Live data from Hacker News

Project Glasswing: what Mythos showed us

blog.cloudflare.com

111–120 of 152 posts

Re: Project Glasswing: what Mythos showed us

#111
'Narrow scope produces better findings - Telling the model "Find vulnerabilities in this repository" makes it wander. Telling it "Look for command injection in this specific function, with this trust boundary above it, here's the architecture document and here's prior coverage of this area" makes it do something much closer to what a researcher would actually do.'

So what, we take every function and every vulnerability type and just run the agents millions of times?

I would expect Mythos to be able to find vulnerabilities without pointing it out for him, otherwise it's no better from other agents. It's just has a better harness.

Re: Project Glasswing: what Mythos showed us

#112
post #32

Earlier quoted context omitted.

Writing and later the printing press have already considerably stifled human expressiveness. Language used to be noch more fragmented and diverse before mass media (or the Bible in every household). In my grandmother’s time you would have difficulty understanding people from three villages down the road.

I'm not sure enabling people three villages apart to communicate with each other counts as "stifling human expressiveness"

I’m not sure that having people read LLM output does that either.

Re: Project Glasswing: what Mythos showed us

#113

'Narrow scope produces better findings - Telling the model "Find vulnerabilities in this repository" makes it wander. Telling it "Look for command injection in this specific function, with this trust boundary above it, here's the architecture document and here's prior coverage of this area" makes it do something much closer to what a researcher would actually do.' So what, we take every function and every vulnerabili…

Who is him?

Re: Project Glasswing: what Mythos showed us

#114

'Narrow scope produces better findings - Telling the model "Find vulnerabilities in this repository" makes it wander. Telling it "Look for command injection in this specific function, with this trust boundary above it, here's the architecture document and here's prior coverage of this area" makes it do something much closer to what a researcher would actually do.' So what, we take every function and every vulnerabili…

Yeah this whole post reads like Anthropic said “make sure you say how awesome Mythos is” but really what they’re saying is that it’s just a better harness.

Re: Project Glasswing: what Mythos showed us

#115

'Narrow scope produces better findings - Telling the model "Find vulnerabilities in this repository" makes it wander. Telling it "Look for command injection in this specific function, with this trust boundary above it, here's the architecture document and here's prior coverage of this area" makes it do something much closer to what a researcher would actually do.' So what, we take every function and every vulnerabili…

I'm still waiting something more specific or groundbreaking too. Feels like a lot of noise with just the goal to get people to talk about it. And now I realize I am talking about it and about nothing at the same time. Just fugazzi.

Re: Project Glasswing: what Mythos showed us

#116

'Narrow scope produces better findings - Telling the model "Find vulnerabilities in this repository" makes it wander. Telling it "Look for command injection in this specific function, with this trust boundary above it, here's the architecture document and here's prior coverage of this area" makes it do something much closer to what a researcher would actually do.' So what, we take every function and every vulnerabili…

I think the idea here is you give the Hunters (stage 2) a narrower scope, but have a parent agent responsible for dividing up the full search space (stage 1).

And note that Hunt tasks can be queued from previous Trace tasks, ie you find a vuln in one layer, so you queue a hunt for corresponding vulns in the layers that could exploit your first finding.

Re: Project Glasswing: what Mythos showed us

#119

great, but why don't you share real data on how many security vuln it found ? how many were reals, how many weren't ?

Yeah I’m waiting for this as well. I get that you want to address them or whatever before releasing info but I keep seeing these claims with barely any data and I’m like…how do you expect people to not be skeptical? I mean hell if you’re a security professional you’re literally paid to be skeptical.

Mozilla published some numbers and actual bugs.

https://hacks.mozilla.org/2026/05/behind-the-scenes-hardenin...

Re: Project Glasswing: what Mythos showed us

#120

What does this mean? > It's a different kind of tool doing a different kind of work, and that makes a clean apples-to-apples comparison to earlier models difficult. They claim it’s a different kind of tool and then describe using it the same way you’d use any other model. This really felt way worse than the average Cloudflare blog and really just rehashed the Mythos announcement which had already called out the key p…

I think they're saying it has qualitatively different capabilities that make certain kinds of security work more worth pursuing with the model, not that the model of human-AI interaction has changed. You're right that they're using a harness like everyone else. The general idea of giving the model a harness is not going to change. I mean even humans need harnesses to accomplish some things.

Google Maps is my favorite human harness.
Post reply on HN