news.mlab.sh
Back to the feed
threat-intel

Anthropic to Open Mythos AI to EU's ENISA

High
Summary

This article reports that Anthropic is granting access to its Mythos AI model to the European Union’s ENISA as part of the Project Glasswing initiative. Mythos, an AI model capable of autonomously discovering and exploiting software vulnerabilities, has raised concerns about its potential to accelerate cyberattacks. The arrangement marks a significant step for the EU in understanding and mitigating the risks associated with AI-assisted vulnerability research and exploitation, while also highlighting a potential strategic divergence between the EU and the US regarding cybersecurity approaches.

Anthropic is providing access to its Mythos AI model to ENISA as part of Project Glasswing, a collaborative effort to research cybersecurity vulnerabilities. Mythos is an AI model designed to rapidly identify and develop exploit chains for software vulnerabilities, having already uncovered flaws in systems like OpenBSD and FreeBSD. This capability raises significant concerns, as it could lower the barrier to entry for both state and non-state actors to automate sophisticated cyberattacks. The European Commission, through spokesperson Thomas Regnier, emphasized the importance of this access to gain a clear understanding of the potential risks associated with AI-assisted vulnerability discovery and exploitation, particularly as new, powerful AI models are emerging.

The arrangement involves a tightly vetted group of companies, including Amazon, Apple, Microsoft, and others, receiving $100 million in usage credits to utilize Mythos. ENISA, similar to the US CISA but with a less operational focus, will be the first EU entity to gain access to the model. This access is considered crucial for building institutional capacity to address the anticipated surge in vulnerabilities and for coordinating responses to threats across Europe. However, the exclusion of CISA has raised questions about strategic priorities, with some observers noting a divergence in approaches between the EU and the US regarding cybersecurity.

Anthropic is still negotiating the terms and conditions for ENISA’s access, focusing on ensuring a safe and mutually acceptable interaction with the model. The initiative aims to proactively identify and address vulnerabilities before adversaries can exploit them, reflecting a broader effort to bolster defensive capabilities against rapidly evolving cyber threats.

Read the full article at Dark Reading