Latest
Anthropic’s Mythos AI found over 2,000 unknown software vulnerabilities in just seven weeks of testing
There is a new AI model called Mythos. Anthropic built it for defensive cybersecurity research. It is so effective at finding software vulnerabilities that Anthropic decided the general public cannot have it. Instead, they are letting a small circle of trusted partners like Microsoft and Google experiment with it first, under controlled conditions, while researchers figure out what guardrails need to exist.
That decision alone should tell you something. When the company that built a tool decides the world is not ready for it, you pay attention. And when you understand what Mythos actually did during testing, that caution starts to make complete sense.
Sign up for my FREE CyberGuy Report
WINDOWS PCS AT RISK AS NEW TOOL DISARMS BUILT-IN SECURITY
Seven weeks. One AI model. One team. More than 2,000 previously unknown software vulnerabilities were found. If you need a moment with that, take it. John Ackerly, CEO and Co-Founder of Virtru, a data security company, put that figure into perspective in a way that is hard to shake.
“Mythos is absolutely a turning point for cybersecurity. Think about it. Mythos didn’t pick a lock; it found thousands of locks that were never locked in the first place (that no one even knew existed) in software that the best human security researchers had studied for decades.
The math is staggering. One AI model, and one team, in seven weeks, found more than 2,000 zero-day vulnerabilities. That is 30% of the world’s entire annual output prior to AI. When thousands of researchers get access to AI models like Mythos, a single year will surface exponentially more zero-days than the 360,000 recorded in all of software history.
Mythos and other AI models like it can now find and exploit software flaws at a speed and scale that is beyond containment. This means that the old approach of building stronger walls around systems and hoping they hold is becoming much less reliable. It also means that the manual ‘find a vulnerability, patch the vulnerability’ process is not going to keep pace with a threat landscape bolstered by the speed and scale of AI.
The threat surface is now expanding faster than any wall can contain it. The only answer to this new dynamic is to protect the data itself, rather than prop up perimeter protection around it.”
Thirty percent of the world’s annual output in seven weeks changes the game entirely.
Cybersecurity teams have used AI tools for years. So what makes this different?
Ackerly explains it this way: “What makes this different is the level of autonomy and speed it enables. Mythos is being described as a system that can discover vulnerabilities and even generate working exploits much faster than traditional human-led workflows. This model could make it easy for a bad actor to identify and exploit vulnerabilities in software, even if that bad actor isn’t knowledgeable or trained.”
That last part matters most. Before a tool like this, exploiting a serious software vulnerability required real technical skill. Mythos AI lowers that barrier significantly. A person with bad intentions and no technical background could potentially use a model like this to cause serious damage. The expertise gap that once offered some natural protection is closing.
FAKE PAYPAL EMAIL LET HACKERS ACCESS COMPUTER AND BANK ACCOUNT
Most cybersecurity spending, the overwhelming majority of it, goes toward what experts call perimeter defense. Think firewalls, network monitoring, endpoint security and intrusion detection. The entire strategy is built on one core idea: keep the bad actors out, and the data inside stays safe.
Ackerly describes how that model is now breaking down.
“The perimeter is the digital wall around your systems and the information you possess. For decades, cyber strategies have primarily focused on the idea that if you protected the perimeter well enough – if you built a strong enough wall – the sensitive data on the inside would stay safe. The industry has poured hundreds of billions of dollars into firewalls, endpoint detection, network security, application security, and other perimeter defenses.
Traditional security architecture by itself cannot keep pace in this new world.
The Mythos development from Anthropic is making a hard truth very apparent: time is running out for companies to prepare for this new reality. Shifting focus from ‘protecting the perimeter’ to ‘protecting the data’ is critically important to mitigate data loss or compromise.”
Hundreds of billions of dollars. And now the model those dollars were built on is becoming unreliable. It forces a full rethink.
This is the question everyone wants a straight answer to. Ackerly offers one that is more nuanced than a simple yes or no.
“I wouldn’t frame it as attackers automatically having an advantage. But over time, it does mean that ‘bad guys’ and ‘good guys’ will have access to essentially the same tools. As a result, I do think defenders absolutely need a different strategy. If you assume the outer wall may fail, then the smarter move is to protect the data itself so it stays controlled even after a breach.”
The playing field is leveling. And that may sound fair until you remember attackers only need to succeed once, while defenders have to succeed every time.
Speed is what makes Mythos AI genuinely alarming. Traditional cyberattacks move through a lifecycle. Reconnaissance takes time. Finding the right vulnerability takes more time. Building an exploit takes more time on top of that.
Ackerly explains what happens when AI compresses all of that.
“AI is accelerating the threat. A model that can find and exploit vulnerabilities autonomously compresses the attack lifecycle from weeks to hours, or even minutes. Every layer of the traditional security stack now has to operate at machine speed. Manual security architectures cannot keep up.
But AI also makes data-centric security more powerful, not less so. When every piece of sensitive data is protected at the object-level, AI agents can enforce governance at scale by checking entitlements, applying attribute-based access controls, and auditing data flows in real time. The same capabilities that make Mythos a dangerous tool in the hands of ‘bad guys’ make it a valuable tool in the hands of ‘good guys’.
The question organizations should be asking shifts from “how do I build higher walls?” to “when the walls fail, is my data still protected?” That is the question worth sitting with.
Most of the Mythos coverage has focused on corporate risk. But your bank account and medical records sit in those same vulnerable systems.
“For everyday people, the first change is that breaches and scams could become more frequent, more targeted, and harder to spot. If AI makes it easier to uncover weak points in the systems we all rely on, that can translate into more pressure on the services that hold our personal data, from email and cloud storage to health, banking, and retail platforms.
Consumers shouldn’t assume a company is doing the right thing with their data. Now, they really can’t assume a company’s outer defenses are enough to protect their information.
This also highlights the importance of basic cyber hygiene like unique passwords and MFA, so that when breaches happen, the scope of impact on your own personal data is contained.”
Your bank account, your medical records, your tax documents, your private messages. All of it already lives across dozens of platforms you trust to protect it. If those platforms’ outer defenses are no longer reliable, what exactly is standing between your data and someone who wants it?
Ackerly goes further on where the exposure actually lives. “Data now travels across clouds, devices, partners, and borders. The risk isn’t just one hacked server in one building anymore. It’s all the places your data passes through or gets copied to along the way.
Anthropic made a choice that is rare in the AI industry. They built something powerful and then decided not to release it widely.
On that decision, Ackerly is direct. “Anthropic’s decision to withhold Mythos from general release is unprecedented and, frankly, responsible. Time will tell what these partners are able to do with regard to safety, but releasing it to the general public would certainly have been ill-advised and dangerous.”
Unprecedented. That word deserves weight here. In an industry that races to release new tech, Anthropic stopped. That speaks volumes.
We reached out to Anthropic for a comment, but did not hear back before our deadline.
THIRD-PARTY BREACH EXPOSES CHATGPT ACCOUNT DETAILS
The perimeter model is deteriorating, but that does not mean you are helpless. Individual behavior still matters, and it matters more now than it did before.
Ackerly’s recommendation is this: “Stop assuming the app, platform, or company perimeter can always protect your information, or that they will do the right thing with your data. People should be much more deliberate about what data they share, where they store it, and who can access it. Protection needs to travel with the data, not just sit at the edge of a network. For you, that means choosing services that give you stronger control over your information and being more cautious about oversharing sensitive data in the first place. The data owner should always have governance over said data.” So where do you start?
A password manager makes this realistic. If one platform gets breached, unique passwords keep the damage isolated to that one account.
Multi-factor authentication (MFA) adds a layer that survives even when a password is compromised. It is one of the highest-impact steps an individual can take.
Outdated software is one of the most common entry points attackers use. Strong antivirus software catches threats your instincts might miss, and keeping apps and operating systems current closes the gaps that models like Mythos are built to find. Get my picks for the best 2026 antivirus protection winners for your Windows, Mac, Android & iOS devices at Cyberguy.com
Every app that holds your data is a potential exposure point. The less you overshare, the smaller your footprint becomes.
Data brokers collect and sell your personal information, often without you ever knowing. Data removal services find where your data is listed and request its removal. You cannot control every place your information travels, but you can shrink the trail it leaves behind. Check out my top picks for data removal services and get a free scan to find out if your personal information is already out on the web by visiting Cyberguy.com
Not all platforms treat your data the same way. Look for services that let you see, manage and limit how your information is used and where it goes.
Catching a breach early limits the damage significantly. Set up account alerts wherever your bank or financial platform allows it. A credit freeze costs nothing and stops new accounts from being opened in your name without your knowledge.
Ackerly warned that scams will get more targeted and harder to spot as AI lowers the barrier for bad actors. Scrutinize every link before you click it and treat unexpected emails or texts asking for login information as suspicious by default. If something feels off, it probably is.
The goal is to limit how much damage they can do. When you operate with that assumption, your decisions about data hygiene get sharper, and your exposure gets smaller.
Take my quiz: How safe is your online security?
Think your devices and data are truly protected? Take this quick quiz to see where your digital habits stand. From passwords to Wi-Fi settings, you’ll get a personalized breakdown of what you’re doing right and what needs improvement. Take my Quiz here: Cyberguy.com
Mythos did not create the vulnerability problem. It made the scale of it visible in a way that is no longer ignorable. The foundation of modern cybersecurity, the idea that strong enough walls will keep data safe, is being tested in real time by a technology that moves faster than any human team can. That is a consumer story as much as it is a corporate one. Your data lives in systems built on that old model. And the moment to think differently about how it is protected is now, not after the next major breach makes the headlines. Anthropic made a responsible call by limiting access to Mythos. But the model exists. The capability is real. Other versions of it are being developed. The question for every organization and every individual becomes the same one Ackerly keeps returning to.
When the walls fail, and experts are telling us they will, what is actually protecting your data on the other side? Let us know your thoughts by writing to us at Cyberguy.com
Sign up for my FREE CyberGuy Report
Copyright 2026 CyberGuy.com. All rights reserved.
Latest
JUST IN: ‘Squad’ Congressional Candidate Arrested
A Democratic congressional nominee who defeated a sitting member of Congress earlier this year was arrested Thursday during a major protest against Israeli Prime Minister Benjamin Netanyahu outside the United Nations in New York City.
Darializa Avila Chevalier, the Democratic nominee for New York’s heavily Democratic 13th Congressional District, was taken into custody as demonstrators gathered near U.N. headquarters ahead of Netanyahu’s address to the General Assembly.
Avila Chevalier defeated five-term Rep. Adriano Espaillat in June’s Democratic primary after campaigning as a critic of U.S. support for Israel and receiving the backing of New York City Mayor Zohran Mamdani.
Now, just months after that upset victory, she was among the politicians, activists and entertainers arrested during Thursday’s demonstration.
The protest, organized by Jewish Voice for Peace, drew roughly 250 people to First Avenue and East 39th Street, just blocks from U.N. headquarters.
Demonstrators sat in the roadway while protesting Netanyahu’s appearance and U.S. support for Israel’s military operations in Gaza.
Police arrested protesters who blocked the road and refused orders to move.
Video of the moment congressional candidate Darializa Avila Chevalier, New York City Council Member Chi Ossé and comedian Caleb Hearon were arrested by NYPD while protesting Israeli Prime Minister Benjamin Netanyahu's UNGA speech today. pic.twitter.com/Oe5OEb5t2A
— Shannon Ryan (@_shanryan) September 24, 2026
Avila Chevalier defended her decision to participate and sharply condemned Netanyahu.
“As the Democratic Nominee for New York’s 13th Congressional District, I refuse to allow a war criminal to roam the streets of our city unchallenged,” she said.
“I refuse to play host to a man who has overseen the slaughter or injury of more than 64,000 children in Gaza with American taxpayer dollars.”
The description of Netanyahu as a “war criminal” reflects Avila Chevalier’s position. Netanyahu and the Israeli government have rejected accusations that Israel’s military campaign constitutes genocide and have maintained that Israel is targeting Hamas while seeking to minimize civilian casualties.
The International Criminal Court has issued an arrest warrant for Netanyahu alleging war crimes and crimes against humanity. Netanyahu and Israel reject the allegations and dispute the court’s jurisdiction.
Avila Chevalier’s arrest comes after a Democratic primary campaign in which U.S. policy toward Israel emerged as a significant dividing line between her and Espaillat.
She has advocated ending U.S. military support for Israel and has aligned herself with the Democratic Party’s democratic-socialist and pro-Palestinian wing.
Espaillat’s support for Israel became one of the issues Avila Chevalier used to challenge the longtime incumbent.
She ultimately defeated him in the June Democratic primary, securing the nomination in a district covering parts of northern Manhattan and the Bronx.
Thursday’s demonstration showed that she has no intention of softening her position after winning the nomination.
As police led her away, Avila Chevalier told reporters:
“We’re standing against war. Stop the genocide. U.S. dollars for health care, for housing, for education. Not for bombing children.”
She was not the only New York political figure taken into custody.
New York City Council Member Chi Ossé was also arrested during the demonstration.
Ossé similarly condemned U.S. financial support for Israel.
“I’m sick and tired of my taxpayer dollars going towards an active genocide,” Ossé said.
Council Member Alexa Avilés was also among those arrested.
The protest attracted a number of prominent activists and entertainers as well.
Actor Hannah Einbinder and whistleblower Chelsea Manning were among those taken into custody, while other reports identified actor Susan Sarandon among those arrested.
The NYPD said more than 100 people were arrested during the protests surrounding Netanyahu’s appearance.
The demonstration unfolded as Netanyahu addressed the United Nations amid intense international criticism of Israel’s military campaign in Gaza.
Netanyahu used his appearance to defend Israel’s conduct and push back against allegations surrounding the war.
The Israeli government maintains that its military campaign is directed against Hamas and points to the Oct. 7, 2023, Hamas attack on Israel, in which about 1,200 people were killed and 251 were taken hostage, as the catalyst for the war.
Palestinian health officials say more than 73,000 people have been killed in Gaza during the ensuing Israeli military campaign. Those figures do not distinguish in their topline count between civilians and combatants.
The political fight over the war has increasingly spilled into Democratic electoral politics in the United States.
Avila Chevalier’s primary victory over Espaillat was one of several 2026 races in which candidates critical of U.S. support for Israel defeated established Democratic politicians.
Her victory also positioned her to potentially become another democratic-socialist voice in Congress if elected in November.
Thursday’s arrest underscored how central the issue remains to her political identity.
Avila Chevalier did not merely issue a statement condemning Netanyahu’s appearance.
She joined demonstrators in the street outside the United Nations and was taken into police custody alongside other protesters.
For a congressional nominee only months away from the general election, it was an unusually visible act of protest.
And it offered voters a clear look at the kind of politics Avila Chevalier intends to bring to Washington if she wins the seat in November.
Latest
Jeanine Pirro Makes Massive Announcement – WH In Total Shock
U.S. Attorney Jeanine Pirro is launching a new federal division in Washington dedicated to pursuing fraud against the government and recovering taxpayer money.
The U.S. Attorney’s Office for the District of Columbia announced Wednesday the creation of its new Fraud and Asset Recovery Division, a specialized unit that will bring prosecutors, investigators, auditors and support personnel together to pursue civil fraud cases.
The new division will put a particular emphasis on the False Claims Act, one of the federal government’s most powerful tools for recovering money lost through fraud.
Pirro tied the sweeping reorganization directly to the Trump administration’s campaign against fraud, waste and abuse throughout the federal government.
“President Trump has prioritized the elimination of fraud, waste, and abuse involving federal agencies and programs,” Pirro said.
“This new Fraud and Asset Recovery Division will reinforce and consolidate our resources to hold fraudsters accountable and recover taxpayer dollars.”
Pirro then delivered an unmistakable warning to anyone attempting to defraud the government.
“We are sending a clear message: those who cheat the federal government will face decisive, coordinated action,” Pirro said.
The new division represents a significant restructuring inside one of the country’s most consequential U.S. Attorney’s Offices.
Pirro’s office is expanding and realigning resources from its existing Affirmative Civil Enforcement unit, which had operated within the Civil Division.
Officials said the change is intended to separate proactive civil enforcement work from much of the Civil Division’s massive defensive caseload.
That workload, according to the Justice Department, had limited the personnel and resources available to launch affirmative investigations and pursue fraud litigation.
The new structure is designed to change that.
Rather than forcing fraud investigations to compete with defensive civil litigation for resources, prosecutors and investigators will now have a dedicated division focused on finding fraud, pursuing cases and recovering federal money.
Assistant U.S. attorneys will work alongside investigators, auditors and support staff inside the new operation.
Dan Schiffer will serve as chief of the Fraud and Asset Recovery Division, while Sean M. Tepe will serve as deputy chief.
One of their primary weapons will be the False Claims Act.
Originally enacted in 1863 amid widespread fraud involving Civil War government contractors, the law allows the federal government to pursue individuals and companies that knowingly submit false claims for government money.
Those found liable can face triple the government’s damages along with additional civil penalties.
The law also contains powerful whistleblower provisions allowing private individuals to bring lawsuits on behalf of the federal government and potentially receive a portion of money successfully recovered.
And the amount of money involved is enormous.
False Claims Act settlements and judgments exceeded $6.8 billion during fiscal year 2025 — the highest single-year total in the law’s history.
Whistleblowers filed a record 1,297 qui tam lawsuits during the same year, while the federal government opened 401 new investigations.
Since Congress substantially strengthened the False Claims Act in 1986, settlements and judgments have surpassed $85 billion.
Pirro’s office already has experience pursuing major civil fraud cases.
According to the Justice Department, previous cases handled by the Washington office have involved allegations against government contractors accused of improperly billing commercial and international costs to federal contracts, software manufacturers accused of false disclosures and intentional overbilling, medical-device companies accused of misbranding and off-label marketing, and pharmaceutical manufacturers accused of violating federal medication regulations.
The new division will go beyond False Claims Act cases.
Its responsibilities will also include civil collections for federal agencies, enforcement of agency and inspector-general subpoenas and civil asset forfeiture actions.
The U.S. Attorney’s Office Financial Litigation Unit is also being folded into the Fraud and Asset Recovery Division.
That unit is responsible for collecting money already owed to the federal government, including criminal fines, special assessments, restitution, civil judgments and settlements.
It also handles certain debts owed to federal agencies, including student-loan debts owed to the Department of Education.
The result is a division with responsibilities on both sides of the government’s financial enforcement system: investigating suspected fraud and pursuing money already determined to be owed.
The restructuring comes as the Justice Department intensifies federal fraud enforcement nationwide.
But Pirro’s Fraud and Asset Recovery Division is specifically housed inside the U.S. Attorney’s Office for the District of Columbia, placing a dedicated civil fraud operation in the nation’s capital and at the center of the federal government.
The announcement itself does not accuse any newly identified company, contractor, nonprofit or individual of wrongdoing, and the Justice Department has not announced the division’s initial investigative targets.
Officials also have not publicly specified the division’s total staffing level or additional budget.
What the Justice Department has made clear is its objective.
Pirro is consolidating prosecutors, investigators, auditors and financial-enforcement personnel into a single operation charged with aggressively pursuing fraud against federal programs and recovering money for taxpayers.
The numbers illustrate the potential stakes.
More than $6.8 billion was recovered through False Claims Act settlements and judgments in fiscal 2025 alone.
More than $85 billion has been recovered since the law was strengthened in 1986.
And now Pirro’s Washington office is establishing an entire division dedicated to expanding that work.
For individuals and companies doing business with the federal government, Pirro’s message was direct:
Those who cheat the government should expect a coordinated response.
Latest
Senate Vote 50-49 On Save America Act — Dems Stunned!
The SAVE America Act secured 50 votes in the U.S. Senate during a dramatic late-night showdown, giving supporters of the Republican-backed election legislation a significant boost even as a procedural hurdle prevented the measure from advancing.
The 50-49 vote came during the Senate’s marathon June 4-5 “vote-a-rama,” when Sen. Mike Lee of Utah brought forward the voting provisions of the House-passed legislation.
At the center of the proposal are two major changes to federal election law: requiring documentary proof of U.S. citizenship to register to vote in federal elections and requiring eligible photo identification when casting a ballot.
The proposal also includes provisions directing states to verify voter rolls and remove noncitizens who are found to be improperly registered.
Lee’s amendment drew 50 votes in support and 49 against.
But that was not enough.
Because the amendment faced a budget point of order under the Senate’s reconciliation rules, Lee needed 60 votes to waive the objection.
His motion fell 10 votes short.
The result meant the proposal could not be added to the broader reconciliation package despite attracting 50 Senate votes.
The late-night tally nevertheless marked an improvement for supporters following an earlier attempt by Sen. Lindsey Graham of South Carolina.
Graham’s broader amendment failed 48-50 after four Republicans — Susan Collins of Maine, Lisa Murkowski of Alaska, Mitch McConnell of Kentucky and Thom Tillis of North Carolina — joined Democrats in opposing the effort.
Lee then brought forward a narrower version focused on the SAVE America Act’s voting provisions.
This time, Collins voted in support.
Murkowski, McConnell and Tillis remained opposed.
The result: 50-49.
That distinction quickly became a major talking point for supporters of the legislation.
They had demonstrated that 50 sitting senators were prepared to vote for the proposal, but Senate procedural rules still stood between those votes and adoption of the amendment.
Vice President JD Vance has the constitutional authority to break a 50-50 Senate tie when one occurs. But the vote before senators Thursday night required 60 votes to waive the budgetary objection, meaning a vice-presidential tiebreaker could not overcome that particular hurdle.
The fight is therefore far from over.
The SAVE America Act has become one of the Republican Party’s major election-policy priorities heading toward the 2026 midterms.
Supporters argue that requiring documentary proof of citizenship would strengthen enforcement of the existing prohibition against noncitizen voting in federal elections and increase confidence that voter rolls contain only eligible voters.
Opponents see the legislation very differently.
Federal law already prohibits noncitizens from voting in federal elections, and critics argue that requiring additional citizenship documentation could make registration more difficult for some eligible American citizens who do not readily possess the required documents.
Those competing arguments have fueled an increasingly intense battle over the legislation.
The House previously approved the SAVE America Act, while President Donald Trump, Vice President Vance and Republican lawmakers have pushed for its enactment.
But the Senate has been the major obstacle.
The chamber voted earlier this year to begin consideration of the legislation, yet supporters have not demonstrated the 60 votes generally needed to overcome a filibuster and bring contested legislation to a final vote.
Republicans subsequently attempted to use the reconciliation process to advance the election provisions alongside a massive immigration and border-security package.
That strategy created a different obstacle.
Senate reconciliation rules restrict the types of provisions that can be included in budget legislation, allowing senators to raise points of order against provisions considered outside those limits.
Overcoming such an objection requires 60 votes.
That is precisely where Lee’s amendment failed.
The underlying proposal attracted 50 votes.
The motion needed 60.
The outcome immediately renewed Republican debate over Senate procedure and the future of the legislation.
Lee has argued that the 50-vote showing demonstrates that the original House-passed proposal has simple-majority support in the Senate, even though supporters remain short of the votes necessary to overcome the chamber’s procedural barriers.
The dispute also places renewed attention on the filibuster.
Republican leaders have repeatedly acknowledged that the 60-vote threshold remains a central obstacle to moving the SAVE America Act through the Senate under ordinary procedures.
But eliminating the legislative filibuster would itself require sufficient support among Republican senators, and GOP leaders have not demonstrated that those votes exist.
That leaves supporters searching for another path.
For now, the SAVE America Act remains stalled.
But the late-night vote established an important piece of the Senate math surrounding the legislation.
An earlier attempt attracted only 48 votes.
Lee’s narrower proposal attracted 50.
That still wasn’t enough to clear the 60-vote procedural threshold.
But it demonstrated that 50 senators were willing to back the voting provisions when they were put before the chamber — a result supporters are certain to point to as they continue pushing for another vote.
The immediate effort failed.
The broader fight over the SAVE America Act did not.
-
Economy6 months agoVance Leaves Meeting, Looks Straight Into Camera, Announces Stunning Arrest
-
Economy5 months agoAdam Schiff Facing 30 Years In Prison After Bank Records Leak
-
Economy6 months agoSupreme Curt Sides With Trump — He Can Remove The All
-
Culture3 months agoMichelle Obama Drops Nasty Bomb About ‘Useless’ Daughter
-
Economy6 months agoAll Hell Breaks Loose On Fox When Jesse Watters Asks Fetterman One Question
-
Economy4 months agoPrayers Pour In After Fox Host Dies: ‘Senseless Murder’
-
Latest3 months agoFox News Stuns With Announcement About 5 Fired Hosts
-
Border & Security2 months agoTop Trump Admin And Wife Found Dead — Chilling Update Just Released
