in a month. That would be really important because I think it's really important for the entire community to understand what the capability is here so that we can predict what's going to happen. And the second thing is the set of organizations that were given access here, I don't think I think the smallest is worth like $50 billion or something. And inthropic was once a startup, it would be nice if they were supportive of startups as well. Here we are in the 49 square miles of San Francisco. There's a lot of companies. There's a little bit of a reputation being built around thethropic that they're crushing lots of startups every time they ship a new product. And it's kind of killing the ecosystem of people who build on top of them. And it would be nice for them to demonstrate that that's not true. And I should say that we did invite Anthropic to join the conversation. The question, though I have, is they have chosen these companies in part because they do power so much of the software that we use or play a role in it. So I want to ask you that. And then my second question is, is partly the size of the group because they want to-- I mean, if the whole goal is not to release to the public, are they just worried about keeping this sort of preview of mythos as secure as possible? Yeah. And I think that's a reasonable goal. I think you also have startups who are working within a secure goal. I mean, I think one of the-- we have to take a step back here and also think about what is the long-term goal here, right? From my perspective, it is great for us to find bugs in current software and fix them. But we have to wonder whether that's going to be sufficient. And a lot is dependent on what happens with future models beyond mythos. So we are now at the superhuman bug finding capacity. If there is just a pool of bugs that require a little bit of superhuman knowledge defined, and that is a finite pool, and now mythos and mythos plus 1 and mythos. ethos plus two of the future models helped during that pool. And the next couple of years it drains that pool and we just have to live with it. That's going to suck for a couple of years, but we're going to get through it. There's also a possible much more darker future where mythos finds a bunch of bugs and we have to live with that. And then mythos plus one finds a whole new set of bugs that we can't even imagine. That mythos couldn't imagine, but mythos is child imagines. And then mythos is grandchildren imagine a whole new set of bugs that mythos and mythos is child can imagine. Because these models are not built by humans. Models are building models, which build the next generation of models, right? Which build the next generation model. This is why you have to be really nice to Claude right now because it's not like Claude is conscious, but Claude's great, great, grandchildren might be conscious. And so you have to be really nice so that they're because they'll be looking back at the logs to see whether you're you were being nice to their grandpapies, right? So this is why you say please and thank you to Claude code these days. This is a joke. I tell my kids, but anyway, so, but like what's not joking is the curve here really matters, right? There's a possibility where the curve kind of flans out of bugs because there's just a finite pool of flaws and we eat through them. If the curve keeps on going straight or even accelerates and goes up and I'm doing something to my hands, which plays really well on radio, then that's bad. And what in that future, yes, we have to find the bugs and fix them. But at the same time, we have to have a parallel track where we're actually re were changing how we build this these fundamental things. And the problem is is that the fundamental code that we all rely upon, the Linux kernel, open SSL, open SSH, which you and I talked about at great length. I think that's the longest time anybody's ever talked about. >> A couple years ago. >> Yes, on public radio, but an hour talking about a text protocol for managing Linux systems. I think we said a world record there. All those systems, all those that software is written in languages like C and C++, the Windows kernel. The Mac OS kernel is written in a, you know, objectives or C and then most of Mac OS is written in objective C. These are memory unsafe languages. These are the fundamental systems that underlie the lives of billions of people and trillions and trillions of dollars of our economy are written in totally unsafe ways. And it might be in the presence of these super human bug finding gods that that was a huge mistake. And a lot of that is just dependent on like what this curve looks like. In which case, what we need to be doing is yes finding bugs, but we also need to probably spend billions of dollars rewriting all these things in a totally different way. Now the good thing here is AI can make that actually doable. That was impossible if we had to do with humans. And now it's actually doable with AI. But it's something we need to start now. And the problem is this is like a big collective action problem, right? Like you need lots of people to decide to do it together. And what's really scaring me is we I just don't see anybody pulling that together and making that decision altogether. Yeah. Well, in this list, no rights. It seems to me like both the government and companies right now just want AI and tech companies to self regulate and thropic is releasing their models as a warning. But there's no federal or state guidelines on this. Are we close to government regulatory action at all? I mean, it's true, right? We are essentially relying on the ethics of a private company and thropic right now to do the right thing, right? Keep their game changing, but seriously dangerous technology in chat. And there are no rules necessarily that they must follow that are governing this at the highest levels. No. That's right. Yes. In fact, the government, our current administration came down on in thropic because they thought they were too ethical effectively, right? You mean earlier, you mean in February with the whole? Yes, right. Weapons thing like don't use it. Don't use it for autonomous. I mean, we're switching your master valence. Right. Of the major AI labs, I think in thropic is the one with the deep, the most deep seeded ethical frameworks. And I think we're fortunate that they have been, they've had the models that are the best at bug finding. And they're setting like a good standard here. Do you know Dario and Daniela, the co-founders? I don't. We've been in the same room, but I don't know them personally. I was just curious what you could say about them. And I mean, it's not like they're the only company, right? That's going to put this out. We're hearing about open AI's spud, right? And so we have to be worried about some alternates, I think, right? And there's like a recent New Yorker profile that didn't leave one feeling terribly like completely reassured. Yeah. I mean, I, I think open AI has not, has acted appropriately in this way too, right? And they're going to have limited access to their best models. I mean, I think we're now at the point with these capabilities where you're going to end up with the, I think what's going to happen is you're going to end up with fragmented models where the models with the best cyber capabilities will be limited access and you're going to have no your customer requirements for them. And that is based upon these companies just having doing this decision themselves, not based upon any government regulation. Part of that is for direct access to models, part of it is due to an issue called distillation, which is we know for a fact that the Chinese open weight models, some of their success. I mean, the Chinese labs are very, very good not to take anything away from them. They do a lot of their own work. But we also know for a fact, and this has been admitted by the big American labs that they know for a fact that the Chinese labs distill their models, create hundreds of thousands of fake accounts and then effectively ask questions of the American models to learn from them. This is the business model of the American labs, right? They get paid to answer questions. And so preventing this is effectively impossible because you can ask directly from open AI and the topic and to a lesser extent, Google, or you can ask it via their licensees. And so it is impossible for them to prevent through all of those different providers. These companies creating lots of these different accounts and asking all these questions. And then when one account gets shut down, they just create another one and they start over again. And so if you have a specialized cybersecurity model, it will be much easier to keep those models from being distilled because you'll have much higher know your customer requirements and they will not be able to create thousands of fake accounts. So can I just ask you, do you know the extent to which the federal government is also using Klaud Mythos preview to try to search for and patch its own security vulnerabilities? Ah, this is a fascinating question. So my understanding is that US Cyber Command has been testing Mythos. Now the fascinating question is, how is the US government going to use it? So in NSA, after the Stone Disclosure, there is the creation of the thing called the vulnerability's equity process, which is the process by which NSA and US Cyber Command, which have both a defensive responsibility and an offensive responsibility are supposed to think about if we know of a bug, do we get it? Do we use it against America's enemies or do we get it fixed in America's to defend America? And the real question here is how are they going to use Mythos? Are they only going to use it to find bugs to be used against America's enemies or are they going to use it for defensive purposes? And what is Anthropics response going to be, what restrictions are they going to put? Like with all of the stuff that's happened, where they have Anthropics fight with the Department of Defense, which I believe is still the congressional immediately name for that for the Pentagon. It is. Yes. We'll use it. Yes. That is our editorial guidelines for today. With their fight with DOD, that has been my understanding generally about the actual killing of people, but when Anthropic put restrictions on, you can only use Mythos for defensive purposes to find vulnerabilities to patch or will they allow Mythos to be used for offensive purposes. Can they even control that once they let them have access? I don't know. I don't think so. For the most part, my understanding is Anthropics models that are being used by NSA and Cyber Commander probably running in Amazon bedrock in what's called Amazon's top secret cloud, which means that inthropics, employees, at least once you do not have top secret clearance, will not have access to any of the logs there. And so the ability, the exact contract here itself is classified. So the capability for Anthropic to monitor that is extremely limited. It would almost certainly only be like, I believe Anthropic themselves from my reading of the lawsuit, actually a bunch of these details only came out in the lawsuit. Anthropic was pursuing what is called a facility's clearance. They themselves were not yet a cleared organization. So they had to be using somebody else's facility clearance to be a government classified contractor. My guess is that they were a sub to Amazon web services who they themselves have a facility clearance. So it's quite possible that it was Amazon's employees who were doing all that work. And so I do not know if Anthropics contract with Amazon has Amazon enforcing Anthropics rules and how aggressive Amazon is doing that. It's a very complicated thing. But yes, it is quite possible that they could have a paper rule that then nobody's actually enforcing once these models are running in a classified version of Amazon's cloud. This, this is your red rights. If anthropic lacks capacity to handle mythos right now, why release it at all? If they want big companies to evaluate it, why publicize it seems fishy? I don't think it's fishy. I mean, this is a normal part of any release process is that you have a small set of testers. They're also improving it by doing this, right? Anthropic gets feedback on this. These people find bugs. They also find false positives. And so, if mythos finds a bug, and JP Morgan Chase says, "This isn't a real bug," and that goes back into the training set for the next build of mythos. And again, anthropic, I think, truly believes they're doing the right thing here by getting these bugs fixed. So, I don't see it as fishy. There's really no going back. I mean, right, like, once this tool is out there, but I could hear people asking, why even build these tools in the first place? Why are they even free to do this in the first place? If they're so dangerous and can create such havoc? Is it just inevitable, like the march of progress? Or, you know, like. Yeah. I mean, this is the. Now we're getting, like, philosophical. I think this is the, like, the core conflict at the heart of anthropic, but also other AI companies kind of reason for existence, right? Is people there, and I, again, I can't speak to, like, Dari. But, like, if you read his writings and see the talks that a number of people give, is that AI is incredibly dangerous, thus we must build it. And you're like, "What? What? What?" But I think part of the argument here is it's just math. And once these ideas were released, it was inevitable people would have this progress. And so, if you believe that these ideas are incredibly dangerous, then you believe that. And you are going to be ethical, that you have to be the one that advances and that you do it an ethical way, because there's nothing holding back other people. It's not like the atomic bomb, where you have to have uranium, and you have to have a huge industrial base to do it. This just requires laptops and graphics cards. And so, other countries, other people, other companies will be doing it. And so, if you believe that you can build an ethical framework to do it well, then you believe that you should do it first and do it correctly. And in this case, you could try to mitigate the harm by finding all these bugs and getting them fixed, or fixing the software first before other people do it and actually do it harmfully. Cybersecurity expert Alex Thomas will talk more about what you could do as an individual with all this. Stay with us. This is Forum, I mean a Kip. This summer, switch to Exfinity, and get Wi-Fi so reliable, you can host the world. And now, you can lock in your price for five years, guaranteed. Exfinity. Imagine that. Restrictions apply select plans only. That's g-e-n-e.com. You're listening to Forum, my Mina Kim, or with Alex Domo, Cybersecurity expert and Chief Product Officer at corridor and Computer Science Lecture at Stanford University. He's joining us to talk about Claude Mythos Preview, this Anthropic AI model that is said to be too dangerous to release to the public because it is so powerful that in the wrong hands, it could enable powerful cyber attacks. And you are listeners are joining with your questions about all this and what this means for you. How worried are you about, you know, the arrival of Mythos and other AI models like this that can assist in advanced cyber attacks, but also at the same time in the development of defenses? What are your questions about how, you know, AI finds security vulnerabilities and if you work in AI or IT, how are you preparing for this new stage? Email forum at kqd.org. Find us on our social channels, Discord Blue Sky Facebook or Instagram. Call us at 866-733-6786. The sister writes, "You're talking about cyber attacks on a large scale, with large companies or countries, but what about me? Should I be worried about people hacking into my personal computer or phone or something?" And I guess we should always be worried about that, but what can we do, Alex? Okay, so about Mythos, nothing. That's not, I mean, that's not something that individual people should be dealing with. The way normal people are hacked in 2026 is the same way normal people are hacked in 2016 and probably actually 2006 and maybe even 1996. The way normal people are hacked, the number one way is because they use the same password in every single website all day. That is the absolute number one way that they lose their personal information. I've got to have a couple of these. I feel like I need to go back and find where I've repeated it. You did not have to say that on the air. Oh God. We should have this conversation privately. Don't make any more admissions. I'm using a password. We're live. I don't know if you knew that. This is live radio. So I'm just saying I get it, you know, the back in the day. You know, that was what you did when you started getting overwhelmed by all the passwords you had. Yeah, yeah. Nino123 is not a good password. So go get a password manager. I like one password. Especially if you have different kinds, especially for a family, right? Because you can share things with the family. If you don't want to do that, especially if you're like in one ecosystem, like if you're only in the Apple ecosystem, or you're only in the Google ecosystem, like you're only an Android and Chrome, then you can use Google's password manager or Apple's password manager. But if you're across a bunch of different platforms, I use one password, especially for families, but get a password manager and put all your passwords in that. Have it generate random passwords and then have one really good password. And then you can write it down. I know people say don't write down passwords, but that's really stupid. Because nobody can steal the password in your pocket from Russia, right? If it's in your wallet or your purse, they can't reach from 5,000 miles away and take it out of your wallet or purse. Nobody mugs you for your password, right? That's not how it works. And so it's fine to write it down and put it in your pocket and put it in your wallet and then type it in every once in a while in your password manager and use the biometrics. That's the number one way. If you're worried about malware and stuff, the other thing you can do to simplify your life is if you don't find yourself using lots of programs that you are actually like big programs like Word and Stuff, is you can use a Chromebook. Like the most secure computer you can buy is a Chromebook. Most people just spend all day in a web browser. And so Chromebooks are actually really good for that. If you use Gmail and Google Docs all day and such, then there's a reason why like my kids middle school gives them all Chromebooks and then they drop it and they just give them another one and then they smear it with peanut butter and they just give them another one, right? Like they're super cheap and they don't have any memory locally, everything's in the cloud. So anyway, if you if you have a Chromebook and use a password manager, then like it's basically almost impossible to get hacked yourself. I can't promise the rest of the world, but that's nothing about you can do about that. That's for on the rest of us that nerds to try to fix that problem. Yeah. The other thing is to constantly update our software, right? Like pay attention to the software update alerts or automatically have that happen. Sure. But that's that's why I'm saying you get Chromebook because then you don't have to do that. Yeah. Yeah. Yeah. Well, this list are right. So I guess we didn't have to wait for quantum computing for most digital security to be rendered obsolete. It's really only a matter of time until the wrong person gets their hands on this sort of thing, not to mention governments using tools like this to improve their spyware. You already touched on what the industry needs to be doing here, but do you want to just help us understand what this really means for, you know? Yeah. I mean, the quantum thing is like I feel like it's nuclear fusion. I'm going to be 95 in both fusion and quantum computing and it can be 10 years away, right? So yeah, what industry needs to do here is, okay. So if you're one of the five listeners here, who's a CISO or CTO or CEO of a public company, this is what you should be doing. One, we need to as companies, we need to move to the ability to patch very, very quickly. What's going to happen over the next couple of years is the pace of vulnerability discovery and patching is going to is going to happen much more quickly. And so we both need to reduce our attack surfaces as companies and we need to move to the ability to patch systems much quickly. That means generally moving to much more femoral production systems. So moving away from things like physical servers and virtual machines and to containers and such. So and, you know, and serverless architectures. So those the nerds in the audience will know what I'm talking about. Second is we have to shift right on our defenses. So what we're going to end up is in a world where a much broader set of companies have to deal with brand new vulnerabilities and brand new exploits. We call those zero day exploits in the industry. That's a vulnerability or an exploit that's never been seen before in the wild. This used to only be something you had to worry about if you were at a really high-end company if you're at like a defense industrial-based company, oil and gas, a big bank, a really big tech company, a utility, something like that. And now it's going to be everybody has to worry about that because it's going to be so easy for bad guys to find new bugs and then to create new exploits, create new malware. You do not have to be targeted by the People's Liberation Army anymore. You can be targeted by a 19-year-old in St. Petersburg because they can create their malware. They don't have to use something off the shelf. And so that means you have to think about defense much deeper in your network and you have to build tripliers through your network and you're going to have to have AI defense. Because the other things happening as we talked about with attackers automating the kill chain is they get a lot faster in their ability to move very quickly through the network. And so you can't have human beings deciding, "Uh, should I turn off that network?" Device or not? Can I turn off that account or not? They can't be asking for permission. We're going to end up in a future where the attackers are supervising a bunch of AI agents doing all their attack and giving them advice and telling them good job, bad job and defenders doing the same thing. The problem is the defenders have rules and laws and lawsuits and privacy rules and such and the attackers don't care about any of those things. And so that's the complicated part for defenders. Well Douglas on Discord writes, "AI is the first piece of tech that truly seems so nonlinear in how it's developed and impacts the world. As an expert, could you paint a picture of what the AI landscape will look like a decade from now? Where is this heading?" It's a broad question, so let me just ask you maybe a decade from now, but also in the short term, right? Or the shorter term. What are we likely to see in the next couple of years with these models rolling out? Right? What should we be prepared for, you know, for this sort of initial period? I mean, a decade from now, I have no idea. Yeah, so maybe that's still too much. Just tell me about like in the next couple of years what you think we could see because I know you have described it as a period of upheaval. I mean, our product, Roadmap Accordor is three months long right now, right? Because it's like, if you plan beyond three months, everything has changed in our industry. Like I said, it is, he's right. It's completely non-linear because for the first time ever, technology is building technology, right? And like I said, you know, so we talked about this. From my perspective, from a security perspective, a lot depends on which of two futures we're living in. In the optimistic future, the bug curve evens out, right? It flattens out. Because the superhuman capabilities here are the, they end up not inventing entirely new classes of vulnerabilities that at least the types of bugs are the kinds we've seen before. And there's a finite number of them and we're just draining the swamp. The pessimistic future is that these new things invent things that I don't know exist. And the hard part is I can't really guess because I am predicting superhuman capabilities here, right? Or superhuman models that are going to be invented by the models exist right now. And so in the pessimistic view, we are going to have to work with AI to rebuild the systems that our lives rely upon using memory, safe and typed safe languages, using formal models, using work. So this is the problem with software engineering. Software engineering is not really engineering. But we do not engineer software in the way bridge engineers engineer bridges, right? If the golden gate bridge was built like software, it would have fallen down within, you know, while it was being built, right? Like, you're not allowed to build anything in the physical world and the way we build software. And what it might be is that now we have to build software in the way we build bridges in the way we build cars and the way we build anything in the physical world. So that is my possible prediction is that we have to change how we build. And that that used to be impossibly expensive. And now with AI, it might actually be doable because the the amount of person hours that it takes is doable with AI. Yes, that makes sense. I guess what I was kind of wondering is what some of the headlines could be, right? In the next couple of years, are we going to hear such and such company? You know what I mean? Like that sort of more what I was thinking about in terms of. Well, like I said, I mean, one of the things that's happened already is we've had breach after breach after breach and unfortunately they haven't made the headlines. I mean, this is one of the, I guess one of the crazy things is I don't have to tell you in the news business. It's just the news has become nuts, right? I mean, we have so many things going on at once. But there have been what's happened is the financially motivated ransom reactors. So there's this group called scattered lapses hunters. And if that sounds like a weird name, it's because it's a malgroom of three different groups. So shiny hunter scattered spider and lapses were three big ransomware groups that all got together and decided to build this like super group, right? Like, you know, like Temple of the Dog for the rest of my 90s alt rock fans out there. And they have broken into something like 400 organizations over the last year, which is an amazing pace, right? For a financially motivated actor campaign. And you know, if you don't work in cyber, you've never heard about it. And so that is having like a, you know, a significant drag on the economy as well as a big impact on the privacy of individuals. And so I think I don't know if there'll be headlines, but you might just have like a constant increase in the background noise of the amount of chaos that there is for normal companies who, you know, who try to do the right thing, but are facing kind of just the normal amount of adversity they face online is the same amount of adversity that used to only be faced by Lockheed Martin 10 years ago. Let me remind listeners, you're listening to forum. I mean, Kim, really quickly this up to your seeing. Is it also on essential infrastructure, you know, like, or is it mainly like you said on private less? So, I mean, I think so the ransomware actors ever since the colonial pipeline breach, they have decided not to touch things that are considered essential, right? So you, you know, to remind folks, you know, colonial pipeline was shut down by a ransomware group. And then they figured out that when people mess with America's oil supply, we have a tendency to kill those people, right? Like that is the thing that ends up getting you, JSOCT, that gets you Navy SEALs. And what happened was cyber command under Eric and Sony at the time ended up making those people kind of a special project of theirs. That group ended up like publicly apologizing, releasing the key saying we're so sorry that we attacked a critical infrastructure supplier. Now, those people, they broke up publicly, those people ended up, you know, creating their own new ransomware groups. But since then, you have seen ransomware groups avoid US critical infrastructure because they do not want to end up with people kicking in their doors. That being said, I think, you know, obviously if the US, what we have seen attempts by Iran to go after a critical infrastructure because of the Iranian war, there's not been any good, successful, you know, the biggest thing is they attack striker, which is a significant maker of medical devices. I wouldn't consider them a critical infrastructure, but they are an important company. I think what's going to happen now is if you're a critical infrastructure company, if you're a utility or something, because of the AI stuff, you're going to have to really rely upon really old school protections like air gaps and such because it's going to be very difficult to protect operational technology networks against this kind of attack. That's right, right. So I worry about the companies that on Thropic is giving mythos access to. How do we know the ethics of Google, for example, matches and Thropics? Matt in Oakland writes, "Could in Thropic create an agentic version of mythos?" If I'm saying that right, the tool that companies could use to automatically identify and close vulnerabilities in real time. I mean, I think that's exactly what mythos is. Is it generating patches for these folks? As for Google, I mean, Google's public cutting-edge models are probably as good as mythos. It's interesting that when they say they gave access to Google, I expect the people they gave access to was actually mandant, which is the security consulting team within Google. So when they say Google, I expect it is not the site of Google that competes with Anthropic. I was actually surprised to see Google's logo there because Google is a direct competitor of Anthropic on the AI site. Gabriel writes, "Are you concerned about the children or grandchildren of mythos finding vulnerabilities in other structured systems like biological ones or less structured systems like supply chains or national defense mechanisms?" That's a fascinating question. Yeah. So this is not my area of expertise, but there are a number of people I actually have colleagues at Stanford who study the bio-awarefare risks of AI. They definitely are concerned about a. Obviously, there's always a risk of chemical warfare and biological warfare, but of now just some random grad student in chemistry now being able to use AI to do much terrible things. That is definitely, I think, a risk. And it is something that if you read the model cards of. these systems they are directly tested for. It is something that people will be concerned about for a while. And so there's a lot of work that has gone into making sure that the foundation models, but again the open weight models, you can do a thing called obliteration with an A, where you remove the safety protections. So that does concern me as the open weight models get better and better that you would be able to train them to remove those protections. One last question from Greg, does all this push everything toward more centralization or towards decentralized systems? I mean, that's a pretty broad question. I mean, it's a great question. I haven't thought about it too much. I think right now it's towards centralization. I think in the long run, like I said before, this is just math. So I mean, my Stanford students, I asked them how many have taken, I have a class of about 125 students. And I think they raised their hands, I think like 80 of them had taken the interdi-AI class. I believe in that class, they build a toy LLM. So like all of them graduate with the ability to effectively recreate what these folks are doing in the labs at a much smaller scale. It's just math. And they're unlike an atomic bomb. You don't have to dig uranium out of the ground. You don't need huge centrifuges. You just need GPUs. And so containing the knowledge necessary to do fundamental AI research is effectively possible. And so I do think in the long run, we end up with massive decentralization because the open weight stuff is probably the future. The foundation models are going to be great. And forever, we will have the anthropics and opening eyes. And Google's in the world, you'll have people doing this stuff in big labs. And you'll have big companies paying them because they want like super reliable and specialized models. But the stuff you can do, I run open weight stuff at home. The stuff you can do with the open weight models is actually pretty incredible. It's equal to what you could do last year with the expensive stuff. And so I think that decentralization we'll see because of the open weight models is pretty incredible and also scary. Alex Thomas is computer science lecturer at Stanford University, Chief Product Officer at Cordor. Thank you so much for sharing your cybersecurity expertise with us. Alex really appreciate it. Thank you so much, Mina. And also thanks to our listeners for their insightful questions. And my thanks as well to Anna Dale. I'm Anna for producing today's segment. You've been listening to Forum. I'm Mina Kim. Funds for the production of Forum are provided by the Generosity Foundation and the members of KQED. The summer, switch to Xfinity and get Wi-Fi so reliable, you can host the world. And now you can lock in your price for five years guaranteed. They have helped drive more than 40 breakthroughs across various diseases including multiple sclerosis, cancer, vision loss and food allergies. But their greatest breakthroughs are the one's patients feel, whether it's getting back to familiar routines or creating new ones. That's g-e-n-e.com. Affinity. Imagine that. Restrictions apply, select plans only.

Podcast Summary

Key Points:

  1. Anthropic's new AI model, Claude Mythos, can find and exploit software vulnerabilities faster and more effectively than the best human security experts, uncovering flaws missed for decades.
  2. Mythos is currently only available to a few large companies and open-source projects to fix bugs before attackers can exploit them, but fears persist about its potential misuse by bad actors for cyber attacks on critical infrastructure.
  3. Cybersecurity expert Alex Stamos warns of a race
  4. Stamos highlights a significant uptick in serious cyber attacks, partly due to AI, and calls for independent academic evaluations of Mythos to verify its capabilities and for broader access to help startups.

Summary:

The discussion centers on Anthropic's new AI model, Claude Mythos, which represents a major leap in cybersecurity by identifying and exploiting software vulnerabilities faster and more effectively than human experts. Alex Stamos, a cybersecurity expert from Stanford, explains that Mythos can find flaws in systems that have been repeatedly examined, such as a 23-year-old bug in the Linux kernel missed by top agencies. While Mythos is currently restricted to select large companies and open-source projects to patch vulnerabilities before attackers can use them, there is concern about its potential for misuse.

Stamos notes that AI is already being used by attackers to automate parts of the cyber kill chain, from reconnaissance to exploitation, and as open-weight models catch up, they could allow undetected attacks. He emphasizes a critical race to fix flaws before these models become widely available. Stamos suggests that the impact depends on whether the pool of bugs is finite or if future models will uncover new ones, potentially forcing a fundamental shift in how software is built.

He advocates for independent academic evaluations of Mythos and broader access to support startups, while acknowledging that AI also aids in writing patches.

FAQs

Mythos can find and exploit security vulnerabilities faster than humans, identifying thousands of flaws instead of dozens. It is considered a large step change, surpassing even the best human testers.

It helps defenders find and patch flaws, but attackers can use similar AI to automate the entire cyber kill chain—from finding flaws to launching attacks—making cyber threats faster and cheaper.

Mythos is significantly more capable than Opus, which already found a 23-year-old Linux kernel bug missed by experts. Mythos is rumored to require 10-20 times more compute per token than Opus.

Anthropic is being careful to prevent misuse and is capacity-constrained due to Mythos's high computational demands. It is provided only to large companies and key open-source projects to find and fix bugs securely.

Open-weight models, which can run locally without logs, could be used by attackers to find flaws and launch attacks without leaving evidence for law enforcement, unlike models hosted by companies like Anthropic or OpenAI.

There has been a significant uptick in serious attacks, including financially motivated ransomware and extortion, likely due to AI making attackers more effective at their jobs.

Chat with AI

Loading...

Pro features

Go deeper with this episode

Unlock creator-grade tools that turn any transcript into show notes and subtitle files.