Home / Press / Cybersecurity

Cybersecurity

OPEN SOURCE

Why your password is the least of your problems in 2026?

After the emergence of the Mythos model and the security breach in Axios, the tech sector warns: in the era of weaponized AI, the strength of our passwords is just the tip of the iceberg

N
Why your password is the least of your problems in 2026?

Just a few days ago, World Password Day was celebrated, a date that year after year reminds us of the importance of changing our passwords and enabling two-factor authentication. However, in the technological context of 2026, complying with these digital hygiene rituals is no longer enough. The recent supply chain compromise of Axios and, above all, the emergence of Mythos —Anthropic’s most advanced model to date— have shown that cybersecurity is no longer about the the strength of a password, but about the resilience of Artificial Intelligence.

The “Mythos Effect”: AI that looks for open doors.

The global anticipation surrounding Mythos is unprecedented, and not precisely because of its creative capabilities. According to the newspaper Público, this model has raised alarms in financial and government institutions due to its structural analysis capability, describing it as “a new AI tool that poses a security risk.”

In statements to Herrera en COPE, technology expert José Ángel Cuadrado has been emphatic about the risk that critical infrastructures face: using Mythos is like “bringing together the 10 best hackers in the world working in coordination.” According to Cuadrado, this AI is capable of reviewing a bank’s security systems “like someone walking through a huge building looking for a poorly closed window,” identifying flaws in ATM networks or databases at a speed that no human cyber defense team can mitigate in real time.

Project Glasswing: The race for containment.

To try to manage this potential, the U.S. company has decided to veto its public launch through Project Glasswing: an elite consortium formed by giants such as Amazon, Google, Microsoft, and Apple, among others. The objective was ambitious: to test Mythos in controlled environments to patch critical vulnerabilities before a large-scale deployment.

According to Diario Público: Project Glasswing, which takes its name from the glasswing butterfly that uses its transparent wings to hide in plain sight. 

However, the shadow of a possible leak of these capabilities has led the White House to urgently evaluate the AI tools available on the market, according to ABC. The possibility that these “white-glove” capabilities fall into the hands of malicious actors has accelerated the implementation of the European Union AI Act, which seeks to ensure that such powerful models comply with strict ethical and security standards from their conception.

Axios Case: The “poison” in the supply chain.

If the post-mortem analysis of the March attack on  Axios (via NPM) has taught us anything, it is that the most dangerous vulnerability is blind trust. Attackers did not need to break a password; they simply “poisoned” the tool that thousands of developers use daily.

By combining these types of supply chain attacks with an AI capable of automating trial and error, the risk of massive infection becomes exponential. As analyst Enrique Dans points out, in 2026 hacking is no longer a matter of individual genius, but of infinite automated iteration. In this scenario, a 20-character password offers no protection against malicious code that is already inside your system.

Conclusion: From Password to “Zero Trust”.

The lesson for the rest of the year is clear: security in 2026 is a matter of architecture, not secret words. Faced with an AI capable of “checking every lock” in our digital lives, the mindset must evolve towards Zero Trust model:

  1. AI Audit: Do not blindly trust what your assistant processes. Invisible instructions are the new attack vector.
  2. Software Transparency: The Axios case demonstrates that we must know the origin of every update we install.
  3. Passkey Adoption: Biometrics and security hardware are now the only real barrier against AI attack automation.

As media outlets like the BBC and El Mundo conclude, cybersecurity is no longer just about locking the door; it’s about ensuring that the “digital brain” that manages our world cannot be deceived or corrupted by a superior intelligence.

N
Nerea López — Redactora y Comunicación Mindden articles are written from real production projects and reviewed by the technical leads of each area.