The myth of Claude Mythos crumbles as small open models hunt the same cybersecurity bugs Anthropic showcased Anthropic has kept its Claude Mythos cybersecurity model on a short leash, pointing to capabilities it says no rival can match. But two new studies suggest that even small, openly available models can reproduce most of the vulnerability analyses Anthropic has put on display. Through Project Glasswing, Anthropic has limited access to Claude Mythos Preview to a consortium of eleven organizations, citing the model's offensive capabilities. Internal tests and an audit by the UK's AI Security Institute found that Mythos can find software bugs, build working exploits on its own, and take over entire corporate networks in simulations, as long as the network is "small, weakly defended and vulnerable." Two independent replication efforts are now poking holes in that exclusivity story, without disputing the model's overall performance. The first comes from AISLE, a company that has been running its own AI-assisted bug hunting on open source software since mid-2025. AISLE says it has reported 15 vulnerabilities in OpenSSL and five in curl. Founder Stanislav Fort fed the code snippets from Anthropic's public samples into a range of models to see how much smaller and partially open models could piece together on their own. The second study comes from Vidoc Security, which paired GPT-5.4 and Claude Opus 4.6 with the open coding agent OpenCode. Small models catch the FreeBSD bug too The FreeBSD NFS bug (CVE-2026-4747) that Anthropic spotlighted was pitched as a showcase for autonomous discovery and exploitation by Mythos. AISLE found that all eight models it tested caught the memory bug in the function in question. That included GPT-OSS-20b, a model with just 3.6 billion active parameters that runs at $0.11 per million tokens. Every model flagged the flaw as critical, though
Apr 18, 2026 · via the-decoder.com
The National Information Technology Development Agency (NITDA) and the Corporate Affairs Commission (CAC) have initiated coordinated measures to strengthen cybersecurity following recent concerns affecting aspects of CAC’s digital systems. Both agencies said they have activated response and assurance mechanisms in line with national cybersecurity frameworks to safeguard critical infrastructure and maintain service integrity. The cybersecurity effort was disclosed in a statement by the NITDA Director, Corporate Communications and Media Relations Department, Hadiza Umar, on Friday. The measures followed alleged breaches of data and information systems of government and private institutions, including CAC, Remita Payment Services Limited, Sterling Bank, and other entities, in the past weeks. The Nigeria Data Protection Commission (NDPC) said it is probing alleged data breaches. | | |---| In the statement on Friday, NITDA reiterated that all ministries, departments, and agencies (MDAs) must adopt proactive cybersecurity measures in compliance with the National Cybersecurity Policy and Strategy (NCPS) 2021. The agency directed all MDAs to immediately review and reinforce their cybersecurity architecture to address emerging threats targeting government systems and sensitive data. As part of the directive, MDAs are also required to conduct comprehensive security assessments, remediate identified vulnerabilities, and strengthen access controls across critical platforms. They are also expected to enhance data protection mechanisms, maintain effective backup and disaster recovery systems, and improve monitoring capabilities to detect and respond to suspicious activities. “In addition, there is the need for functional incident response frameworks, including prompt reporting of cybersecurity breaches for coordinated intervention. “Detailed cybersecurity guidelines have already been issued to MDAs for implementation as part of ongoing efforts to strengthen resilience across public sector digital infrastructure,” the NITDA stated. According to the agency, the measures are aimed at improving the overall security posture of government institutions and ensuring the continued protection of national digital assets. NITDA reaffirmed
Apr 18, 2026 · via premiumtimesng.com
Presentation providing analysis of the leading cybersecurity vendors’ recent financial results compared with their competitors. The Cybersecurity Titans are Akamai, Check Point, Cisco (including Splunk), Cloudflare, CrowdStrike, CyberArk, Elastic, F5, Fortinet, Varonis, Okta, Palo Alto Networks, Qualys, Rapid7, SentinelOne, Tenable, Trend Micro and Zscaler. These vendors have annual revenue of over US$300 million, were publicly trading for at least four quarters and broke out their cybersecurity revenue numbers quarterly. Email Article All set! This article has been sent to my@email.address. All fields are required. For multiple recipients, separate email addresses with a semicolon. Please Note: Only individuals with an active subscription will be able to access the full article. All other readers will be directed to the abstract and would need to subscribe. The Analyst Team Srikara Upadhyaya Follow AnalystResearch Analyst Srikara Upadhyaya works as a research analyst and is based in the Bangalore office. His research is focused on the cybersecurity and infrastructure markets. Prior to joining Canalys, now part of Omdia, Srikara spent two years working as an associate market analyst for IDC India, with a focus on worldwide software, artificial intelligence, and the public cloud service market. He also worked as an analyst at John Crane India Limited, where he worked closely with the production team to analyze SAP production and material management module data. Srikara holds an MBA from Jain University Bangalore and a bachelor’s degree in mechanical engineering from Vishweshwaraiah Technological University.More Content By Srikara Upadhyaya Become A Client Find out more about our full suite of products and solutions. Become A ClientYou must sign in to use this functionality Authentication.SignIn.HeadSignInHeader These are Omdia driven recommendations based on content that is both similar, and has been frequently visited by other users in combination with the content you are currently viewing. Omdia Recommends These are Omdia
Apr 18, 2026 · via omdia.tech.informa.com
Techie buys fake Ledger Nano S+ hardware crypto wallet and almost falls for phishing — a convincing clone would have caught newbies unaware Hardware verification check was the one thing standing between virtual coins and a virtual robbery. Get Tom's Hardware's best news and in-depth reviews, straight to your inbox. You are now subscribed Your newsletter sign-up was successful Score one for the safety-minded and cryptographic hardware checks. Joje Mendes, a Brazilian cybersecurity professional, almost got bitten by a sophisticated hardware-and-software phishing attack, in the form of a fake Ledger Nano S+ cryptocurrency wallet. The only barrier between Past's virtual currency and the device's remote operators was Ledger's software, which verified that it was running on legitimate hardware. The story starts when Mendes decided to order the Ledger device from a "major marketplace" in China. He chose to do so because, being a non-Chinese citizen currently located in Shenzhen, importing one from abroad, directly from Ledger, "comes with its own headaches." The device's price was reportedly the same as that of a legitimate unit, but nevertheless, Mendes kept his suspicion mode engaged and installed Ledger's official software before the Nano S+ arrived. True to the unfortunately expected form, after the device arrived, Mendes noticed it was "clearly" a counterfeit, a fact verified by the Ledger software, which marked it as non-genuine. True to his profession, Mendes decided to tear apart the device instead of tossing it, and found quite an elaborate scheme at work — one that's likely catching other unsuspecting users off guard. Article continues belowAfter prying open the case, Mendes found that all chip markings had been scraped off, but eventually managed to identify the central unit as an ESP32-S3 system-on-a-chip (SoC). The device spoofed its identification, claiming it was a "Nano S+ 7704" from Ledger's factory, complete
Apr 18, 2026 · via tomshardware.com
Please SUBSCRIBE HERE for free or get DTNS Live ad-free. A special thanks to all our supporters–without you, none of this would be possible. If you enjoy what you see you can support the show on Patreon, Thank you! Send us email to feedback@dailytechnewsshow.com Show Notes Anthropic launches Claude Design for fast visual creation Anthropic introduced Claude Design, an experimental tool that generates and refines visuals like prototypes, slides, and one-pagers using natural language. Built on Claude Opus 4.7, it targets non-designers and integrates with tools like Canva while supporting company-specific design systems pulled from codebases and design files. It is currently in research preview for paid users. Source: TechCrunch AI demand is making the Mac Mini harder to find Apple’s Mac Mini is seeing supply constraints driven by surging demand from AI users running local models and always-on agents. High-memory configurations are especially affected, with shipping delays stretching up to 12 weeks and frequent stockouts. Analysts say it has become a popular low-cost option for local AI workloads. Source: 9to5Mac EU age-verification app found to have major security flaws Researchers identified major vulnerabilities in the European Commission’s age-verification app, including bypassable biometric protections and insecure local data storage. Security experts said the system could be compromised in minutes, raising concerns about identity misuse. The Commission says the app remains under active development and updates are ongoing. Source: POLITICO OpenAI loses key leaders as it scales back experimental projects OpenAI is seeing departures including Kevin Weil and Bill Peebles as it winds down experimental initiatives like Sora and OpenAI for Science. The company is consolidating around more commercially focused AI products, while reducing investment in side projects. Additional leadership changes include enterprise CTO Srinivas Narayanan. Source: TechCrunch TCL expands Mini LED TV lineup with premium RGB models TCL is expanding
Apr 18, 2026 · via dailytechnewsshow.com
The authorities of the U.S., U.K., and Canada have conducted a joint operation focused on dismantling a widespread cryptocurrency fraud network that allegedly caused losses exceeding $45 million. The intervention, called 'Operation Atlantic,' aimed primarily to halt the progress of criminal networks, as well as to track funds and identify victims. According to information released by various involved agencies, including the U.S. Secret Service, the U.K.'s National Crime Agency (NCA), and Canadian police forces, the operation was carried out as a coordinated international action over approximately one week. The main focus of the investigation has been a scam modality known as 'approval phishing,' a type of fraud particularly widespread in the crypto ecosystem. This method involves deceiving victims into granting access permissions to their digital wallets through fake interfaces that simulate legitimate services. Once authorization is granted, the attackers can move the funds without needing further confirmations from the user. Authorities link these types of attacks to broader online fraud schemes, including the well-known investment scams or 'pig butchering,' where criminals psychologically manipulate victims into progressively depositing more funds. More than 20,000 identified victims The operation has led to the identification of more than 20,000 crypto wallet addresses linked to victims distributed across more than 30 countries, including the U.S., U.K., and Canada. The participating agencies have noted that, thanks to collaboration with blockchain analysis companies and industry platforms, they have been able to track the movement of stolen funds and detect patterns used by criminal groups to hide the money. During the operation, authorities managed to freeze approximately $12 million in stolen cryptocurrencies, a portion of the misappropriated funds, which are now under review for possible restitution to the victims. Additionally, another $33 million related to fraudulent activities has been identified and continues under investigation. Security forces have also
Apr 18, 2026 · via escudodigital.com
CENTRAL FLORIDA — From hospitals to utilities and even local governments, cyberattacks are becoming more frequent—and more sophisticated. Now, a Central Florida company and state leaders are working to train the next generation to defend against them. Experts say cyber threats are no longer distant concerns. They’re hitting closer to home, targeting critical systems that people rely on every day—from healthcare networks to city infrastructure. ThreatLocker, based in Central Florida, says it is already seeing the impact firsthand. CEO Danny Jenkins said the company blocks thousands of cyberattacks every week. “We’re stopping an airport from getting shut down… we’re protecting people’s data, their healthcare, everything else,” Jenkins said. As Florida continues to grow, so does the demand for cybersecurity professionals. Industry data shows there are between 500,000 and 700,000 unfilled cybersecurity jobs across the United States. State-funded group Cyber Florida is working to close that gap by training professionals and building a pipeline of future talent. “We need to encourage more people to discover their passion in cybersecurity so that they can fill those positions,” said James Welsh. One effort to spark that interest is CyberLaunch, one of the largest cybersecurity competitions in the country. On April 24, students from Orange and Seminole counties, along with others from across the state, will compete in the event. Organizers say introducing students to cybersecurity early is key to building a strong workforce. “You need to get people in it when they’re really young… when they can understand and learn much, much faster,” Welsh said. Even as interest grows, experts say one major challenge remains: experience. Employers are looking for candidates with hands-on skills who can immediately step into critical roles. “The colleges need to step up and train better… the high schools… but companies as well,” Jenkins said. Leaders say the push
Apr 18, 2026 · via wftv.com
The 2026 CEO & Board Confidence Monitor by Heidrick & Struggles International, Inc. found that the Asia Pacific (APAC) region reports strong confidence in their ability to navigate issues such as artificial intelligence and cybersecurity risk. “The breadth of what is landing on leadership agendas across APAC right now is significant. The real test for leaders is carrying the weight of today’s volatility while simultaneously transforming for what comes next,” said Jiat-Hui Wu, partner-in-charge at Heidrick & Struggles Singapore. Significant issues in APAC Based on responses from 254 leaders in the region, the report found that artificial intelligence and economic uncertainty were each cited by 44% of respondents as among the most significant issues their organisations expect to face in 2026. Some 39% cited cybersecurity risk, above the global average of 31%. APAC leaders reported the highest confidence among the five regions surveyed in their ability to manage AI risks. Half of respondents said they were confident in handling AI, compared with a global average of 39%. Confidence in managing cybersecurity risk was also higher at 55%, compared with 51% globally. While 75% of respondents are confident in their executive teams for 2026, only 55% trust board evaluation and refreshment practices. “Confidence in today’s leadership is just part of the picture. Even as organisations grow more confident in managing technological risk, a more uncertain geopolitical environment is testing leadership readiness,” said Guy Farrow, regional managing partner of the CEO & Board of Directors Practice for Asia Pacific and the Middle East at Heidrick & Struggles. He added that organisations need to strengthen governance structures as geopolitical uncertainty and technology disruption continue to test leadership readiness.
Apr 18, 2026 · via futurecio.tech
How AI intelligence and human expertise combined to identify threats 66% faster Cybersecurity is at an inflection point. The scale of data, the speed of attacks and the sophistication of threat actors mean that traditional approaches are no longer fit for purpose. In this case, a major European government organisation faced a highly advanced state-sponsored cyberattack. The attacker had gained access to the environment, creating a real risk of disrupting critical digital services and exposing highly sensitive data linked to senior individuals. “The client could no longer assure the quality of the security of their data and environment,” explains Paul Beverley-Paddock, Director at Deloitte and Security Operations Lead. “We were dealing with nation-state threat actors operating with tools that can appear indistinguishable from legitimate IT activity,” shares Caroline Honeycombe, Director at Deloitte and Cyber Incident Response Lead. The organisation needed to respond immediately, regain control, stop the threat and strengthen its ability to defend against future attacks. This required not just new technology, but a fundamentally different approach: combining AI, including Generative AI, with human expertise to detect and respond to threats at scale. Deloitte combined cyber incident response expertise with advanced AI capabilities from Google Cloud to transform how the threat was identified, understood and removed. At the core was a threat-led approach. Billions of data points were inputted into Google SecOps, creating a unified, real-time view of activity. This was enriched with integrated threat intelligence, enabling rapid attribution and a deeper understanding of the attacker’s tactics. By using Gemini, analysts could interact with this data in a fundamentally new way. Instead of manually complex queries to search through vast datasets, they could ask natural language questions, generate and evolve detection rules in real time and quickly identify patterns linked to the threat actor. Gemini enabled us to reduce
Apr 18, 2026 · via deloitte.com
Bank of Canada Governor Tiff Macklem said governments and regulators need to move quickly to get a handle on the cybersecurity risks posed by powerful new artificial intelligence tools such as Anthropic’s Claude Mythos model. The emergence of new AI models adept at hacking into secure systems was widely discussed at the spring meetings of the International Monetary Fund and World Bank in Washington over the past week, Mr. Macklem said. San Francisco-based Anthropic announced the Mythos model earlier this month, but opted not to make it widely available because of the risks it presents. The model has shown unprecedented skill at finding and exploiting vulnerabilities in software, according to Anthropic. “This isn’t a one-off. Mythos has arrived, it’s a lot more powerful than what came before. But something else will come that’s even more powerful than that,” Mr. Macklem told reporters on a call from Washington. “As a [financial] system, both within Canada, but internationally, we’re going to need to come to grips with how we’re going to manage this on an ongoing basis.” Artificial Intelligence Minister says Anthropic taking ‘responsible’ approach with Mythos Mr. Macklem said he discussed Mythos with U.S. Federal Reserve Chair Jerome Powell this week, while Finance Minister François-Philippe Champagne talked to his counterpart U.S. Treasury Secretary Scott Bessent. He also said the Canadian Financial Sector Resiliency Group (CFRG), which is chaired by the Bank of Canada and includes representatives from other regulators and Canada’s big banks, met a second time this week to discuss the financial system security implications of Mythos. Questions about the potential impact of Mythos on the financial system emerged last week after Mr. Powell and Mr. Bessent convened a meeting of top U.S. bank CEOs to discuss the issue. News of the meeting sent central banks and regulators around the
Apr 18, 2026 · via theglobeandmail.com
Hackers are attempting to exploit a high-severity flaw found in several end-of-life routers from TP-Link, according to a blog post published Friday by Palo Alto Networks’ Unit 42. Researchers warn the observed payloads share similarities to those found in malware used in Mirai-like botnets. Such activity would involve attempts to download the malware and execute on vulnerable devices, according to researchers. The vulnerability was originally disclosed in June 2023, and proof of concept exploits appeared prior to the disclosure, wrote Unit 42 researchers. The Cybersecurity and Infrastructure Security Agency previously added the command injection vulnerability, tracked as CVE-2023-33538, to its Known Exploited Vulnerabilities catalog in July 2025. Palo Alto Networks telemetry detected large-scale exploitation attempts at the time. Researchers caution that recently observed exploitation attempts have not been successful, but the underlying vulnerability is real. They said successful exploitation would require authentication to the router’s web interface. TP-Link confirmed the routers have reached end-of-life status and are no longer being supported and should therefore be replaced with hardware that is under support, according to the Unit 42 post. Users should also make sure default credentials are not being used. The research follows years of concerns about the security of TP-Link routers, which have raised larger concerns about the security of foreign-linked networking equipment. Forescout Research in October warned of critical flaws in TP-Link Omada routers. In early 2025 a botnet targeted critical flaws in TP-Link Archer routers in a campaign targeting U.S. organizations.
Apr 18, 2026 · via cybersecuritydive.com
NEW BRITAIN — The Common Council approved several measures, including a new cybersecurity system, funding for road paving and a resolution recognizing Earth Day. At its meeting, the council approved funding for new cybersecurity services following a January ransomware attack that affected the city’s information technology systems. The breach disrupted phones and computers across departments, though officials said emergency services were not affected. The council approved a three-year agreement with Cowbell MDR to monitor and protect city systems. According to the resolution, Cowbell MDR “is a fully managed detection and response service that provides continuous monitoring, threat detection and response across endpoint, identity and cloud applications.” The service will cost $66,000 per year and includes a “$25,000 breach response fund” to help address future incidents. Following the January attack, Mayor Bobby Sanchez said the city responded quickly and is working closely with state and federal partners, law enforcement and an outside cybersecurity expert to investigate the incident and restore systems safely and securely. The council also approved funding for the city’s annual road paving program. About $2 million in state aid, along with additional city funds, will be used to repair and repave roads this summer. Contracts were awarded to Tilcon Inc. and Garrity Asphalt Reclaiming for materials, milling and paving work. City officials said roadwork is based on a pavement rating system that helps determine which streets are repaired each year. In addition, the council passed a resolution recognizing Earth Day, to be observed Wednesday. The resolution highlights the city’s ongoing efforts to protect the environment and promote sustainability. The measure, introduced by Ward 3 Alderwoman Candyce Scott, seeks to promote conservation, energy efficiency and the study of the use of clean energy sources” in municipal government and throughout the community. It also notes steps the city has taken,
Apr 18, 2026 · via bristolpress.com
About
Press
Copyright
Contact us
Creators
Advertise
Developers
Terms
Privacy
Policy & Safety
How YouTube works
Test new features
NFL Sunday Ticket
© 2026 Google LLC
Apr 18, 2026 · via youtube.com
Siobhan Harms reports:
The Ohio Auditor of State’s Office will begin evaluating school districts’ cybersecurity policies in July.
As outlined by House Bill 96, districts had to implement a cybersecurity program that safeguards the district’s data, information technology and information technology resources to ensure availability, confidentiality and integrity.
The law reads, “The program shall be consistent with generally accepted best practices for cybersecurity, such as the national institute of standards and technology cybersecurity framework, and the center for internet security cybersecurity best practices.”
Read more at Spectrum News1.
Apr 18, 2026 · via databreaches.net
17 Apr He Pled Guilty To Blackmailing Apple. What Really Happened. This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Apr. 17, 2026 – Listen to the podcast episode Kerem Albayrak from north London threatened to wipe 319 million accounts unless Apple gave him iTunes gift cards worth $100,000 (£76,000), BBC reported in a Dec. 2019 story. An investigation found that Albayrak had not compromised Apple’s systems. He was given a two year suspended jail sentence and ordered to do 300 hours of unpaid work. In Mar. 2017, Albayrak emailed Apple’s security team, claiming to have breached millions of iCloud accounts. He posted a video on YouTube that appeared to show him breaking into two accounts. He threatened to sell the account information, dump his database online and reset the accounts, unless Apple paid his iTunes gift card demand. Albayrak also said he would accept $75,000 worth of cryptocurrency, but later increased this to $100,000. He was arrested at his home in north London about two weeks after sending his threat. Apple investigated his claims but could not find evidence that its systems had been compromised. In addition to the 300 hours of unpaid work, he was given a six month electronic curfew. The incident was later deemed to be part of a publicity stunt to promote a tool Albayrak was developing. In a new Cybercrime Magazine Podcast episode Albayrak publicly discusses his side of the story for the first time; he has since gone on to work in cybersecurity. Cybercrime Magazine is Page ONE for Cybersecurity. Go to any of our sections to read the latest: - SCAM. The latest schemes, frauds, and social engineering attacks being launched on consumers globally. - NEWS. Breaking coverage on cyberattacks and data breaches, and the most recent privacy
Apr 18, 2026 · via cybersecurityventures.com
Acknowledgments: Special thanks to Harlan Carvey and Lindsey O’Donnell-Welch for their contributions to this blog and research. Everyone’s talking about AI’s impact on cybersecurity, from how it will affect vulnerability management to what it means for threat actor campaigns. Over the past year, we’ve seen how threat actors are relying on AI to increase their productivity across campaigns, specifically for drafting scripts, assembling commands, and more. At the same time, defenders like Huntress Security Operations Center (SOC) analysts use AI tools in many places across their investigations to connect the dots faster, with experienced analysts reviewing the results and owning every verdict and report at the end of the investigation. But what happens if a user with Managed Endpoint Detection and Response (EDR) installed tries to use an AI tool for troubleshooting or responding to suspicious behavior? We recently triaged an interesting case where this happened, and it had unexpected consequences when our analysts investigated the endpoint. This is a tale with three storylines: the Huntress SOC, a group of at least two different threat actors, and a third-party developer using OpenAI’s Codex coding agent to try to knock down malicious activity on their Linux system. In this first part of our two-part blog series, we will break down how the end user prompted Codex to help them troubleshoot and respond to suspected malicious behavior on their endpoint. In the second part, we will look at how that complicated the initial triage and investigation into the incident from the perspective of the SOC. Key takeaways After being installed mid-incident, Huntress investigated an endpoint belonging to an organization in the tech sector that was being targeted by multiple threat actors, who installed cryptominers, harvested credentials, and more. The user behind the targeted endpoint was relying on an AI agent (Codex) to
Apr 18, 2026 · via huntress.com
Ghana and Italy Deepen Cybersecurity Cooperation to Strengthen Digital Resilience The partnership reflects a shared focus on building resilient digital systems and protecting critical information infrastructure amid growing cyber threats. Ministry of Communication, Digital Technology and Innovations Ghana has reaffirmed Ghana’s commitment to international collaboration in cybersecurity through strengthened ties with Italy, aimed at securing the digital future of both economies and their citizens. The partnership reflects a shared focus on building resilient digital systems and protecting critical information infrastructure amid growing cyber threats. As part of this effort, Ghana continues to advance key national initiatives that integrate cybersecurity awareness and secure digital practices. Flagship programmes such as the One Million Coders Programme and Girls in ICT are playing a central role in developing a future-ready workforce. These initiatives are designed to equip young people with the technical skills and cybersecurity knowledge required to safeguard digital ecosystems and support national digital transformation goals. The Cyber Security Authority Ghana is also engaged in these efforts, contributing to the broader objective of strengthening the country’s cyber resilience and promoting secure digital innovation. Government officials emphasised that cybersecurity remains a shared responsibility, highlighting the importance of international partnerships in building secure, inclusive, and sustainable digital economies.
Apr 18, 2026 · via techafricanews.com
The California Governor’s Office of Emergency Services (Cal OES), through the California Cybersecurity Integration Center (Cal-CSIC), is now offering the Multi-State Information Sharing and Analysis Center (MS-ISAC) to qualified agencies for free. This Cal OES-sponsored initiative is available to California’s public agencies, including state, local, and tribal partners. Some examples of public agencies include schools, utilities, emergency services, and more. MS-ISAC has a special focus on helping underserved communities and organizations with fewer cybersecurity resources. MS-ISAC operates 24/7 and provides access to experts and tools that help organizations prevent, and if necessary, respond quickly to cyber incidents. It serves as the nation’s only cybersecurity resource solely dedicated to serving state, local, and tribal agencies stay ahead of evolving threats and build stronger cybersecurity defenses. The center is part of the Center for Internet Security, a non-profit that works with a global IT community to help protect organizations from cyber threats. It offers paid MS-ISAC memberships to individual organizations as well as statewide packages that cover state, local, and tribal agencies. Cal OES’s statewide sponsorship shows its commitment to helping organizations strengthen their cyber defense systems. It also helps state, local, and tribal agencies to follow best practices and stay connected with a trusted cybersecurity network. The benefits of the MS-ISAC include: - Sharing information about cyber threats - Early warnings about possible cyber incidents and how to respond and investigate them. - A 24/7 security operations center - Access to MemberConnect, a communications platform that allows the enrolled California agencies to share information and coordinate on cybersecurity-related matters. Cybersecurity is essential for public entities. It safeguards critical public services like healthcare, sensitive resident data such as tax information, and continuity of government operations, including emergency response services. MS-ISAC helps Cal OES and Cal-CSIC make California more resilient by building strong
Apr 18, 2026 · via news.caloes.ca.gov
In the wake of Anthropic’s announcement of its latest artificial intelligence model, Mythos, on April 7, the company has stood by an unusual decision: refusing to release it to the public. Not since OpenAI temporarily withheld its GPT-2 model in 2019 has a major developer deemed a system too dangerous for the public. More than a week later, that choice is still reverberating through finance and regulatory circles. “The fallout—for economies, public safety, and national security—could be severe,” Anthropic said on its website. But while officials scramble to gauge the implications of the model’s unprecedented hacking capabilities, cybersecurity experts are divided over whether Mythos marks a major break from what came before or an expected step down an already troubling path. Anthropic did not respond to a request for comment from Scientific American. On supporting science journalism If you're enjoying this article, consider supporting our award-winning journalism by subscribing. By purchasing a subscription you are helping to ensure the future of impactful stories about the discoveries and ideas shaping our world today. A 245-page technical document released alongside the announcement outlines what the company presents as a major leap in capability. The model operates like a senior software engineer, demonstrating an ability to spot subtle bugs and self-correct mistakes. It also scored 31 percentage points higher than Anthropic’s previous cutting-edge model, Opus 4.6, on the USAMO 2026 Mathematical Olympiad, a grueling, two-day proof-based competition. But that same coding prowess makes Mythos a formidable offensive weapon, and Anthropic says it can outstrip all but the most skilled humans at identifying and exploiting software vulnerabilities. In tests, it found critical faults in every widely used operating system and web browser. Of those vulernabilities, 99 percent have not yet been patched. And Anthropic has disclosed only a fraction of what it says it
Apr 18, 2026 · via scientificamerican.com
Fact Check Team: Anthropic’s Mythos AI raises cybersecurity promise, but poses risk WASHINGTON (TNND) — A powerful new artificial intelligence model is drawing attention in the tech and cybersecurity world — not just for what it can do, but for how it could be used if it falls into the wrong hands. Anthropic, one of the leading AI firms, is developing an experimental system known as “Mythos.” Unlike consumer-facing AI tools, this model is not publicly available. Instead, it’s being quietly tested with a small group of major companies due to concerns over its capabilities. A Tool Built for Cybersecurity — and Potential Exploitation At its core, Mythos is designed to excel at cybersecurity tasks. According to Anthropic, the model has already identified thousands of high-severity software vulnerabilities, including flaws in widely used operating systems and web browsers. In some cases, the system has even demonstrated the ability to identify and exploit so-called “zero-day” vulnerabilities — previously unknown weaknesses that can be especially dangerous if discovered by malicious actors. Independent testing by the UK AI Security Institute underscores both the promise and the risk. Evaluators found the model succeeded in expert-level cybersecurity challenges roughly 73% of the time and, in certain scenarios, could carry out complex, multi-step simulated cyberattacks from start to finish. However, those tests were conducted in controlled environments — not against real-world, highly defended systems. Why Access Is Being Restricted Because of these capabilities, Anthropic and other AI companies are taking a cautious approach. Rather than releasing Mythos publicly, access is limited to a small group of major tech firms, including Google, Amazon, Apple, and Microsoft. The goal is to test the system while minimizing the risk of misuse. The company has also launched “Project Glasswing,” an initiative focused on using advanced AI capabilities for defensive cybersecurity
Apr 17, 2026 · via foxsanantonio.com