CompanyOct 6, 20265 min read

Mythos Shaped How We Provide Cyber Resilience

We knew that frontier AI models would transform threat discovery.

At AI speed, threat discovery experiences immense pressure on every stage downstream. Triage, validation, and remediation all became immediate bottlenecks. 

Over the last few months, working directly with Anthropic’s Mythos Preview model, we set out to build the software harness and verification pipelines necessary to bridge that gap—and the results have reshaped how we think about cyber resilience.


Project Glasswing

As part of Project Glasswing, Rubrik gained early access to Anthropic’s Mythos Preview. Our primary focus was building an engineering harness that wraps the AI model, adding structural business context, trust boundaries, and verification checkpoints to drastically reduce false positives and automate fixes safely.

Through this high-fidelity approach, we have remediated a broad set of exploitable vulnerabilities across our systems during initial Glasswing testing. We prioritize real exploit paths over theoretical findings. The most notable pattern was in attack chaining: the model proved strong at identifying individual vulnerabilities and even more capable at composing them into multi-component exploit paths, elevating weaknesses that appeared low-risk in isolation into genuine attack chains. These complex, multi-step chains (and the underlying issues that fed them) were systematically identified, analyzed, and closed.

Throughout this process, our close partnership with Anthropic has been invaluable. Anthropic’s commitment to learning, adapting, and collaborating alongside security teams has helped define how frontier models can be safely deployed for defensive security.


The Path Forward

Frontier models continue to evolve rapidly and we are already integrating the latest releases from Anthropic, including Mythos 5, into our development workflows.

Rather than treating model upgrades as ad-hoc events, we have established an ongoing, continuous defense process. Our harness is model-agnostic by design: the routing taxonomy, verification logic, and context injection are decoupled into the surrounding orchestration layer. As newer models deliver sharper signals, our automated workflow processes findings, applies machine-driven patches where appropriate, and routes nuanced remediation plans directly to human engineers for review.

This continuous pipeline ensures that Rubrik’s platform stays ahead of advancing AI capabilities, so we can deliver secure software that protects our customers against emerging AI-driven attacks.


Code Guardian

As we put the system into production, we realized that building the right harness, context isolation, and verification infrastructure is extraordinarily difficult, even for dedicated software vendors. There are immense technical challenges, from isolating compute environments to preventing cross-tenant leakage and understanding complex trust boundaries. Reducing false positives also requires the right kind of harness. 

To solve this challenge for our customers, we launched Code Guardian.

Code Guardian brings the same harness and infrastructure we built internally directly to our customers’ codebases. Operating within a fully secure, air-gapped environment, Code Guardian runs deep, multi-repository scans to identify vulnerabilities and cross-component attack chains. It then relays detailed, high-fidelity findings and structured remediation plans back to security and engineering teams—delivering machine-speed defense with human-in-the-loop trust.

 

Blog by This Author