Earlier quoted context omitted.
"it can almost like write 2 paragraphs!" "It might be conscious" "this is basically AGI, we had to fire someone who spilled the beans"
I always thought he was fired for making crackpot statements to the press in reference to his professional capacity, and thus creating bad PR and embarrassing spectacle for his employer. Seems like legitimate reasons to me.
Mythos Finds a Curl Vulnerability
221–230 of 298 posts
Re: Mythos Finds a Curl Vulnerability
#222Earlier quoted context omitted.
>> Anthropic using marketing to convince people their models are more advanced, better built, or that AI is a threat that needs to be regulated because only they have the answer? I’m shocked. I remember when OpenAI was saying GPT-2 was too dangerous to release.
Context from 2019: https://en.wikipedia.org/wiki/GPT-2 >While previous OpenAI models had been made immediately available to the public, OpenAI initially refused to make a public release of GPT-2's source code when announcing it in February, citing the risk of malicious use;[8][5] limited access to the model (i.e. an interface that allowed input and provided output, not the source code itself) was allowed for selected…
"AI can't do anything harmful at all, kick this shit up to 11. It's all marketing, bla bla"
and
"My grandma gave away all her money to AI bots and is now starving in the street. My uncle murdered his wife and is trying to get married to GPT-4o. He thinks they are going to elope to a data center on a tropical island and live happily ever after".
I think the 'AI can do no harm, it's marketing" people are really disconnected from reality and that any other product that behaved in the same manner would have been banned in most places.
Re: Mythos Finds a Curl Vulnerability
#223Should have scanned it with Mythos on an older code base before all these other sec issues was resolved with other tools. Or use the other tools to introduce the same kind of errors in other parts of the code base to see if Mythos would have found it. A problem is that these tools seems smarter than they are cause they already read seen the answer key.
Re: Mythos Finds a Curl Vulnerability
#224Kinda burying the lede: AI tools found over a dozen CVEs in curl last year, and hundreds of bugs. "Primarily AISLE, Zeropath and OpenAI’s Codex Security have been used to scrutinize the code with AI. These tools and the analyses they have done have triggered somewhere between two and three hundred bugfixes merged in curl through-out the recent 8-10 months or so. A bunch of the findings these AI tools reported were co…
[1] https://lists.haxx.se/pipermail/daniel/2025-September/000127...
[2] https://www.theregister.com/software/2025/10/02/curl-project...
Re: Mythos Finds a Curl Vulnerability
#225Earlier quoted context omitted.
I remember when there was a guy at Google years a few years ago that was convinced that they had an internal, sentient creature in their labs (I think maybe 4 years ago?) If I’m not mistaken, after the media cycle, he lost his job for breaking confidentiality. That was the opposite of marketing, Google really didn’t get how to turn this into a product until ChatGPT happened.
They most likely understood that it wasn't viable for anything. OpenAI just yolo'd it and now we're dealing with the fallout. I'm fairly certain that any management layer at google isn't going to say yes to "invest 5 billion to make 10 million" scheme that OpenAI, Anthropic, are currently running.
Re: Mythos Finds a Curl Vulnerability
#226> An amazingly successful marketing stunt for sure. This. Well done by Antropic. It even reached the CISO of my small semi-government org in the Netherlands, who slightly panicked at the announced 'tsunami' of vulnerabilities that was coming with Mythos. Got us some more money and priority with the board, though. Never waste a good marketing scare.
Re: Mythos Finds a Curl Vulnerability
#227Earlier quoted context omitted.
I had a totally different take. The fact that Mythos found only one vulnerability is testament to how solid curl is, not how bad Mythos is. Look at the Firefox blog post where they found something like 400 (or more) findings. I have no doubt Mythos is very good at this, but I also don't think it's something unattainable by other labs within the next few months, with focus.
The point is that Anthropic claims it’s a huge leap over everything else. But it isn’t.
Re: Mythos Finds a Curl Vulnerability
#228Earlier quoted context omitted.
None of those other LLM tooling made the claims they're too dangerous to be released and used though, unlike Anthropic did with Mythos. What it highlights, is that Mythos doesn't seem so much better than other LLM driven tooling at finding security issues, which was the strongest claim Anthropic made in the first place.
People love defending Anthropics shortcomings… “Mythos isn’t supposed to be that good at security, because actually Anthropic was referring more about running llms than mythos specifically” “The opus model is worse because they have no compute because they are training mythos. The degraded performance is justified!” “All the bugs in Claude code is just because the models are so good they are just looping and are ship…
Re: Mythos Finds a Curl Vulnerability
#229Earlier quoted context omitted.
I don't agree with the "no tsunami in sight": if you don't look at 100+ bugs in Firefox and many more OSS projects, bunch of old unseen-before OpenBSD/Linux RCEs, and a few LPE in just 2 or 3 weeks for Linux itself... IMO, this does not sound like marketing scare, there is spike of vulnerability disclosures - high quality, low false positives - that can be sensed... It feels like we're speedrunning through few-years…
Mythos isn’t released yet. Anthropic noticed the trend of AI vulnerability scanning and started advertising Mythos, which is unreleased, as being very good at it. Then they donated very large token budgets for using Mythos privately to several teams. Those teams used the free token spend for security research (that was the deal) and anything they found got attributed to Mythos, not the token budget. Mythos looks like…
Close enough that you can probably get a good sense of Mythos' performance by using GPT-5.5.
One thing I noticed while using GPT-5.5 for this is that the ability of the model to turn the bug into an outright vulnerability is less relevant than you might intuitively think. All that is really necessary is for the model to point out that something is smelly, and you should just fix it. Turning it into a runnable exploit has very limited utility for the defender. It does turn heads and may get the attention of some otherwise reluctant people, but everything I found was obviously enough wrong that the exploit was just decorative.
Re: Mythos Finds a Curl Vulnerability
#230If priced like other Anthropic models, Mythos will make vulnerability discovery a lot more accessible. The author compares it to AISLE, ZeroPath, and OpenAI’s Codex Security. AISLE and ZeroPath are much more expensive. OpenAI’s Codex Security is gated. Most people don't care about the first two and don't complain about the latter's policy because they are all specialized models and/or harnesses. Mythos will be availa…
AISLE is *cheaper* for sure