@cryptopunk7213: claude mythos just broke Apple's $2 billion defense system. it did so by discovering a completely different attack vect…
Summary
Claude Mythos AI discovered a novel attack vector that bypassed Apple's M5 chip defense system in five days at a cost of $35K, producing a 55-page report delivered to Apple. The exploit poisons data ingested by the chip, evading Apple's MIE system.
Similar Articles
@igus_ai: Apple spent 5 years building a protection to shield its operating system. Three researchers bypassed it in 6 days using…
Three security researchers bypassed Apple's MIE protection in six days using AI model Claude Mythos, demonstrating a rare exploit that requires no traditional malware and gains root access on macOS. The full paper will be published after Apple releases a patch.
The first public macOS kernel memory corruption exploit on Apple M5 was built with Mythos Preview's help, and it only took 5 days.
Calif researchers, with help from the AI tool Mythos Preview, built the first public macOS kernel memory corruption exploit on Apple M5 hardware, bypassing MIE. The exploit chain took 5 days and will be fully disclosed after Apple fixes the vulnerabilities.
Anthropic's Mythos Just Helped Find macOS vulnerability That Could Break Apple's Security Protections
Anthropic's Mythos AI model helped cybersecurity firm Calif discover two previously undocumented macOS vulnerabilities that could bypass Apple's memory integrity enforcement, demonstrating the model's offensive capabilities under controlled access via Project Glasswing.
Discovering cryptographic weaknesses with Claude
Anthropic researchers used Claude Mythos, with extensive prompting to persist and find publishable results, to discover mathematical weaknesses in HAWK and a weakened AES variant, costing ~$100k in API usage. The work also produced a new cryptanalysis benchmark, CryptanalysisBench.
Claude Mythos Opens The Cybersecurity Pandora's box
Anthropic has unveiled Claude Mythos, a highly capable AI model designed to automatically discover security vulnerabilities in operating systems, browsers, and software libraries. Initially restricted to select enterprise and open-source partners under Project Glasswing due to dual-use risks, the release has sparked industry debate over AI security capabilities and corporate marketing tactics.