Greatly appreciated the candor. I've included a few slides into text that i thought were eye-opening to me:
From his Kernel Recipes 2026 slide on Mythos
```
Mythos's 79 vulnerabilities:
24 - no detail at all "something crashed"
14 - not a bug at all
3 - totally made up data
15 - already fixed in latest release
- 11 by others
- 4 by anthropic
20 - fixes were needed
- 7 "assume a malicious filesystem image"
- 2 "assume you can inject a malicious network packet into the middle of the stack"
- 2 "NOMMU"
- 6 sctp networking issues for untrusted devices
- 2 ipv6 minor network issues
- 1 gpu driver for local malicious user
```
GHK called this "10 'real' bugfixes", which to me sounds like there's a wild hype machine around these companies and uncritical parroting of every press release they make that falls apart when you engage the affected real experts.
>7 "assume a malicious filesystem image"
If you ever used a USB storage device you're vulnerable to this one. Not even a strict chain of custody guarantees safety, because USB devices are often powered by exploitable programmable microcontrollers. If a known good USB device can be converted to a malicious USB device by unprivileged software, the malicious filesystem exploit becomes a local privilege escalation. It works better than tampering with the files on the filesystem because it escapes signature checks and gets you directly into kernel mode.
> ... or does the USB handshake happen with or involve the host OS?
It depends on how your host is configured: just as you can do GPU-passthrough, you can passthrough a single USB device or passthrough an entire USB controller to a VM.
usernomdeguerre · · focus · HN ↗
From his Kernel Recipes 2026 slide on Mythos
```
```GHK called this "10 'real' bugfixes", which to me sounds like there's a wild hype machine around these companies and uncritical parroting of every press release they make that falls apart when you engage the affected real experts.
mrob · · focus · HN ↗
If you ever used a USB storage device you're vulnerable to this one. Not even a strict chain of custody guarantees safety, because USB devices are often powered by exploitable programmable microcontrollers. If a known good USB device can be converted to a malicious USB device by unprivileged software, the malicious filesystem exploit becomes a local privilege escalation. It works better than tampering with the files on the filesystem because it escapes signature checks and gets you directly into kernel mode.
yubblegum · · focus · HN ↗
TacticalCoder · · focus · HN ↗
It depends on how your host is configured: just as you can do GPU-passthrough, you can passthrough a single USB device or passthrough an entire USB controller to a VM.