Showing posts with label security vulnerabilities. Show all posts
Showing posts with label security vulnerabilities. Show all posts

Wednesday, May 27, 2026

Claude Mythos discovers bugs and vulnerabilities so fast and in large numbers that patching them is not keeping up?

Amazing stuff! What a conundrum!

"Mythos discovers bugs and vulnerabilities faster than patches
 
Anthropic and its approximately 50 Project Glasswing partners used Claude Mythos Preview to discover over 10,000 high- or critical-severity vulnerabilities across critical software systems in the first month after Glasswing’s April 2026 launch — including both partner codebases and over 1,000 open-source projects scanned by Anthropic itself.
The real problem has become obvious: nobody can fix them fast enough. Cloudflare alone surfaced 2,000 bugs—400 critical—with fewer false positives than human testers would generate.
Mozilla patched 271 vulnerabilities in Firefox 150, more than ten times the count from previous Claude versions.
Yet of 530 critical bugs disclosed across the program, only 75 have been patched so far, with high-severity fixes averaging two weeks to roll out.
Anthropic scanned over 1,000 open-source projects and confirmed that 90.6 percent of flagged issues were valid after manual review.
The asymmetry matters: attackers with access to similar models could soon exploit this window between discovery and remediation, while maintainers remain swamped by the sheer volume of findings."

"Last month, we launched Project Glasswing, our collaborative effort to secure the world’s most critical software before increasingly capable AI models can be turned against it.

Since then, we and our approximately 50 partners have used Claude Mythos Preview to find more than ten thousand high- or critical-severity vulnerabilities across the most systemically important software in the world. ..."




Our dashboard of open-source vulnerabilities, showing vulnerabilities of all severities (rather than only those estimated high- or critical-severity by Mythos Preview).


Saturday, May 16, 2026

The third major Linux kernel flaw in two weeks has been found - thanks to AI

Good news! I also noticed more than usual software update notifications lately with Fedora Linux on my laptop.

AI may not only find security vulnerabilities or software flaws much faster, but also may provide usable information how to fix them without breaking the operation system or causing a bug.

"... According to Linus's law, "Given enough eyeballs, all bugs are shallow," is fundamental to open source. ...

thanks to AI bug-finding tools, such as Claude Mythos and OpenAI Daybreak, behind most of those eyeballs are AI engines, and they're proving to be much faster at finding security problems than human ones. ..."

The third major Linux kernel flaw in two weeks has been found - thanks to AI | ZDNET "AI is exposing Linux security holes faster than developers can patch them. Fragnesia is the latest. Here's what we know about it."

Thursday, May 07, 2026

How Anthropic’s Mythos has rewritten Firefox’s approach to cybersecurity of its web browser

Good and bad news! How long and how severely was the security of the Firefox browser vulnerable!

"... Now, security researchers for Mozilla’s Firefox browser are providing a closer look at what that process has looked like in practice, and what Mythos’ powers mean for software security at large.

In a post published on Thursday, Mozilla said Mythos has unearthed a wealth of high-severity bugs, including some that had lain dormant in the code for more than a decade.

That’s a significant improvement from what AI security tools were capable of even six months ago. Until now, AI bug-finding tools have come with severe drawbacks, often inundating security teams with low-quality reports and false positives. But Mozilla’s researchers say the latest generation of tools have turned a corner, particularly now that agentic systems can assess their own work and filter out bad results. ...

fixing the 271 bugs identified by Claude Mythos Preview ..."

How Anthropic’s Mythos has rewritten Firefox’s approach to cybersecurity | TechCrunch



What a jump in April 2026!


Wednesday, July 09, 2025

Fitness App Trap: World Leaders Exposed by Strava with Palki Sharma

Very recommendable! A serious security issue! When bodyguards of VIPs upload their Strava data, the enemy learns the whereabouts and movements!