How are these reports verified to be valid? If there are too many some could be hallucinations too.
We (Project Glasswing users) follow a proof-of-concept approach. We create the exploit and verify that it behaves as the AI claims. Given our experience as security engineers (many of us with 10+ YoE) we don’t simply report every critical bug Mythos claims to have found. We verify each one carefully. At least, that’s what most of the high-visibility users in Project Glasswing are doing. There are bad apples everywher…
Or it functionally does not exist.
(No, long hashes with an equally mythic promise of reproducibility don’t count)