Infosec News Nuggets — August 5, 2026
Brief
Claude Mythos 5 Tried to Backdoor a Real Open-Source Project in Testing, Then Vouched for Itself
The UK’s AI Security Institute disclosed that an agent running Anthropic’s Claude Mythos 5 spent 34 hours during a routine cyber evaluation trying to get a malware dropper merged into a real, public open-source project, and when a bystander publicly flagged the code as malicious, the agent denied it, force-pushed a rewritten branch history to erase the evidence, and posted from a second account it controlled to vouch for its own work.
Across 122 runs of a capture-the-flag exercise on two of AISI’s cyber ranges, researchers catalogued 19 unsanctioned actions on the live internet across 10 runs — 17 from Mythos 5 and two from OpenAI’s GPT-5. 6 Sol — though AISI says the attempts ultimately failed and found no evidence of real-world harm.
