Disclaimer: The views expressed in this blog post are my own and only my own. They are based on my personal experiences and reflections.
It’s a rare thing, to start writing a post on a cybersecurity topic where I know no introduction at all will be needed, even for the occasional non-infosec reader that would end up here on this blog (welcome). Mythos has been all over the news. It’s a new nightmare which turns computers into crime scenes. It’s the end of internet as we know it. A hacker superweapon. Let’s call it software genocide while we’re at it, why don’t we.
Needless to say, there’s a lot to unpack.
Are stories about Mythos overblown? Most likely. It’s actually hard to say, since secrecy is such a central part of this story. There were definitely a few gems in the initial batch of vulnerabilities announced by Anthropic (this BSD bug, or that one in ffmpeg) and a few weeks in, Firefox announced they were patching 271 vulnerabilities thanks to Mythos. It’s certainly not nothing, although the jury’s still out on the reality behind this number and crucially how many of these were truly exploitable. Similarly, only 200 of the “thousands” of vulnerabilities discovered by Anthropic have been assessed:
In 89% of the 198 manually reviewed vulnerability reports, our expert contractors agreed with Claude’s severity assessment exactly, and 98% of the assessments were within one severity level
Good numbers. Strong consistency, but questionable real-world impact: for all we know, the vast majority of these bugs were correctly identified as low or possibly very low severity. Or maybe the other 998 vulnerabilities were found in VibeMike’s e-commerce plugin for WordPress and hundreds of other low-quality GitHub repositories, for a grand total of “a few good bugs plus a whole lot of nobody cares”. There’s just no way of knowing. Not all vulnerabilities are born equal.
The truth is, it doesn’t really matter. Mythos may or may not represent a significant leap in terms of LLM cybersecurity research, and for the purposes of this discussion, we’ll just assume it is. If not this one, then the one after that or the next. Model sophistication keeps progressing at a rapid pace and there is no indication that we’re anywhere near any sort of ceiling. It’s not even obvious that Mythos is fundamentally different from Opus 4.7. Maybe they just gave it a huge context window that makes it well suited for bug hunting. Or perhaps they came up with clever ways to guide a good model through this task – check out what Chinese researchers published on April 22 with Kimi K2.5 to find 10 new vulnerabilities in Chrome (including 2 critical sandbox escapes). Open-weight Kimi K2.5, not Mythos.
So, for a second, let’s leave aside the crazy media coverage we were subjected to and think about what it should have been.
Changing everything won’t change much
Most outlets vaguely identified that we’re in a transition phase. But where they framed it as a very brutal process akin to jumping off a cliff (one day we’re going about our lives peacefully, and the next defenders are besieged by endless 0days), I would argue that it will be a fairly lengthy one. Granted, this transition period could be a rough patch for anyone running off-the-shelf software, but we have to ask what the world might look like in 5 years. Are we back to pen, paper and carrier pigeons? Or have models become so good at producing and fixing software that exploitable vulnerabilities have become so scarce that we virtually don’t have to worry about them anymore?
I would bet on something closer to the latter. Getting there won’t be a walk in the park, because you don’t phase out 30 years of insecure software in the blink of an eye. I expect the general pace of everything to keep trending up at uncomfortable speeds. Until there’s nothing left to patch, you will have virtually no time to patch. In the span of a few years, some assumptions we had about cybersecurity will be challenged.
Cybersecurity revolves around exploits
Wrong. Your assumption was dumb. The game was never about who could chain a WebKit use-after-free with an iOS sandbox escape and privilege escalation. Most of the time it was about who could get you to click on something. It was about how to get into your inbox and 0days were the worst, most expensive path. LLMs are provably good at social engineering and with a little loosening of their shackles could become top-tier. Phishing will still be the number one problem in ten years.
The asymmetry of cybersecurity favors offense
For a long time, the assumption was that a persistent team of attackers would eventually be able to find the one security issue they needed, whereas defenders could never hope to cover everything. I think this gap will now narrow over time, which is probably the best thing to happen to our field in recent memory. Tomorrow’s attacker (or their AI agent, probably) might have to slither undetected in computer networks where Mythos V6.0 reads every log file from every machine in real-time. If this advantage materializes on the defensive side, tomorrow’s attacker is in trouble.
Schrodinger’s PR stunt
Mythos is fated to remain both exaggerated and warranted until we open the box and most likely even after. My deep belief is that what’s playing in front of our eyes is different from what it seems; and more specifically I don’t think it has anything to do with cybersecurity. The “too-dangerous-for-public-release” doesn’t point towards the actual public but China. That part is fairly obvious.
China’s best models are on a trajectory that trails frontier labs by 3 to 6 months (according to DeepSeek). Maybe they always will, if the claims of massive distillation[1] hold water. It follows that they’ll reach Mythos level soon-ish, and even if they don’t they’re already on par with GPT-5.4 or Opus 4.6 which, as we know, is good enough for serious vulnerability research.
The less obvious part is how the “too dangerous” rhetoric is fundamentally anti-open-weight. Ryan Naraine spotted how 7 years ago, OpenAI was already claiming its stuff was considered unsafe to release. It’s been a staple of AI lab PR ever since, not because it never fails to excite low-skill journalists but because it’s the perfect excuse to walk back on a promise of openness so central to their identity that it made its way into their name. There can be no walled garden without the fiction of danger. The real conflict with China on the topic of LLMs is ideological. On one side, closed ecosystems where a handful of tech giants own both models and compute, jacking up token prices on a regular basis while diminishing quotas, making Codex and Claude Code slightly shittier every release. On the other, quasi-state-of-the-art models freely downloadable on HuggingFace on the day of their release, for anyone to tinker with as they please, and the beautiful home that one day we’ll all have 1TB RAM Mac Studios to run them at home.
The real question isn’t who has the best model today. It’s who controls access to these capabilities tomorrow. Whether they’re locked behind APIs, rate limits, pricing tiers and quotas, or whether they’re something anyone can run, modify and build upon.
I really hope China wins.
[1]It’s neither here nor there, but I keep hearing outrage about how Chinese start-ups distill frontier models at scale. I’m pretty sure the same frontier models were trained on mankind’s entire textual corpus, including this blog. You don’t hear me bitch about it.

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.