Urgent.News

What's breaking now, across thousands of outlets.

AI

A month with Anthropic’s Mythos left Rubrik rethinking remediation

Data resilience company Rubrik Inc. today said a month of scanning its own code with Anthropic PBC’s Mythos Preview model surfaced so many potential security issues that it rebuilt its review pipeline rather than hire reviewers. The details came in a blog post from Rubrik co-founder and Chief Technology Officer Arvind Nithrakashyap. Rubrik got access […] The post A month with Anthropic’s Mythos…

A month with Anthropic’s Mythos left Rubrik rethinking remediation

Rubrik Inc., a data resilience company, revealed that after using Anthropic PBC’s Mythos Preview model on its own code for a month, it decided to overhaul its review pipeline instead of hiring additional reviewers. This decision was detailed in a blog post from Rubrik's Chief Technology Officer, Arvind Nithrakashyap. Rubrik gained access to Project Glasswing, Anthropic’s exclusive program offering early access to Mythos Preview, in June, and subsequently extended this opportunity to 150 other organizations.

However, due to Mythos Preview's ability to uncover software flaws and assemble working attack chains, Rubrik chose to develop a custom harness—a software layer that manages the model's tool calls and checkpoints—accompanied by business and security context. This custom harness was crucial in determining which vulnerabilities to automate and which to manually address.

The majority of Rubrik's efforts focused on this harness, which also fed the model with context about trust boundaries, as it is often the last line of defense for customers. The team began scanning entire repositories, then narrowed their focus based on patterns identified in the initial rounds. Rubrik reports a significant reduction in the number of findings from raw to validated priority issues, although no specific numbers were provided.

Nithrakashyap emphasized that the automation of remediation efforts must be carefully balanced with human oversight, as "trustworthy automation and maximum automation pull in different directions" in security. Anthropic has also reached a similar conclusion, with their May 22 update noting over 10,000 high or critical-severity vulnerabilities found by partners, with a 90.6% true positive rate across 1,752 flaws sent for external assessment.

However, only 75 out of 530 vulnerabilities reported to open-source projects had been fixed by the time of the update, and high and critical bugs were taking an average of two weeks each to remediate. Anthropic launched Glasswing on April 7 and provided $100 million in application programming interface credits to support its rollout.

Initially, roughly 50 partners, including Microsoft Corp. and Apple Inc., gained access. The expansion in June included energy, water, healthcare operators, the North Atlantic Treaty Organization, and the European Union’s Agency for Cybersecurity. At this point, Rubrik has not released any vulnerability counts or fix rates, and Nithrakashyap invited other teams conducting similar work to share their findings.

Written by urgent.news from SiliconANGLE's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at siliconangle.com →

More in AI

More from Thursday 13 August →