Live data from Hacker News

New serious vulnerabilities spiked around release of Claude Mythos Preview

epoch.ai

11–20 of 82 posts

Re: New serious vulnerabilities spiked around release of Claude Mythos Preview

#11

Earlier quoted context omitted.

The best case scenario for AI companies is, people receive those bug reports, look at the model that produced it and not even look at the details, just apply the fix mindlessly This gives Anthropic a staggering amount of power. Oh it came from Mythos? We will just lose time trying to analyze it, better apply the fix ASAP

> The best case scenario for AI companies is, people receive those bug reports, look at the model that produced it and not even look at the details, just apply the fix mindlessly Do people maintaining serious software do this, though?

The problem is that serious software is drowning in AI vulnerability reports. There is not enough manpower to analyze them properly. And if you ignore the reports (like curl is doing in their 1-month vacation), malicious actors will just exploit them. At some point it's inevitable to just rubber stamp whatever is coming from AI.

The actual, underlying problem is that software is buggy and current programming languages aren't fit for writing reliable software. There's a wide gap between the state of art in formal verification, and what is actually practiced in the industry. It's because of this general unreliability that AI has a large supply of vulnerabilities to find. The situation will only get better if software becomes reliable and written in solid foundations.

My guess is that AI will be even more useful to verify software (something like, write Lean or Coq proofs that the software is not vulnerable, things like that), rather than finding vulnerabilities piecemeal but still letting software be written in unsuitable languages, with no formal verification to prevent bugs from sneaking through.

Re: New serious vulnerabilities spiked around release of Claude Mythos Preview

#14
post #4

How are these reports verified to be valid? If there are too many some could be hallucinations too.

We (Project Glasswing users) follow a proof-of-concept approach. We create the exploit and verify that it behaves as the AI claims. Given our experience as security engineers (many of us with 10+ YoE) we don’t simply report every critical bug Mythos claims to have found. We verify each one carefully. At least, that’s what most of the high-visibility users in Project Glasswing are doing. There are bad apples everywher…

>We (Project Glasswing users) follow a proof-of-concept approach. We create the exploit and verify that it behaves as the AI claims. Given our experience as security engineers (many of us with 10+ YoE) we don’t simply report every critical bug Mythos claims to have found. We verify each one carefully.

>That incident showed that not everyone involved in Project Glasswing follows the same standards.

Re: New serious vulnerabilities spiked around release of Claude Mythos Preview

#18
post #4

How are these reports verified to be valid? If there are too many some could be hallucinations too.

We (Project Glasswing users) follow a proof-of-concept approach. We create the exploit and verify that it behaves as the AI claims. Given our experience as security engineers (many of us with 10+ YoE) we don’t simply report every critical bug Mythos claims to have found. We verify each one carefully. At least, that’s what most of the high-visibility users in Project Glasswing are doing. There are bad apples everywher…

Its very hard to understand what you're saying with the comment - like you have 10+ years of experience and you verify each bug because you know Mythos can provide fake positives. But other teams (which also should have people equivalent to your skill and experience level) suck at it so much that CVP level workers are having to spend time on their fake reports. Then you say Anthropic should stop theater. Then you say the cve count is real.

It genuinely felt like the aladin scene in The Dictator reading this comment.

Re: New serious vulnerabilities spiked around release of Claude Mythos Preview

#19

This is hardly news? We've known for months that a flood of AI-assisted vulnerabilities was coming; I posted on Twitter in March calling 2026 the year of a million CVEs: https://x.com/i/status/2035045573116789002

In pretty much every single HN post on this topic, there are a number of commenters claiming it’s false. Continued quantifiable data like this seems very important at hopefully resolving the ongoing disagreement about the facts.

Re: New serious vulnerabilities spiked around release of Claude Mythos Preview

#20

…are we really drawing conclusions on this starting at April? When it was released in June?

Not really special, which was the point, its a general model. This is really good marketing as all other LLMs are able to do the same work.
Post reply on HN