Skip to main content
Software Engineering Daily

SED News: Anthropic’s Mythos, Supply Chain Hacks, and the AI Spending Surge

52 min episode · 2 min read

Episode

52 min

Read time

2 min

Topics

Career Growth, Fundraising & VC, Artificial Intelligence

AI-Generated Summary

Key Takeaways

  • Mythos model access: Anthropic's Mythos security model, released only to firms including Amazon, Apple, Microsoft, and JPMorgan Chase under Project Glasswing, autonomously identifies previously unknown vulnerabilities — including a 27-year-old OpenBSD flaw — in major operating systems and browsers. Teams building on legacy infrastructure should treat this as a signal to prioritize proactive vulnerability auditing now.
  • Supply chain attack vector: The Vercel breach originated from a single Context.ai employee downloading fake Roblox cheats, which installed Luma Stealer malware, harvested OAuth tokens, and cascaded into Vercel's internal systems. The direct mitigation Vercel implemented — encrypting all environment variables as sensitive by default — should be treated as a baseline configuration standard, not a post-breach reaction.
  • Secure-by-default gap: Cisco's 2026 State of AI Security report finds 83% of organizations plan to deploy agentic AI, but only 29% report readiness to secure it. Teams adopting AI tooling should audit OAuth permission scopes immediately, restricting agent access to only the specific data sources required rather than granting broad workspace-level credentials.
  • AI CapEx structural lock-in: Google and Amazon have each committed tens of billions to Anthropic while simultaneously building competing models on proprietary chips — Trainium, Graviton, and TPUs. Because model training becomes structurally tied to a cloud provider's chip roadmap, teams selecting a cloud platform for AI workloads are effectively choosing a model performance trajectory for multiple years ahead.
  • Engineering hiring rebound: TrueUp data shows 67,000 open software engineering roles across 9,000 tech companies — double mid-2023 levels and up 30% in 2026. IBM and Intuit are specifically targeting junior, AI-native engineers rather than exclusively senior hires, signaling that entry-level candidates who demonstrate fluency with agentic coding tools carry measurable hiring advantage in the current market.

What It Covers

Anthropic's restricted Mythos security model, a supply chain breach tracing from Roblox malware through Context.ai to Vercel, Meta and Snap layoffs tied to AI infrastructure costs, and the $650–700 billion projected hyperscaler CapEx for 2026 reshaping cloud, chip, and talent markets simultaneously.

Key Questions Answered

  • Mythos model access: Anthropic's Mythos security model, released only to firms including Amazon, Apple, Microsoft, and JPMorgan Chase under Project Glasswing, autonomously identifies previously unknown vulnerabilities — including a 27-year-old OpenBSD flaw — in major operating systems and browsers. Teams building on legacy infrastructure should treat this as a signal to prioritize proactive vulnerability auditing now.
  • Supply chain attack vector: The Vercel breach originated from a single Context.ai employee downloading fake Roblox cheats, which installed Luma Stealer malware, harvested OAuth tokens, and cascaded into Vercel's internal systems. The direct mitigation Vercel implemented — encrypting all environment variables as sensitive by default — should be treated as a baseline configuration standard, not a post-breach reaction.
  • Secure-by-default gap: Cisco's 2026 State of AI Security report finds 83% of organizations plan to deploy agentic AI, but only 29% report readiness to secure it. Teams adopting AI tooling should audit OAuth permission scopes immediately, restricting agent access to only the specific data sources required rather than granting broad workspace-level credentials.
  • AI CapEx structural lock-in: Google and Amazon have each committed tens of billions to Anthropic while simultaneously building competing models on proprietary chips — Trainium, Graviton, and TPUs. Because model training becomes structurally tied to a cloud provider's chip roadmap, teams selecting a cloud platform for AI workloads are effectively choosing a model performance trajectory for multiple years ahead.
  • Engineering hiring rebound: TrueUp data shows 67,000 open software engineering roles across 9,000 tech companies — double mid-2023 levels and up 30% in 2026. IBM and Intuit are specifically targeting junior, AI-native engineers rather than exclusively senior hires, signaling that entry-level candidates who demonstrate fluency with agentic coding tools carry measurable hiring advantage in the current market.

Notable Moment

Anthropic's Mythos model identified a 27-year-old flaw in OpenBSD that thousands of skilled engineers had reviewed for decades without detecting. The hosts frame this as a direct parallel to Garry Kasparov losing to Deep Blue — a concrete marker of AI surpassing human security auditing at scale.

Know someone who'd find this useful?

Episode Transcript

Hello, and welcome to SED News. As I'm sure some of you know already, this is a different format of software engineering daily where Sean and I I've got Sean with me, I should say. Say hi, Sean, as usual. Hey. Hey, Gregor. Hey, everyone. Hey. Often forget to let Sean say hello. Yes. We are here slightly different format where we touch on some of the main headlines in tech. We then go into a bigger topic in the middle, and then we take a fun spin look at Hacker News highlights that Sean and I have picked up over the last couple of weeks. So as we often do, though, bit of a catch up. I think Sean and I have both been wrapped up in conferences over the last couple of weeks. So, yeah, Sean, which exactly. Yeah. So where have you been and how was it going? So I was in Las Vegas recently for Cloud Next, which was fun. I've never actually been to Cloud Next even though I worked at Google I worked in Google Cloud and I've partnered with them a number of times. But for whatever reason, I just never ended up at Cloud Next. But it was good. And then I was actually supposed to be in India this week, but thankfully, that trip got postponed because I would have been back to back to back because I leave for Boston for IBM think Sunday night. So there's a kind of a lot going on. We're thick into the spring event season anyway with, like, May, June, and so forth. So you're in San Francisco where I live. So how are things going? How are you enjoying it so far? Yeah. Absolutely. No. It's nice to be back. I think last time I was in SF was 2024, actually. So, yeah, been a while in tech terms, but really nice to be back. Always like the weather here. Nice change from Singapore. I was at Stripe Sessions, which has grown enough. So it's in Moscone West, which is, like, the sort of second largest, I think, probably venue in SF. So, yeah, really awesome production. I think my just to call out one little detail, I'm not sure if people watch the Stripe podcast. I'm sure many of you do. It's called Cheeky Pint, and it has John or Patrick Collison sitting in a mock Irish pub having a pint of Guinness with a guest. And they had actually put together, like, a full mock up of that set in the venue, and people could go in and get, free pints of free little mini pints of Guinness. I just thought it again in a in a mock Irish pub. I thought that was an amazing detail. Yeah. That's cool. Yeah. Very cool. But, yeah, it's exhausting as I think you know Sean going to conferences. I was on the SuperBase booth for quite a few hours each day. So by …

Get the full transcript (10,269 words) + summary by email — free

One-time email with the complete transcript and AI summary of this episode. No account needed.

One email, no spam. We’ll also show you what SignalCast does.

Browse all Software Engineering Daily transcripts →

You just read a 3-minute summary of a 49-minute episode.

Get Software Engineering Daily summarized like this every Monday — plus up to 2 more podcasts, free.

Pick Your Podcasts — Free

Keep Reading

Books, tools, and gear mentioned in this episode

SignalCast may earn commission on purchases via these links.

Tools

company

More from Software Engineering Daily

We summarize every new episode. Want them in your inbox?

Similar Episodes

Related episodes from other podcasts

Explore Related Topics

This podcast is featured in Best Cybersecurity Podcasts (2026) — ranked and reviewed with AI summaries.

Read this week's AI & Machine Learning Podcast Insights — cross-podcast analysis updated weekly.

You're clearly into Software Engineering Daily.

Every Monday, we deliver AI summaries of the latest episodes from Software Engineering Daily and 192+ other podcasts. Free for one show.

Start My Monday Digest

No credit card · Unsubscribe anytime