I’ve had a bunch of people ask my thoughts on Anthropic’s Mythos. I’ve read the research paper they released and the numbers, and basically I agree with @malwaretech’s take. It’s marketing. The cybersecurity industry is historically very good at marketing cyber pearl harbour and the need to buy magic boxes.
Is Cybersecurity Over?

YouTube

I don't think anybody actually watches videos any more, so here's MWT's core point -

The flagship and lead vuln in the research is a BSD vuln, it cost $20k to discover with Mythos. Anthropic only reached a crash, and the vuln class in 99%+ cases never reaches RCE, just crashes.

So.. cool.. you spent $20k of VC money to find a crash as the flagship vuln. But... uhm... that isn't the end of the world.

The proof is going to be if any of the open source vulns turn out to be important. So far:

@GossiTheDog from a practical perspective what worries me more is time to poc/working exploit for known vulns.

OSS library releases patch, model looks at diff + cve description and drops a working exploit for a couple of hundred $ of compute.

Most companies (at least this side of the pond) are not currently equipped to deal with continuously applying patches for 1-day vulns in prod.
Many large orgs here are proud that they've managed to get on a monthly update cycle

@GossiTheDog to be fair, the current time to poc is in many cases already down ≤ 1 day or so, but this could take some of the skill out of it and make it more broadly available

@GossiTheDog but other than that... yeah hype-marketing playbook 101.

Didn't OpenAI pull the:"oh no it's too powerful, humanity couldn't take it yet so we're not releasing it to the public", stunt with one of their earlier models as well?^^