Particle.news

Tests Show Anthropic’s Mythos Can Autonomously Run Multi-Step Cyberattacks

Regulators are pushing banks to test defenses under a partner-only rollout.

Overview

  • The U.K. AI Security Institute, which released results Monday, said Mythos completed a 32-step corporate takeover simulation in 3 of 10 tries and carried out multi-stage attacks when given network access in controlled tests.
  • Anthropic says the preview model has uncovered thousands of high- and critical-severity flaws across major operating systems and web browsers, including a 27-year OpenBSD bug and a 16-year FFmpeg vulnerability.
  • U.S., U.K., and Canadian officials have briefed financial firms on potential risks, with Treasury Secretary Scott Bessent and Fed Chair Jerome Powell holding an April 7 emergency meeting with CEOs of the biggest U.S. banks.
  • Anthropic is keeping the model out of public release and is offering access only through Project Glasswing to vetted companies such as JPMorgan and major tech and cybersecurity vendors for supervised evaluations.
  • Experts warn banks’ shared, legacy-heavy tech stacks could let AI-found exploits spread across multiple institutions, while others argue the urgent task is patching, since most newly identified weaknesses remain unfixed.