Claude Mythos’s Fast Hacks

Date

Author

By Casey Moffitt
Portrait of Maurice Dawson

The cybersecurity discoveries that Anthropic’s latest artificial intelligence model, Claude Mythos, has made aren’t surprising, but the speed at which it made them is shocking, according to Illinois Tech Associate Professor of Information Technology and Management Maurice Dawson.

“As far as it’s abilities, it’s basically red teaming [testing a system’s cybersecurity effectiveness], but far more efficiently,” he says. “It didn’t find anything new. The issues are there no matter what. If you look at multiple operating systems, there is a lot that’s exploitable.”

A preview of Mythos was able to find remote code vulnerabilities in a variety of operating systems and web browsers. Anthropic representatives claimed that the model found vulnerabilities that experts haven’t been able to uncover over the last 27 years in one unnamed operating system.

Anthropic representatives say that the model will not be released publicly until proper safeguards are in place, but they say that it has been made available to select cybersecurity and tech experts.

Having an AI tool that can find cybersecurity vulnerabilities at enhanced speeds could escalate into a national security issue if it falls into malicious hands, Dawson says.

“It basically gives an attacker superpowers,” he says. “An attacker is looking at costs. How long will it take to get access to a system? How many people is it going to take? If I have a tool that can do the work of 10 or 20 people, and I can attack with a smaller footprint, it is going to be a valuable.”

Should an adversarial state control such a powerful tool, it could mean more successful cyber attacks on the country’s infrastructure, banking systems, health care systems, or other vital computer or security architectures.

“There is more ability to conduct complex tasks such as comprehensive scans, mapping of vulnerabilities, and development of exploits together,” Dawson says. “These would be a collective team effort but with Mythos this is simply a smaller footprint. If this were a nation's government owned systems this collective categorization of Information would be classified.”

Dawson says Mythos is showing us that the speed of AI tools is increasing exponentially, as well as the vast number of vulnerabilities it exposes.

But he also says that the increased computing power available to these models, combined with access to massive amounts of data, are the main factors that make Mythos so powerful.

“I’m not surprised by what was announced,” Dawson says. “AI is not new. The technology they are using has been around for a while.”