What do cybersecurity experts criticize about Claude Mythos?
Cybersecurity critics admit that Claude Mythos is undoubtedly sophisticated. However, the marketing claim that it can reliably cripple productive IT systems exceeds its actual capabilities.
In addition, security experts complain – for example in podcasts – about Claude Fable’s excessively restrictive security mechanisms: requests to summarize a security-relevant blog post or even to spell the word “exploit” would be downgraded to the significantly weaker Opus 4.8 model. This would make even everyday tasks in information security unnecessarily difficult.
Other experts warn that frontier AI models are prone to false positives. The more fundamental criticism is that detecting more vulnerabilities more quickly does not solve the actual problem, namely reliably fixing security gaps or preventing non-technical attack vectors such as social engineering.
How should CISOs respond to myth?
The intelligence agencies of the Five Eyes (US, UK, Canada, Australia and New Zealand) warn that cutting-edge AI models like Claude Mythos will “fundamentally transform both offensive and defensive cyber capabilities” – over a period of months rather than years.
“While AI will help us improve cyber defenses over time, it also increases the speed, scale and sophistication of cyber threats,” the group said in the statement. Companies should therefore use AI to improve their defense mechanisms as part of broader strategies to strengthen cybersecurity resilience.
However, most companies are far from prepared for what this means for their threat models, warns one expert. “We now have AI systems that can map realistic attack paths across software, vendors and critical infrastructure faster than human attackers can capture them,” explains Joe Hubback, partner and CISO at consulting firm Elixirr and a former McKinsey partner. Because “myth-class capabilities” are about to be introduced widely commercially, they are no longer “a niche research problem,” he adds. Rather, it is now a factor that every company must include in its threat model, said the expert.
A report from the Cloud Security Alliance also warns that AI has drastically shortened the time between the discovery of a vulnerability and its exploitation. This means that traditional security models based on “patch and respond” are outdated. Rather, companies should prepare for continued waves of vulnerabilities uncovered by Project Glasswing and other sources using AI.
“The capabilities observed at Mythos will soon become more widely available, dramatically increasing the number and frequency of complex, novel attacks that organizations face,” the alert says. Security leaders would therefore need to shift their defense strategies to a “myth-ready” approach based on continuous vulnerability management, faster prioritization and improved response to security incidents. (tf)
This article is based on a contribution from CSO.
