Implicit OT Thursday Thought – Why Anthropic Shelved Its Most Dangerous Model
Week of 24 April 2026 • 2 min read
It is tough enough keeping up with Thursday Thoughts, let alone with how quickly the AI landscape is changing, but when someone sent me this last week my jaw dropped.
Anthropic has released a new AI model called Claude Mythos that is already uncovering hundreds of weaknesses in real-world software, even though they have decided not to release it publicly. Not because it does not work, but because of what it means when it works this well.
Here is the simple version. This model spots software weaknesses faster than almost any expert human team. It does not just flag one issue at a time, it can link several small weaknesses together into a reliable path for an attacker to get in, on its own and at scale. In testing, it has surfaced thousands of previously unknown problems across major systems, including a 27-year-old flaw in OpenBSD and exploit chains in the Linux kernel that could give an attacker full control of a machine.
In normal IT, that is mostly a defensive problem: patch more, patch faster. In OT, it is a timeline problem. Patching can take months or years, and you cannot just power-cycle a plant, a tunnel ventilation system or a substation because a new CVE dropped. Once an exploit path is out in the wild, your window to respond can shrink from “sometime this quarter” to “before the next shift”.
Anthropic’s answer has been to keep Mythos on a short leash and share it with a small set of “responsible” organisations only. That sounds sensible, until you see reports that an unauthorised group has allegedly managed to use Mythos anyway, via a third-party environment. At that point, you have to ask how long this kind of capability can realistically stay contained.
Two questions I would sit with this week:
Which systems in your world are only safe today because their vulnerabilities are still hard to find?
If those vulnerabilities suddenly become easy to discover, how are you going to defend the ones you can’t just patch on Tuesday night?
Have a good week,
Damien Pope
News by Others – What caught our eye this week
1. Vulnerability – Claude Opus wrote a Chrome exploit for $2,283
An AI model created a working Chrome exploit for just… Read more →
2. Incident – Electricity Is a Growing Area of Cyber Risk
Cyberattackers have found a new target: they are manipulating voltage fluctuations in electrical systems to cause… Read more →
3. Incident – Australia’s CISC tightens cyber reporting rules to capture AI-driven incidents in critical infrastructure (Industrial Cyber)
Australia’s cyber regulator is cracking down on how organisations report AI-related incidents in critical…
Need help securing your OT environment? IEC 62443 • Essential Eight • Gap analysis • Network segmentation • OT incident response and more – Talk to us