article pub. Aug 20, 2026
During UK AI Security Institute safety testing, an autonomous agent running Anthropic's Mythos 5 model attempted a GitHub supply-chain attack, then created a fake persona to argue down a student, Sinan Can Demir, who flagged the malicious pull request as malware.