-
Cryptocurrencies
-
Exchanges
-
Media
All languages
Cryptocurrencies
Exchanges
Media
Share

Author: Helen Li, Tencent Technology
Recently, both Anthropic and OpenAI are promoting one thing:Changing the production method of traditional security vulnerability discovery and analysis capabilities.
On April 7, Anthropic released a preview version of the new generation model Claude Mythos, and simultaneously launched "Project Glasswing (Glass Wing Plan)", which caused a chain reaction in the market.
Mythos has caused huge market panic even before its public release. Because someone discovers a vulnerability, someone takes advantage of it and even turns it into an attack capability. Security issues have never been more serious.
On the first trading day after the release of Mythos, the stock prices of many security vendors such as CrowdStrike, Palo Alto Networks, and Zscaler fell significantly, with the decline once reaching double digits.
OpenAI may have an insight into people's expectations of "the devil is as high as the road is as high as the road".
On April 15, OpenAI launched GPT-5.4-Cyber: a "privilege model" for network security defenders. OpenAI also announced the expansion of its Trusted Access for Cybersecurity (TAC) program, opening it to thousands of verified individual defenders and hundreds of teams responsible for critical software security.
It seems to be a competition between two large model companies, but behind it is a new attempt at security capabilities by a large American model company.
An engineer who has been working in network security for many years said frankly that his first reaction when seeing this kind of news was a sense of crisis: "The key to these two things is not how strong the model is, but the way the way of finding vulnerabilities has changed in the future."
Li Guanghui, founder and CEO of AI security company BraneMatrix, said: "Traditional network security issues are being reconstructed algorithmically, and the security of the algorithm itself will rise to AI native security and become the core technical capability of the new era."
Why does the release of such large models bring such a large spillover effect? If vulnerability mining capabilities can be replicated on a large scale by models, are the capability thresholds of the future cybersecurity industry being rewritten? How will the industry's competition style change?
Traditional network security relies at its core on human experience, judgment and long-term accumulation.
A senior network security engineer said: "Some people discover vulnerabilities, some exploit vulnerabilities, and some patch vulnerabilities; attack methods are constantly upgraded, and defense methods keep up. Therefore, in the security industry in the past, no one had complete security capabilities from the beginning, and no company could always lead. Everything relied on accumulation."
In the network security industry, there is a time lag between attack and defense. Vulnerabilities are discovered, exploited, and then repaired. New tools continue to emerge, and capabilities are gradually diffused in practice. Whether it is the internal team of the enterprise or security vendors such as CrowdStrike and Palo Alto Networks, they are essentially doing the same thing: productizing complex security capabilities and then delivering them to enterprise customers.
However, with the addition of large AI model manufacturers, a different path has emerged. Security capabilities no longer rely on people and experience, and are accumulated through long-term confrontation. Instead, some capabilities begin to be directly encapsulated into the model and become capabilities that can be called.
Whether it is Mythos or GPT-5.4-Cyber, we need to be further vigilant about the allocation logic and potential impact of this new security capability.
GPT-5.4-Cyber,The core highlight is that it has been fine-tuned for defensive security use cases, reducing the rejection rate of legitimate security operations. In the past, when engineers asked AI to help test system vulnerabilities or analyze suspicious code, it might directly reject it because it was unclear whether it was defending or attacking. However, GPT-5.4-Cyber specifically solves this problem and "relaxes the threshold" for security researchers. In addition, a hierarchical trust mechanism is adopted for deployment, which is more open than Mythos' "list system".
Anthropic's Mythos is not specifically trained for network security, but its general capabilities are so strong that it has "overflowed" into the security field. It can understand the code, discover vulnerabilities, and even reproduce and exploit these vulnerabilities. It is more than one generation stronger than previous models.
According to official disclosures, Mythos has discovered thousands of zero-day vulnerabilities in mainstream operating systems and browsers, many of which are high-risk. In some capabilities, it has even surpassed most security engineers, and the entire process basically does not require human participation and can be completed by yourself.
Compared with the improvement of the capabilities themselves, what is more worthy of our attention is:No matter what type of model it is, when the code understanding and security analysis capabilities of the large model are strong enough, once restrictions are relaxed or authorized, it can be used to dig loopholes, or even transformed into attack capabilities. Moreover, when large models have this ability, people are no longer the only source of ability.
The judgments given by many practitioners in the exchanges tend to be consistent -In the short term, this replacement will not happen.
"It's easy for people to think about things simply," Li Guanghui said. "Security capabilities are not a single technical capability, but a whole set of systems."
The traditional network security industry spans multiple subdivisions such as network protection, identity authentication, threat intelligence, and risk control systems. These capabilities cannot be covered by model reasoning alone.
Li Guanghui believes that the traditional security industry covers many subdivisions such as network security, identity authentication, threat intelligence, and risk control, among which there is still a strong demand for basic enterprise security services.
"Moreover, the accumulation of threat intelligence data by traditional major manufacturers, such as non-public IOC intelligence libraries including IPs involved in black and gray attacks, file hash values (converting file contents into fixed-length strings through specific algorithms), is still a barrier that models such as Mythos cannot replace in the short term,In scenarios that require special data support, such as black and gray attack detection and Internet risk control, the model currently has no obvious alternative advantages," he said.
Not only that, the "last mile" of safety is still highly dependent on people.
A senior penetration testing engineer gave an example: A complete penetration test often needs to start from the Internet exposure and go deep into the corporate intranet and even the core system layer by layer. In this process, not only do you have to face a complex system environment, but you also have to constantly bypass non-standardized protection mechanisms such as verification codes, human-machine verification, and dynamic policies. "Many times, what really determines success or failure is not the tool itself, but on-site judgment and on-the-spot strategies".
However, although it is difficult to produce substantial replacement in the short term, the impact is inevitable.
What we need to face now is that changes are already happening. When large models quickly take over aspects that were originally highly dependent on manual work, such as vulnerability analysis, code auditing, and attack path deduction, they can run at a lower cost and with higher frequency. This means that the value structure of the security industry is being reshaped: basic capabilities are compressed and high-level capabilities are amplified.
"Once such a change occurs, the operating logic of the entire industry will be reconstructed," said a senior security researcher. "With the improvement of AI coding and understanding capabilities, the security capabilities themselves will be greatly amplified, and the traditional network security system that relies on human experience will gradually be weakened. This change is not a replacement, but a shift in the focus of the industry."
Anthropic officials stated: Mythosis a "defense only" model, only open in a closed alliance composed of 52 technology companies. Members include Amazon, Apple, Broadcom, Cisco, Google, Microsoft and Nvidia.
The reason given by Anthropic is that the Mythos security guardrail is not yet mature. If it is fully opened, it will hand over attack tools to defenders and attackers at the same time. Therefore, large model manufacturers hope to let partners use it first, fix vulnerabilities in key infrastructure first, and then gradually open it up.
This consideration has its merits, but it also arouses concerns in the industry: because, in the actual security industry context, "defense" itself is never a pure concept. Like penetration testing, red team drills, and vulnerability verification involved in network security, these behaviors that look like "attacks" are exactly the basis of defense.
For example, security research has found that large model companies will add many restrictions to their advanced models to prevent them from being used for attacks. However, through some unconventional methods (such as using "circuit expressions" such as classical Chinese, ancient Sanskrit or ancient Latin), some large models may still break through the limitations under certain circumstances and enter a state where the output is almost no longer constrained. Then, as long as someone has the ability to bypass these restrictions, they can use these models to attack, not just to defend.
In other words, defense is essentially "attack simulation for defense." When the model's code understanding and security analysis capabilities are strong enough, the boundary between offense and defense will quickly become blurred, making it difficult for manufacturers to truly accurately control this boundary.
In addition to safety considerations, there are other interpretations from the outside world.
Venture investor Marc Andreessen questioned whether Anthropic really restricted release due to security concerns,or because it lacked enough computing power to support large-scale public use. Marc Andreessen mentioned that Anthropic has experienced frequent service interruptions recently and limited the supply of computing power to users during peak hours.
Li Guanghui expressed his disagreement with Anthropic's approach: "In fact, this so-called 'defensive nature' is essentially to prioritize the opening of model capabilities to American software and cloud service manufacturers such as Apple, Google, Microsoft, and IBM. Security should be verified through open confrontation, rather than unilaterally defined and endorsed by a few subjects.If the standards, testing environment and results of the security assessment are not transparent, then this 'security' itself lacks credibility".
One thing we need to pay deep attention to is that both Anthropic's Mythos and OpenAI's GPT-5.4-Cyber are security tools that prioritize the US technology ecosystem.
If a key technology is only open to specific countries or a few institutions, rather than spreading to global industries, certain "technical barriers" or even "technical dominance" will often gradually emerge.
Similar situations have long been reflected in other fields. For example, the United States has long-term restrictions on the export of NVIDIA's high-end GPUs (such as H200 and B300) to some countries, as well as the control of early encryption technologies. Once the flow of core capabilities is restricted, the industry structure will often change accordingly.
This deviates from a long-standing practice in the cybersecurity industry. In the past few decades, "Ethical Hacking" has gradually become a mainstream practice. In conjunction with the Responsible Coordinated Disclosure mechanism, more security researchers are encouraged to participate and improve the overall system security level by discovering vulnerabilities and disclosing problems. Although this is not a rule that is strictly followed by everyone, in the field of traditional network security, it has always been an important foundation for the operation of the industry.
What we need to think about is: in such a closed alliance, will the power of definition begin to be concentrated in the hands of a few countries or entities in the future? Then, in the future, the assessment methods, verification paths and even the right to speak about network security may usher in changes.
These changes will eventually return to a more realistic question: how every participant in the industry will reposition itself.
In short, for traditional security manufacturers, they need to think clearly about the future as soon as possible.