The script covers two major Claude updates: Mythos-1 and leaked details on Sonnet 4.8. It claims Claude Mythos Preview scanned 1,000+ open-source projects in 30 days, found 23,019 vulnerabilities (6,202 high/critical) with a 90% true-positive verification rate, including large sets of issues for Cloudflare and Firefox, and it reportedly blocked a $1.5M wire-fraud attempt at a partner bank by detecting behavioral patterns without human intervention. It describes the challenge that AI can find vulnerabilities faster than humans can patch them, Anthropic’s response via Claude Security auto-patching, and an open-sourced bug-finding pipeline, plus Cisco building a similar system. It also discusses brief sightings of Mythos-1 Preview in Claude Code/Security despite public caution, Jack Clark’s Oxford remarks on AI risk, and accidental leaks indicating Sonnet/Opus 4.8 testing in Google Vertex with an expected mid-to-late June timeframe and new reasoning improvements.
00:00 Mythos-1 and Sonnet Leaks
00:26 Mythos Scanning Results
01:05 Real World Bug Finds
01:32 Bank Fraud Stopped
02:13 Patch Backlog Problem
02:54 Claude Security Auto Patching
04:16 Mythos-1 Preview Spotted
05:05 Safety Messaging Tension
06:27 Sonnet 4.8 Leak Details
06:55 Vertex Testing Signals
07:27 Expected Sonnet 4.8 Upgrades
08:11 Big Picture Takeaways
09:09 Business Implications
09:28 Three Common Objections
10:25 How to Get Started
11:15 Final Wrap Up
Full transcript
two huge updates on Claude today as number one we've got Mythos 1 which is the new version of Mythos and then number two we have new leaks on Sonic 4.8. So I'm going to get straight into this and throw a pick and basically have one of the most dangerous AI models ever built and some crazy stories about this including how it actually stopped a 1.5 million fraud transaction. So let's start with Mythos 1. In one month just 30 days Claude Mythos preview scanned over 1,000 open source projects that basically run the internet.
We were talking for example the software inside your browser, your router, your bank's login page and in that single month actually found 23,019 vulnerabilities. Of those 6,202 were classified as high severity or critical and independent security firms verified those results at a 90% true positive rate. To put that in plain English Mythos found more real security holes in 30 days than the entire global cyber security industry typically finds in years. Here's the part of the matter though.
This wasn't a lab test these were actually real companies so for example Cloudflare the company that sits between you and most of the internet got 2,000 bugs found in its core systems. 400 of those were high or critical severity. Mozilla's Firefox browser had 271 vulnerabilities patched in one go and that's 10 times more than what the previous Claude model found. Nobody knew about this stuff.
Mythos found it in weeks and there's one case that actually shows how powerful this stuff is right. Mythos literally two days ago this was announced. Mythos stopped a 1.5 million dollar wire fraud in real time at a partner bank right. Hackers had already compromised customer emails used AI voice cloning to make fake calls and were seconds away from completing the transfer.
Mythos detected the scam by reading behavioral patterns and blocked it. There was no human in the loop just a model catching what most humans have missed and this is why Anthropic called it Project Glasswing because there's 50 partners involved. You got AWS, you got Apple, you got Google, Microsoft and the idea is to use Mythos to patch the internet before bad actors build something similar and use it offensively. Now here's a problem nobody is talking about enough.
Mythos can find vulnerabilities faster than humans can fix them way faster so the average time for a human developer to patch a single high severity vulnerability even with a detailed report handed to them is about two weeks two weeks per bug. Now Mythos found over 6,000 critical ones. Anthropic submitted 1,129 of those vulnerabilities to open source maintainers. So far only 75 has been patched.
Some open source maintainers sent pleading emails to Anthropic asking them to slow down because they're completely overwhelmed. So we now have a world where AI can find security holes faster than people can actually seal them and that gap is probably only going to grow. Anthropic's answer to this is Cloud Security which is an enterprise tool that doesn't just find the vulnerability but actually generates a fixed patch automatically. In the first three weeks since launch enterprise clients used it to fix over 2,100 vulnerabilities.
Anthropic also open sourced a bug finding pipeline that lets Cloud navigate large code bases, clone sub-agents for parallel scanning and automatically identify the most exposed parts of your system. And Cisco announced a build similar called the Foundry Security Spec System modeled on what Mythos can do. The vision everyone is describing is the same though. AI finds a hole, AI writes a patch, human does the final review.
That's the future of cybersecurity. Not humans scanning code manually but humans reviewing what AI already fixed. Now if you want to understand how to actually use AI agents like this in your own business not just for cybersecurity but for getting more clients, building lead generation systems and automating the day-to-day work that's eating up your time, that's exactly what we do inside the AI Profit Boarding. We've actually got an agent operating system that helps you achieve this.
We've got members right now building agent systems that work 24-7 whilst they sleep, step-by-step playbooks for setting up your own AI powered business workflows and coaching calls where you can ask questions live about your specific setup. If that sounds useful, link in the comments in the description for the AI Profit Boarding or just go to aiprofitboarding.com. Back to Mythos 1 and here's where it gets really interesting too. So publicly Anthropic have said on record that Mythos would remain restricted.
They said they were unlikely to release it to the general public anytime soon and that they needed far stronger safeguards for making Mythos class models available. That was very recently. Now the very next day users actually spotted something called Mythos 1 and Claude Mythos 1 preview appearing inside Claude Code and Claude Security. It was only visible briefly, people grabbed screenshots before it disappeared, new strings inside the source code explicitly referenced models to the Claude Mythos model inside Claude Code and Claude Security.
So either Anthropic is preparing a reliant rollout much faster than they publicly admitted or something changed dramatically in their safety assessment overnight. Neither of those options are small and look there's a real tension here that's worth talking about as well. On one hand Anthropic co-founder Jack Clarke gave a lecture at Oxford this week saying AI poses a non-zero chance of basically wiping everyone out, predicted that by 2028 or probably zero by sooner AI will reach recursive self-improvement meaning it can improve itself without human help. He said most of the world is in denial about current AI capabilities let alone what's coming in the next six months.
He even said that when Mythos finished training the internal reaction at Anthropic was it's here faster than before and we've done insufficient preparation. That's the co-founder of the company saying that out loud at Oxford which is like one of the biggest universities in the world. And the day before that Anthropic was hosting a developer event in Europe called Code with Claude where Boris Cherny, the person who built Claude Code, was talking about the magic of programming and reconnecting with creativity. Developers were eating free lunch and getting mini computers.
The mood was celebration. So you got two events with two completely different stories one for developers and one for academics and policy makers and that's not necessarily sinister you know companies tailor messages to different audiences all the time but it tells you something about the scale of what's actually happening here and how it can be both amazing but also a double-edged sword in terms of like the security risks and all the risks that come with all this stuff right. Now next up let's talk about Sonnet 4.8 because this is the second thing Anthropic accidentally leaked. On March 31st 2026 when Anthropic pushed on update to Claude Code's npm package he accidentally included a 512,000 line internal debugging source map and that basically leaked references to Claude Sonnet 4.8 and there's been two updates on Sonnet 4.8 today.
So two more things actually dropped alongside the Mythos 1 news. Number one is Opus 4.8 was spotted in Google Vertex AI backend this morning. Just a model identifier sitting in there so it was Claude Opus 4.8. Both Opus 4.6 and Opus 4.7 were discovered the same way in Vertex before their official launches.
That's a pattern Opus 4.8 is in testing and June looks like a likely release date. Sonnet 4.8 slugs are also now visible in Vertex too. So select Anthropic partners are reportedly already running internal evaluations. Now here's what Sonnet 4.8 is expected to bring.
Vision accuracy is improving that's expected to go up to about 98%. You've also got 4.7 which already hit 98.5% so the difference would be pricing as well. I would expect coding to get better, UI etc reasoning etc to improve. There's also a new reasoning level 4.Has that's called X High Stronger.
Basically stronger logical reasoning without the slow generation times that current high effort models typically suffer with. One trade-off the new tokenizer uses around 30% more tokens on the same prompts so costs could go up because you use more tokens and mid to late June is the current expectation for that. So here's what I want you to actually take away from all of this. Miphos 1 is real, it's coming and the preview is already inside.
Claude code and Claude security for a select few enterprise users. The question of when it hits general access is still open but Anthropic is clearly building toward a broader rollout even whilst publicly saying they're being cautious. The infrastructure is being built, the enterprise tooling is there. They just hired Andrej Karpathy as well, co-founder of OpenAI, Tesla's computer vision lead to join their pre-training team.
They also brought on Ross Nordin, founding member of XAI and former Tesla. You don't hire people like that slowed down right. Sonic 4.8 is likely weeks away possibly already in testing with partners right now. It's the model that will matter most for everyday users and business owners running AI agents so I'd keep an eye on that.
And the cyber security angle here is pretty wild right, especially that situation with the banking fraud, wild stuff. So for anyone running a business in 2026, the practical implication is straightforward. AI is getting better at finding problems, writing fixes, detecting stuff and operating without human supervision. The businesses that figure out how to put those capabilities to work for their own workflows, their own customer acquisition, their own operations are going to have a real edge over those that don't.
And there's a real limiting belief that I hear all the time. Those people say you know this is interesting but I'm not technical enough to use it and I get why it feels that way but when you hear about for example 27 year old vulnerabilities and exploit chains and wolf SSL and all this sort of stuff, it sounds super technical but in reality that's not really how this plays out right. You can speak to most of these tools just through plain text. It's super simple, super relaxed and the people who win here are the ones who understand what these tools can do for their situation and just build workflows around there.
So the technical complexity lives in the model, you don't need to worry about that, your job is just a strategy. The second problem that I hear a lot of people say is like you know I'll wait until it's more mature but SONIC 4.8 is arriving now, MIPHOS 1 enterprise access is being built on, Andrej Karpathy just joined the pre-training team. This isn't a thing that's going to mature in a vacuum whilst you wait right, it matures by being used. The people inside it right now are building the playbooks that will matter right now in six months to 12 months etc and have a massive head start.
And the third one is you know some people say I don't know where to start, that's the only valid one that I see and it has a real answer. If you want a clear starting point, a structured way to build AI agent systems into your business, you actually generate more leads, saving time and running more of your operation on autopilot, that's exactly what our agent operating system and the AI profit board is actually built for. Inside AgentOS we've got members already running AI powered lead generation content systems and client workflows using cloud as a backbone. We've got step-by-step playbooks, daily tutorials walking you through new features of the ship and coaching calls where you can get your specific setup reviewed.
When SONIC 4.8 drops we'll be walking you through exactly how to use it inside your AI agents, what changed, what improves and how to get the most out of it for your business. And when MIPHOS 1 hits, broader access, same thing, link in the comments description or go to the AIprofitboard.com to get access. Anthropic is moving faster than they're publicly saying they are, MIPHOS 1 is closer than the press release suggests, SONIC 4.8 is right around the corner and this is something you can implement today right now. That's where things start, I'll keep covering things as they develop.
Thanks for watching.
More episodes