Is Claude Mythos hype? It doesn’t matter. Here’s what does (and what we can learn from Coca-Cola).
There’s a lot of “chatter” ongoing in the infosec community, with many diverse opinions about whether and to what degree Anthropic’s “Mythos is too dangerous to release” stance is true, hype, marketing genius, conspiracy theory, or some combination thereof.
The reality is that it doesn’t matter.
Every single release of every major AI model has demonstrated an improved ability to discover and weaponize software vulnerabilities. Even if new AI models “only” provide incremental improvements, as opposed to the alleged step-function increase in Mythos, we still need to anticipate and prepare for a significant increase in the number and frequency of software patches as well as library updates.
That is, the patch tsunami is coming, and it’s not going to be easy for us to handle.
Take Advice from…Coca-Cola?
There are several parallel approaches that enterprises need to take, in order to be well-prepared:
- Improved Visibility
- Applying and Automating Software Updates
- Network Segmentation
All of these could be encapsulated under the historical Coca-Cola advertising slogan, “The Pause That Refreshes”. Take this seriously; by deliberately putting a visible “pause” on other tasks, you have the opportunity to highlight the importance and urgency of these actions. The good news is that these activities are not just one-offs; they are investments in resiliency that will pay ongoing dividends. Let’s take a look at each one.
Improved Visibility
By ensuring that you have an accurate and machine-readable inventory of software in use by your enterprise, you’ll be in a much stronger position when you begin prioritizing and applying updates to these systems. Most importantly, design workflows and processes so that updating this inventory becomes a byproduct of everyday operations. (This is a topic that we’ll be writing about in upcoming posts).
Applying and Automating Software Updates
In many enterprises, internally developed custom software, while important to the business, does not always utilize software engineering best practices around automated build and deployment. This is especially true for older, “legacy” systems, which ironically are often the most likely to be impacted by a vulnerability. We’ve seen teams have to go through a painful and high-pressure “scramble” to update multiple dependent libraries, debug problems, and deploy systems.
This can be avoided by regularly and proactively “touching” each software component, ensuring that every N months (6 or 12 are good choices), the system is re-built and re-deployed. This ensures that when a component library needs to be updated to address a security issue, it can follow a known and reliable process.
Network Segmentation
Reducing the blast radius of any compromise is important, and often makes the difference between a bad afternoon and a major incident. Start planning and implementing Zero Trust principles now, to segment the applications and systems on your networks. Even without perfect or complete information – which no enterprise realistically has – you can still make substantial progress even with basic segmentation. For example, non-technical users likely have no reason to SSH or RDP to a remote system. Block them, and warn your SOC if their device attempts this. Begin applying a default-deny stance to network access; for example, only people on the Finance team will need access to the Web UI for the finance application. These are just two examples of many you could take.
Don’t Wait, Start Today
We’ll close out this article by reminding you that the specifics of Claude Mythos’ announcement are not relevant, although they do make for an interesting conversation over a nice, cold Coca-Cola. What matters is your acknowledgement that AI model vulnerability discovery and exploitation skills are only going to improve and accelerate. As a security leader, you have a responsibility to get your organization ready. The proactive steps we’ve outlined above can be portrayed as “the pause that refreshes”; as the investment of time and energy that will stave off an unexpected, unplanned, and disruptive incident
Read more in our original patch tsunami post here.
Want to learn more about how quickly and effectively to apply Zero Trust principles to your enterprise? Read about our proven Zero Trust Blueprint, and take our free readiness assessment here.