3 Sources
[1]
Cisco sings Mythos' praises - but doesn't say how many bugs the model uncovered
Bug hunting has become a whole lot more exciting in recent months with both Anthropic and OpenAI touting their latest models (that also happen to be super-scary exploit machines). On Tuesday, as Anthropic announced a fourfold expansion to its Mythos preview program, Cisco jumped into the fray,
[2]
8 Years of Security Research in 8 Weeks: Transforming Cybersecurity with AI
In just eight weeks, we scanned 1.8 billion lines of code in over 25 coding languages across the breadth of Cisco's portfolio, a process that would have taken our world-class security research team eight years to complete. We are only getting started. But speed is only half the story. The real
[3]
Cisco overhauls vulnerability disclosures as AI accelerates bug hunting
Why it matters: New AI models are pouring gasoline on bug discovery, forcing technology and security vendors to rethink how they responsibly disclose the bugs that researchers find in their products before malicious hackers get hold of them. Driving the news: Starting in July, Cisco will start
Share
Copy Link
Cisco deployed frontier AI models including Claude Mythos Preview and GPT 5.5-Cyber to scan 1.8 billion lines of code across 25 programming languages in just eight weeks—work that would have required eight years manually. The networking giant achieved a false positive rate under 3 percent but hasn't disclosed the total number of bugs found. Starting July, Cisco will publish security fixes twice monthly instead of once.
Cisco has completed what Anthony Grieco, the company's senior vice president and chief security and trust officer, calls a transformative milestone in AI bug hunting. Using frontier AI models including Claude Mythos Preview and GPT 5.5-Cyber, the networking giant scanned 1.8 billion lines of code across more than 25 programming languages in just eight weeks
1
2
. This accelerated rate of bug discovery represents work that would have taken Cisco's advanced security team eight years to complete manually3
.While Cisco praised the scale and quality of findings, the company notably did not disclose how many vulnerabilities the AI models uncovered or whether all identified flaws have been fixed
1
. Grieco emphasized that speed represents only half the story, with the real breakthrough being the "scale, quality, and impact" of the models' findings2
.
Source: Axios
The code scanning effort spanned Cisco's entire product portfolio, paired with what the company describes as a "human-guided harness" built on the Cisco Foundry Security Spec
2
. This AI-driven security approach achieved a false positive rate of under 3 percent—a stark contrast to traditional static analysis tools that historically produced one useful finding for every 10,000 warnings2
."Rather than focusing on a specific scope for a security evaluation, we can assess entire code bases of a product," Grieco explained. "It's like switching from a flashlight to a flood light to illuminate a dark room"
1
. Because each finding is validated through a hybrid of AI and human expertise, engineering teams receive actionable intelligence rather than overwhelming warnings2
.Cisco tested its framework across six frontier AI models to ensure a model-agnostic methodology. "The model is the accelerant; the harness is the engine," the company stated, emphasizing that the orchestration framework embedded years of domain knowledge from the Cisco Advanced Security Initiatives Group
2
.Cisco's announcement came as Anthropic expanded Project Glasswing, its controlled partner program for Claude Mythos Preview, to approximately 200 organizations across more than 15 countries
1
. The expansion added about 150 new partners, including Rubrik, Korea Internet and Security Agency (KISA), Samsung Electronics, SK hynix, and SK Telecom1
.Palo Alto Networks, an original Glasswing partner, reported uncovering 26 CVEs representing 75 underlying security issues after scanning more than 130 products for one month—compared to typically disclosing fewer than five CVEs per month
1
. A company executive forecast "a narrow three-to-five-month window for organizations to outpace the adversary before AI-driven exploits start to become the new norm"1
.Last month, Anthropic revealed that the roughly 50 partners using Mythos Preview had already uncovered more than 10,000 high- or critical-severity vulnerabilities across systemically important software worldwide
3
.Related Stories
Recognizing that cyber defenders face challenges keeping pace with AI-accelerated vulnerability discovery, Cisco is fundamentally restructuring its approach. Starting in July, the company will publish security disclosures on the first and third Wednesdays of each month—doubling the frequency from current monthly updates
3
."This isn't just about keeping pace with an individual thing with an individual threat," Grieco told Axios. "It's about how we're addressing the system-hardening and vulnerabilities at a depth and speed that previously was unattainable"
3
. The shift represents a move from reactive responses to proactive system-hardening3
.Cisco also plans to introduce Live Protect, a new product designed to provide customers with temporary shields against exploitation of newly discovered vulnerabilities while they work to deploy permanent fixes
3
. This addresses a critical gap, as many systems require complete reboots to install patches, and IT teams often need extensive testing before comfortable rolling out updates3
.Summarized by
Navi
21 Jul 2026•Technology

14 May 2026•Technology

22 Apr 2026•Technology

1
Technology

2
Technology

3
Policy and Regulation
