7 Sources
[1]
Mozilla says 271 vulnerabilities found by Mythos have "almost no false positives"
The disbelief was palpable when Mozilla's CTO last month declared that AI-assisted vulnerability detection meant "zero-days are numbered" and "defenders finally have a chance to win, decisively." After all, it looked like part of an all-too familiar pattern: Cherry pick a handful of impressive
[2]
How Anthropic's Mythos has rewritten Firefox's approach to cybersecurity | TechCrunch
When Anthropic unveiled its new Mythos model in April, it also delivered a stern warning to anyone developing software. The model was so powerful at sniffing out software vulnerabilities, the lab claimed, that it had discovered thousands of high-severity bugs that would need to be fixed before it
[3]
Mythos found 271 Firefox flaws - none a human couldn't spot
Mozilla CTO says AI means developers finally have a chance to get on top of security The Mozilla has revealed it tested Anthropic's bug-finding "Mythos" AI model and feels the results it experienced represent a watershed moment for software defenders. The FOSS outfit on Tuesday reminded readers
[4]
Anthropic's bug-hunting Mythos was greatest marketing stunt ever, says cURL creator
cURL developer Daniel Stenberg has seen Anthropic's Mythos, a model the AI biz has suggested is too capable at finding security holes to release publicly, scan his popular open source project. But after the system turned up just a single vulnerability, he concluded the hype around Mythos was
[5]
Mozilla boasts Mythos boosted Firefox bug cull
Yet it remains unclear if Anthropic's uber model was effective, or if better model middleware is what makes the difference Mozilla fixed 423 Firefox security bugs in April, a repair rate more than five times higher than the 76 fixes issued in March and almost 20 times higher than its 21.5 monthly
[6]
Claude Mythos Just Flagged 271 Hidden Vulnerabilities in Firefox
Mozilla's Claude Mythos AI experiment has unveiled a striking new chapter in software vulnerability detection. By employing advanced AI to analyze the Firefox 150 codebase, the project identified 271 vulnerabilities in a single release cycle, an extraordinary leap from the 22 issues found in a
[7]
Claude Mythos found decade old Firefox bugs that years of fuzzing missed
There's a 15-year-old bug hiding in Firefox's <legend> element - one of the most boring tags in HTML. It survived over a decade of fuzzing, manual audits, and security research. Claude Mythos found it in days. Also read: Genesis AI's human-sized robotic hands can cook, play piano, and solve a
Share
Copy Link
Anthropic Mythos identified 271 security vulnerabilities in Firefox with almost no false positives, helping Mozilla ship 423 bug fixes in April 2026. But cURL creator Daniel Stenberg questions the hype after the AI model found just one confirmed vulnerability in his widely-tested codebase, calling it primarily a marketing stunt.
Mozilla has revealed detailed findings from its use of Anthropic Mythos, an AI model designed for finding security flaws, which identified 271 Firefox security vulnerabilities over two months
1
. The discovery helped Mozilla ship 423 Firefox bug fixes in April 2026, compared to just 31 exactly a year earlier2
. This represents more than five times the 76 fixes issued in March and almost 20 times higher than the 21.5 monthly average from last year5
. Mozilla Distinguished Engineer Brian Grinstead emphasized that "in terms of the bugs coming out on the other side, there are almost no false positives"1
.
Source: Geeky Gadgets
The team published details on 12 of the bugs, ranging from unusual sandbox issues to a 15-year-old error in HTML element parsing
2
. Mozilla CTO Bobby Holley declared that "defenders finally have a chance to win, decisively" and suggested zero-days are numbered3
. The bug-hunting AI proved particularly effective at identifying sandbox vulnerabilities, which Mozilla's bug bounty program pays up to $20,000 for researchers to find2
.Mozilla engineers attribute their success to two factors: improvements in the AI model itself and their development of a custom agent harness that guided Mythos through Firefox source code analysis
1
. The harness wraps around the large language model to guide it through specific tasks, providing instructions and tools that mirror what human Mozilla developers use, including specialized Firefox builds for testing1
.Grinstead explained that earlier attempts at AI-assisted vulnerability detection produced "unwanted slop" with plausible-sounding bug reports that often contained hallucinated details requiring significant human verification
1
. The new approach uses a second LLM to grade output from the first, providing developers with the same confidence level as traditional discovery methods1
. For memory safety issues, the system leverages Mozilla's sanitizer build of Firefox, where successfully crashing the browser confirms a vulnerability1
.
Source: The Register
Not everyone shares Mozilla's enthusiasm about Anthropic Mythos. Daniel Stenberg, creator of the widely-used cURL project, concluded that the hype around the AI model was "primarily marketing" after it found just one confirmed vulnerability in his codebase
4
. Mythos initially flagged five potential security vulnerabilities in cURL, but after hours of investigation by Stenberg's security team, only one was confirmed as a low-severity issue planned for CVE publication4
.Stenberg noted that cURL has undergone extensive testing with AI-powered code analyzers over recent months, with tools like AISLE, Zeropath, and OpenAI Codex Security triggering between 200 and 300 bugfixes in the past 8-10 months
4
. He acknowledged that AI tools have improved at finding security flaws compared to traditional analyzers, but emphasized that "all modern AI models are good at this now" and that Mythos doesn't represent a significant advancement4
.Related Stories
Security consultant Davi Ottenheimer raised concerns about Mozilla's methodology, noting that the organization never quantified what Opus 4.6 accomplished before attributing results to Mythos
5
. He demonstrated that Anthropic's lesser models Sonnet 4.6 and Haiku 4.5, when equipped with a harness called Wirken, produced eight findings in two minutes at approximately $0.75, with two matching bugs Mythos had identified5
.
Source: The Register
Ottenheimer criticized Mozilla for not providing transparent comparisons between Mythos and other models, stating there's "a fundamental philosophical failure" in treating readings as measurements without proper evidence
5
. Mozilla acknowledged that Opus 4.6 was already identifying "an impressive amount of previously unknown vulnerabilities" before Mythos deployment5
.The debate centers on whether Anthropic Mythos represents a genuine breakthrough in software security or if effective middleware makes any capable AI model sufficient for finding security flaws. Mozilla's Brian Grinstead acknowledged uncertainty about the broader implications, stating "it's useful for both attackers and defenders, but having the tool available shifts the advantage a little bit to defense"
2
. Anthropic CEO Dario Amodei suggested that fixing discovered bugs could leave defenders in a better position since "there are only so many bugs to find"2
.Holley noted that Mythos hasn't discovered any bugs that elite human researchers couldn't find, countering speculation about AI uncovering entirely new vulnerability categories
3
. Mozilla still relies on human engineers to write and review patches for every bug, as AI-generated fixes cannot be deployed directly2
. The question remains whether bad actors using similar techniques with less capable models pose an immediate threat, and whether the industry's focus should shift toward developing better harnesses rather than pursuing more advanced AI models for high-severity software vulnerabilities detection.Summarized by
Navi
[3]
[5]
14 May 2026•Technology

13 May 2026•Technology

06 Mar 2026•Technology

1
Science and Research

2
Technology

3
Policy and Regulation
