20 Sources
[1]
Mozilla: Anthropic's Mythos found 271 zero-day vulnerabilities in Firefox 150
Earlier this month, Anthropic said its Mythos Preview model was so good at finding cybersecurity vulnerabilities that the company was limiting its initial release to "a limited group of critical industry partners." Since then, debate has raged over whether the model presages an era of turbocharged
[2]
Project Glasswing Aims to Catch Critical Software Bugs
Malicious actors are now exploiting generative AI to carry out cyberattacks: scamming victims using AI-generated deepfakes, deploying malware developed with the help of AI coding tools, using chatbots to pull off phishing campaigns, and hacking widely used open-source code repositories with AI
[3]
Mozilla Used Anthropic's Mythos to Find and Fix 151 Bugs in Firefox
Amid a raging debate over the impact that new AI models will have on cybersecurity, Mozilla said on Tuesday that its Firefox 150 browser release this week includes protections for 271 vulnerabilities identified using early access to Anthropic's Mythos Preview. The Firefox team says that it has
[4]
Attack of the killer script kiddies
Last August, some of the best cybersecurity teams in the business gathered in Las Vegas to demonstrate the strength of their AI bug-finding systems at DARPA's Artificial Intelligence Cyber Challenge (AIxCC). The tools had scanned 54 million lines of actual software code that DARPA had injected with
[5]
New Firefox update patches a whopping 271 bugs, thanks to Claude Mythos
Anthropic's Claude Mythos Preview AI model found the many flaws. Keeping your web browser updated can be a hassle. But typically, you want to snag the latest updates as they introduce new features and fix security holes. That's certainly the case with the newest update to Firefox. Released on
[6]
Mythos sniffs out your bugs, can't fix your bloody idiots
Opinion In retrospect, calling it Mythos made it a hostage to fortune. Anthropic may have hoped that the name implied its AI code security model had mythical god-like powers, but there's an alternate reading. Another definition for Mythos is a set of beliefs of obscure origin which are incompatible
[7]
After Mythos: New Playbooks For a Zero-Window Era
When patching isn't fast enough, NDR helps contain the next era of threats. If you've been tracking advancements in AI, you know the exploit window, the short buffer that organizations relied on to patch and protect after a vulnerability disclosure, is closing fast. Anthropic's new model, Claude
[8]
Mozilla says it patched 271 Firefox vulnerabilities thanks to Anthropic's Claude Mythos
Anthropic's buzzy announcement about using AI to improve cybersecurity earlier this month was met with plenty of skepticism. However, Mozilla shared some details that support use of the company's special Claude Mythos Preview model as a way to protect critical services. Using Mythos helped
[9]
Mythos found 271 Firefox flaws - none a human couldn't spot
Mozilla CTO says AI means developers finally have a chance to get on top of security The Mozilla Foundation has revealed it tested Anthropic's bug-finding "Mythos" AI model and feels the results it experienced represent a watershed moment for software defenders. The FOSS outfit on Tuesday
[10]
Mozilla fixes 271 Firefox vulnerabilities found by Anthropic's Claude Mythos in a single evaluation pass
Summary: Mozilla released Firefox 150 with fixes for 271 security vulnerabilities identified by Anthropic's Claude Mythos Preview, an unreleased frontier AI model distributed under the restricted Project Glasswing programme. The collaboration began with Claude Opus 4.6 finding 22 bugs in Firefox
[11]
Mythos Changed the Math on Vulnerability Discovery. Most Teams Aren't Ready for the Remediation Side
Anthropic's Claude Mythos Preview has dominated security discussions since its April 7 announcement. Early reporting describes a powerful cybersecurity-focused AI system capable of identifying vulnerabilities at scale and raising serious questions about how quickly organizations can validate,
[12]
AI has led to a zero-day bug discovery crisis, and it's getting worse
Tech companies and open-source teams are facing a deluge of AI-discovered software vulnerabilities. Now we're starting to get a sense of how big a deluge it is. The Zero Day Initiative, the largest vendor-agnostic bug bounty program in the world, has already seen a 490 percent increase in
[13]
Mozilla says Anthropic's Mythos is 'every bit as capable' as 'the world's best security researchers' after Firefox experiment -- and says the 'zero-days are numbered'
New AI tools could shift the balance of power in cybersecurity * Mozilla used Anthropic's Mythos AI to find hundreds of Firefox vulnerabilities, matching top human researchers in capability * The experiment suggests AI can now reason through code to uncover complex bugs at scale * This shift
[14]
Project Glasswing Proved AI Can Find the Bugs. Who's Going to Fix Them?
Last week, Anthropic announced Project Glasswing, an AI model so effective at discovering software vulnerabilities that they took the extraordinary step of postponing its public release. Instead, the company has given access to Apple, Microsoft, Google, Amazon, and a coalition of others to find and
[15]
Anthropic's Claude Mythos AI Finds 271 Vulnerabilities in Firefox -- Yes, It's Seriously Powerful - Decrypt
Researchers warn that the same capability could accelerate automated cyberattacks. For decades, attackers have had the advantage in cybersecurity. Artificial intelligence may be about to change that. In a blog post published on Tuesday, Firefox browser developer Mozilla said an early version of
[16]
'Defenders finally have a chance to win, decisively': Firefox CTO raves about Claude Mythos' bug hunting capabilities after it finds 271 vulnerabilities
When you create anything, whether that be software or a short story about two characters that never meet, there's no telling what a fresh pair of eyes will bring to the work. Once a work breaches containment, your adoring audience may reward you with a short work of fanfiction -- or make you kick
[17]
Anthropic's Claude Mythos found 271 Firefox vulnerabilities - CTO calls it just as capable as 'elite security researchers'
Anthropic's unreleased Claude Mythos is at the center of a cybersecurity debate. Its coding capabilities are so powerful that in pre-release tests, the model identified thousands of previously unknown vulnerabilities in major operating systems and web browsers. Since then, many have questioned
[18]
Mozilla fixes 271 Firefox vulnerabilities found by Anthropic's AI
Mozilla announced that Anthropic's Claude Mythos AI identified 271 vulnerabilities in Firefox during internal testing, with all bugs patched in the same week. This result underscores the ability of advanced AI systems to analyze extensive codebases and identify weaknesses that had previously
[19]
How CISOs Need To Prepare For The Claude Mythos Era Of Cyberattacks: Experts
Gaining improved visibility and implementing compensating controls are the most important steps for many organizations alongside shifting to accelerated patching cycles, cybersecurity experts tell CRN. As CISOs rethink their approaches to exposure management and cyber defense following recent
[20]
Zscaler CEO On Vulnerability Surge From AI: 'We All Need To Be Paranoid'
In an interview with CRN, Zscaler CEO Jay Chaudhry says there's no question that Anthropic's Claude Mythos model is 'very powerful' for vulnerability discovery -- and other AI models that could be available to attackers 'aren't too far behind.' In the wake of Anthropic's initiative to make its
Share
Copy Link
Mozilla's Firefox 150 includes fixes for 271 security flaws discovered by Anthropic Mythos Preview, a new AI model with advanced bug-finding capabilities. The AI identified vulnerabilities by analyzing unreleased source code, a task that would have required months of human effort. Firefox CTO Bobby Holley says defenders now have a decisive advantage in cybersecurity.
Mozilla revealed that early access to Anthropic Mythos Preview helped pre-identify 271 software vulnerabilities in Firefox 150, released this week
1
. The discovery represents a significant leap in AI bug finding capabilities, with Firefox CTO Bobby Holley declaring that "defenders finally have a chance to win, decisively" in the ongoing battle between cyberattackers and defenders1
. The AI model analyzed unreleased source code to detect critical software vulnerabilities that would have required months of concentrated human effort to uncover through traditional methods.
Source: TweakTown
The scale of this achievement becomes clear when compared to previous efforts. Anthropic's Opus 4.6 model found only 22 security-sensitive bugs when analyzing Firefox 148 last month
1
. While these vulnerabilities could theoretically be discovered through automated fuzzing techniques or elite security researchers reasoning through complex source code analysis, using Anthropic Mythos eliminated the need to concentrate costly human resources on finding individual bugs1
.Holley emphasized that AI-aided security analysis fundamentally changes the economics of vulnerability discovery. When automated vulnerability hunting becomes cheaper for both attackers and defenders, defenders benefit because they can proactively patch security bugs before exploitation
1
. "Computers were completely incapable of doing this a few months ago, and now they excel at it," Holley wrote, adding that Mythos Preview is "every bit as capable" as the world's best security researchers1
.
Source: Hacker News
In an interview with Wired, Holley stated that every piece of software will need to engage with this type of semantic bug detection "because every piece of software has a lot of bugs buried underneath the surface that are now discoverable"
3
. He expressed confidence that Firefox has "rounded the curve" on this transition, even as future models may become more advanced3
.Anthropics launched Project Glasswing to help thwart AI-driven cyberattacks, with launch partners including Amazon Web Services, Apple, Google, Microsoft, and Nvidia
2
. These companies will use Mythos Preview to scan and secure their software. The model has identified thousands of high- and critical-severity vulnerabilities across major operating systems and web browsers, despite not being explicitly trained for this purpose2
.Among the discoveries are a 27-year-old bug in OpenBSD enabling remote attackers to crash machines, web browser exploits allowing cross-domain data theft, and weaknesses in cryptography libraries that could let hackers decrypt encrypted communications
2
. The model can even chain together separate vulnerabilities to form step-by-step exploits granting root access to the Linux kernel2
.The implications for open-source software are particularly significant. Mozilla Firefox and other open-source projects could be especially impacted by zero-day vulnerability discovery capabilities, since their public codebases are easier for AI systems to explore and many rely on volunteer maintenance with wildly insufficient security resources
1
. Mozilla CTO Raffi Krikorian argued in a New York Times essay that "the programmer who gave 20 years of his life to maintain code that runs inside products used by billions of people" should have access to Mythos1
.Nayan Goel, principal application security engineer at Upgrade, noted that speed and semantics set AI models apart from traditional tools. They can pinpoint vulnerabilities faster than humans, and their ability to reason about code semantics and follow data flows across abstraction layers exceeds pattern-matching functionalities of static analysis tools
2
. "That's the kind of cross-component reasoning that is structurally beyond what rule-based tools can do," Goel explained2
.Related Stories
While Anthropic Mythos offers powerful defensive capabilities, cybersecurity experts warn about dual-use AI risks. The same capabilities that enable vulnerability disclosure can be weaponized for exploit development
4
. Security researchers fear that AI could put advanced hacking skills into the hands of script kiddies—no-skill hackers who previously relied on copying exploits without understanding them4
.
Source: The Verge
"There's a tidal wave coming. You can see it. We can all see it," said Dan Guido, CEO of Trail of Bits
4
. Tim Becker, senior security researcher at Theori, noted that "you can use AI tools and with very minimal human guidance, and in some cases no human guidance, find a zero day in widely used software"4
.Anthropics is attempting to prevent misuse by limiting initial release to critical industry partners and building safeguards into Claude Opus 4.7 to block malicious cybersecurity requests
4
. Security professionals wanting defensive use can apply to the company's Cyber Verification Program.Despite promising potential, large language models remain prone to generating false positives in red teaming scenarios—incorrectly flagging bugs as security vulnerabilities or overstating severity
2
. Jeremy Katz, vice president of code security at Sonar, reported "a drastic uptick in the number of things being reported" to open-source maintainers, many being real bugs but not actual security vulnerabilities2
. The volume creates significant triage challenges for volunteers under pressure to provide prompt fixes.Tools like Claude Code Security and Google's CodeMender conduct adversarial self-review passes, challenging their own results before presentation to reduce false positives and build verification layers
2
. This additional scrutiny helps maintain the cybersecurity balance while managing the firehose of discovered bugs.Summarized by
Navi
[4]
13 May 2026•Technology

14 May 2026•Technology

01 Jun 2026•Policy and Regulation

1
Technology

2
Technology

3
Technology
