惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Application and Cybersecurity Blog
Application and Cybersecurity Blog
S
Securelist
K
Kaspersky official blog
Scott Helme
Scott Helme
C
CXSECURITY Database RSS Feed - CXSecurity.com
GbyAI
GbyAI
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
C
Cisco Blogs
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
博客园 - Franky
Security Latest
Security Latest
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
Y
Y Combinator Blog
T
Threat Research - Cisco Blogs
L
LINUX DO - 热门话题
C
Cyber Attacks, Cyber Crime and Cyber Security
Project Zero
Project Zero
Cisco Talos Blog
Cisco Talos Blog
月光博客
月光博客
I
Intezer
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
人人都是产品经理
人人都是产品经理
L
Lohrmann on Cybersecurity
Recorded Future
Recorded Future
Latest news
Latest news
V2EX - 技术
V2EX - 技术
T
The Exploit Database - CXSecurity.com
H
Heimdal Security Blog
F
Fortinet All Blogs
Cloudbric
Cloudbric
IT之家
IT之家
博客园 - 叶小钗
Microsoft Security Blog
Microsoft Security Blog
P
Proofpoint News Feed
博客园 - 司徒正美
Apple Machine Learning Research
Apple Machine Learning Research
PCI Perspectives
PCI Perspectives
AWS News Blog
AWS News Blog
H
Help Net Security
S
Security @ Cisco Blogs
酷 壳 – CoolShell
酷 壳 – CoolShell
Recent Announcements
Recent Announcements
Hacker News - Newest:
Hacker News - Newest: "LLM"
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
F
Full Disclosure
S
Schneier on Security
S
Security Affairs
T
Tenable Blog

Forbes - Innovation

Why Do Humans Have Fingerprints? Hint: It’s Not What You Think Booking.com Confirms Data Breach, Reservation PIN Codes Changed Why Major News Sites Are Blocking The Internet Archive’s Wayback Machine iPhone Fold Release Date: New Report Details Frustrating Apple News Comet Tracker: How To See Pan-STARRS And Three Planets On Wednesday NYT Mini Crossword Today: Tuesday, April 14 Hints And Answers Today’s NYT Strands Hints, Spangram, Answers: Tuesday, April 14 (It’s A Little Unclear) Today’s Wordle #1760 Hints And Answer For Tuesday, April 14 Most Of The Microplastics In Urban Air Come From Tires Today’s Wordle #1759 Hints And Answer For Monday, April 13 NYT Mini Crossword Today: Monday, April 13 Hints And Answers NYT Pips Today: Hints, Answers And Walkthrough For Monday, April 13 The YC Chief Who Codes 10,000 Lines A Day Has A Simple Secret Samsung Expands One UI 8.5 Beta To More Galaxy Owners Why You Should Stop Using Your iPhone If It’s On This List Chamath Says Firms That Treat AI As A Strategy Hand Rivals Their Edge 3 Unexpected Habits Of Secure Couples, By A Psychologist The First Lamp That Folds Your Clothes Samsung’s Disappointing Price Update For Galaxy Phone Buyers 3 Subtle Signs Someone Is Falling In Love With You, By A Psychologist Do Mantis Shrimp See More Colors Than Humans? A Biologist Explains NYT Connections Answers Explained For Monday, April 13 (#1,037) NYT Connections Hints Today: Monday, April 13 Clues And Answers (#1,037) LEGO Luigi & Mach 8 (72050) Review: 2026’s Best Set Yet? Marc Andreessen Says AI Productivity Will Trigger A Hiring Boom 3D Printing Is The Ultimate Hack To Reduce Household Spending Apple iPhone Fold: Striking Design Revealed In Leaked Photos Apple Smart Glasses: New Leak Reveals A Major Design Twist To Beat Meta Tested: The AI Coming To The Rivian R2 Quordle Hints Today: Monday, April 13 Clues And Answers Companies And H-1B Employees Endure Immigration Waits At Consulates 3 Easy Ways To Turn Anxiety Into Sustained Focus, By A Psychologist Here’s The Most Affordable Humanoid Robot You Can Buy Now UFC 327 Results: 5 Biggest Takeaways From A Wild Night In Miami UFC 327 Results, Bonus Winners, Highlights And Reactions Dana White Announces Huge New Fight For UFC White House Today’s NYT Strands Hints, Spangram, Answers: Sunday, April 12 (Get Ready) Tesla ‘Model 2’ Rises From The Ashes Today’s Wordle #1758 Hints And Answer For Sunday, April 12 NYT Pips Today: Hints, Answers And Walkthrough For Sunday, April 12 Tyson Fury Vs. Arslanbek Mahkmudov Results: Highlights and Reaction NYT Mini Crossword Today: Sunday, April 12 Hints And Answers How Shadow AI Culture Is Destroying Your Business Venture Capital Funds That Market Like Startups Win More Deals Conor Benn Vs. Regis Prograis Results: Highlights and Reaction Samsung’s Disappointing Price Update For Galaxy Phone Buyers Artemis Reached The Moon. The Grid Can Reach The 21st Century A Biologist Explains How Archerfish Shoot Down Prey. Hint: Their Aim Rivals Human Throwing Is It Time For Apple To Forget About The MacBook Air NYT Connections Hints Today: Sunday, April 12 Clues And Answers (#1036) Trump’s 2027 Budget To Reshape U.S. Environmental And Energy Policy CDC Delays Reporting Of COVID-19 Vaccine Benefits—Here’s What To Know Oura Has Designed A Solution To A Big Smart Ring Problem Netflix’s Best New Show Has A Near-Perfect 95% Rotten Tomatoes Score Coachella 2026 Is Being Taken Over By Creator Streams Quordle Hints Today: Sunday, April 12 Clues And Answers This Startup Wants To Use AI To Help Digitize History How To Get The Best Shield In ‘Crimson Desert’ Microsoft Venom Attack Targets C-Suite Executives ‘Maul: Shadow Lord’ Sets Even More Star Wars Rotten Tomatoes Records 3 Ways Happy Couples Argue Differently, By A Psychologist Success For Leapmotor Might Have Negatives For Stellantis New Names Surface As Potential Rogue And Wonder Woman In The MCU And DCU 4 Reasons Artemis Mission Matters Even If You Think It Is Wasteful Fast ‘Crimson Desert’ Patch Adds New Moves, Shield Hiding And One Great Feature Why Do Humans Blush? An Evolutionary Biologist Explains The Signal We Can’t Control Apple iPhone Fold: Striking Design Revealed In Leaked Photos Adobe Attacks Underway—Windows And Mac Users Given 72 Hours To Update iOS 26.4.1 Release: Crucial iPhone Feature Update Arrives, But No Security Fix Fury vs. Makhmudov Full Card, Ring Walk Times and How to Watch Can’t Stand Liquid Glass? This New Hidden iPhone Setting Is A Game-Changer Test-Driving The 2026 Changan Deepal S05: Italian Style Made In China NSA Warning—Reboot Your Internet Router Now Ways That Human-AI Collaboration Slides People Into ‘AI Brain Fry’ And Cognitive Downturns Stop Using These Networks—Google, NSA And TSA Warn NASA Changes Moon Plan: Landing Now Depends On SpaceX Or Blue Origin Samsung Expands One UI 8.5 Beta To More Galaxy Owners The Evolution Of Programmable Hardware At Xilinx NYT Mini Today: Saturday, April 11 Hints And Answers Today’s NYT Strands Hints, Spangram, Answers: Saturday, April 11 (You’re Putting Me On) Splashdown! NASA’s Artemis II Returns To Earth After Moon Mission Attention Is All You Need. The Human Kind Is Still The One That Counts Today’s Wordle #1757 Hints And Answer For Saturday, April 11 NYT Pips Today: Hints, Answers And Walkthrough For Saturday, April 11 Android Circuit: Galaxy S27 Pro Emerges, Honor 600 Pre-Order Offers, Pixel 11 Display Leaks Apple Loop: iPhone 18 Pro Leak, Urgent iOS Update, MacBook Neo Issues Morgan Stanley Has Mostly Positive Outlook On Tesla Robotaxi, FSD V15 Running Out Of AI Tokens Faster Than Ever? Here’s Why CoreWeave Shares Pop 13% After Anthropic Deal ‘Euphoria’ Season 3’s Rotten Tomatoes Score Crashes, Has Lost Key Player People Don’t Agree On What AI Can Do, But They Don’t Even Use The Same Product ‘Overwhelming’—Google Issues Gemini Update For Gmail Users NYT Connections Hints Today: Saturday, April 11 Clues And Answers (#1035) Quordle Hints Today: Saturday, April 11 Clues And Answers The Costly Dream Of Space-Based AI Infrastructure Can You See The Watcher In This ‘Daredevil: Born Again’ Shot? Adobe Attacks Underway—Windows And Mac Users Given 72 Hours To Update You Just Watched The Backdoor Pilot For ‘The Pitt: Night Shift’ Are Nicotine Pouches Like Zyn And VELO Safe To Use? A Doctor Answers Human Resources (HR) Is The Key To AI Success Per WalkMe ( SAP)
Mythos Is The Past-Due Notice On 20 Years Of Deferred Software Quality
Saša Zdjelar · 2026-05-08 · via Forbes - Innovation

Saša Zdjelar is Chief Trust Officer at ReversingLabs, a leader in software supply chain, AI, malware, and threat intelligence security.

getty

Recently, Anthropic announced Claude Mythos and then announced it would not be released. Mythos has found thousands of zero-day vulnerabilities in major operating systems and browsers, including a 27-year-old bug in OpenBSD, an operating system known for being hard to break. Anthropic decided the capabilities were too dangerous and handed preview access to a small consortium under Project Glasswing.

The coverage has framed this as restraint, a responsible lab choosing safety over revenue and giving defenders a head start.

I've spent two decades on the buying side of this industry across energy, technology and now private equity, and that framing strikes me as dangerously comforting.

The First-Mover Assumption

Nation-state programs have been investing in AI for years at a scale rivaling the commercial sector, and we have seen it twice in public.

DeepSeek's R1 caught the industry flat-footed in January 2025 by matching frontier systems on a fraction of the compute, and Reuters confirmed last week that its next model will run entirely on Huawei Ascend chips, putting a parallel compute stack outside U.S. export controls. If two surprises can come from one Chinese company in 15 months, the assumption that the first Mythos-class capability is uniquely American is almost certainly wrong.

Even if Anthropic is first, the Glasswing model of containment in the open is a delay function with an unknown decay rate, because every additional handle is another seam for leaks or reverse-engineering. As Daniel Miessler observed, Mythos is a general frontier model, not a cyber tool, which means any lab training a sufficiently capable general model is a candidate for the same risk. And the threat is the kill chain compressing to machine speed in a market where exploitation already precedes disclosure, and disclosure often arrives only alongside the patch.

Mythos is best read as a past-due notice rather than a head start, and any organization still planning to fix software quality next quarter has already lost the argument.

The Deferred Maintenance Bill Is Being Called

The industry treats software quality as a cost center. Vulnerabilities get triaged instead of fixed, SBOMs become a compliance checkbox, and security tools deployed with deep privileges are assumed safer than the things they watch. I've watched this from the buyer's chair.

The questions a CISO asks about third-party software today are the ones I asked early in my career, and the answers are still assurances and attestations that close the procurement cycle without looking inside the box. A model that autonomously chains four bugs into a browser sandbox escape treats those rationalizations as just another target list.

The answers have not changed because the incentives have not. Software is still the only product category where a vendor can knowingly ship defects, disclaim liability in the EULA, cap damages at fees paid, and leave the buyer to absorb the fallout. Every other industry that matters has passed through that phase and out of it, from automotive to medical devices, and software is the holdout.

Where The Leverage Already Exists

A year ago at RSA, JPMorgan Chase's Pat Opet sent his software vendors an open letter under his own name making clear their security work was no longer acceptable. He recently shared the result at RSA: JPMC vendors now close findings 45 to 90 days ahead of the industry because JPMorgan tied contract renewal to supplier security. Joe Levy, CEO of Sophos, said "secure by design" only works if "secure by demand" makes it happen, and the only thing that ever moved a line item in a vendor's budget is a purchase order.

Other forcing functions are taking shape, including the EU Cyber Resilience Act and revised Product Liability Directive on the regulatory side, the SEC's cyber disclosure rules and the SolarWinds enforcement action on the personal-liability side, and cyber insurance underwriting on the coverage side. All matter because they converge on the same mechanism: attaching economic consequence to software failure rather than the buyer's books, and none does it fast enough yet to override the contractual liability shields vendors rely on.

The Procurement Ask

Every buyer can do one thing at their next vendor review, which is to ask for a contractual warranty that vendor software meets a defined, verifiable standard. The standard has to cover what every CISO knows matters, from the absence of malware and tampering to leaked information and known-exploited vulnerabilities. It should also extend to emergent concerns like poisoned AI and ML models.

Most vendors will offer a SOC 2 report or a secure-by-design signature instead, but a warranty creates real legal exposure when software fails, while a pledge binds nothing. The realistic version is not an absolute guarantee against every vulnerability, which no competent vendor counsel will sign. It is a tiered warranty covering malware, tampering, leaked secrets and known-exploited vulnerabilities at delivery, with penalties tied to exploitability thresholds in CISA's Known Exploited Vulnerabilities catalog, which lists vulnerabilities being actively exploited in the wild rather than every theoretical defect. That is something a competent vendor can commit to and a court can enforce, and asking the question is the entire argument: Will they warrant their software free of malware, tampering, leaked information and known-exploited vulnerabilities?

The Next 12 Months

Mythos did not create the problem so much as make the deferral untenable. Builders won't fix it on their own because 20 years of incentives have rewarded shipping over fixing, and CISOs and procurement leaders can act this quarter.

The next 12 months will determine whether the past-due notice Anthropic just handed the industry gets paid, or filed alongside SolarWinds, Log4j and CrowdStrike as warnings the industry chose not to act on.

The leverage has always belonged to buyers, and Mythos has removed the last excuse for not using it: the belief that the threat was still theoretical and the timeline still comfortable.​


Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?