Skip to main content Skip to search Skip to main navigation
Menu
Important Cybersecurity Score: 7/10

BSI Warns About Anthropic's AI Tool Mythos

Anthropic's new AI model Mythos is finding thousands of vulnerabilities in operating systems and browsers. The BSI warns of considerable implications for national security.

BSI warns about new AI technology for vulnerability detection

The German Federal Office for Information Security (BSI) has examined Anthropic's new AI model "Mythos" in detail and is warning of considerable implications for the cyber threat situation and national security. The technology marks a significant turning point in the cybersecurity landscape, as it automatically uncovers hidden software vulnerabilities in widely used operating systems and web browsers.

What is the AI model Mythos?

Mythos is an artificial intelligence model developed by the US company Anthropic and specifically designed to detect hidden software vulnerabilities automatically. The company announced that it has already found thousands of serious vulnerabilities with this tool – including in every widely used operating system and web browser. These discoveries underline the technology's practical capability in real-world environments.

It is particularly notable that Anthropic itself warns that, given the rapid progress of artificial intelligence, such capabilities in AI tools could soon also be available to online attackers. This makes controlling and limiting the availability of such tools a central security issue.

Controlled access through high-profile partners

Anthropic does not plan to make Mythos generally publicly available. Instead, it is pursuing controlled cooperation with selected large technology companies and security specialists. Apple, Amazon and Microsoft are among the cooperation partners granted access to Mythos in order to identify and close security gaps in their own software.

Alongside the major tech corporations, further partners are involved in the project: the Linux Foundation, the IT security companies Crowdstrike and Palo Alto Networks, and the networking specialist Cisco. This selection points to a strategy that relies on established and trusted players in the security sector.

The BSI's perspective: national security in focus

A comprehensive reassessment of the vulnerability landscape

BSI President Claudia Plattner expressed concern about the far-reaching implications of the technology. While the BSI has not yet been able to test the new tool itself, it has gained insight into how it works through direct discussions with the developers. The agency takes Anthropic's announcements very seriously and expects "upheavals in how security gaps are handled and in the vulnerability landscape as a whole".

Followed through to its logical conclusion, there could in the medium term be no unknown classic software vulnerabilities left. This would result in a fundamental shift in attack vectors and a paradigm shift with regard to the cyber threat situation. Attackers would be forced to develop new methods and exploit other weak points.

Sovereignty and strategic control

The BSI also raises the question of whether – and if so, for how long – such powerful tools will be available on the open market or to other countries at all. This question leads directly to considerations of national and European security as well as technological sovereignty. Whoever controls such powerful security tools also holds a strategic advantage in the cybersecurity landscape.

The critical context: why vulnerabilities are so dangerous

Gateways for cybercrime and espionage

Vulnerabilities in software, hardware or networks are gateways for cyberattacks by criminals or by hackers working in the service of foreign intelligence services. The longer a vulnerability is known but not closed, the greater the risk for companies, government institutions and private users of falling victim to data theft or to extortion after malware has been installed.

Particularly critical are so-called zero-day vulnerabilities, which are not yet known to the manufacturers. These are often the first targets used by cybercriminals and intelligence services, since companies and public authorities cannot yet take countermeasures.

A historical example: WannaCry and the NSA gap

History shows the dramatic consequences when vulnerabilities are not closed in time. In 2017, hackers exploited a security gap known to the US intelligence service NSA in order to infect computers on a large scale with the ransomware WannaCry. Such programs encrypt the hard drive and demand money to release the data. At the time, British hospitals and Deutsche Bahn departure boards were among those affected. The NSA came under criticism because it had not had the security gap closed, even though the danger was obvious.

German intelligence services and investigators do, however, also use vulnerabilities for certain purposes – for example to investigate terrorist networks or serious crimes, or to avert danger. This illustrates the complex trade-off between security and certain investigative powers.

Practical relevance for security managers

Patching and regular updates as a critical practice

The immediate consequence of this situation for companies and operators of critical infrastructure is that installing security updates and systematic patching must be a top priority. With modern AI tools that detect vulnerabilities automatically, these become known earlier and in greater numbers. Companies must accelerate and optimise their update processes accordingly.

This applies in particular to operators of systems with a high protection requirement: proactive vulnerability analysis and regular security audits are becoming even more indispensable. It also applies to specialised security facilities that protect critical assets – banks storing cash and securities, for example, could benefit from additional security measures in order to be protected against technical attacks as well.

Outlook and strategic implications

The development of Mythos by Anthropic marks a new milestone in cybersecurity technology. With controlled access to the technology, Anthropic is attempting to strike a balance between innovation and security – a balance that will be difficult to maintain once similar capabilities emerge in other AI systems as well.

The BSI will continue to monitor developments closely and remain in dialogue with Anthropic. At the same time, national and European authorities will have to address the question of how such strategically important technologies can be regulated and controlled – in the interests of the security and sovereignty of Germany and Europe.

For companies and organisations this means: the time to prepare for modern threat landscapes is now. AI-supported vulnerability detection will become reality – and those who are not well prepared today will come under all the more pressure tomorrow.