@heyshrutimishra: We've been watching the wrong AI story. While the timeline keeps debating whether Mythos is real, hyped, or just well-m…

X AI KOLs Following 新闻

摘要

A thread contrasts the hype around AI security startup Mythos with 360's practical achievement of autonomously discovering 23 vulnerabilities (including two criticals) in the OpenClaw ecosystem, highlighting the real direction of AI security.

We've been watching the wrong AI story. While the timeline keeps debating whether Mythos is real, hyped, or just well-marketed, 360 has quietly taken an autonomous vulnerability-mining agent into the OpenClaw ecosystem and walked out with 23 confirmed vulnerabilities, including two Criticals, all filed into the CNNVD and CNVD national vulnerability databases. That is the gap most of the timeline is stepping over. The OpenClaw work is also closer to where AI security is actually heading. Agents are a fuzzy-boundary target where prompts double as instructions, where the static-analysis baseline barely exists, and where a breach at any one of authentication, network, execution, or control cascades through the rest. The 23 findings cover all four layers. Where the Mythos conversation is still about whether the capability is real, the 360 work shows the same capability already running as operating infrastructure, on a target that better reflects the next phase of AI security. The interesting question stopped being "is AI-on-AI security real." It is who owns enough attacker-perspective data to make it production-grade.
查看原文
查看缓存全文

缓存时间: 2026/05/20 04:25

We’ve been watching the wrong AI story.

While the timeline keeps debating whether Mythos is real, hyped, or just well-marketed, 360 has quietly taken an autonomous vulnerability-mining agent into the OpenClaw ecosystem and walked out with 23 confirmed vulnerabilities, including two Criticals, all filed into the CNNVD and CNVD national vulnerability databases.

That is the gap most of the timeline is stepping over.

The OpenClaw work is also closer to where AI security is actually heading. Agents are a fuzzy-boundary target where prompts double as instructions, where the static-analysis baseline barely exists, and where a breach at any one of authentication, network, execution, or control cascades through the rest. The 23 findings cover all four layers.

Where the Mythos conversation is still about whether the capability is real, the 360 work shows the same capability already running as operating infrastructure, on a target that better reflects the next phase of AI security.

The interesting question stopped being “is AI-on-AI security real.” It is who owns enough attacker-perspective data to make it production-grade.

Charly Wargnier (@DataChaz): 🚨 The Mythos vs. 360 showdown is the perfect case study of hype vs. reality in AI security right now.

On one side: Mythos

Blockbuster launch. Massive benchmark claims.

On the other: 360.

Busy tearing apart OpenClaw, going ruthlessly deep into actual agent security. 🧵↓

相似文章

@daniel_mac8: https://x.com/daniel_mac8/status/2054994899422826592

X AI KOLs Following

该讨论串指出,有最新证据表明AI代理已基本实现自主运作,其中Claude Mythos成功解决了此前未破解的网络攻击模拟实例,并超出当前基准测试测量极限,显示出超指数级进步。同时强调了安全影响及机构应对措施。

Anthropic 新模型一个月内发现超一万个安全漏洞

Reddit r/ArtificialInteligence

Anthropic 的新 AI 模型 Claude Mythos 在一个月内识别出全球系统软件中超过一万个高危和严重安全漏洞,其误报率优于人类测试人员,显著推动了 AI 驱动的网络安全。