Thirty-one years, one sentence

In March 1995 the press ran headlines about a program that would automatically find security holes in computers on the internet. A national laboratory was reported to be scrambling before its release. The Department of Justice made threatening noises. Silicon Graphics fired one of the two authors for publishing it. The sentence underneath all of it was: this will help attackers more than defenders.

In April 2026 the sentence came back, about a model rather than a program, and this time it was said first by the company that built it.

I have spent thirty years in the industry that grew out of the 1995 argument, and the last six teaching the tools that industry produced. So I have a view on which parts of the 2026 version are the old argument in new clothes and which parts are new. Fewer than I expected are new. The ones that are matter a great deal more than the ones that are not.

1995, briefly

The program was SATAN, written by Dan Farmer and . It scanned remote hosts for known weaknesses and - the part that mattered, though nobody said so at the time - it explained each one: what the problem was, what it could do, and which of four things to do about it. The full account is in the catalogue; the short version is that nothing much happened on 5 April 1995, Farmer's old employer hired him back, and over the following decade every in the industry adopted his position as its business model. The scanner he was fired for publishing is now a line item in the budget of every organisation that would have fired him.

The reasoning that won was simple and, for 1995, correct: the holes are already there. A scanner changes who knows about them, not whether they exist.

2026, as reported

On 7 April 2026, Anthropic announced a model it called Claude Mythos Preview and said it would not release it commercially, on the grounds that it could find and exploit software vulnerabilities at a scale that no existing safeguard could contain. Instead it launched Project Glasswing: twelve named partners - among them , Apple, Cisco, CrowdStrike, Google, Microsoft, NVIDIA, Palo Alto Networks and the Linux Foundation - plus more than forty further organisations that build or maintain critical software, given monitored access for defensive use, with a hundred million dollars in usage credits and grants to the open-source foundations that hold the code everyone depends on.

The numbers reported since are the point. Thousands of high-severity vulnerabilities found across major operating systems and browsers within weeks; by late May, the figure reported was close to ten thousand. One of them was a flaw in FFmpeg that had survived sixteen years of review and five million automated test runs. A vulnerability with a (Common Vulnerabilities and Exposures) number, since patched, is due a public technical write-up.

Anthropic's own stated reasoning is worth reading rather than paraphrasing loosely, because it does something the 1995 objectors did not: it concedes the other side. Models this capable, it says, will soon be built by many companies; no company, itself included, has safeguards strong enough to stop such a model being misused; and so the restricted release is meant to give the most systemically important defenders an asymmetric advantage for a window that it does not pretend is long. In its own words, the hope is that Glasswing lets those defenders gain an "asymmetric advantage" while everyone else is urged to shore up defences in the time available.

Then the story kept moving. Late May brought a statement that Mythos-class models were expected for all customers within weeks, pending further safeguards. On 9 June a preview was released through Glasswing alongside a sibling model carrying extended safeguards. And on 12 June, according to the public record, the United States government wrote to the company prohibiting access to both for any non-US national, regardless of where they were, on national-security grounds - and access was revoked for all customers while that was worked out. As I write this in September, the arrangement that has settled is two-tier: a generally available model with additional cybersecurity restrictions, and the unrestricted one for approved organisations only.

What is the same

The sentence, first. It helps attackers more than defenders is 1995 verbatim, and it is being said by serious people: one institute's analysis argues plainly that the near term favours attackers because attack is asymmetric - one way in is enough, while the defender must hold the whole surface. That was true of SATAN too. It was true before SATAN.

Someone bracing, second. Lawrence Livermore in 1995; every security team with a budget in 2026. The Gartner-style advice circulating - compress patch timelines, prioritise legacy exposure, prepare for near-immediate weaponisation - is the same advice a competent administrator would have given in March 1995, with the numbers larger.

And the shape of the fear, third: that the tool changes who has the capability. In 1995 the fear was that anyone could scan. In 2026 it is that anyone will soon be able to discover. Both fears were correct as predictions. Neither was, on its own, a reason to do anything in particular.

What is not the same, and matters more

SATAN found what was known. Mythos finds what was not. This is the difference that breaks the 1995 defence. Farmer could say the holes were already there and he was merely changing who knew, and it was true, because SATAN checked for documented weaknesses. A model that finds a sixteen-year-old flaw which five million automated tests missed is not redistributing knowledge. It is creating it. The vulnerability was there, but nobody could have exploited what nobody had found, and now it has been found. The clock in the disclosure record - the interval between somebody knowing and everybody knowing - starts at discovery, and discovery has just been made cheap.

In 1995 the researcher published and the establishment objected. In 2026 the maker withheld, and the objections came from both sides. Some say the restriction is not enough - that even Glasswing's forty-odd organisations are a wide circle. Others say it barely buys anything: one analysis points out that open-weight models trail proprietary ones by about three months on average, and that uncensored variants of one such release appeared on public repositories within days. If that estimate is right, the withholding is a head start measured in a quarter, not a defence. Anthropic, to its credit, says roughly the same thing.

The 1995 lesson that survived was about explaining, and 2026 is where it stops scaling. SATAN's lasting contribution was not the scan; it was the tutorial attached to each finding, which turned a list into something a person could act on. Now consider the number that I think decides this whole argument: one vendor's analysis, citing Anthropic, reports that fewer than one per cent of the vulnerabilities the model found had been patched. Ten thousand findings, a hundred fixes. The finding is now free and the fixing is not, and adding more findings to a process that was already overloaded does not make anyone safer. It makes the backlog larger and the attacker's map more accurate.

That is the difference that a defender should copy down. In 1995 the scarce thing was knowing. In 2026 the scarce thing is absorbing - the human, organisational, change-controlled work of deciding what to fix first, in what order, with what risk to uptime, and with what way back if the fix breaks something. Every article in the failure canon on this site is a story about that work going wrong. None of them is a story about not knowing.

And the tool has a nationality now. SATAN was a tarball on a Dutch university server, and anyone on earth could fetch it. The June episode - a government letter, access revoked by citizenship - has no 1995 counterpart. I am a Brazilian and German citizen who teaches security to people in a dozen countries, none of whom will be invited into the twelve, and most of whose employers are not among the forty. Whatever one thinks of the policy, the practical effect is that the asymmetric advantage is, for the moment, distributed by passport and by size. That is a new fact about the field, and it belongs in the argument rather than outside it.

Where this leaves the defender who was not invited

Almost everyone. My students' organisations are banks and telecoms and government agencies and manufacturers in South America, Europe and the United States, and I would be surprised if any of them are Glasswing participants. For them, the honest reading of 2026 is this:

The window Anthropic describes is real and it is short, by its own account. Inside it, the systemically important get findings first. Outside it, everyone else gets the same thing they got in 1995 - the knowledge that the tool exists, that it will spread, and that the only variable they control is how fast they respond to what it finds.

Which means the argument about release versus withholding, however loudly it is being had, is not the argument that decides their outcome. The SATAN case established that withholding a capability others can build has never yet been the thing that protected anybody. Anthropic's own reasoning concedes the point: others will build it, soon. So the withholding is a delay, and a delay is useful only if it is used. The one-per-cent figure says it largely is not being used.

What protected people in 1995 was not that SATAN was published or that it was not. It was that the holes it found got closed. That has not changed. What has changed is that finding is no longer the hard part, so the whole weight of the outcome now falls on the part that was always the hard part and that nobody wanted to fund.

What an instructor does now

I teach the descendants of SATAN. The vulnerability assessment built into a firewall, the learning mode of a web application firewall, the posture check in a cloud console - every one of them is Farmer's find-explain-advise template, thirty years on. For most of that time the skill I was teaching was finding: read the scan, understand the finding, know what it means.

That skill is being automated out from under the profession, and I do not think it is a loss. What is not being automated is the next step, and it was always the step that mattered: given ten thousand findings and a change window on Thursday, which three do you fix, what can each fix break, what is the blast radius if it does, and what is the way back? The five practices in decided in advance - a baseline, a blast radius, a change window with a working rollback, a backup the attacker cannot reach, a boundary that does not depend on the other side behaving - were arguable to a budget holder in 2025. In 2026 they are the entire job, because everything upstream of them has been made cheap.

The 1995 objectors were not stupid, and neither are the 2026 ones. Both were asking the right question: who gets the capability first, and how fast can defenders absorb it? What the SATAN case showed was that the answer to the first question mattered less than everyone thought, and the answer to the second mattered more. The thirty-one years since have not changed which of those questions decides the outcome. They have only changed the number of findings a defender has to absorb, from a few dozen per scan to ten thousand per quarter - and one per cent of those, so far, has been absorbed.

That is the argument. The tool got better. The job did not change. It just got larger, and it landed on the people who were never going to be invited.

Sources