惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

WordPress大学
WordPress大学
F
Fortinet All Blogs
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
S
Secure Thoughts
SecWiki News
SecWiki News
Hacker News: Ask HN
Hacker News: Ask HN
Google DeepMind News
Google DeepMind News
N
Netflix TechBlog - Medium
Recorded Future
Recorded Future
Hacker News - Newest:
Hacker News - Newest: "LLM"
Webroot Blog
Webroot Blog
Cloudbric
Cloudbric
博客园 - 司徒正美
The Cloudflare Blog
W
WeLiveSecurity
T
Tailwind CSS Blog
V2EX - 技术
V2EX - 技术
H
Heimdal Security Blog
Jina AI
Jina AI
MyScale Blog
MyScale Blog
S
SegmentFault 最新的问题
Apple Machine Learning Research
Apple Machine Learning Research
雷峰网
雷峰网
罗磊的独立博客
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Project Zero
Project Zero
C
CXSECURITY Database RSS Feed - CXSecurity.com
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
博客园 - 【当耐特】
Forbes - Security
Forbes - Security
Last Week in AI
Last Week in AI
G
GRAHAM CLULEY
C
Check Point Blog
P
Proofpoint News Feed
L
LINUX DO - 最新话题
博客园 - Franky
P
Proofpoint News Feed
T
Tor Project blog
S
Security @ Cisco Blogs
Hugging Face - Blog
Hugging Face - Blog
阮一峰的网络日志
阮一峰的网络日志
J
Java Code Geeks
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
宝玉的分享
宝玉的分享
C
Cyber Attacks, Cyber Crime and Cyber Security
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
O
OpenAI News
小众软件
小众软件
云风的 BLOG
云风的 BLOG
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报

Cyber Daily News

Real estate giant Cushman & Wakefield confirms cyber incident, Qilin and ShinyHunters claim attack CrowdStrike expands Project QuiltWorks as more partners join AI security coalition Attackers increasingly turning to trusted security tools to compromise Aussie victims Exclusive: Champion Homes confirms customer data compromised in “cyber event” Australia, Japan commit to partnership to meet cyber security challenges & strengthen cyber defences NSW Treasury cyber incident contained, impact no longer ‘significant’ Report: AI-based data incidents on the rise in Australia WA rental scam surge: Tenants targeted with fake $500 discount trap Aussie Information Commissioner launches Privacy Awareness Week 2026 Unregistered branded text messages to be labelled ‘Unverified’ from 1 July US Federal Reserve outlines AI's influence on the finance sector Exclusive: Major Australian jewellery brand confirms cyber incident Australian government establishes new Cyber Incident Review Board Watch this! Komari server monitor tool abused by hackers Act Now! ACSC warns of active exploitation of cPanel & WHM critical vulnerability Exclusive: Kiwi electrical contractor confirms cyber attack Over 1 in 2 firms have AI privacy concerns: Intuit Exclusive: Prime Properties listed as breach victim by M3rx ransomware Anthropic launches dedicated Claude Security platform to public beta DigiCert launches AI Trust architecture to secure agents, models, and content ‘Rebuilding the enterprise’: How CEOs are preparing for automation Op-Ed: Redefining performance in the AI-powered SOC Ukrainian official advocates for artificial intelligence, autonomous drones for battlefield deployment NZ council cyber attack leads to ID and financial data being exposed ‘Building confidence’: The key to effective AI implementation Vect unveiled: Inside an emerging ransomware group’s affiliate network Exclusive: Gelatissimo confirms unauthorised access, investigates DragonForce hack claims US Department of War launches cyber-focused apprenticeship program CrowdStrike launches Project QuiltWorks to tackle skyrocketing AI-discovered vulnerabilities Australian government stands up new ‘tripartite forum’ to tackle AI challenges in the workforce Aussie ice-cream franchise Gelatissimo suffers alleged hack by DragonForce Report: Aussie small businesses doing it tough as job scams double, losses rise Cyber attacks on medical devices pose ‘significant’ impact on real-life patient care Twisted Firestarter! Aussie, US, and UK cyber agencies warn of Cisco malware campaign Generation Life informs customers of “cyber incident” as owner shares incident with ASX CBA launches new scam-finding AI agent Australian Army research paper advocates for Australian national cyber reserve force, volunteer cyber organisations ANZ appoints its first chief AI officer Westpac appoints Chief AI Innovation Officer as part of technology push ADF strengthens skills as Cyber Command marks 2 years of operation Sri Lankan government hack sees $3.7m destined for Australia stolen Outsiders are already accessing Anthropic’s new AI model, but is Claude Mythos really that powerful? CrowdStrike extends cloud threat detection to Google Cloud Hey big spender! Microsoft to invest $25bn in Australian AI infrastructure AI adoption highest for finance and property SMEs, says NAB Genetec marks Sydney milestone with visit by high commissioner of Canada to Australia Rental platform under fire for collecting excessive personal data Exclusive: SA genealogical research firm confirms cyber incident following SafePay ransom claims Q&A: Quantum cryptography will be a “Y2k times 10 problem,” says DigiCert CEO PentenAmio announces acquisition of Armour Communications Exclusive: Aussie passports compromised in alleged Favelle Favco data breach Cutting edge: Anthropic’s Claude Mythos preview is a ‘double-edged sword’, expert says Treasury staffer charged for NSW government data breach Op-Ed: AI won’t patch the holes in your SOC AI is helping young investors get into the property market Australia’s financial regulators are keeping a close eye on Mythos Game on! More than a third of FIFA World Cup 2026 partners expose Aussies to email fraud risk Dark web markets: A complete Aussie identity costs as little as $200 Your next car may be designed by AI Exclusive: NSW-based Strata Republic allegedly breached by Kairos ransomware group Braclays warns that Mythos could prove a problem for larger banks with legacy systems Report: Data collection by school-backed apps in Australia is out of control and a risk to kids Kinetic IT appoints Kishore Jayaram in new chief transformation officer role Anthropic launches Claude Opus 4.7 as researchers reveal fake Claude installer spreading malware Australian Federal Court embraces AI in new practice note FOI docs reveal information commissioner’s concerns over Age Assurance Technology Trial Mortgage fraud now harder to detect thanks to AI McGraw Hill confirms ShinyHunters breach, won’t confirm if any Aussie customers impacted Update now: Active exploitation of Nginx UI vulnerability CVE-2026-33032 underway Op-Ed: Australia inspired the EU’s online age restrictions, now it’s time for us to learn from them National Defence Strategy 2026: Spending on military cyber capability to reach at least $15bn Exclusive: Qld pharmacy chain allegedly breached by Kairos ransomware Anthropic co-founder confirms Trump admin was informed about Mythos AI model European Commission’s new age verification app removes privacy risk of third-party data collection Op-Ed: ASIO has broken its silence on cyber crime, and you should listen Too-hard basket: NIST to scale back CVE updates as vulnerabilities soar OpenAI launches GPT 5.4-Cyber in response to Anthropic Glasswing CHROs must lead the AI transformation, AI CEO says Op-Ed: Microsoft April Patch Tuesday reveals 167 vulnerabilities Kid stuff: Roblox to introduce safety improvements following Aus government warnings ADF joins international military exercise focused on cyber resilience and multi-domain operations The workforces impacted by the ‘AI axe’ OpenAI CEO’s home targeted in attempted drive-by just days after Molotov attack Report: Aussie youth increasingly turning to AI for mental health advice Exclusive: Aussie communications company Mastercom ‘aware’ of INC Ransom claims Booking.com confirms cyber incident, customer reservation data potentially compromised Report: Majority of CISOs not ready for the next big cyber attack Exclusive: Aboriginal community organisation confirms cyber incident following INC Ransom claims AMP to ‘embrace’ AI as tech reshapes banking WASTED! GTA developer Rockstar Games confirms hack as ShinyHunters demands ‘pay or leak’ Exclusive: Gunra ransomware lists Eric Davis Dental as breach victim Op-Ed: Why zero trust for OT should start at the boundary, not the boiler room Exclusive: NSW pharmacy management firm allegedly breached by INC Ransom US Treasury launches intelligence-sharing initiative with crypto companies Citigroup says AI speeds up new account openings Cyber war: Pro-Iranian hackers vow to fight on despite a fragile ceasefire with the US Exclusive: Victorian resort hotel allegedly breached by Space Bears ransomware Game on! Nationwide student competition aims to tackle Australia’s cyber skills gap Exclusive: Anubis ransomware gang claims hack of WA-based Shine Aviation Atlassian’s Confluence gets a dose of AI as standard SaaS loses steam
Q&A with Adam Meyers: “It's going to be an absolute bloodbath.”
david.hollin · 2026-05-15 · via Cyber Daily News

Cyber Daily chats Claude Mythos and how to tackle the flood of AI-powered vulnerability disclosures with CrowdStrike’s Senior VP, Counter Adversary.

Cyber Daily: Everyone’s talking about frontier AI and its power to find vulnerabilities and speed and scale, but there seems to be a lot of noise and not much signal right now. What’s the real deal?

Adam Meyers: Well, you know the real deal is that vulnerabilities are always happening.

You’re out of free articles for this month

To continue reading the rest of this article, please log in.

I think we've seen a couple of interesting experiments and some interesting data around one particular model, in particular Mythos, right? We've been saying since November, or even before, that we're looking down the barrel at an influx of vulnerabilities, because AI is ideally suited for being able to find and exploit vulnerabilities. When you think about how you find a vulnerability, there are really two ways.

There's what I like to call the artisanal way, where you find a target, and you completely reverse engineer everything about it, how it works, and you find a bug, and you write the world's most beautiful, perfect exploit that will enable you to exploit that target. But then what most people do to do this at scale is fuzzing. And with fuzzing, you're throwing a bunch of garbage at an input, and you're hoping it crashes the program or the software, and then when that software crashes, it creates a log or a crash dump, which has information about what caused it to crash, or the state when it crashed.

And then if you look at that log, you can see if it's exploitable, and perhaps it gives you a path to exploitation. So that's kind of the two ways that people do vulnerability exploitation.

What we've seen so far with AI is they're using it for static code analysis, which is great if you have the source code, which is why you see a lot of the work so far has been done that's public is on open source projects, because you have the source code for those; when you start getting into black box testing, you actually have to instrument the software. And there are a lot more steps to it that are, I think, a lot more complex. It's doable with AI, but for what we've seen so far right now, it's really been focused on the software source code and finding bugs there.

AI can be really useful at dialling in what garbage you throw at the input to try to break the software. And it's extremely good at analysing the crash dumps to see if they're exploitable. You know, for that, I would argue even smaller models, not general-purpose models like CHatGPT or Mythos or something like that, but you could build custom models that will really be dialled in and more deterministic, meaning you're going to have the same outcome every time. And then you can use a general-purpose model to help write the exploit.

So I think we'll see, over the next couple of months, more specific tools and models for different pieces of this. And you're already hearing about harnesses and scaffolding inside the AI. That's all because that's how you can help the AI get access to do the thing that you're trying to ask it to do.

But yeah, this is coming either way, and I think it's model independent. The thing that everybody's focused on is the exploits and zero days, right? We've been kind of trained by the media and the security industry that zero days are the thing that you can't plan for, and it's the worst possible situation, right? A cyber Pearl Harbor, or something to that effect. And the reality is, a zero day is not that big of a deal.

We find zero days once a quarter, on average, at CrowdStrike. And for us, zero day is not the end of the story. It's the start of the story, because everything that happens after that zero day gets exploited by the threat actor, whether it's a human or a machine, they still have to move laterally, they still have to escalate privilege, they still have to accomplish the thing that they're trying to do. They're not just finding a bug; they're trying to execute a mission.

So that's where we hunt, right? That's where we find bad guys. Every single day at CrowdStrike, we look at 6.7 trillion events per day, and we see something like 65 million events per second at peak that we're hunting on. So there's a tremendous amount of data, a tremendous amount of grey space for us to hunt adversaries, whether they be machine or human. So I don't really think that that's going to be the big issue here.

For me, the big issue is on the solution to this, which is… If you look at last year, there were 48,000 roughly, CVE or common vulnerability exposures, and that's a lot. We’re already looking at, I think, a 27 per cent increase in the first quarter of this year over last year. So there's more bugs being found. Whether it's by a human or a machine, is irrelevant. The Chinese can weaponise a vulnerability inside of two days when it's disclosed, and that's what we call an n-day, when there's a vulnerability that's found and a patch is available. So threat actors have figured out how to weaponize N days, China in particular, very quickly.

In fact, at their Tianfu Cup, which just wrapped up in January, there was a whole track that was really about “How do we weaponise known vulnerabilities”, right? Because they understand the value of that. But let's say AI has an impact here. Let's say it's modest, which I think, you know, 10x would not be a leap of imagination for what an AI can do.

So let's say a 10x is it, and there are now 480,000 CVEs. I don't think the CVE system can even handle that. But now, as a CISO, as a defender, as somebody that's responsible for patching systems, you have to start prioritising, because you can't patch everything at once. That's impossible, and most organisations… I mean, take a look at Salt Typhoon, what we call Operator Panda. They hacked into a telco and got access to the President of the United States, when he was president-elect; they got access to his cell phone data. That's a hard target in my mind, and they did it using not a zero-day but a two-year-old Cisco vulnerability that wasn't patched, right?

That's a huge problem. So now, if you 10x the number of vulnerabilities that all these folks are dealing with, it's going to be an absolute bloodbath.

Cyber Daily: So, how do we educate organisations to follow that basic cyber hygiene and patch?

Adam Meyers: Well, it's not just about patching, which is, I think, where a lot of people think “Oh, it's just simple, just patch”. But when you patch something…

Think about that telco example, right? Let's say it was a Cisco switch that was routing traffic at the telco. If they shut that down to patch, they're going to disrupt how many phone calls, how many text messages, how much network traffic? And so they have to have a good strategy for patching, and they have to schedule downtime, they have to have failover, and they have to have all of these conditions that are ideal so that they can do the patch, and if something goes wrong with the patch, they're running up against the clock, and they're going to have a real bad day.

So patching is not as simple as patching, and with the number of vulnerabilities, 48,000 vulnerabilities, you can't patch everything, so you have to prioritise. Organizations have historically prioritised based on one or two things. The first one is prevalence. Kind of like an old method, which is to say, if there's a bug or if there's a patch that I need to issue, how much of it is in my environment, and the one that's the highest amount, that's what I'm going to patch first.

That methodology has kind of gone by the wayside, and more organisations gravitate towards criticality-based patching. So they look at the CVSS, which is a component of the CVE, and they look at that score, and they say, “Okay, if it's above a certain threshold, that's break glass,” right? We're gonna have a network outage. We're gonna do whatever we need to do, because that's going to be a bad day if somebody exploits that.

The problem is that they're looking at these vulnerabilities, and they're looking at that CVSS score. So let's go with Palo Alto. They have this GlobalProtect VPN product, and a lot of people use it, and there were two vulnerabilities in GlobalProtect about a year and a half ago. The first one was a remote unauthenticated access. So any user who exploited this vulnerability could get unauthenticated access to the device, unprivileged but unauthenticated access to the device, and that had a CVSS score of like 5.5 and organisations would look at that, and they would say, "Well, that doesn't hit our threshold, so we're not going to patch it. We'll schedule that for the next maintenance window,” right?

Then they look at the next vulnerability that comes out; same time, same patch cycle. And this one is a local privilege escalation. That's 8.5, that means that if you have access to that device, you can escalate privilege to system or admin or whatever it is. And they look at that, and they say, “8.5 that's at our threshold. We should probably patch this”. And then somebody pipes in, and they say, “Well, it's 8.5, but it's a local privilege, so they'd have to have access to the box to be able to use it. So it's really not that big of a deal, right?”

And then they forgot about that first vulnerability. So now if you chain those two together, what is going to happen is it's a kill shot, right? Unauthenticated access with a local privilege escalation – game over. And they don't look at those two together. They're looking at them in a bubble, and so that really makes it difficult for them to leverage criticality-based patching.

And then the third model, which is one that I promote, and I think people should adopt, is to look at what is being exploited in the wild, because then at least you know this is actively being exploited. In that Palo Alto situation, both were being exploited together in the wild, CISA puts out something called the Known Exploited Vulnerability Catalog, and that lets organisations see all the things that are actively being exploited, and we contribute to that all the time. We'll notify CISA if we see vulnerabilities being exploited, they add it to the catalogue, and that helps people patch.

So I think particularly as we start to see the increase in vulnerabilities at the hands of AI, and the effectiveness of those vulnerabilities that organisations are going to need to certainly adopt a prioritisation based off of what is actively being exploited, and that's where threat intelligence will be really useful for them to understand what's out there, who's using it, and what are they doing with it.

Cyber Daily: You mentioned the volume of vulnerabilities that are being reported, and it's just skyrocketing year over year, quarter over quarter. And I know that recently, NIST said that it was no longer going to be enriching every CVE that crossed its desk; it was going to announce new prioritisation criteria. Is that a response to this Vulnerability Apocalypse, that we just can't cover all of them?

Adam Meyers: I think it's a response to a few things.

I mean, I think they've had some funding issues as well, associated with CVE. And I think, you know, CVE was designed many, many, many years ago, when we had far fewer vulnerabilities, far less software sprawl. And, oftentimes, as you look at the number of vulnerabilities year over year, I think it wasn't built to this scale. And I think they recognise that it's unmanageable.

And there are some other issues with CVE. For instance, you don't see a lot of cloud-based CVEs, because if it's a SaaS vulnerability, they patch it on the cloud side; there's nothing for the customer to do. So you don't really need to call it out as a CVE, because once the bug is found, you fix it, it's game over. So there are aspects of the whole vulnerability landscape that have been changed by cloud and by SaaS.

CVE also doesn't cover… If you look back at the last couple of weeks, we've seen a massive uptick in supply chain attacks, and they're targeting software libraries that are being used across the supply chain, and CVE doesn't account for that. So I think it is not the solution that it was back when you were dealing with the Morris worm and a handful of Unix vulnerabilities. To defend NIST here, you can't possibly expect them to cover every single product. And when you look at the enrichments, they're not super detailed, you know, it's not, it's basically metadata, usually, just what's come from the initial disclosure anyway. It's usually exactly the same thing, and the vendors typically have way more information in their disclosure than the CVE does anyway.

CVE is really useful for categorising vulnerabilities when you're doing a vulnerability assessment on a network, and then you could give them a list of all the CVEs that you found, and frankly, most of the auditors that were doing that had no idea what those vulnerabilities were anyway. I've been in places where they found a vulnerability that was 15 years old, and they're like, “You need to patch this”. But as far as I’m concerned, you need to burn that system out in the woods, because if it's been exposed for 15 years, vulnerability patching is not going to fix your problem.

Cyber DailyWant to see more stories from trusted news sources?
Make Cyber Daily a preferred news source on Google.

David Hollingworth

David Hollingworth has been writing about technology for over 20 years, and has worked for a range of print and online titles in his career. He is enjoying getting to grips with cyber security, especially when it lets him talk about Lego.

Tags: