Published Product3 min read
Rubrik's month with Mythos says the model was never the hard part
A month scanning its own code with Anthropic's unreleased Mythos Preview pushed Rubrik to rebuild its review pipeline.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- Data resilience company Rubrik Inc. said a month of scanning its own code with Anthropic PBC's Mythos Preview model surfaced so many potential security issues that it rebuilt its review pipeline rather than hire reviewers.
- The details came in a blog post from Rubrik co-founder and Chief Technology Officer Arvind Nithrakashyap.
- Rubrik got access in June to Project Glasswing, Anthropic's limited program that gives defenders early use of Mythos Preview, after the company opened it to another 150 organizations.
- Anthropic has kept Mythos out of general release; the model finds software flaws and strings them into working attack chains too well to hand out freely.
- Most of the tiger team's work went into the harness, the software layer that wraps the model and manages its tool calls and checkpoints.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
Rubrik Inc. says a month of scanning its own code with Anthropic PBC's unreleased Mythos Preview model surfaced so many potential security issues that it rebuilt its review pipeline rather than hire reviewers [1]. The useful detail in the account is not the model, which nobody can buy, but where the labour went: most of the work fell on the harness, the software layer that wraps the model and manages its tool calls and checkpoints [5].
The disclosure came in a blog post from Rubrik co-founder and Chief Technology Officer Arvind Nithrakashyap [2]. Rubrik got access in June through Project Glasswing, Anthropic's limited program giving defenders early use of Mythos Preview, after the program opened to another 150 organizations [3]. Anthropic has kept the model out of general release on the grounds that it finds software flaws and chains them into working attacks too well to distribute freely [4].
So Rubrik pulled engineers and infosec staff onto a tiger team [c5a], and the team's output was mostly plumbing. Its harness feeds in business and security context and encodes where the trust boundaries sit for a vendor whose customers treat it as a last line of recovery [6]. Nithrakashyap's argument for putting that in code rather than instructions: "Prompts drift. Harness architecture doesn't" [7].
The scanning method was unglamorous. First passes covered whole repositories, every file, no assumptions about where problems were likely to be; later passes narrowed, seeded by patterns the early rounds exposed [8]. Rubrik reports a significant reduction from raw findings to validated priority issues but publishes no numbers behind that claim [9], and no vulnerability counts or fix rates have come out of the company at all [13].
The second cost centre was scoping. According to Nithrakashyap, what surprised the team most was how much engineering time went into deciding what not to automate [10]. Machine remediation covers a deliberate subset of vulnerability classes that Rubrik judges reliable and well-scoped; anything outside that set gets a structured plan and richer context, with an engineer owning the fix [11]. "In security, trustworthy automation and maximum automation pull in different directions," he wrote. "We chose the former" [12].
Anthropic's own numbers point the same way, and they point at the gap after detection. Its May 22 update counted more than 10,000 high- or critical-severity vulnerabilities found by partners, with a 90.6% true positive rate across 1,752 flaws sent for outside assessment [14] - fewer than one in five of the total was externally checked [2], and roughly 165 of those 1,752 were false positives [3]. Patching lagged: of 530 vulnerabilities reported to open-source projects, 75 had been fixed when the update ran [15], about 14% [1], with high and critical bugs taking around two weeks each [c15a].
Glasswing launched April 7 with $100 million in API credits behind it and roughly 50 initial partners including Microsoft Corp. and Apple Inc. [16]. June's expansion reached power, water and healthcare operators, NATO and the European Union's Agency for Cybersecurity [17]. Those are organisations with far less harness-building capacity than Rubrik's tiger team, receiving a model whose output volume is the problem Rubrik just spent a month absorbing.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Data resilience company Rubrik Inc. said a month of scanning its own code with Anthropic PBC's Mythos Preview model surfaced so many potential security issues that it rebuilt its review pipeline rather than hire reviewers.
- [2]
The details came in a blog post from Rubrik co-founder and Chief Technology Officer Arvind Nithrakashyap.
ReportedView cited source - [3]
Rubrik got access in June to Project Glasswing, Anthropic's limited program that gives defenders early use of Mythos Preview, after the company opened it to another 150 organizations.
ReportedView cited source - [4]
Anthropic has kept Mythos out of general release; the model finds software flaws and strings them into working attack chains too well to hand out freely.
ReportedView cited source - [5]
Most of the tiger team's work went into the harness, the software layer that wraps the model and manages its tool calls and checkpoints.
ReportedView cited source - [c5a]
Rubrik pulled engineers and infosec staff onto a tiger team for the work.
ReportedView cited source
Sources & coverage · 1 publisher
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- siliconangle.comDuncan RileyAug 13A month with Anthropic’s Mythos left Rubrik rethinking remediation
Additional citations
- Rubrik, via SiliconANGLE
- Arvind Nithrakashyap, Rubrik CTO
- Anthropic program update, May 22



