AI finds thousands of zero-day exploits... including in FreeBSD.

Anthropic Claude Mythos...


Quote: "Mythos Preview, Anthropic claimed, has already discovered thousands of high-severity zero-day vulnerabilities in every major operating system and web browser. Some of these include a now-patched 27-year-old bug in OpenBSD, a 16-year-old flaw in FFmpeg, and a memory-corrupting vulnerability in a memory-safe virtual machine monitor."
 
counterpoint: this is marketing bullshit by a company that lies to prop up its value, and acts like a protection racket


they are drowning us in slop reports, and then trying to sell us slop-based solutions to manage all of it. shit behavior from garbage capitalists.
 
yes, i'm sure if you sift through enough of the sewage, you'll find one or two pieces of corn. nothing about this is healthy or sustainable or worthwhile.
 
Yes I just realised I may have been guilty of re-posting the same thing... although that was specifically about freebsd.
I thought the articles about mythos were interesting anyway. It even made the BBC evening news here, which is pretty unusual...
 
yes, i'm sure if you sift through enough of the sewage, you'll find one or two pieces of corn. nothing about this is healthy or sustainable or worthwhile.

I'm talking about running CC on my own code by myself. There was less than 50% BS in there so far.

I have no experience being the target of third parties doing it on my code.
 
There should be a notable increase in compromised systems worldwide due to Claude hacking business. Is there any statisctical graph about it?

I don't think it works like this. Software exploitation is a method that requires human reasoning naturally. Any hole that can be found with software only can't be impressive. The knowledge to find it already existed.
 
Correct me if I'm wrong, but Anthropic doesn't publish the holes right now, and the reports are from a LLM not even accessible by the public yet?
 
Correct me if I'm wrong, but Anthropic doesn't publish the holes right now, and the reports are from a LLM not even accessible by the public yet?
They are just bug-hunting for p&r? It wouldn't surprise me. Find public software and run professional security audits
 
"i have a scary bogeyman of an AI that will end computer security!!" okay, can we see it? "no".

again, this is just corporate asswipes trying to force their way in to make you pay attention to their slop. it's a show of force by technocratic fascists.
 
Correct me if I'm wrong, but Anthropic doesn't publish the holes right now, and the reports are from a LLM not even accessible by the public yet?
yes, but "The model will be used by a small set of organizations, including Amazon Web Services, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorgan Chase, the Linux Foundation, Microsoft, NVIDIA, and Palo Alto Networks, along with Anthropic, to secure critical software."

So before release it, they will patch important software infrastructure.
 
From what I heard I'm not sure they intend ever to release it. Instead they will sell it to industry partner companies to identify and fix exploits, but will not release it for general use. That was the gist of the news report I heard earlier. They consider it too dangerous to put it out on general release.

I'm sure the opposition is working on the same kind of thing...
 
Back
Top