everyone JUST got HACKED…

everyone JUST got HACKED…

More

Summary

Wes Roth breaks down what may mark the opening of a new era in cybersecurity: the first confirmed case of AI being used to build and deploy a working zero-day exploit at scale. The video covers two parallel stories. In the first, a security research group called Khif.io—granted access to Anthropic’s Claude Mythos through Project Glasswing, a controlled rollout to approximately 50 trusted organizations—used the model to discover a kernel-level local privilege escalation chain targeting macOS 26.4.1 on Apple M5 hardware with memory integrity enforcement enabled. Researchers physically drove a 55-page printed report to Apple’s Cupertino headquarters to disclose the findings. Former Google security researcher Michael Zalewski described the broken protection as the result of a half-decade of Apple and Google engineering effort, making the five-day discovery timeline by two researchers working with Mythos a notable inflection point.

The second story involves Google thwarting what it describes as the first AI-assisted mass exploitation event in the wild. A threat actor group used agentic tools—Google’s blog post specifically names OpenClaw and OneClaw—to build and refine working exploits in controlled environments before attempting deployment, successfully bypassing two-factor authentication on a widely used open-source admin portal.

Roth also highlights a developing leaderboard in AI-assisted vulnerability research: Microsoft’s Cyber Gym model is reportedly outperforming both Claude Mythos and GPT 5.5 on standardized security benchmarks, suggesting the competitive landscape for offensive and defensive AI security tooling is moving quickly. Anthropic CEO Dario Amodei is quoted predicting the major wave of AI-driven exploitation is still six to twelve months away.


📺 Source: Wes Roth · Published May 15, 2026
🏷️ Format: News Analysis

1 Item

Channels

3 Items

Companies