Category Archives: History

Tulips Too Late? Dutch Anger Grows at Tesla Fraud

In 1566 the dangerous autocrat stood in front of you.

The Dutch built centuries of defensive mechanisms as non-repudiation against Spanish inquisitorial authority, coded into Dutch business culture as Calvinist truth-telling.

The famous “tulip market speculation crash” cautionary tale was one output. Amsterdam archival records show no mass bankruptcies and no documented suicides. The ruin narrative was shaped by moralizing pamphleteers in 1637 and cemented by Mackay in 1841. Propaganda at its finest. The underlying apparatus was much older and deeper.

Tesla FSD now sits in the functional class the Dutch anti-autocrat apparatus evolved to resist. A self-promoting, self-valuing authority that claims it cannot be wrong. A promise verified only by the authority making it. Old class, new vector, who this? In 2019 the Tesla autocrat sold Holland a future-dated capability, verified by a state stamp that arrived seven years later, to legitimize a deliverable that excluded the buyer.

The historic defense apparatus was built for face-to-face deceit. Tesla’s remote algorithmic deceit through future-dated capability claims is a pre-authentication attack on a verification system that expected the attacker to show up in person.

The 2019 buyer faced the familiar class in an unfamiliar form. Founder-cult oracle. American export. Charismatic owner-as-truth, verified by market capitalization and fan base. The Spanish inquisitor wore robes and spoke Latin in a room you could enter, and the Dutch consider themselves free of it all. Musk speaks in eXcrement (tweets) and earnings calls from a platform he owns. The 1566 defense stack recognized the function and missed the form. The Calvinist reflex fires on detected deceit. Undetected deceit flies straight past the reflex like an open door.

Front-end failure was the purchase in 2019. RDW arrived seven years later and approved a driver-assist system, not autonomy. Their own statement says the vehicle “is not self-driving.” That is the trap. Tesla sold “full self-drive capability” in 2019. RDW certified “FSD Supervised” in 2026. Different categories, shared acronym. The state stamp on the narrow thing becomes marketing cover for the broad promise.

Category laundering is fraud. The regulator that operated within its mandate failed to stop the crime.

The certification regime has no procedure for what Tesla did to its output. RDW examined a vehicle in front of the inspector and approved what it found. No framework exists for the vehicle promise that was sold but never built, or for the regulator’s own approval being repurposed to validate a deferred promise the regulator explicitly did not validate. Type approval is a product test. It was never designed to resist a seller who collapses categories the state kept distinct.

Realizing the magnitude of the Tesla attack very late, the unfortunate Dutch owners now seem very pissed.

Electrek writes about a man named Sigtermans who is doing classic Dutch directness. Recording a Tesla call, publishing the transcript, launching hw3claim.nl, aggregating 3,000 claimants across 29 countries. The reflex still fires. Late.

“Be patient” is an extraordinary thing to tell someone who paid you €6,400 seven years ago for a product you now admit you can’t deliver on their hardware.

The tulip tale was propaganda dressed as warning. Fabricated cautionary tales do not inoculate a culture. They flatter it into believing the warning took. The apparatus that beat the 1500s inquisition catches the 2020s autocrat only on the very late back end. Seven years of lost use. €6.5 million in claims filed. Tesla drivers burned alive in vehicles whose doors would not open, a rising body count the propaganda tale never needed to invent.

Can you see this? How many Dutch have been trapped and burned to death by Tesla?

Holland has a dangerous blindness problem. Human and machine.

Tesla is a Crime: Fifty Funerals Before the First Verdict

Every layer that could have stopped Tesla fraud was designed to monetize harm after it occurred. Prevention of murder was never in scope, which enabled Elon Musk to get rich on fraud even despite mass suffering.

Big Tech billionaires are exhibiting historic levels of cruelty towards society, as if to usher in harms

Criminal fraud prosecution of a sitting CEO requires DOJ willingness. SEC enforcement requires a functioning SEC. NHTSA enforcement requires a functioning NHTSA. All three were initially weakened by Trump’s indifference.

Source: Twitter

The indifference worsened into directly hollowing out protections, when he gave Musk a federal position whose explicit function was deleting the investigative apparatus with his name on the docket.

Elon Musk celebrates the Trump family turning the White House into a corrupt monarchy, serving only billionare interests.

What Musk-at-DOGE actually represented was the subject of pending federal investigations being handed authority to delete the investigators and reclassify himself as untouchable. DOGE was a ruthless, murderous, sharpened acceleration of a 120-year-old template of harm-for-profit. Every prior case involved lobbying, revolving doors, regulatory capture from outside. DOGE was direct appointment of the defendant to dissolve any offices or courts protecting the public.

Pending investigations by the government vanished because the agencies were gutted by the subject of the investigations.

Tesla harms already remained dubiously legal because no US institution was ever given full authority to stop a car from being sold over a design flaw, until enough people have died to force a NHTSA recall, where the recall is negotiated with the manufacturer. Musk in 2025 cemented his profit by fraud, not just because the US enforcement stack was built to extract penalties after the fact, but because he captured the part of the stack that could still catch the fraud later.

Compare this with other countries. China and the EU use pre-market approval. A car must be certified by the regulator before it can be sold. When the Dutch Data Protection Authority ruled Sentry Mode violated GDPR, Tesla had to change the feature from on-by-default to opt-in and add a flashing-lights warning before it could keep shipping. When Chinese authorities decided Tesla’s always-on cameras were a surveillance risk, the cars were banned from military bases and government compounds. FSD was blocked from Chinese roads until Tesla met data localization requirements. The regulator has a veto, because they protect the public from obvious fraud.

Without fraud, there would be no Tesla.

Why? Four million cars worth little more than a 1992 Kia, or even negative value as threat to public safety, carry false FSD promises, false robotaxi promises, false autonomy timelines, and false HW3 “all hardware needed” claims. They repeatedly “veered” uncontrollably, exploding and killing trapped passengers. Courts constantly issue “death trap” dollars to grieving families. Without fraud there would be no trillion-dollar market cap and no Musk compensation package. Arguably there would be no Musk story at all, except about a criminal who goes to jail before hundreds of lawsuits have to be filed.

The most important thing to understand about this litigation landscape is the timing. The lawsuits being resolved right now — Benavides, Huang, and the handful of post-verdict settlements — all stem from crashes that happened in 2018-2020, when Autopilot was less capable and far fewer vehicles were on the road with the feature. FSD beta only launched publicly in late 2020. The hundreds of thousands of vehicles that have been running FSD in the years since will generate a second, much larger wave of litigation that is still in its infancy.

Tesla stockpuppets re-ratified Musk’s pay package by majority vote after a Delaware court voided it as a breach of fiduciary duty. People still believed the lies and bought cars on promises the CEO had already broken publicly. The victim participation angle in the fraud is truly problematic.

NHTSA has no veto, so Musk has more and more victims every year. NHTSA has a complaint form and an investigation pipeline measured in years. They won’t even accurately report the Tesla deaths, as I’ve explained here before, because Trump blocked honoring the dead to instead personally promote Tesla profit on harms.

Source: White House Press Secretary

Musk made money because the US treats CEO claims about product capability as puffery, treats securities fraud as a civil penalty paid from shareholder funds, and treats consumer fraud as recoverable only through individual arbitration and slow class actions. The 2018 SEC weak-kneed settlement set the template. Sneeze twenty million. Laugh at a fig-leaf Twitter oversight provision. Keep the job, keep the equity, keep mass killing innocent people.

The billionaire equity has compounded faster than the penalties for depraved indifference, reckless homicide, wrongful death… fraud.

This is not a Trump invention, because Trump isn’t capable of inventing anything. It is the default setting of US corporate liability since at least 1906 and the Meat Inspection Act, which was itself a response to Upton Sinclair documenting mass harm the regulator refused to see.

Ford Pinto? A known fuel tank defect, doors that wouldn’t open, internal cost-benefit memo, no executive prosecuted.

You think lawsuits about door handles failing in a fiery crash are new? Think again. That’s just Ford Pinto economics coming back into accounting like Elon Musk DGAF. Seems like Tesla at least has a direct precedent here.

GM ignition switch? 124 dead, GM knew for a decade, $900M deferred prosecution, no executive prosecuted.

Purdue/Sacklers? Over 500,000 opioid deaths, $6B settlement, Sacklers kept most of their wealth, no Sackler prosecuted.

Boeing 737 MAX? 346 dead, MCAS fraud on the FAA itself, $2.5B deferred prosecution, no executive prosecuted.

BP Deepwater Horizon? 11 dead, $20B penalty, no senior executive criminally prosecuted.

Johns Manville? More than 40 years of asbestos concealment, bankruptcy used as liability shield.

Takata? Over 30 dead, mass recall, company bankrupted, executives paid fines.

Leaded gasoline, leaded paint, leaded buckshot… don’t even get me started.

Tobacco? 50 years of cancer fraud, Master Settlement extracted money and prosecuted nobody.

You arrest the poor Black people, while I smoke weed openly, that’s why I emigrated from South Africa to America with bags full of money to escape the fall of apartheid. Think about it. How many non-whites can I openly mock and kill in America with no penalty? Have you seen my Hitler salute?

Regulators were designed to arrive after the funerals, enabling shareholders to re-ratify fraud, doubling-down on a century of the same deal from Pinto to Purdue, allowing a defendant to be appointed where he could dissolve his own investigators.

Hungary Election Misread: Politico Pumps Nazi Führerprinzip

Alexander Burns wrote a fascist op-ed in Politico today and framed it as electoral advice for Democrats.

His argument is so weak it’s hard to understand how it made it out. He says Viktor Orbán’s defeat in Hungary proves that “disruptive” leaders who commandeer institutions and remake them through force of personality represent the winning “path to power.”

Marvel comics make some want to believe in a supermensch, yet really the stories should do the exact opposite.

His examples include Trump, Macron, Milei, Meloni, Carney, and now Peter Magyar. Burns treats this list as evidence of characters with ideological range. Never mind how the power hungry flip to whatever party cedes them control, it is evidence of something else entirely.

Every figure in Burns’s “eclectic club” shares exactly one trait. They personalized institutional power. They treated party structures as vehicles to be seized, deliberative processes as obstacles, and democratic legitimacy as something conferred by the act of disruption itself. Burns calls this a “path to power” as though the mechanism were ideologically neutral.

The mechanism is the ideology. It has an actual name in history. The Führerprinzip: the leader embodies the movement, the institution exists to serve the leader, the program is the leader’s will. Trump incidentally tried to promote himself as Jesus Christ today. while insulting the Pope.

Burns describes such personality-driven concentration of power with sheer admiration, cataloging each successful seizure as though collecting trading cards. Magyar is “stubborn, imperious and self-absorbed.” Carney defied predictions. Trump devoured a party from inside. Burns presents all of this as a winning formula rather than a recognizable pattern of democratic erosion.

Sewer Socialists Knew What’s Wrong

There is a strong American counter-tradition Burns should have consulted. Milwaukee’s sewer socialists governed America’s largest Socialist-led city for most of the first half of the twentieth century. Victor Berger, Daniel Hoan, and Frank Zeidler won elections repeatedly. They held power for decades.

They did it by building sewers. Their personalities aren’t the point.

Click to enlarge. Source: In These Times

The sewer socialists defeated the patronage machines of both major parties through visible, material competence. Clean water. Honest books. Public health infrastructure. The leader was interchangeable because the platform was the point. Milwaukee kept electing socialists because the city worked. Voters responded to demonstrated governance against a backdrop of corruption.

Burns’s frame makes this tradition invisible. Once you define successful politics as personality-driven disruption, governance competence becomes irrelevant. The program disappears. The leader becomes the program.

Two Mamdanis

Mahmood Mamdani’s Citizen and Subject offers the structural critique Burns needed and ignored. Mamdani argued that colonial and postcolonial institutional structures create the categories of political possibility. The bifurcated state does not get fixed by swapping personnel at the top. The question is what the institutions connect to, who they serve, and what they reproduce.

Burns treats institutions as empty vehicles waiting for the right driver. Mamdani would say the vehicle determines the destination. When you celebrate the seizure of institutional power as the defining act of politics, you foreclose the question of what institutions should actually do. You make governance reform structurally unthinkable. All that remains is the next seizure.

And then there is Mahmood Mamdani’s son.

Zohran Mamdani is the 112th mayor of New York City. A democratic socialist state assemblyman from Queens who beat Andrew Cuomo in the primary. He took office on January 1, 2026. On the same day Burns published his column about how Democrats need a charismatic disruptor, Mayor Mamdani marked his 100th day in office by filling potholes in the Bronx.

He called it “pothole politics,” and he used the exact phrase: “our 2026 answer to sewer socialism.”

Mamdani has spent his first hundred days riding the subway, fielding 311 calls, cleaning up illegal dumping sites, and securing $1.2 billion for universal childcare with Governor Hochul. His argument is the sewer socialist argument: basic services rebuild trust in government. Competence is the platform. The program is the point.

Burns could have looked across the East River. The largest city in America is being governed right now by a democratic socialist who explicitly rejects the model Burns is selling. A mayor whose father wrote the definitive structural critique of the personality-driven politics Burns celebrates. A mayor who won a massive upset against the ultimate insider candidate and then governed through potholes and childcare instead of spectacle.

Burns did not mention him! The guy who claims to admire personality, omitted one of the strongest personality victories in American history.

That omission tells you everything about what the Politico column was actually supposed to pump.

Fascist Complicity

Burns covered Trump’s takeover of the Republican Party. He wrote a book about it. He watched Meloni’s rise in real time. He knows what he is describing.

He describes it anyway. He puts Trump and Macron in the same analytical bucket and claims that as an insight. He lists Meloni alongside Carney and treats the juxtaposition as evidence of range rather than a warning. He advises Democrats to find their own version of a Mussolini-strongman pattern while the living counter-example fills potholes ten blocks from the Politico newsroom.

This is his complicity. Burns understands he is celebrating a cult of personality. He has the historical knowledge to see what it produces. He packages it as horse-race analysis because that is what he probably expects to deliver him rewards.

The Receipts

The Führerprinzip was not a metaphor. It was Article 1 of the NSDAP’s organizational principles: the leader’s authority flows downward, accountability flows upward, the party exists as an instrument of the leader’s will. Every “disruptive insurgent” Burns admires followed this operational template. Some produced better outcomes than others. The template meanwhile remained the same.

The sewer socialists produced fifty years of effective municipal governance, exposed machine corruption through performance rather than spectacle, and built lasting institutional capacity. Milwaukee’s socialist administrations are studied in public administration programs to this day. They are the bedrock of American infrastructure.

Mahmood Mamdani’s work has shaped a generation of scholarship on how institutional design reproduces or disrupts power relations. His argument is precisely that the personality of the leader is the least important variable. Structure reproduces itself, while dictators have yet to clone themselves.

His son is proving it in real time, in America’s largest city, on the same day that Burns filed a fascist column.

Burns had all of this available to him. He chose the wrong frame. He chose it because it makes the column he is primed to adore. His poor choice is his column’s actual subject.

America Prepares as Anthropic Mythos is 100X More Deadly Than Martian Death Ray

NBC News just ran a story called The Vulnpocalypse about Anthropic’s decision to withhold its Mythos model from the public. The tone is, well, you know.

The author, Kevin Collier, lined up well-known cybersecurity vendors to stoke fear that AI-powered hackers will crash financial systems, lock up hospitals, and shut down water treatment plants.

Sigh.

Anyone who has worked in security long enough will recognize this FUD genre immediately. Replace “AI” with “war dialer” and this is the exact same article the movie WarGames generated in 1983. At least back then we said the word war out loud instead of just implying it.

Captain Crunch Whistles for Everyone!

Back in 1983 some Milwaukee teenagers called the 414s (Milwaukee area code, yeah) waltzed into the unprotected computers at Los Alamos National Laboratory and Memorial Sloan-Kettering Cancer Center using nothing more exotic than a modem and a telephone line. The Newsweek cover on September 5, 1983 featured the word “hacker” for the first time on a major magazine cover.

The youngest of the 414s, therefore able to pose on the cover of Newsweek, September 5, 1983

Congress held hearings. Ronald Reagan was shown WarGames and asked the Joint Chiefs if the premise was real. Within a week the answer was: “Yes, the premise was technically possible.” Eighteen months later he pushed a signature onto NSDD-145, the first Presidential directive on computer security.

The actual legal consequences for the 414s were two years’ probation and a $500 fine for phone harassment. And even that seemed a bit much.

Time Magazine in 1983 with stern warning that network attacks on computers will kill someone.

Neal Patrick became a media star. John Draper, Captain Crunch himself, had been phreaking the phone system with a cereal box whistle and people talked about it as though he were going to bring down AT&T. The whistle found in kids’ cereal boxes exploited in-band signaling on the analog phone network (2600 Hz tone on the same channel as voice). The fix was to push for the long-overdue move to out-of-band signaling (SS7). It stands as proof of the harm from natural monopolies refusing to invest in baseline safety. Dare I say history tends to rhyme even when it doesn’t repeat?

The vulnerability landscape was real, the exploitation was incremental, and the apocalyptic framing served the companies selling defenses. McAfee built an entire empire on this dynamic, most memorably during the 1992 Michelangelo virus panic, when John McAfee personally stoked fear that millions of computers would be destroyed on March 6th. The press amplified, the public panicked, almost nothing happened, and McAfee’s sales went through the roof. Perhaps most bizarre was how he became a security industry celebrity for undermining trust in the security industry. The vendors and conference attendees at events like BlackHat or Defcon acted as if Enron’s CEO should have been the toast of Wall Street.

The Same Article, Forty-Three Years Later

Collier’s piece follows the 1983 script with remarkable fidelity. The threat model is identical: hypothetical unsophisticated attackers gain access to powerful tools, critical infrastructure is vulnerable, and the proposed solution is withholding the tool from the public while sharing it with “partners.” By this logic we should be terrified of kids getting a hold of sophisticated string and precision percussion instruments. Jazz? Rock and Roll? Catastrophe.

The Soviet state both said “today he plays jazz, tomorrow he betrays his country” and also printed cheerful matchbox art of ФЕСТИВАЛЬ (Festival) when the political winds shifted. The threat level of the instrument depended entirely on who was in charge that year.

His expert sourcing follows a similar pattern. Quote a government official convening emergency meetings (Treasury Secretary Bessent gathering the banks). Quote a vendor whose business model depends on threats expanding (Casey Ellis, founder of Bugcrowd). Quote a former FBI official warning about “wannabes” (Cynthia Kaiser, now a senior vice president at Halcyon). Close with water treatment plants. Everyone drinks water, it’s life. That’s a strong FUD move. Every quoted source in this piece stands to gain from security industry services related to the scariest story possible. Bugcrowd, Halcyon, Luta Security, Scythe. Who needs advertising when the article is the ad?

The Atlantic’s Priority

The Atlantic’s Matteo Wong went even further than Collier. His hyperventilated lede described Mythos as “a tool potentially capable of commandeering most computer servers in the world” that could “hack into banks, exfiltrate state secrets, and fry crucial infrastructure.”

It’s the opposite of reporting. It is the language of a film trailer. Anyone deep inside AI at the operations level knows how fundamentally flawed it remains versus humans.

Wong’s most consequential move was positioning Anthropic as a peer to nation-state intelligence services: “This level of cyberattack is typically available only to elite, state-sponsored hacking cells.” This framing matters because once the press treats a private company as operating at nation-state capability, the company inherits the presumption of nation-state authority over disclosure, access, and classification. Which is precisely what Project Glasswing establishes.

The Atlantic in 2023 published my co-authored article on real, documented AI harm. Tesla’s vehicles have been crashing into trees, killing motorcyclists, and veering off roads for years. The body count is in the hundreds now and the design flaws are landing in court cases. No Treasury Secretary convenes an emergency meeting over it. No consortium of tech giants receives $100 million to address it.

Tesla AI notoriously “veers” uncontrollably and fatally crashes. Design defects (e.g. Pinto doors) trap occupants and burn them to death as horrified witnesses and emergency responders watch helplessly. Source: VoCoFM, Korea, 2024

But a company announces that its AI could hypothetically find software vulnerabilities faster than defenders could close them, and the entire press corps treats it like the fall of civilization.

WIRED Gets It

WIRED’s Lily Hay Newman was the exception. She included skeptics, named Anthropic’s financial incentive, and quoted Niels Provos saying the model “doesn’t intrinsically change the problem space.” She quoted me, and so I’m pointing right back at her. Cisco’s president is out there calling Mythos “a very, very big deal” and Anthropic’s own red team lead is describing how “the phone calls got shorter and shorter.” Well, ok, but the counterargument at least got a seat at the table and may be the least prone to hallucinations.

Water Tanks

In 1915, a battle-hardened and war-weary Winston Churchill funded development of armored tractors meant to break through trenches, barbed wire, and machine gun nests. The British War Office ordered hundreds built under strict secrecy. The project was initially disguised as “water tanks”, which denied German intelligence any insight into what was actually being manufactured. The codename stuck, which is why ironically we still say tanks to speak of things that are not tanks.

The tank changed battlefield tactics, but it most certainly did not end battlefields. The immediate response was to dig better trenches and adapt doctrine. And, as always, a side that understood a new weapon’s limitations and integrated it into combined-arms operations won. A side that waxed about mythical wonder weapons, lost.

The history of the rifle tells the same story even more precisely. The bolt-action rifle gave way to the repeating rifle, which gave way to automatic fire. Each transition made a previous method more specialized. Each technology innovation demanded doctrinal adaptation. None of the innovations ended war. A rifle is not only still a rifle, the NRA whines constantly that you shouldn’t regulate an automatic rifle differently from a powder musket.

Vulnerability discovery has a similar question of progression. Manual research was bolt-action. Automated scanners were repeating. AI-assisted discovery is automatic. What Anthropic built with Mythos is a much faster fuzzer. And since they aren’t a security company at all, they probably are running around the office as if their hair is on fire yelling “what do we do, what do we do” instead of seeing it the way Churchill looked at a tank.

I say this from battle experience. When cloud computing arguably was first launched (e.g. Loudcloud, by Andreessen et al) I punched a massive hole right through claims about customer isolation. It was a normal finding, in my estimation. A service provider says customers are isolated, and my tool says nope. I handed the finding to the man sitting next to me and he literally jumped out of his chair, waved his hands in the air, ran out of the room and around the office yelling “OMG we’re in! We’re in!” He was, shall we say, less experienced.

Zero-day vulnerabilities have been found and disclosed continuously since the term was coined. Google’s Project Zero has been publishing them for a decade. The entire bug bounty industry exists because this is ordinary work. Finding two hundred exploits faster than the previous tool found 2 is an efficiency gain in the rate of fire. It is not a civilizational rupture. And here is what the coverage systematically omits: faster discovery means faster patching. A tool that finds vulnerabilities at scale is, by definition, a tool that enables remediation at scale. That makes it a patch accelerator. The question is who controls the framing.

I have spent over a decade working with AI and showing companies both how to break and how to secure it. What I can report from being deep in the field for so long is that the fundamentals have not changed. You still need someone who knows where to point the weapon, and you still need a trench to fight from. The obfuscation is in calling the automatic rifle a magic alien death ray.

Withholding as the Product

“Our model is so dangerous we can’t release it” is, of course, the same sentence as “our model is so valuable you need us.” Such product mystique reads to me more like another geturked presentation to those in power than a proper public threat modeling disclosure.

Kupferstich eines “Schachtürken”

Rename “we built a better fuzzer” to “we possess a weapon too dangerous for the public” and you have a centuries-old trick in the defense contractor playbook.

Anthropic announced that Mythos produced 181 working exploits from a vulnerability set where the previous flagship model succeeded only twice. That is a real capability jump and should be taken seriously.

What should also be taken seriously is what happened next: Anthropic shared the model exclusively with twelve tech giants under Project Glasswing, backed by $100 million in usage credits. The withholding became the product launch. “Too dangerous to release” turned out to be the most effective marketing copy the industry has ever produced, and both Collier and Wong ran it as news.

The Treasury meeting completes a very shady picture. Bessent convenes the banks, Anthropic briefs the banks, and suddenly every major financial institution has a rather convenient public-private attachment to Anthropic’s vulnerability discovery capability. That is an undemocratic merger wrapped in false national security fearmongering.

Back Door

The timeline gives it away. On February 27, 2026, Defense Secretary Hegseth raged about making Anthropic a supply chain risk after the company refused his demands to strip safeguards against mass surveillance and autonomous weapons from Claude. Hegseth bloviated so hard, he made Anthropic the first American company ever given a designation normally reserved for foreign adversaries. Anthropic naturally sued, because common sense has to go to court. A judge blocked the designation.

Five weeks later, Anthropic announced Mythos and handed it directly to Microsoft, Google, Apple, Amazon, and the rest of the companies the Pentagon depends on for its entire technology stack. The front door closed and the back door opened wider. When the Secretary of Defense designates you a foreign adversary over a contract dispute, the direct route to military integration is blocked. But you can achieve the same position by making yourself the security backbone of every company the military depends on. No contract. No congressional testimony. No use restrictions. The money flows through the same channels. The brand stays “clean” of Hegseth.

The Doctrine, Not the Weapon

Grant and Sherman won the Civil War by combining coordinated force with the systematic destruction of the enemy’s capacity to produce war. The engagement mattered less than the doctrine. AI vulnerability discovery tools follow the same logic: they are force multipliers for whatever doctrine you already have. If your doctrine is “sell fear,” they push a LOT of fear. If your doctrine is “map the attack surface and hold the line,” they multiply that.

The question nobody in the Vulnpocalypse coverage has asked is whether zero-day resolution is now accelerating faster than zero-day discovery. If it is, then Mythos is a net defensive tool and the entire panic narrative collapses. Anthropic has the data to answer this. They have not published it, to my knowledge. My guess is they lack the security experience to frame it that way.

The 1983 version of this panic produced NSDD-145 and eventually the Computer Fraud and Abuse Act, real legislation born from manufactured urgency. The 2026 version is producing something structurally different: a private company functioning as a classification authority that decides who gets access to vulnerability discovery capabilities and on what terms. That is a larger institutional shift than the old Presidential directive, and it is happening while the press runs “Vulnpocalypse” headlines and quotes panic pill vendors.

The exhausted CISOs and security teams I talk to many times every day already know the AI tools are real and they know the rate of fire has changed. What they need is a defensible position against the flood of AI vendors who confuse a product launch with the end of the world.

Anthropic calls its patch accelerator Mythos for the same reason Churchill called his tractors tanks. The name disguises the use, preventing doctrinal analysis.

Churchill hid the function so the enemy couldn’t develop counterdoctrine. Anthropic hides the function so the market can’t judge how a defensive tool is being pitched as an offensive threat.