OALABS published the full session logs on June 16 of an amateur attacker in Addis Ababa who used Claude Opus 4.5 and OpenAI Codex to breach at least fourteen companies. The attacker typed prompts like “recon this” and “before you erite the report tell does an attaker has a chance of getting a shell.” Old … Continue reading Mythos Buster: Novice On Opus Breached 14 Companies→
In April “The Boy That Cried Mythos” caught Anthropic collapsing its own credibility. In June “Mythos dressed up in a coat, should be called Opus with a moat” caught it again. Anthropic wants to play God, feed on claims only they can verify, which is to say it feeds beliefs based on lies. If that … Continue reading The National Academies Launders Mythos: “Implications of AI for Cybersecurity”→
Let’s recap what we know since April, when Anthropic’s marketing department started coal-rolling the industry with their nonsense about novelty. A model with 3.6 billion active parameters reproduced Anthropic’s flagship Mythos discovery, the FreeBSD RCE CVE-2026-4747, and the most consistent open-weight model in that test ran about six hundred times cheaper per token than Mythos. … Continue reading Got Local? Match Mythos Findings for Under a Dollar→
Anthropic allegedly built Mythos so good at finding vulnerabilities that it was too dangerous to release. Then it was handed to only a few dozen very wealthy organizations under Project Glasswing. One of them ran it against curl and sent the project a report claiming five confirmed security vulnerabilities. The curl security team dug in. … Continue reading Still No Evidence Mythos Better at Security Than Self-hosted LLMs→
a blog about the poetry of information security, since 1995