Public Statement from the Cyber Capabilities Branch
Todd Hemmen, who heads the FBI’s Cyber Capabilities Branch, spoke at the 930gov conference organized by the Digital Government Institute in Washington, according to Tech Times. His statement concerns a measured performance gain: the Mythos model is said to have increased the success rate of autonomous exploitation of vulnerabilities on a single target by a factor of 90, compared to the agency’s previously observed capabilities. This figure comes from an oral statement reported by a single specialized media outlet; no official written statement from the FBI could be located to independently corroborate it.
This limitation in sourcing does not call into question the veracity of the statement itself, but it does call for explicit methodological caution: a single figure, cited by a single secondary source, should be treated as such rather than as an official statistic validated by independent public data. A statement made at a conference is not yet a published report.
The quote that quantifies the perceived risk
Hemmen explained that “Mythos has found vulnerabilities in certain open-source code so widespread that it is found in the vast majority of our foundational code for things like operating systems, security, web infrastructure, and encryption,” according to the quote reported by Tech Times. A model that reads the foundational code of the Internet like a map is no longer a research tool; it is a permanent scanner deployed across the entire digital infrastructure.
This quote, if accurate, places the risk not in a single piece of software but in the software foundations shared by most of the world’s critical systems. It is this systemic scope—more than the figure of 90 times—that explains why a federal official chose to publicly name a specific model rather than speak in generic terms about artificial intelligence.
A 27-Year-Old Vulnerability Found in OpenBSD
What Mythos May Have Discovered in a Critical System
According to Tech Times, Mythos reportedly identified a 27-year-old remote denial-of-service vulnerability in OpenBSD, an operating system known for its security-first approach and widely used in firewalls and critical Internet infrastructure. A flaw that survived 27 years of human audits, community code reviews, and security tests before an AI model found it.
If confirmed in technical detail, this fact illustrates a capability that is qualitatively different from previous automation: it is not just speed that has changed, but the ability to identify flaws that generations of human experts had failed to detect in software that is nonetheless continuously scrutinized by a global security community. OpenBSD is not neglected software; it is one of the most thoroughly audited in the world.
Why This Technical Detail Matters for Global Security
OpenBSD powers firewalls, routers, and systems considered to be trusted building blocks in the global Internet infrastructure. A remote denial-of-service vulnerability in such a system could, in theory, render critical network equipment inaccessible without requiring prior physical access. This article does not claim that this vulnerability has been exploited in reality; it reports on its announced discovery, with no evidence of confirmed malicious exploitation to date.
Finding a flaw is not the same as exploiting it; however, whoever finds it first decides what happens next. It is this uncertainty regarding the ultimate use of the discovery—rather than the discovery itself—that underlies the concern expressed by the FBI.
The Lutnick Suspension and Its 19 Days
A national security decision made on June 12
On June 12, 2026, Secretary of Commerce Howard Lutnick ordered the suspension of all access by foreign nationals—including non-citizen employees of Anthropic—to the Fable 5 and Mythos 5 models. This measure, taken by the Department of Commerce, places these two models in an export control category typically reserved for technologies deemed sensitive to national security.
None of the sources consulted provide details on the specific incident that triggered this decision; the exact link between the suspension and the vulnerability discovery capabilities later revealed by Hemmen is not explicitly confirmed in the available sources. This text notes this lack of a confirmed link rather than assuming one.
The Lifting of Restrictions and Anthropic’s Commitments
The restrictions were lifted on July 1, 2026, after Anthropic committed to proactively detecting and addressing security risks, cooperating on security standards, and reporting any detected malicious activity, according to Tech Times. Nineteen days elapsed between the suspension and the lifting of restrictions—a short timeframe for negotiations between a cutting-edge AI company and the federal government on national security issues.
Nineteen days to reassure Washington about a technology that even its own creator does not fully control: that’s either a quick turnaround, or a sign that more was negotiated than was actually resolved. This article cannot determine which of the two interpretations is correct based on the available information.
Mythos 5 Still Restricted, Fable 5 Widely Open
The current status of the two models following the lifting of restrictions
Despite the lifting of general restrictions, Mythos 5 remains limited to verified partners in the “Project Glasswing” program, according to Tech Times, while Fable 5 is now widely available. This disparity in treatment between the two models suggests that, in the eyes of Anthropic or the authorities, Mythos 5 still poses a higher risk profile than Fable 5, though the sources consulted do not detail the exact criteria for this distinction.
The name “Project Glasswing” itself is not further documented in the available sources beyond its mention as a verified partnership framework. This text is limited to reporting its existence without speculating on its exact composition or admission criteria, due to the lack of primary sources consulted.
What This Selective Restriction Reveals About Security Policy
Restricting a model to verified partners rather than withdrawing it completely from the market reflects a specific doctrinal choice: that of managing risk through access control rather than through a total ban. This choice assumes that the risk is manageable, not that it is zero. This is an essential nuance for understanding why Mythos continues to exist in a restricted form rather than being suspended entirely.
Restricting access does not mean neutralizing the capability; it means betting that the right people will gain control of it before the wrong ones do. This bet remains, by its very nature, unverifiable as long as no concrete incident confirms or refutes it.
What the FBI Says and What It Does Not Confirm
The distinction between a potential threat and a confirmed attack
The FBI, through Todd Hemmen, asserts that a future date will come when Mythos’s capabilities will be exploited on a large scale by malicious actors. This statement is explicitly forward-looking: Hemmen does not describe any incident that has already occurred on a large scale. The FBI is documenting a trajectory, not an incident.
This distinction must remain clear throughout any reading of this report: confusing an official prediction with a confirmed attack would turn a cautious statement into a false alarm. This text therefore maintains, throughout its analysis, the exact wording used by Hemmen rather than rephrasing it in a way that would exaggerate the certainty of the risk.
What remains explicitly unverified in this report
No publicly available evidence establishes that a malicious actor, whether state-sponsored or not, has used Mythos to carry out an actual attack against critical infrastructure. Tech Times’ characterization that this is “the first time a senior U.S. law enforcement official has publicly named a specific AI model” as crossing a critical threshold is itself an assessment by the media outlet, not a fact independently verified by this text.
Being the first to name a risk does not prove that the risk has already materialized; it only proves that someone has decided to speak out. This article reports this claim of journalistic primacy with the explicit attribution it deserves.
Anthropic Faces Regulatory Pressure in the U.S.
A Broader Context of Dispute Over Export Controls
The Mythos case is part of a broader legal dispute between Anthropic and the Trump administration over export controls on advanced artificial intelligence technologies. The sources consulted for this report do not detail the exact status of this dispute or its specific legal arguments; this text merely notes its existence as background information, without drawing any conclusions about its likely outcome.
A company under regulatory scrutiny is not necessarily a company at fault: export controls on advanced technologies are based on a precautionary approach that does not, in and of itself, imply that a violation has been found. This nuance must be kept in mind when reading the Lutnick-Anthropic case.
Voluntary Cooperation as a Corporate Response
Anthropic chose the path of voluntary engagement—proactive detection, cooperation on standards, and reporting of malicious activities—rather than directly challenging the June suspension. This strategic choice led to a rapid lifting of the restrictions—within nineteen days—but it keeps the company under continuous oversight through the Project Glasswing program for its most advanced model.
Cooperating quickly can defuse a regulatory crisis; however, it does not eliminate the need to prove, over time, that cooperation delivers on its promises. It is this long-term proof—not the initial declaration of intent—that will determine whether the June incident remains an isolated incident or becomes a precedent.
Open-source code: the fragile foundation of digital infrastructure
Why the Ubiquity of Open-Source Code Is Changing the Scale of Risk
The open-source code Hemmen refers to is not niche software: it constitutes, in his own words, the foundation of the vast majority of operating systems, security layers, web infrastructure, and encryption tools used worldwide. A vulnerability discovered in such a widely shared component inherently affects a far greater number of systems than a single piece of proprietary software.
It was the sharing of code that made the Internet possible; it is this same sharing that multiplies the impact of a single flaw. This structural paradox of open source—collective strength in development, collective vulnerability in the event of a severe flaw—predates the advent of artificial intelligence by a wide margin, but AI is changing the speed at which these flaws can be discovered.
What This Means for Defensive Security Teams
If an AI model can find vulnerabilities in a matter of weeks that have eluded decades of human review, defensive security teams are facing a change in the scale of the work to be done—not just another tool among many. None of the sources consulted specify whether equivalent defensive measures—the use of AI models for preventive auditing on the defender’s side—are already being deployed on a comparable scale.
A race between offensive AI and defensive AI has no finish line; it only involves temporary and reversible leads. It is this potential imbalance—more than the discovery of an isolated vulnerability—that justifies the FBI’s public focus.
The 930gov conference as a venue for the announcement
What the Choice of This Forum Reveals
The 930gov conference, organized by the Digital Government Institute in Washington, brings together government officials to discuss the challenges of digital transformation in the public sector. The choice of this forum—rather than an official FBI statement or a formal congressional hearing—for such a significant statement is noteworthy in and of itself.
A statement made at a professional conference has a different status than a published official report: it reflects an individual official’s personal views, in a less restrictive setting than a document that formally commits the institution. This text therefore treats Hemmen’s statement as a qualified source but not an institutional one in the strict sense—a nuance that Tech Times’ coverage does not explicitly detail.
The absence of a corresponding official written document
No written statement from the FBI, nor any official publication on the agency’s website, could be located to independently corroborate the figures and quotes attributed to Hemmen. This lack of documentation constitutes an explicit methodological limitation of this report, which is noted here rather than addressed through speculation. A public statement without written documentation remains a public statement; it deserves to be reported, not amplified beyond what it substantiates.
Precedents for the U.S. government's suspension of AI models
An export control mechanism already in use elsewhere
The suspension imposed by Lutnick in June 2026 is part of a broader practice of export controls on advanced technologies, historically applied to semiconductors and certain military equipment before being extended to the most capable artificial intelligence models. The sources available for this report do not allow for the compilation of an exhaustive list of comparable precedents involving AI companies other than Anthropic.
A control mechanism that shifts from chips to the models themselves marks a change in doctrine, not just a change in target. It is this shift—documented here by the sole Anthropic case available in the sources consulted—that warrants further attention beyond this specific report.
What This Portends for the Future Regulation of AI
If the sequence of suspension-negotiation-lift observed with Anthropic becomes a replicable model, it would establish a de facto governance mechanism for AI models deemed the most capable, operating through cycles of pressure and concession rather than through a stable legislative framework. Based on the available information, this article cannot confirm whether such a mechanism is already institutionalized or remains an isolated case.
A precedent is only a precedent the second time it occurs; before that, it is merely an episode. This case will need to be monitored to determine whether it is the first episode of a future mechanism or an isolated incident.
The Role of Zero-Day Vulnerabilities in Digital Geopolitics
Why a 27-Year-Old Vulnerability Changes the Strategic Value of Intelligence
A vulnerability that remained undetected for 27 years inherently has a different strategic value than a recent vulnerability: it could potentially have been exploited undetected for an extended period by any actor with access to comparable research capabilities—even before Mythos existed. This article cannot determine whether this specific vulnerability in OpenBSD was exploited in the past; no evidence to that effect has been reported in the sources consulted.
What Mythos reveals may not be a new vulnerability, but one that has finally come to light. This distinction changes the nature of the concern: it is not just a matter of knowing what an AI model might do tomorrow, but of asking what similar, as-yet-undiscovered vulnerabilities might pose today.
State Actors and the Race for Offensive Capabilities
None of the sources consulted for this report attribute to any specific state—China, Russia, North Korea, or any other—confirmed use of models comparable to Mythos for offensive purposes. This report therefore refrains from establishing an undocumented link between the capabilities described by Hemmen and a specific, named state-sponsored threat. Identifying a technical risk does not require naming a culprit; the latter would be an accusation, while the former remains an observation.
What This Means for North American Critical Infrastructure
The sectors most at risk, based on the nature of the vulnerability described
Systems using OpenBSD or equivalent open-source components in firewalls, routers, and core network infrastructure are, by design, most directly affected by the type of vulnerability described by Hemmen. This potentially includes government, financial, and industrial infrastructure, although the sources consulted do not provide a specific list of affected organizations or identify any immediate risks.
A widespread risk, present in code shared by thousands of organizations, cannot be addressed by a single targeted patch. It is this widespread nature that makes the defensive response particularly complex: fixing a fundamental vulnerability requires coordination among multiple open-source project maintainers—often volunteers—rather than a simple patch from a single company.
Shared Responsibility Between Model Developers and Software Maintainers
This case raises a question of responsibility that goes beyond the Anthropic case alone: who should be the first to report, the first to fix, and who should take on the burden of coordination when an AI model discovers a flaw in a community-driven open-source project that lacks a centralized governance structure comparable to that of a company? The sources consulted do not specify whether Anthropic directly notified the OpenBSD maintainers before or after Hemmen’s public statement.
Discovering a vulnerability imposes a responsibility to disclose it; remaining silent about who was notified and when casts doubt on the rigor of the process. This text highlights this methodological gray area rather than filling it in with assumptions.
What the report leaves open for the near future
Questions This Article Cannot Answer at This Time
Three questions remain unanswered at the conclusion of this report: the exact date on which the FBI anticipates large-scale deployment of Mythos’s capabilities, the specific eligibility criteria for the Project Glasswing program, and the actual progress made on the patch for the identified OpenBSD vulnerability. None of these three questions has a verifiable answer in the sources currently available.
An honest investigation sometimes ends with questions rather than certainties. This article has chosen this methodological honesty rather than filling these gaps with speculative reconstruction that would give the reader a false impression of certainty.
Why This Story Deserves Ongoing Journalistic Coverage
The fact that a senior federal official chose to publicly name a specific model is, in itself, a rare enough event to warrant long-term follow-up, regardless of whether the large-scale exploitation anticipated by Hemmen actually materializes. A named warning deserves to be followed up on until it is confirmed or refuted; to ignore it would be just as irresponsible as to amplify it without evidence.
How Other Federal Agencies Might Use the Mythos Precedent
A model of vigilance that could extend beyond the FBI
If Todd Hemmen’s statement sets a precedent, other U.S. federal agencies responsible for cybersecurity—CISA, the NSA, or the Department of Homeland Security—might also choose to publicly identify specific examples in the future rather than speaking in general terms about risks associated with artificial intelligence. None of the sources consulted confirm that such an approach is already underway elsewhere within the U.S. federal government.
An isolated precedent may remain isolated, or it may become established doctrine; only if other agencies follow suit will it be possible to determine which of these two trajectories prevails. At this stage, this article cannot anticipate this institutional evolution without further evidence.
Interagency Coordination as a Blind Spot in This Issue
The sources consulted do not specify whether the FBI coordinated its public statement with other federal agencies prior to Hemmen’s remarks at the 930gov conference. This lack of detail regarding interagency coordination constitutes an additional limitation of this case, distinct from the one already noted regarding the absence of an official written document.
An agency speaking on its own may issue a warning; multiple agencies speaking in unison alter the political significance of the warning itself. It is this difference in significance that remains, for the time being, impossible to gauge based on the available information.
Conclusion
What July 28, 2026 establishes—through Todd Hemmen’s statement at the 930gov conference—is not evidence of a cyberattack that has already occurred, but rather the public acknowledgment by a federal authority that an artificial intelligence model named Mythos has reached a threshold of capability sufficient to warrant explicit institutional vigilance. The FBI is documenting a future risk in precise terms, not an incident that has already occurred. A 27-year-old vulnerability discovered in OpenBSD, a 19-day regulatory suspension, a program of verified partners with an enigmatic name: each of these elements, taken separately, remains limited. Together, they outline a transition in which authorities are beginning to name specific tools rather than merely threat categories.
A system that learns to find vulnerabilities faster than those who fix them doesn’t need to be malicious to become dangerous; it only needs to fall into the wrong hands. What happens next will depend on facts that are still out of reach: the date the FBI fears, and what will happen before it arrives.
Signature
By Maxime Marquette, columnist
Sources
Primary Sources
Secondary Sources
- NPR — Background on federal regulation and transparency in the U.S. executive branch — July 28, 2026
- Cointelegraph — Legislative context on the regulation of technologies and markets — July 23, 2026
- CNBC — Background on U.S. institutional trust in 2026 — July 28, 2026
- The Hill — Background on tensions between the executive branch and federal regulators — July 28, 2026
- Mackinac Center — Background on court rulings affecting federal agencies — 2026
- Delaware Online — Background on the U.S. political climate in the summer of 2026 — July 28, 2026
This content was created with the help of AI.