frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Anthropic scales Claude Mythos to critical infrastructure in 15 countries

https://techcrunch.com/2026/06/02/anthropic-scales-claude-mythos-to-critical-infrastructure-in-15-countries/
42•Timofeibu•1h ago

Comments

cassianoleal•1h ago
In the meantime, not everyone with actual access to the model are all that impressed.

https://cyberplace.social/@GossiTheDog/116679693992983945

dymk•55m ago
“Cybersecurity weather person and award winning shitposter.” why are they someone we should pay attention to the opinion of?
jchw•30m ago
That's someone who is confident enough to have an evidently successful enough career to be able to access Mythos in its currently-limited rollout and yet not take themselves terribly seriously online.

Realistically their opinion deserves to hold more weight than the median HN comment.

dymk•27m ago
I dunno, I trust the engineers working on Firefox or the Linux kernel more than some random pseudo-anonymous Mastodon account -

https://arstechnica.com/information-technology/2026/05/mozil...

https://www.theregister.com/software/2026/03/26/linux-kernel...

airstrike•57m ago
I'll share the first-hand account I recently got from someone else.

> We've used it at work

> it is... not as hype as everyone is concerned about

> I'd argue the framework around it for security scanning is the arguably more useful side of the tool, definitely doesnt take a huge model to get all the issues it flagged on our systems

> For us, it absolutely flooded us with noise

> I mean hundreds if not thousands of false positives or minor issues or not applicable

> For every one reasonable issue

> The biggest issue it created was the execs treated every issue it produced like it was a drop everything and fix the issue type deal

> I'm talking company wide drop all things "we need to patch nginx because this module that no one uses and is disabled by default has this RCE vulnerability™

> Or "all ec2 AMIs need to be upgraded because it flagged a a version specific docker vulnerability", it flagged every single machine with docker regardless of if the actual vulnerability was relevant

> Vulnerability was with a very specific Auth plugin configuration you could enable with docker and specifically the Mosley docker compatible tool, but it is clear it only knew there was a vulnerability in docker, not if it was applicable or not

> Meanwhile dirtyfrag and friends not a single peep from btw despite it allowing for container escape

> Idk, I was underwhelmed with the quality of the reporting it gave really. If the company allowed me to get information about all the infrastructure in our entire organisation to run Claude over it repeatedly looking for recent CVEs I'm sure I could produce the same results...

jr-throw•33m ago
I'm pretty impressed with regular Claude Code with Opus 4.7/4.8 in finding vulnerabilities in our code. Maybe 70% are false positives though. It's a lot of work to manually push back on the findings. Still worth it.
bgilroy26•30m ago
It seems like there is a genuine communication breakdown between management and engineering. Engineers know that there are vulnerabilities all over the place and that there have been for ages and that where the rubber hits the road every vulnerability does not represent a successful exploit by some nefarious actor.

Management can often treat cybersecurity like a black box that represents millions upon millions in liability. If Mythos represents an opportunity to bring management's understanding of the amount of "security vulnerability debt" everyone carries into the real world, it might be a good thing

aliljet•54m ago
Is this just one giant marketing plot?
hasteg•46m ago
There's a lot of speculation that it is indeed a marketing plot and the model is just a step improvement over current capabilities... and the real reason they aren't releasing the model is they are compute constrained and cannot serve the model. To my knowledge there's no proof of this however, but given the fact that literally 60 days ago they made Mythos out to be the end of the world and last Friday they announced that they will release the model in a few weeks, I feel like it was indeed something along those lines (marketing ploy).
basch•28m ago
Or just control of supply and demand. If they can charge twice as much serving half as many customers, that leaves a lot of potential future customers leftover.
kspacewalk2•16m ago
Their IPO is coming up soon. It would be interesting if Mythos remained mythical right up until then, wouldn't it?
datakan•36m ago
The week before they released Mythos to governments they had all their source code stolen. It's all about improving their image and creating propoganda.
pixelesque•31m ago
waffleiron•53m ago
Not so sure I would want a company that does not see any issues with mass surveillance of my country [1] to have access to critical infrastructure or its source code where I live.

[1] https://www.anthropic.com/news/statement-department-of-war :

> But using these systems for mass domestic surveillance is incompatible with democratic values.

merrvk•36m ago
Got to say, Anthropic have hell of a marketing team.
maipen•29m ago
I don't get how this is event front page of HN.
ChrisArchitect•19m ago
[dupe] Discussion on source: https://news.ycombinator.com/item?id=48369863
thewebguyd•16m ago
It won't bring understanding though is the problem. You get situations like the parent, where the execs don't have the knowledge, time, or care to learn beyond "vulnerability bad, must patch now"

Execs/Management types getting extra visibility into the technical side, in my experience, has only ever resulted in additional but meaningless work, like just checking boxes on a compliance/audit checklist without actually considering the impacts of those changes, or whether a company is actually vulnerable to the disclosed CVE.

It's along the same lines of the BS I deal with day to day from upper management arguing back with "But ChatGPT said..." meanwhile pasting some hallucinated crap that doesn't even apply to our environment.

LLMs are basically a dunning-kruger machine for management. Engineering is best left alone and trusted to do what they are being paid to do.

mohamedkoubaa•24m ago
In other words it is equivalent to spending a million dollars on an audit by a software security consulting company
lgpartman•11m ago
Or to RedHat for rewriting Python core 500 times.

The "humans do it too" argument gets tiresome. Even if the consulting company fails, the money goes back to employees and back into the real economy. Now it goes to Don Amodei.

The consulting company could be local, which provides a higher degree of confidence, though not proof, that no data is exfiltrated to the US.

And so on.

It wasn't "all their source code", it was the source code to Claude Code: not really any of their internal secret sauce, at least directly.

Microsoft's MAI-Code-1-Flash Scores 51% SWE-Bench Pro with Just 5B Active Params

https://microsoft.ai/models/mai-code-1-flash/
91•EvanZhouDev•43m ago•22 comments

A walking tour of surveillance infrastructure in Seattle

https://coveillance.org/a-walking-tour-of-surveillance-infrastructure-in-seattle/
294•eustoria•6h ago•156 comments

QBE – Compiler Back end: Version 1.3

https://c9x.me/compile/release/qbe-1.3.html
36•birdculture•1h ago•1 comments

GitHub Copilot App

https://github.com/features/preview/github-app
25•theanonymousone•1h ago•17 comments

Adafruit Receives Demand Letter from Fenwick Legal Counsel on Behalf of Flux.ai

https://blog.adafruit.com/
507•semanser•9h ago•219 comments

Launch HN: Rudus (YC P26) – AI for concrete contractors

9•rishipankhaniya•39m ago•0 comments

Fidonet: Technology, Use, Tools, and History (1993)

https://www.fidonet.org/inet92_Randy_Bush.txt
115•BruceEel•5h ago•35 comments

Why Janet? (2023)

https://ianthehenry.com/posts/why-janet/
390•yacin•9h ago•195 comments

Rethinking Search as Code Generation

https://research.perplexity.ai/articles/rethinking-search-as-code-generation
38•1zael•2h ago•7 comments

Three Ways to Get Paid (2018)

https://jasonzweig.com/three-ways-to-get-paid/
160•nate•2h ago•100 comments

Expanding Project Glasswing

https://www.anthropic.com/news/expanding-project-glasswing
120•surprisetalk•6h ago•138 comments

Coreutils for Windows

https://github.com/microsoft/coreutils
151•gigel82•2h ago•140 comments

BQN: What Is a Primitive?

https://mlochbaum.github.io/BQN/commentary/primitive.html
12•tosh•3d ago•1 comments

Love systemd timers

https://blog.tjll.net/you-dont-love-systemd-timers-enough/
266•yacin•9h ago•177 comments

Bringing Up DeepSeek-V4-Flash on AMD MI300X

https://fergusfinn.com/blog/deepseek-v4-flash-mi300x/
17•kkm•1h ago•1 comments

Stop Ruining It

https://seths.blog/2026/06/stop-ruining-it/
196•herbertl•9h ago•93 comments

Key chemistry question answered, no quantum computer required

https://www.quantamagazine.org/key-chemistry-question-answered-no-quantum-computer-required-20260...
17•defrost•4d ago•0 comments

On the nature of autobiographical memory

https://theamericanscholar.org/you-must-remember-this/
12•prismatic•19h ago•2 comments

Show HN: RePlaya – self-hosted browser session replay with live tailing

https://github.com/s2-streamstore/replaya
9•shikhar•1h ago•1 comments

CSS-Native Parallax Effect

https://dan-webnotes.com/posts/2026-06-02-css-native-parallax-effect/
117•dandep•9h ago•46 comments

Great Question (YC W21) Is Hiring Applied AI Interns

https://www.ycombinator.com/companies/great-question/jobs/J5TNvQH-ai-engineer-intern
1•nedwin•7h ago

Can the stockmarket swallow Anthropic, SpaceX and OpenAI?

https://www.economist.com/finance-and-economics/2026/06/01/can-the-stockmarket-swallow-anthropic-...
648•1vuio0pswjnm7•19h ago•1114 comments

Show HN: Eyeball

https://eyeball.rory.codes/
195•mrroryflint•10h ago•68 comments

Trump signs downsized AI order after weeks of reversals

https://www.politico.com/news/2026/06/02/trump-signs-downsized-ai-order-00946389
68•_alternator_•2h ago•48 comments

Reviving Teletext for Ham Radio

https://spectrum.ieee.org/reviving-teletext-for-ham-radio
53•yarapavan•4d ago•27 comments

Pyro Caml Continuous Profiler for OCaml

https://semgrep.dev/blog/2026/announcing-pyro-caml-continuous-profiler-ocaml/
8•j12y•1h ago•0 comments

Anthropic scales Claude Mythos to critical infrastructure in 15 countries

https://techcrunch.com/2026/06/02/anthropic-scales-claude-mythos-to-critical-infrastructure-in-15...
42•Timofeibu•1h ago•20 comments

Why Custom Attributes in .NET Give Me Nightmares

https://blog.washi.dev/posts/custom-attributes-and-why-they-suck/
71•jandeboevrie•2d ago•23 comments

Squillions: How money laundering won

https://www.lrb.co.uk/the-paper/v48/n09/john-lanchester/squillions
144•rwmj•2d ago•143 comments

Apple rejected my dictation app for using the accessibility API

https://www.mitmllc.com/blog/apple-rejected-my-dictation-app/
261•RZelaya•7h ago•156 comments