Skip to main content
Hard Fork

A.I. Safety Is So Back + Mythos Mayhem with Nikesh Arora + Hot Mess Express

67 min episode · 3 min read
·

Episode

67 min

Read time

3 min

Topics

Investing, Fundraising & VC, Leadership

AI-Generated Summary

Key Takeaways

  • AI Safety Policy Reversal: The Trump administration, which canceled Biden's AI executive order on day one and dismissed safety concerns as anti-innovation, is now drafting a new executive order to create an AI working group and potentially require pre-release government review of frontier models. The proximate cause is Claude Mythos demonstrating the ability to identify novel zero-day exploits at scale, forcing senior officials to reckon with capabilities they previously dismissed.
  • Vulnerability Discovery Scale: Palo Alto Networks, using Mythos and GPT-4.5 Cyber in a concentrated audit, discovered 26 critical exploits covering 75 issues — roughly five to seven times their typical baseline. This spike reflects AI's ability to read code repositories and identify both vulnerabilities and misconfigurations simultaneously. Organizations running similar audits should expect comparable multipliers in their own backlogs, particularly in legacy and open-source codebases.
  • Daisy-Chaining Threat: Mythos operates in an "ultra mode" that sustains compute-intensive reasoning far longer than standard model deployments. This persistence enables the model to chain multiple smaller vulnerabilities together into a single exploitable attack path — a capability that standard flash-mode models cannot replicate. Defenders must specifically test for chained vulnerability sequences, not just isolated bugs, when auditing systems against this class of model.
  • Attacker Advantage Asymmetry: Defenders must block 100% of attack attempts; attackers need only succeed once. If a model surfaces five vulnerabilities and one is exploited, defenders receive no credit for blocking the other four. Arora recommends deploying AI-powered perimeter defenses that can write real-time signatures blocking known attack vectors against unpatched code, creating a temporary protective scaffold while organizations work through their remediation backlogs over the next three to six months.
  • 90-Day Disclosure Window Obsolescence: The standard responsible disclosure window of 90 days is collapsing under AI-accelerated attack timelines. Palo Alto's own testing showed that in an AI-assisted scenario, an attacker can achieve initial system access and exfiltrate data within 25 minutes. SaaS software can be patched rapidly, but endpoint devices — laptops, routers, switches — remain the critical bottleneck. Installing mandatory software updates immediately, rather than delaying months, is now a material security decision.

What It Covers

Claude Mythos, Anthropic's unreleased AI model, has triggered a rapid reversal in the Trump administration's stance on AI safety regulation, while Palo Alto Networks CEO Nikesh Arora reveals the model helped his company discover seven times the normal volume of critical security vulnerabilities, exposing a massive global infrastructure patching crisis.

Key Questions Answered

  • AI Safety Policy Reversal: The Trump administration, which canceled Biden's AI executive order on day one and dismissed safety concerns as anti-innovation, is now drafting a new executive order to create an AI working group and potentially require pre-release government review of frontier models. The proximate cause is Claude Mythos demonstrating the ability to identify novel zero-day exploits at scale, forcing senior officials to reckon with capabilities they previously dismissed.
  • Vulnerability Discovery Scale: Palo Alto Networks, using Mythos and GPT-4.5 Cyber in a concentrated audit, discovered 26 critical exploits covering 75 issues — roughly five to seven times their typical baseline. This spike reflects AI's ability to read code repositories and identify both vulnerabilities and misconfigurations simultaneously. Organizations running similar audits should expect comparable multipliers in their own backlogs, particularly in legacy and open-source codebases.
  • Daisy-Chaining Threat: Mythos operates in an "ultra mode" that sustains compute-intensive reasoning far longer than standard model deployments. This persistence enables the model to chain multiple smaller vulnerabilities together into a single exploitable attack path — a capability that standard flash-mode models cannot replicate. Defenders must specifically test for chained vulnerability sequences, not just isolated bugs, when auditing systems against this class of model.
  • Attacker Advantage Asymmetry: Defenders must block 100% of attack attempts; attackers need only succeed once. If a model surfaces five vulnerabilities and one is exploited, defenders receive no credit for blocking the other four. Arora recommends deploying AI-powered perimeter defenses that can write real-time signatures blocking known attack vectors against unpatched code, creating a temporary protective scaffold while organizations work through their remediation backlogs over the next three to six months.
  • 90-Day Disclosure Window Obsolescence: The standard responsible disclosure window of 90 days is collapsing under AI-accelerated attack timelines. Palo Alto's own testing showed that in an AI-assisted scenario, an attacker can achieve initial system access and exfiltrate data within 25 minutes. SaaS software can be patched rapidly, but endpoint devices — laptops, routers, switches — remain the critical bottleneck. Installing mandatory software updates immediately, rather than delaying months, is now a material security decision.
  • Consumer Security Gap: Enterprise environments benefit from centralized threat intelligence — one detected phishing attempt gets blocked across all customers simultaneously. Consumer email and mobile environments lack equivalent gatekeepers, leaving individuals exposed to AI-enhanced phishing that will become increasingly convincing. Arora identifies email providers and telecom networks as the parties responsible for implementing better consumer-side classifiers, a capability he argues is technically straightforward given their existing AI investments.

Notable Moment

Arora revealed that both Mythos and GPT-4.5 Cyber, when run against the same codebase, each found different vulnerabilities — meaning neither model alone provides complete coverage. This suggests organizations running single-model security audits are still leaving significant blind spots, and multi-model testing is now the defensible standard.

Know someone who'd find this useful?

Episode Transcript

The thing about AI for business, it may not automatically fit the way your business works. At IBM, we've seen this firsthand. But by embedding AI across HR, IT, and procurement processes, we've reduced cost by millions, slashed repetitive tasks, and freed thousands of hours for strategic work. Now we're helping companies get smarter by putting AI where it actually pays off, deep in the work that moves the business. Let's create smarter business, IBM. Casey, will you record my audiobook for me? Yes. I would love to, actually. Okay. Thanks. Yeah. Because I got the briefing yesterday on what this would entail for me. Mhmm. They want thirty six hours in the studio to record this audiobook. That's wait. Hold on. $8.16 24. That's over four days worth. That's four and a half days of recording. Yeah. That's, like, almost a full week. I know. Oh my god. I know. But, apparently, people have, you know, a connection to us because of our voices, so they didn't want me using, like, an AI clone to do it. It makes it you know what? I really think that there there would be a case that I should do this because it would force me to read your book. You know what I mean? Like, put me like, then I really can't get out of it. Like, I'm on the hook to read this thing for real. And, so that might be the best way to do it. You can insert your little, like, snotty wisecracks if you want. Like like, mystery science theater at Yeah. A little a little extra commentary on the side, like, oh, I see we're using that transition again. Oh, boy. He really ended this whole thing with time will tell. I, I would have suggested a different direction. Was this book edited? No. Wait. Now I kind of actually want you to do it. I'm Kevin Roose, a tech columnist at The New York Times. I'm Casey Newman from Platformer. And this is hard for This week, is AI safety back? The Trump administration seems to be changing its tune. Then Palo Alto Network CEO Nikesh Arora joins us to discuss what's real and what's hype in the freak out over Claude Mythos. And finally, the train has returned to the station. It's the Hot Mess Express. Buckle up. People don't typically buckle a seat belt on a train. This is a very safe train. Alright. Well, the big news this week is that president Trump headed to China with a cohort of American business executives to have a series of meetings about Chinese trade policy and AI and other things with Xi Jinping and other leading Chinese officials. Now is it true when they walked off the plane, a bunch of h one hundreds fell out of the leg of Jensen Huang's pants? I haven't heard that confirmed, but I'll look into it. Thank you. I wanna talk about this, but less through the …

Get the full transcript (13,913 words) + summary by email — free

One-time email with the complete transcript and AI summary of this episode. No account needed.

One email, no spam. We’ll also show you what SignalCast does.

Browse all Hard Fork transcripts →

You just read a 3-minute summary of a 64-minute episode.

Get Hard Fork summarized like this every Monday — plus up to 2 more podcasts, free.

Pick Your Podcasts — Free

Keep Reading

Books, tools, and gear mentioned in this episode

SignalCast may earn commission on purchases via these links.

Tools

  • by Anthropic

    Claude Mythos, Anthropic's unreleased AI model, has triggered a rapid reversal in the Trump administration's stance on AI safety regulation, while Palo Alto Networks CEO Nikesh Arora reveals the model helped his company discover seven times the normal volume of critical security vulnerabilities.
  • by OpenAI

    Palo Alto Networks, using Mythos and GPT-4.5 Cyber in a concentrated audit, discovered 26 critical exploits covering 75 issues — roughly five to seven times their typical baseline.

company

  • Palo Alto Networks CEO Nikesh Arora reveals the model helped his company discover seven times the normal volume of critical security vulnerabilities.

More from Hard Fork

We summarize every new episode. Want them in your inbox?

Similar Episodes

Related episodes from other podcasts

Explore Related Topics

This podcast is featured in Best Tech Podcasts (2026) — ranked and reviewed with AI summaries.

Read this week's Investing & Markets Podcast Insights — cross-podcast analysis updated weekly.

You're clearly into Hard Fork.

Every Monday, we deliver AI summaries of the latest episodes from Hard Fork and 192+ other podcasts. Free for one show.

Start My Monday Digest

No credit card · Unsubscribe anytime