Mythos finds a curl vulnerability

yes, as in singular one. Back in April 2026 Anthropic caused a lot of media noise when they concluded that their new AI model Mythos is dangerously good at finding security flaws in source code. Apparently Mythos was so good at this that Anthropic would not release this model to the public yet but instead … Continue reading Mythos finds a curl vulnerability →

daniel.haxx.se
My personal conclusion can however not end up with anything else than that the big hype around this model so far was primarily marketing. I see no evidence that this setup finds issues to any particular higher or more advanced degree than the other tools have done before Mythos. Maybe this model is a little bit better, but even if it is, it is not better to a degree that seems to make a significant dent in code analyzing.
@bagder How do you explain that Mythos found 271 bugs in Firefox, and counting, and only 1 in cURL. Is the Firefox code base 271 times larger?
@gnirre I do not explain that at all because I don't have enough knowledge to do so.
@bagder Did Anthropic know that you finally had gotten access to Mythos?
@gnirre no idea, probably not
@bagder Maybe my question should have been if Alpha Omega knew? Your access was "inofficial"?
@gnirre I don't know how much they asked or told A about when this was done. It's not "my" access, someone else has the access and ran the analysis