**SPEAKER_1** (0:00)
Hey babes, it's Paris Hilton. So I was checking my points balance in the Hilton Honors app the other day, and yeah, I've got about a billion, which feels excessive, even for me. Just kidding, you can never have too many Hilton Honors points. And I wanna do something iconic this summer, so I'm giving away all my Paris points. Just find somewhere you've always wanted to stay, then go to my socials or Hilton's and tell me about it. Just make sure you're a Hilton Honors member, and I might be sending you Paris points, because when you want points that make your summer even hotter, it matters where you stay.
**SPEAKER_2** (0:31)
When you need to build up your team to handle the growing chaos at work, use Indeed Sponsored Jobs. It gives your job post the boost it needs to be seen and helps reach people with the right skills, certifications and more. Spend less time searching and more time actually interviewing candidates who check all your boxes. Listeners of this show will get a $75 sponsored job credit at indeed.com/podcast. That's indeed.com/podcast. Terms and conditions apply. Need a hiring hero? This is a job for Indeed Sponsored Jobs.
**SPEAKER_3** (1:01)
This episode is brought to you by Google Health. Stop chasing someone else's definition of health. What matters is what's healthy for you. Google Health offers a new kind of coach built with Gemini for effortless tracking, sleep insights, and holistic coaching tailored to you. Visit googlestore.com to learn more and start a new relationship with your health. Requires Google account, Google Health app, Internet, and Google Health premium subscription. Features subject to change. Availability and results vary. Not intended for medical purposes. Works independently of Gemini apps. Check responses for accuracy.
**SPEAKER_4** (1:30)
The United States military blacklisted Anthropic, the creator of the Claude artificial intelligence models, as a national security threat, because the company refused to allow its software to be used for mass surveillance or autonomous weapons.
**SPEAKER_5** (1:43)
Which is wild because that kind of supply chain risk label is historically reserved for foreign adversaries.
**SPEAKER_4** (1:50)
Right, like hostile state-backed telecom firms.
**SPEAKER_5** (1:52)
Exactly. We usually see it applied to telecommunications firms tied to hostile intelligence services. But right now, the US government's own civilian cyber defense agency and the NSA are actively using Anthropic's most powerful software to hunt for vulnerabilities in highly classified federal systems.
**SPEAKER_4** (2:10)
So how does a single piece of software end up being classified as an illegal national defense threat and the backbone of the government's own cyber defense infrastructure at the exact same time?
**SPEAKER_5** (2:19)
Well, the software causing all this friction is a specific AI model called Mythos, along with its public counterpart, Fable.
**SPEAKER_4** (2:27)
The raw capability of Mythos became really clear during a series of controlled Red Team tests where it penetrated classified NSA and US cyber command systems in a matter of hours.
**SPEAKER_5** (2:38)
Yeah, because we are moving away from the concept of AI as just a static text generator, where you feed it a prompt and wait for an essay.
**SPEAKER_4** (2:45)
Right. Mythos operates as an autonomous agentic vulnerability hunter.
**SPEAKER_5** (2:49)
Meaning it searches, it tests, and it adapts its approach to locate structural weaknesses in complex network environments. And it does all of this without needing a human to guide every individual step.
**SPEAKER_4** (3:00)
It acts more like a persistent investigator, reading the environment and adjusting tactics on the fly.
**SPEAKER_5** (3:05)
Which is how it uncovered thousands of vulnerabilities. I mean, it identified 271 security flaws in Firefox alone. It also found a 27-year-old flaw in OpenBSD.
**SPEAKER_4** (3:16)
If you're not subscribed yet, take a second and hit follow on whatever podcast app you're using. It helps us keep making this. We appreciate you being here. And for a different social media experience, no bots, no billionaires, check out pushdup.com and ad, that's pushaupd.com.
There's a link in the show notes.
**SPEAKER_5** (3:34)
And for anyone who knows OpenBSD, security researchers consider it to be one of the most hardened operating systems in existence.
**SPEAKER_4** (3:41)
Yeah. Locating a bug that is hidden in that specific, heavily audited codebase for nearly three decades requires a level of analysis that goes way beyond, you know, simple pattern matching.
**SPEAKER_5** (3:52)
You can see the exact mechanics of this by looking at CVE-2026-5194.
**SPEAKER_4** (3:57)
The Wolf SSL-1.
**SPEAKER_5** (3:58)
Right, the certificate verification flaw. The model doesn't just scan the code and flag a potential issue for a human to review. It actually graphs a working reproduction of the bug.
**SPEAKER_4** (4:07)
It explains the exact impact. It demonstrated how missing hash or digest size checks allow smaller digests to be accepted when verifying ECDSA certificates.
15 more minutes of transcript below
Try it now — copy, paste, done:
curl -H "x-api-key: pt_demo" \
https://spoken.md/transcripts/1000651996090
Works with Claude, ChatGPT, Cursor, and any agent that makes HTTP calls.
From $0.10 per transcript. No subscription. Credits never expire.
Using your own key:
curl -H "x-api-key: YOUR_KEY" \
https://spoken.md/transcripts/1000776162765