GeistHaus
log in · sign up

Mythos finds a curl vulnerability

daniel.haxx.se

yes, as in singular one. Back in April 2026 Anthropic caused a lot of media noise when they concluded that their new AI model Mythos is dangerously good at finding security flaws in source code. Apparently Mythos was so good at this that Anthropic would not release this model to the public yet but instead … Continue reading Mythos finds a curl vulnerability →

34 pages link to this URL
Mythos: Given Enough Inference, All Bugs Are Shallow | Corgea

Anthropic's Mythos showed that given enough inference, all bugs are shallow. But who pays for the inference? We benchmarked Claude Opus 4.6 against Corgea v1 and v2 to show why purpose-built scanner architecture beats raw model capability on precision, recall, cost, and speed.

0 inbound links article en
The Floor Doesn't Exist

AI did not invent new attacks. It billed the old ones monthly. Crypto is the only place we can count it, and the early signals are in.

0 inbound links article en
AI might cut false positives, but it won’t stop the slop

GitHub and industry leaders warn of a massive surge in unvalidated AI vulnerability reporting, forcing bug bounty programs to tighten rules against the noise.

0 inbound links article en AI anthropicartificial intelligence (ai)bug bountydaybreakgithubmythosopenaisoftwaresoftware securityvulnerabilities
This Week In Security: Android Exposes ADB, ShinyHunters Get Paid, Robot Dogs, And More

Google has patched an Android ADB bug in the May security patch set. If you have a Pixel phone you should already have the patches, and most other major manufacturers should be close behind. Unfort…

0 inbound links article en Hackaday ColumnsSecurity Hacks adbandroidbenn jordancopyfailcurlEximfccmalwaremicrosoftmythossecurityspamThis Week in Computer Securitytrojantwisunitree
IT News | Slashdot

Slashdot: News for nerds, stuff that matters. Timely news source for technology related news and B2B software reviews & comparisons.

Adële 🐁! (@adele@social.pollux.casa)

aka 아델 #French 🇫🇷 #PHP / #JavaScript and #Java developer #Korean 🇰🇷 ancestry (but I don’t speak the language) Into #SmolWeb, #GeminiProtocol, #Smolnet, #LowTech #ArchLinux / #Debian user #Markdown 🇲⬇️ enthusiast Instance running #GoToSocial 🦥 en / fr :straightally:

1 inbound link profile en
What the CVE?

How I'm using Claude Opus 4.7 to find and report CVEs in popular Hex packages to make the BEAM ecosystem safer.

0 inbound links website en
Weekly Notes 20/2026

We are in Thrissur. We left at around 2 AM and reached by 11 AM, with two breaks. The drive was comfortable. The traffic was friendly this time. Echo is getting old, and Uma is more active now. So …

1 inbound link article en
CTO at NCSC Summary: week ending May 17th

My Ministers will also introduce legislation to improve the country’s defences against cyber-security threats [Cyber Security and Resilience Bill].

0 inbound links article en
Lobsters

A computing-focused community centered around link aggregation and discussion.

0 inbound links website en
On curl and Mythos

Yesterday, I wrote about the massive increase in security issues being identified by AI. Daniel Stenberg, the author of curl, was a key part of that story. At first he was being overwhelmed by a torrent of “AI slop” reports. In the last few months, the reports have become almost all legitimate, but the pace hasn’t changed. Today, Stenberg posted about his recent experience with Claude Mythos.

0 inbound links article en