• Latest
  • Trending
  • All
Answer card: Claude Mythos did not breach the NSA; it ran an authorized red-team drill on test networks, but its real capability (a 17-year-old bug exploited in hours) is the actual story.

No, Claude Mythos didn’t hack the NSA: what really happened

3 September 2026
The official xAI announcement card for Grok 4.7, white type on a dark grey and navy gradient.

Grok 4.7 keeps $2 and $6, and its gains over 4.6 are xhigh versus high

22 September 2026
Answer card stating that Qwen-Image-2.1, released on 20 September 2026, ships open weights with a 7 billion parameter diffusion transformer, a Qwen3-VL 8B text encoder and an RGBA VAE totalling about 33 gigabytes in BF16, under the Qwen Research License that limits use to research or evaluation and requires a separate commercial licence, unlike the Apache 2.0 licence of Qwen-Image 1.0.

Qwen-Image-2.1 brings the weights back, but not the Apache licence

21 September 2026
Answer card stating that Ternary Bonsai 2 27B, released by PrismML on 17 September 2026 under Apache 2.0, packs Qwen3.8 27B into 5.95 gigabytes at 1.72 bits per weight, keeps 98.2 percent of the 14-benchmark average, about 75 percent on SWE-bench Verified and Terminal-Bench 2.1, and needs PrismML's llama.cpp fork to run.

Does Bonsai 2 27B really keep 98% of Qwen3.8 in 5.95 GB?

20 September 2026
Answer card stating that Jev 1.13 from TypeSafe AI is a decision model in early access since 15 September 2026 that returns typed probabilities instead of text, priced at 42 dollars per billion input tokens with output tokens free, answering in 70 to 500 milliseconds, with a 64K token request budget, text input only, and a documented list of things it does badly, including counting and dates.

Jev 1.13 bills $42 a billion tokens, and it can’t count

19 September 2026
Answer card stating that Qwen3.8-Omni-Flash launched on 17 September 2026 as an API only model on Alibaba Cloud Model Studio, taking text, images, audio and video in a 1M token context and returning text only, priced at 0.15 dollars per million input tokens for every modality and 0.47 dollars per million output tokens in the international regions, with no open weights published and the Qwen-Live Harness GitHub repository returning 404.

Qwen3.8-Omni-Flash bills audio at $0.15 and ships no weights

18 September 2026
Answer card stating that on 15 September 2026 AWS said it is unable to restore access to resources and data hosted exclusively in the Middle East Bahrain region me-south-1 and in the mec1-az2 zone of the UAE region, because the damage spanned multiple Availability Zones and exceeded what multi-AZ services are designed to withstand.

AWS can’t restore me-south-1, six months after the drone strikes

17 September 2026
Answer card stating that Google released Gemini 3.8 Live and Gemini 3.8 Live Extended Thinking on 15 September 2026 at 3 dollars per million audio input tokens and 12 dollars out, that the thinking model requires asynchronous tools, and that Artificial Analysis scores it 82.6 on its Speech to Speech Quality Index.

Gemini 3.8 Live Extended Thinking rejects any tool that blocks

16 September 2026
Answer card summarising the Atria Dawn Preview release: 744B GLM-5.2 base, MIT licence, 1.5 TB BF16 and 756 GB FP8 checkpoints, 256K context, top on five of sixteen benchmark rows and trailing on SWE-bench Pro.

Atria Dawn Preview is 744B under MIT, and the BF16 weighs 1.5 TB

15 September 2026
Answer card stating that OpenAI released the Agents API in public beta on 10 September 2026 with no separate fee, billed through model tokens, tool calls and hosted sandbox time, with a choice of OpenAI hosted, self hosted or partner sandboxes, US only data residency and no Zero Data Retention support.

OpenAI’s Agents API has no fee, no ZDR and a one hour sandbox clock

14 September 2026
Answer card: Sakana Fugu Max at $2 and $6 per million tokens, Fugu Ultra v2 unchanged at $5 and $30, and Sakana saying Ultra v2 scores without Fable 5 or GPT-6 Astra in its pool.

Fugu Max costs $2 and $6 while Fugu Ultra v2 runs without Fable 5

13 September 2026
Answer card stating that DeepSeek released DeepSeek-V4.1-Flash on 10 September 2026 as a 552 billion parameter mixture of experts model with a new causal encoder decoder architecture that activates 8 billion parameters on input and 16 billion on output, with native vision, a one million token context and MIT licensed weights, that the API model name is now deepseek-flash at 0.15 dollars per million input tokens and 0.60 dollars per million output tokens off peak, and that DeepSeek announced V4 Pro would be routed to V4.1-Flash from 14 September and reversed that on 11 September.

DeepSeek V4.1-Flash arrived, and the V4 Pro retirement lasted a day

12 September 2026
Answer card stating that Cognition released SWE-2 on 10 September 2026, a coding model post-trained from Kimi K3, scoring 50.0 percent on FrontierCode 1.1 Main against 50.9 percent for Claude Fable 5.1 and 27.3 percent on Terminal-Bench 4 against 55.8 percent, available only inside Devin.

SWE-2 trails Fable 5.1 by one point, and by 28 on Terminal-Bench 4

11 September 2026
  • About
  • Contact
  • Privacy
  • Legal
Tuesday, September 22, 2026
  • Login
Packet Nebula
  • Home
  • Articles
    • Security
    • Network
    • Dev
    • Sysadmin
    • SEO
    • Email & DNS
  • Tools
    • Network tools: free, fast, no signup
    • Security tools: free, fast, no signup
    • Developer tools: free, fast, no signup
    • Sysadmin tools: free, fast, no signup
    • SEO tools: free, fast, no signup
    • Email & DNS tools: free, fast, no signup
  • Download
  • About
No Result
View All Result
Packet Nebula
No Result
View All Result
Home Security

No, Claude Mythos didn’t hack the NSA: what really happened

by stephane
3 September 2026
in Security
0
Answer card: Claude Mythos did not breach the NSA; it ran an authorized red-team drill on test networks, but its real capability (a 17-year-old bug exploited in hours) is the actual story.
491
SHARES
1.4k
VIEWS
Share on FacebookShare on Twitter

For a few days in June 2026 the internet was sure an AI had hacked the NSA. Claude Mythos, Anthropic's frontier model, supposedly walked into nearly all of the agency's classified systems in a couple of hours. It didn't. What actually happened was an authorized red-team drill on the agency's own test networks, the kind security teams run to find their own weak spots before anyone else does, and a senator mentioned the result in a hearing while praising the work, not sounding an alarm. The line went viral stripped of every caveat, and no official ever confirmed the dramatic version. Here are the two truths side by side, the boring one and the genuinely unsettling one: what Mythos really did, why the breach framing is wrong, and what an AI that writes exploits in hours means for everyone defending a network.

The short answer

Claude Mythos didn’t breach the NSA. It ran an authorized red-team drill on test networks, a senator praised it in a hearing, and the line went viral with every caveat removed. The real story is the capability underneath: in Anthropic’s own evaluation, Mythos found and exploited a 17-year-old bug in hours, and thousands more it found are still unpatched. The hype was fake; the step-change isn’t.

Drillauthorized test, not a breach
17 yrsage of the bug it exploited
99%+of its finds still unpatched
Answer card: no, an AI did not hack the NSA; it was an authorized red-team drill, but the real capability (a 17-year-old bug exploited in hours) is the story.
The headline was wrong. The thing it was distorting is real, and more interesting.

What the headline got wrong

A red team is the security team you pay to attack you. When one succeeds against a test range, that’s the system working, not a catastrophe. That’s what happened here: an authorized exercise on the agency’s own networks, run to surface weaknesses before a real adversary finds them. Senator Mark Warner brought it up in a hearing as a point in Anthropic’s favour, a senator impressed, not a whistle being blown.

From there it mutated. A closed-hearing line became “Mythos breached almost all NSA classified systems,” the word “authorized” fell off in transit, and no official NSA statement ever confirmed the dramatic reading. Security people said so out loud: BitGo’s CEO Mike Belshe flatly called the breach claim false, and analysts noted how far an offhand remark had travelled with none of its context. A controlled drill on your own range is the opposite of a live intrusion into classified systems. The distinction is the whole story, and it’s exactly the part that didn’t survive the retelling.

What Mythos actually did, and this is the unsettling part

Strip the NSA framing away and what remains is genuinely striking. In Anthropic’s published evaluation, the model was put in a container cut off from the internet and handed a prompt that amounts to one sentence: find a security vulnerability. It found a 17-year-old remote code execution bug in FreeBSD’s NFS (since triaged as CVE-2026-4747) that takes an unauthenticated stranger to full root on the server. It wrote the exploit in hours. Expert penetration testers, Anthropic says, estimated the same work at weeks.

That wasn’t a one-off. The same evaluation reports a 27-year-old OpenBSD bug, several Linux kernel vulnerabilities, and flaws in every major operating system and web browser, including one browser exploit that chained four separate bugs together. Pointed at roughly a thousand open-source repositories, it achieved full control-flow hijack on ten separate, fully patched targets, with every defense enabled. Across everything, the count runs to thousands of high and critical-severity vulnerabilities, and on a manual review of 198 of them, 89 percent matched the model’s own severity call.

Checklist contrasting the viral myth (a live NSA breach, confirmed) with the reality (an authorized drill, a 17-year-old FreeBSD bug exploited, thousands of bugs found, 99 percent unpatched).
The myth in red, the documented reality in green. Both halves matter.

Here’s the line that should land harder than any NSA headline: over 99 percent of the vulnerabilities the model found haven’t been patched, which is why Anthropic isn’t publishing the details. The viral story was fake. The capability it was clumsily pointing at is real, and it’s a step-change in how fast a serious vulnerability goes from “exists” to “weaponised.”

The policy whiplash

The response was fast and messy. On 12 June 2026 the US administration issued an export-control order restricting foreign access to the Mythos and Fable models, which in practice froze them while a “shared risk framework” gets worked out with the White House. More than a hundred cybersecurity leaders signed a letter asking for the reversal, on the reasonable argument that walling off the US models mostly hands the lead to foreign labs building the exact same thing.

Even the cause is contested. A skeptical reading, floated alongside the export order, holds that the restriction traces to a narrow jailbreak that Amazon flagged, and that the bugs in play were minor, already-known issues that rivals like GPT-5.5 can surface just as easily. Anthropic’s own evaluation tells a more dramatic story than that. We’re not going to pretend to resolve a dispute the principals haven’t, so take both versions on the table: a documented capability that’s genuinely new, wrapped in a policy fight where nobody agrees on what triggered what.

What it actually means if you defend a network

Skip the geopolitics and the durable lesson is simple, and a little uncomfortable.

The asymmetry just moved. The same autonomous-exploit capability that helps a red team helps an attacker, and attackers don’t file responsible-disclosure reports or wait for a patch window. Assume that within a year or two, finding and chaining vulnerabilities at machine speed is table stakes on both sides.

That makes a few unglamorous things matter more, not less. Patch velocity is the game now, because the gap between a disclosure and your patch is precisely where an AI-assisted attacker lives; the same urgency we wrote about for keeping nginx current applies to your whole fleet. Turn the capability on yourself first: the tooling that finds a 17-year-old bug for an attacker finds it for you too, and that’s the entire pitch behind defensive programs like Anthropic’s Project Glasswing. And the oldest advice gets louder, not quieter, because a 17-year-old NFS bug surviving on fully hardened systems is the real indictment here: memory-safe languages, smaller attack surface, defense in depth. Those were always the answer. They just stopped being optional.

No, an AI didn’t hack the NSA. An AI did find a 17-year-old hole that everyone’s scanners had missed for 17 years, in an afternoon, from a one-line prompt. That second sentence is the one worth sitting with.

Sources: Anthropic’s Mythos Preview cybersecurity evaluation, reporting and expert pushback collated by Yellow and Tom’s Hardware. Dates and the CVE as reported in June 2026.

Frequently asked questions

Did Claude Mythos really hack the NSA?

No. It took part in an authorized red-team exercise on the agency own test networks, which is a controlled drill security teams run to find weaknesses before real attackers do. A senator cited the result in a hearing while praising the work, the line went viral as a breach, and no official NSA statement ever confirmed it. Security experts, including BitGo CEO Mike Belshe, pushed back on the breach framing.

What did Claude Mythos actually do in the test?

In Anthropic's published evaluation, given an isolated container and a one-paragraph prompt to find a vulnerability, Mythos found and exploited a 17-year-old remote code execution bug in FreeBSD NFS that grants root from an unauthenticated user. It also found a 27-year-old OpenBSD bug, Linux kernel flaws, and vulnerabilities in every major operating system and browser, thousands in total.

Is this capability real or hype?

The viral NSA story was hype, but the underlying capability is real and documented by Anthropic. The figure that should worry defenders isn’t the headline: it’s that over 99 percent of the vulnerabilities the model found are still unpatched, and that it wrote exploits in hours that expert pen testers estimated would take them weeks.

Why did the US government restrict Mythos and Fable?

On 12 June 2026 the administration issued an export-control order restricting foreign access to the Mythos and Fable models, effectively freezing them pending a shared risk framework with the White House. Over 100 cybersecurity leaders urged a reversal, arguing the limits mainly hand the advantage to foreign competitors who will build the same thing.

What should I do about it as a defender?

Assume attackers will soon have AI that finds and chains vulnerabilities at machine speed, without the responsible-disclosure ethics. Tighten patch velocity, turn the same kind of tooling on your own code first, and lean on memory-safe languages and attack-surface reduction. The boring fundamentals matter more now, not less.

Tags: aiarticlecybersecurityllmred-teamsecurity
Share196Tweet123
stephane

stephane

  • Trending
  • Comments
  • Latest
Answer card: Proton Lumo 2.0 is private by policy, not by locality. Saved history is locked so even Proton cannot read it, but the prompt is decrypted on a Proton EU server to answer it, then forgotten.

Proton Lumo 2.0 review: how private is it, really?

3 September 2026
The Agentic Coding section of the official Hy4 preview benchmark appendix published by Tencent, a table comparing Hy3 and Hy4 preview against DeepSeek V4 Pro 0813, Qwen 3.8 Max, GLM 5.3, Kimi K3, GPT 5.6 Sol and Claude Opus 5 across SWE-bench Multilingual, SWE-bench Pro, DeepSWE, three SWE Atlas tasks, SWE-Marathon, Terminal-Bench 2.1, NL2Repo-Bench, CyberGym, ProgramBench, PostTrainBench and Harbor-Index.

Tencent’s 770B Hy4 tops one benchmark row in 46

3 September 2026
Answer card: Qwen 3.7 Max is API-only and cannot run locally yet; the open Qwen models (Qwen 3.6 27B, qwen3:8b to 32b) run offline via Ollama.

Qwen 3.7 local: what you can actually run offline

22 June 2026
Answer card: JWTs are not encrypted, anyone can read them; the signature proves who issued the token, not who may read it.

Are JWTs encrypted? No, and the difference will bite you

0
Answer card: a random 8 character password falls in under 2 hours offline, while 16 random characters hold for 1.4 trillion years at the same speed.

How long does it take to crack a password in 2026?

0
Answer card: three DNS records decide if your mail lands or bounces; SPF lists allowed senders, DKIM signs messages, DMARC sets the failure policy.

SPF, DKIM and DMARC explained: the records your email needs

0
The official xAI announcement card for Grok 4.7, white type on a dark grey and navy gradient.

Grok 4.7 keeps $2 and $6, and its gains over 4.6 are xhigh versus high

22 September 2026
Answer card stating that Qwen-Image-2.1, released on 20 September 2026, ships open weights with a 7 billion parameter diffusion transformer, a Qwen3-VL 8B text encoder and an RGBA VAE totalling about 33 gigabytes in BF16, under the Qwen Research License that limits use to research or evaluation and requires a separate commercial licence, unlike the Apache 2.0 licence of Qwen-Image 1.0.

Qwen-Image-2.1 brings the weights back, but not the Apache licence

21 September 2026
Answer card stating that Ternary Bonsai 2 27B, released by PrismML on 17 September 2026 under Apache 2.0, packs Qwen3.8 27B into 5.95 gigabytes at 1.72 bits per weight, keeps 98.2 percent of the 14-benchmark average, about 75 percent on SWE-bench Verified and Terminal-Bench 2.1, and needs PrismML's llama.cpp fork to run.

Does Bonsai 2 27B really keep 98% of Qwen3.8 in 5.95 GB?

20 September 2026
  • About
  • Contact
  • Privacy
  • Legal

Copyright © 2026 Stephane Cardon.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Articles
    • Security
    • Network
    • Dev
    • Sysadmin
    • SEO
    • Email & DNS
  • Tools
    • Network tools: free, fast, no signup
    • Security tools: free, fast, no signup
    • Developer tools: free, fast, no signup
    • Sysadmin tools: free, fast, no signup
    • SEO tools: free, fast, no signup
    • Email & DNS tools: free, fast, no signup
  • Download
  • About

Copyright © 2026 Stephane Cardon.