AI Can Turn Security Fixes into Hacks in Hours
In brief
- Anthropic's study reveals that their Mythos Preview AI model can rapidly convert security patches for Firefox and Windows kernel into functional exploits within just hours.
- This process requires minimal cost-around a few thousand dollars-and no specialized expertise, making it accessible to a broader range of potential attackers.
- Eight complete attack chains were developed before Microsoft's automatic updates could be deployed on any device.
- This development highlights a critical flaw in the current patch update cycle, which has traditionally taken weeks.
- Anthropic argues that this outdated rhythm leaves systems vulnerable for too long, allowing AI-driven attacks to exploit these patches quickly.
- The study underscores the urgent need for a new approach to software security and updates.
- Looking ahead, experts suggest that organizations will need to adopt faster update cycles or develop more robust defenses against AI-powered threats.
- This shift could redefine how software vulnerabilities are managed in the future.
Terms in this brief
- Mythos Preview
- A model developed by Anthropic that was found to convert security patches into functional exploits within hours, highlighting vulnerabilities in software update cycles and raising concerns about AI's potential misuse in cybersecurity.
Read full story at The Decoder →
More briefs
SK Hynix Sees 1242 Percent Net Profit Boost
SK hynix said its second-quarter net profit soared 1242 percent year-on-year. This was driven by demand for its memory chips from the artificial intelligence industry. The company's quarterly net profit was 94 trillion won, an all-time high. Operating profit jumped 557 percent from last year to 60 trillion won. Revenue stood at 79 trillion won. SK hynix will invest around 40 trillion won this year. The company expects demand for its memory chips to persist as tech companies increase their AI infrastructure investments. SK hynix will continue to grow with the evolving AI technology.
UK Introduces AI-Enabled Smart Lamp-Posts
The UK has introduced AI-enabled smart lamp-posts that can recognize number plates and faces. These lamp-posts can power themselves through solar panels and have the potential to fight crime and track down missing persons. They can also incorporate new AI capability such as gait analysis and suspicious behaviors. The use of these lamp-posts has raised concerns about surveillance and data ownership, with 50,000 of them set to be installed in Nigeria. The technology will continue to develop and expand in the future.
AI Companies Destroying Millions of Books for Training Data
AI companies are destroying millions of physical books to use for training data. They scan the books and then discard them. This matters because the books are a valuable source of human-authored text. The AI companies need this text to improve their models. One company, Anthropic, was sued for copyright infringement and paid a $1.5 billion settlement. The AI companies are now hiring middlemen to buy the books for them. They want to keep their involvement a secret because they know it is not popular. The demand for human-authored text will continue to drive the destruction of physical books.
AI Sees Through Leaves to Help Farmers
Scientists created a new AI technology that can see through leaves to identify and measure hidden fruit. This technology can help farmers by creating a complete 3D model of each plant, including what is behind the leaves. It can open the door to automating tasks like crop forecasting. Current methods can produce inaccuracies of up to 23%, but the new technology has achieved fruit counts within 2% to 3% of the correct figure. The technology can save large growers millions of dollars and reduce waste. It will help farmers understand how much fruit they will produce and the size of the fruit. Farmers will be able to plan better with this new technology.
Microsoft's New Cybersecurity Model Delivers Big Efficiency Gains
Microsoft has unveiled MAI-Cyber-1-Flash, a compact cybersecurity model that achieves an impressive 96 percent score on the CyberGym benchmark when integrated into its MDASH multi-agent system. This new tool significantly reduces costs by cutting down reliance on expensive pure frontier models-costs are expected to drop by 50 percent since only the most challenging cases will be handled by GPT-5.4. While MAI-Cyber-1-Flash excels in efficiency, Microsoft still turns to OpenAI for complex reasoning tasks. This hybrid approach allows Microsoft to leverage its own model where it shines brightest while relying on OpenAI's expertise for tougher problems. Looking ahead, this cost-effective solution could expand cybersecurity capabilities for businesses, making advanced protection more accessible. The integration with MDASH suggests a broader push toward multi-agent systems in security, potentially leading to even smarter and more coordinated defenses in the future.