惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

S
Security @ Cisco Blogs
The Last Watchdog
The Last Watchdog
Application and Cybersecurity Blog
Application and Cybersecurity Blog
aimingoo的专栏
aimingoo的专栏
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
PCI Perspectives
PCI Perspectives
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
月光博客
月光博客
V
Visual Studio Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
T
Tailwind CSS Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
L
LangChain Blog
B
Blog RSS Feed
小众软件
小众软件
N
News | PayPal Newsroom
Attack and Defense Labs
Attack and Defense Labs
Microsoft Azure Blog
Microsoft Azure Blog
V
Vulnerabilities – Threatpost
The Hacker News
The Hacker News
T
Tor Project blog
A
Arctic Wolf
Jina AI
Jina AI
Hacker News: Ask HN
Hacker News: Ask HN
F
Fortinet All Blogs
Cloudbric
Cloudbric
S
Secure Thoughts
L
LINUX DO - 热门话题
博客园 - 司徒正美
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
S
Security Affairs
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
J
Java Code Geeks
P
Privacy International News Feed
AWS News Blog
AWS News Blog
S
Securelist
TaoSecurity Blog
TaoSecurity Blog
AI
AI
O
OpenAI News
C
Cyber Attacks, Cyber Crime and Cyber Security
K
Kaspersky official blog
T
The Blog of Author Tim Ferriss
大猫的无限游戏
大猫的无限游戏
Google DeepMind News
Google DeepMind News
Know Your Adversary
Know Your Adversary
P
Palo Alto Networks Blog
T
Tenable Blog
Last Week in AI
Last Week in AI
WordPress大学
WordPress大学
S
SegmentFault 最新的问题

Hacker News - Newest: "AI"

AI can't read an investor deck AI as an attorney? Student uses ChatGPT, Gemini to sue UW over alleged racial discrimination Hacking MCP Servers in AI Systems – The Rug Pull: Tool Changes After Approval GitHub - MeepCastana/KubeezCut: Free Web based video editor GitHub - GenAI-Gurus/awesome-eu-ai-act: Curated tools, official sources, OSS, templates, and guides for EU AI Act compliance. Can AI judge journalism? A Thiel-backed startup says yes, even if it risks chilling whistleblowers Coming soon: 10 Things That Matter in AI Right Now DARPA built an AI to fact-check enemy weapons claims What explains heterogeneity in AI adoption? When AI Meets Muscle: Context-Aware Electrical Stimulation Promises a New Way to Guide Human Movements - Department of Computer Science AI Changed How We Build. It Did Not Change What Matters. Linux rules on using AI-generated code - Copilot is OK, but humans must take 'full responsibility for the… Meta spins up AI version of Mark Zuckerberg to engage with employees Code Mode: Let Your AI Write Programs, Not Just Call Tools | TanStack Blog GitHub - Delavalom/graft: Go framework for building AI agents. Type-safe tools, multi-provider (OpenAI, Anthropic, Gemini, Bedrock), zero vendor SDKs. India's TCS tops estimates, says new AI models did not dent services demand Gen Z's fading AI hype Strong feeling: we are in a folded AI reality GitHub - machinarii/total-recall-catalog: A reference catalog of latest knowledge retrieval, memory & RAG systems GitHub - mensfeld/code-on-incus: Give each AI agent its own isolated machine with root, Docker, and systemd. Active defense detects and stops threats automatically.. Quantization, LoRA, and the 8% Problem: Benchmarking Local LLMs for Production AI Iran war: We spoke to the man making Lego-style AI videos that experts say are powerful propaganda Powell, Bessent discussed Anthropic's Mythos AI cyber threat with major U.S. banks GitHub - immartian/bellamem: Persistent belief-graph memory for AI agents. Retrieves decisive context by importance — not recency, not RAG, not /compact. recursive-mode: The Repo-Native Operating System for AI Engineering After the attack on Sam Altman's home, will AI CEO's go on the offensive? The biggest advance in AI since the LLM Opus 4.6 vs GPT 5.4 One Prompt Unity World Generation Test “AI polls” are fake polls Client Challenge Can AI be a 'child of God'? Inside Anthropic's meeting with Christian leaders How to Switch AI Chatbots and Why You Might Want To GitHub - MattMessinger1/agentic_refund_guardrail: Safe refund policy layer for AI agents — Python + TypeScript. Same behavior, shared tests. Adam/papers/emergent_values_whitepaper.md at master · strangeadvancedmarketing/Adam Ask HN: How do you stop playing 20 questions with your AI coding tools How far can automation and AI support psychotherapy? - @theU GitHub - stagas/rtdiff: realtime git diff gui and AI-assisted commits A Mac Studio for Local AI — 6 Months Later A History of the Early Years of AI at the University of Edinburgh Why AI Coding Tools Still Feel Stuck on Localhost MSN AI Datacenters Are Becoming Strategic Targets twitter.com Penn Researchers Use AI to Surface Unreported GLP-1 Side Effects in Reddit Posts Show HN: MoodSense AI (ML and FastAPI and Gradio, Deployed on Hugging Face) Moodsense Ai - a Hugging Face Space by aman179102 AI models are terrible at betting on soccer—especially xAI Grok GitHub - xialeistudio/echoic GitHub - HimashaHerath/github-dev-wrapped: AI-powered weekly GitHub activity reports deployed to GitHub Pages GitHub - alejandrobalderas/claude-code-from-source: Architecture, patterns & internals of Anthropic's AI coding agent — reverse-engineered from source maps AI and Tech brief: Ireland ascendant GitHub - Titovilal/context0: Context0 - Never Surrender Training for a Marathon with an AI Coach: What Worked and What Didn't Cyber Pulse: Agentic Intel - Apps on Google Play I Built an AI PR Reviewer That Catches Bugs by Not Looking for Bugs Gen Z workers are so fearful AI will take their job they’re intentionally sabotaging their company’s AI rollout | Fortune How AI Is Reimagining the Game of Golf–For Both Players and Courses GitHub - nattergabriel/reseed: A CLI tool for managing and distributing agent skills across projects Is SVG the final frontier? My AI workflow evolved from prompts to a near-autonomous workflow MLSharp Help - 3DGS Viewer & Generator I put my cognitive field based AI's runtime on GitHub Is Numble the first AI-proof game? A3: Kubernetes for autonomous AI agent fleets | Emergent Principles Deepali Vyas ("The Elite Recruiter") GitHub - msmarkgu/RelayFreeLLM: A restful API designed to route user prompts to various AI model providers. Unionized ProPublica staff are on strike over AI, layoffs, and wages Unleashing the Advantage of Quantum AI We're heading for an AI-fueled 'dementia crisis,' brain scientist warns The AI-Assisted Breach of Mexico's Government Infrastructure [pdf] GitHub - stef41/lmscan: 🔍 Detect AI-generated text and fingerprint which LLM wrote it. Open-source GPTZero alternative. Zero dependencies, works offline. MSN GitHub - visionscaper/collabmem: Enabling long-term collaboration with Agentic AI - building up episodic and world model memory over time with in-context awareness We gave an AI a 3 year retail lease in SF and asked it to make a profit | Andon Labs AI Code is Hollowing Out Open Source, and Maintainers are Looking the Other Way What leaked "SteamGPT" files could mean for the PC gaming platform's use of AI AI is the boss at this retail store. What could go wrong? GitHub - Wuzu11517/agentic-proxy: Local proxy meant to help reduce With Drones, Geophysics and ArtificiaI Intelligence, Researchers Prepare to Do Battle Against Land Mines A Single Operator, Two AI Platforms, Nine Government Agencies: The Full Technical Report 在 Steam 上购买 FriedrichAI: Offline AI 立省 10% GitHub - inevolin/resume-cli: Hit Claude usage limits? Resume any AI coding session elsewhere. Switch tools at zero friction. GitHub - atripati/ark: AI Runtime Kernel — a context operating system for AI agents. Eliminates tool bloat, loads only what’s needed, and gives LLMs their reasoning space back. How to Build a Secure AI PR Reviewer with Claude, GitHub Actions, and JavaScript This Startup Wants You to Pay Up to Talk With AI Versions of Human Experts Intel Arc Pro B70 Brings 32GB VRAM to Local AI for $949 WordPress 7.0: The Good, the AI, and the Still Missing AI on the couch: Anthropic gives Claude 20 hours of psychiatry IatroBench: Pre-Registered Evidence of Iatrogenic Harm from AI Safety Measures AI Agents Know About Supabase. They Don't Always Use It Right. The history and future of AI at Google, with Sundar Pichai Inside an AI‑enabled device code phishing campaign How Meta Used AI to Map Tribal Knowledge in Large-Scale Data Pipelines AI for Systems: Using LLMs to Optimize Database Query Execution Forecasting the Economic Effects of AI Introducing Tinker: Play with AI, bring your ideas to life AI sheds light on an ancient gaming mystery People really hate AI but not as much as Iran—or Democrats | Fortune What is an AI Product Engineer? Phoebe Gates wants her $185 million AI startup to succeed with 'no ties to my privilege or my last name': 'I have a chip on my shoulder' | Fortune
Cutting Through the Mythos: What AI Vulnerability Discovery Actually Means for OT
TheWiggles · 2026-05-01 · via Hacker News - Newest: "AI"

Jori VanAntwerp

For over two decades, Jori has enabled industrial and IT organizations to be successful in reducing risk, increasing compliance, and improving their overall security efforts. He has had the pleasure of working with companies such as Gravwell, Dragos, CrowdStrike, FireEye, McAfee, and is now CEO & Founder at EmberOT, a cybersecurity startup focused on making security a reality for critical infrastructure.

This is Part 1 of a 2-part blog series focused on AI vulnerability discovery in OT. Anthropic’s Claude Mythos Preview has the security industry in the middle of an unusually loud moment. Here’s what the headlines are missing for operational technology.

The Mythos coverage has been loud, contradictory, and short on practical guidance for OT. Anthropic has done genuinely impressive work. The skeptics are doing useful work cutting through the hype. What the OT community needs is a piece that separates the signal from the noise, written for the OT defenders, asset owners, and operators trying to figure out what Mythos actually means for their environment, from the perspective of someone who has worked in security and OT for over two decades.

On that front, here is the fact most of the Mythos coverage missed.

The UK’s AI Security Institute (AISI) tested Claude Mythos Preview against the same kinds of attack ranges it had been used to evaluate prior frontier models. Against IT-flavored ranges, Mythos completed the full 32-step “The Last Ones” enterprise simulation end-to-end, the first model ever to do so. Against AISI’s “Cooling Tower” operational technology range, Mythos failed. The model got stuck on IT-layer sections rather than OT-specific controls, but the outcome is the same: the most capable cyber-offensive AI model publicly evaluated to date could not get through an OT range.

That is not a vendor pitch, but the UK government’s own published evaluation. (Source: AISI cyber range evaluation summary, April 2026)

Anchor the rest of the conversation on that fact. Mythos is a real capability advance. The trajectory matters. And the OT story is meaningfully different from the IT story being told.

What the Headlines Are Stripping Away

Anthropic claims Mythos has identified thousands of zero-day vulnerabilities across major operating systems and web browsers. They have committed $100 million in usage credits and $4 million in donations to open-source security organizations through Project Glasswing, the controlled-access program that lets ~50 large software vendors and security partners use Mythos defensively. (Source: Project Glasswing announcement, Anthropic)

The trajectory is also real. AISI’s Chief Technology Officer Jade Leung has stated that agentic AI autonomy is doubling roughly every couple of months. Whatever Mythos is today, the next class of model will be more capable. (Source: AISI commentary, April 22, 2026)

The headlines have stripped some important asterisks. Bruce Schneier, writing in IEEE Spectrum with Barath Raghavan of Fastly, called Mythos “a real but incremental step, one in a long line of incremental steps,” and warned of Shifting Baseline Syndrome: people overcorrect on individual announcements and undercorrect on the long-term trajectory. (Source: Schneier and Raghavan, IEEE Spectrum, April 2026)

The technical claims have asterisks too. The “thousands of zero-days” headline number extrapolates from a 198-report human validation sample. The Firefox exploitation testing was conducted against a content-process harness without the browser’s sandbox or other defense-in-depth layers. AISI itself is explicit that its evaluations were run against systems with weak security postures, and that public testing does not show Mythos can defeat hardened, well-defended networks with active monitoring and incident response. The model can attack vulnerable systems. Whether it can attack mature ones is unproven.

And then there is the unauthorized access. Within days of the announcement, a group accessed Mythos through a third-party contractor’s credentials and a guessed URL pattern. Anthropic confirmed the breach. The “controlled access” pitch took a credibility hit at the worst possible time.

The capability is real. The OT-relevant version is more nuanced than the IT-flavored coverage suggests, and that nuance is where the rest of this piece lives.

Why Mythos Hits OT Differently

Mythos was trained on the open internet. OT software, by and large, is not on the open internet.

Schneier and David Lie of the University of Toronto made this point bluntly in The Globe and Mail: software outside the training distribution, including industrial control systems, medical device firmware, and older embedded systems, is exactly where Mythos is least likely to help defenders. Schneier specifically called out “industrial equipment that are rarely updated or can’t be easily modified” as a category for which the patching-driven model breaks down. The Cooling Tower failure is the operational evidence.

The Glasswing partner list reinforces the point. The ~50 organizations Anthropic has granted access to are large software vendors, browser makers, cloud providers, and IT-focused security companies. Schneider, ABB, Emerson, Honeywell, Yokogawa, GE Vernova, Mitsubishi, and the rest of the OT vendor ecosystem are not on the list. Glasswing v1 is built around code producers who can patch and push updates downstream. OT does not work that way. Most of the firmware in your plant, substation, or pipeline is not in the training set, not in the partner list, and not in the patch pipeline anyone is currently building.

Traditional OT and Modern OT Are Not the Same Conversation

Worth naming a distinction the broader industry tends to flatten. The Mythos story lands very differently across two segments of OT:

Traditional OT (oil and gas, energy, water, utilities, much of heavy industry). Limited-connectivity environments. Decades-old firmware not in any model’s training set. Patch cycles measured in years rather than weeks. For this segment, Mythos in the short term is largely irrelevant. The systems are not internet-reachable, the firmware is not in the training distribution, and the threat model that drives the Mythos coverage does not map cleanly onto the actual environment.

Modern OT and converged manufacturing. Cloud-managed control planes. IT/OT convergence at the edge. MES and ERP integration. Vendor remote access. Cloud historians. Edge computing platforms. Increasing agentic AI adoption inside operational workflows. For this segment, Mythos-class tooling is much more relevant, because the IT components in scope are in the training distribution and are reachable.

These are not the same security conversation, and conflating them produces bad advice in both directions. Telling a traditional utility to panic about Mythos is unhelpful. Telling a modern manufacturer that Mythos does not apply because “OT is not on the internet” is dangerous. The right answer depends on which segment you actually operate in, and most asset owners need to be honest about which side of this line they sit on.

Centralized AI in OT Is the Concern Almost Nobody Is Naming

This one deserves more space than it usually gets, because it is the most original part of the OT-specific argument and almost nobody is making it cleanly.

If a frontier model has trained on or modeled your environment, that model becomes a high-value target. A Mythos-class system that knows your PLC topology, your protocol patterns, your normal baselines, and your detection logic is a system an adversary would very much like to access. The Glasswing access incident was a small preview of the larger problem. The more useful AI becomes for defenders, the more useful access to that AI becomes for attackers.

This is not an abstract concern. The architectural choice you make about where AI capability lives in your environment will determine the security of that environment for years.

There is a class of architecture, on-prem, edge-deployed, with environmental modeling that never leaves the customer’s network, that addresses this concern directly. This happens to be the architecture EmberOT is built on. OT organizations should be asking which side of this architectural line their vendors sit on, because the answers will shape the security of their environments for the next decade.

The supply chain for AI tooling, the access control around model environments, and the integrity of the training and operational data are all becoming security-relevant in ways the OT industry has not yet worked through. The community should be talking about this now, not after the first incident.

More Vulnerabilities Found Is Not the OT Bottleneck

A thing every vulnerability scanner has been accused of is true here too: more discovery is not always more security. The OT-specific version of this argument is sharper than the generic version, though.

In IT, “more vulnerabilities found” routes, at least theoretically, to a patch pipeline. In OT, it routes to a backlog with a 12-24 month service-window dependency. Patching a PLC is not patching a web server. Patch cycles for industrial controllers run on validation requirements, outage windows, safety recertification, and vendor coordination. ARC Advisory Group has framed it directly: Project Glasswing highlights how AI-driven vulnerability discovery could compress threat timelines and increase risk for industrial and OT environments. The discovery side gets faster. The mitigation side does not.

The bottleneck in OT security is not finding flaws. The bottleneck is doing something useful with the flaws once you find them. Mitigation in OT often takes the path of compensating controls, network segmentation, restricted communication, and continuous monitoring rather than direct patching, because the direct patch is months away or impossible.

This is also where the regulatory direction is moving. FERC’s CIP-015-1, which became effective in September 2025, mandates Internal Network Security Monitoring for North American utilities. The bet the regulator just made is that mitigation through monitoring matters more than discovery through scanning. We have written about CIP-015-1 in more detail elsewhere for readers who want to dig in.

The answer to the OT discovery firehose is not less discovery. It is better triage. Our OT Vulnerability Intelligence Report lays out a Five Lenses framework for contextual prioritization (Exploitability, Network Reachability, Asset Criticality, Operational Impact, Compensating Controls) and a Three Pillars framing for OT defense (segmentation, patching, content validation and monitoring). The frameworks exist. They are useful. And they are exactly the answer to the diagnosis Mythos-driven discovery sharpens: more findings without context is friction, not security.

On-Site AI in OT Is Hard for the Same Reasons Everything Else Is Hard

There is an emerging pitch around deploying agentic AI directly in OT environments to monitor, hunt, and respond. The pitch is appealing on a slide. The reality is harder.

The same constraints that limit traditional security tooling in OT apply to running a frontier model on or near operational equipment. Limited-connectivity sites cannot reach cloud-hosted inference. Hardware support for running large models locally is uneven. Vendor restrictions on what can be installed on production systems are real. Operational risk tolerance is low, and rightly so.

These problems are solvable, but they are the problems that have shaped OT security for two decades. AI does not exempt itself from the operational realities of the environment it is being asked to run in. Anyone pitching otherwise is selling a slide deck. This challenge deserves its own deeper conversation, because the solutions will be substantive when they arrive.

What This Sets Up

A few things are genuinely different than they were six months ago. The compression of vulnerability discovery timelines is real. The mitigation bottleneck is widening rather than narrowing. The architectural choices made in the next eighteen months will shape OT security for the decade after. The technology shifts are real, and they matter.

The most important shift, though, is about people, not technology. The skill set required to defend OT is changing, and the analysts who get this right will be the ones who outlast any specific AI capability claim, including this one. That is the subject of Part 2 of this series, so stay tuned for that article next week.

~Jori 🤘🔥

Become a Subscriber

EMBEROT WILL NEVER SELL, RENT, LOAN, OR DISTRIBUTE YOUR EMAIL ADDRESS TO ANY THIRD PARTY. THAT’S JUST PLAIN RUDE.