@heyshrutimishra: We've been watching the wrong AI story. While the timeline keeps debating whether Mythos is real, hyped, or just well-m…
摘要
A thread contrasts the hype around AI security startup Mythos with 360's practical achievement of autonomously discovering 23 vulnerabilities (including two criticals) in the OpenClaw ecosystem, highlighting the real direction of AI security.
查看缓存全文
缓存时间: 2026/05/20 04:25
We’ve been watching the wrong AI story.
While the timeline keeps debating whether Mythos is real, hyped, or just well-marketed, 360 has quietly taken an autonomous vulnerability-mining agent into the OpenClaw ecosystem and walked out with 23 confirmed vulnerabilities, including two Criticals, all filed into the CNNVD and CNVD national vulnerability databases.
That is the gap most of the timeline is stepping over.
The OpenClaw work is also closer to where AI security is actually heading. Agents are a fuzzy-boundary target where prompts double as instructions, where the static-analysis baseline barely exists, and where a breach at any one of authentication, network, execution, or control cascades through the rest. The 23 findings cover all four layers.
Where the Mythos conversation is still about whether the capability is real, the 360 work shows the same capability already running as operating infrastructure, on a target that better reflects the next phase of AI security.
The interesting question stopped being “is AI-on-AI security real.” It is who owns enough attacker-perspective data to make it production-grade.
Charly Wargnier (@DataChaz): 🚨 The Mythos vs. 360 showdown is the perfect case study of hype vs. reality in AI security right now.
On one side: Mythos
Blockbuster launch. Massive benchmark claims.
On the other: 360.
Busy tearing apart OpenClaw, going ruthlessly deep into actual agent security. 🧵↓
相似文章
@logangraham: 很多人一直在关注Mythos、Glasswing以及我们/合作伙伴正在修复的漏洞。今天,我很兴奋……
Anthropic的Claude Mythos Preview模型已经过XBOW和英国AISI的评估,展示了前所未有的自主网络安全能力,包括解决端到端网络靶场以及发现数千个漏洞。该公告强调需要为网络安全领域快速发展的AI能力做好准备。
@Dan_Jeffries1: 终于有一篇关于Mythos的半有用读物,不涉及神话,而是更实际地谈论这意味着什么(不是……
Dan Jeffries评论了Cloudflare对Anthropic的Mythos的测试,认为真正的讨论应聚焦于针对AI驱动的攻击的实际安全改进,并且如果团队调整工作流程,AI最终会让软件更安全。
@daniel_mac8: https://x.com/daniel_mac8/status/2054994899422826592
该讨论串指出,有最新证据表明AI代理已基本实现自主运作,其中Claude Mythos成功解决了此前未破解的网络攻击模拟实例,并超出当前基准测试测量极限,显示出超指数级进步。同时强调了安全影响及机构应对措施。
Anthropic 新模型一个月内发现超一万个安全漏洞
Anthropic 的新 AI 模型 Claude Mythos 在一个月内识别出全球系统软件中超过一万个高危和严重安全漏洞,其误报率优于人类测试人员,显著推动了 AI 驱动的网络安全。
Cloudflare警告:在AI巨头G20简报之前,Mythos AI能构建真实网络攻击
Cloudflare对Anthropic的Mythos Preview的测试显示,该模型能够将多个低严重性漏洞串联成可用的利用代码,这是进攻性网络安全AI的一大步,同时Anthropic正准备向G20官员简报相关风险。