Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. I found out my employer doesn’t have access to Mythos.

I found out my employer doesn’t have access to Mythos.

Scheduled Pinned Locked Moved Uncategorized
37 Posts 28 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

    Mythos is not great btw. Running it over a bunch of code, it’s similar findings to tools from a few years ago. It’s marketing, essentially. Viral marketing as people doing the marketing are companies and governments.

    It’s really good at finding vulns in vibe coded stuff from Claude.. because apparently AI must be both the cause and solution to all life’s problems, like beer.

    bontchev@infosec.exchangeB This user is from outside of this forum
    bontchev@infosec.exchangeB This user is from outside of this forum
    bontchev@infosec.exchange
    wrote last edited by
    #27

    @GossiTheDog Can you run it on my honeypots to see if it finds anything worthwhile?

    Link Preview Image
    Vesselin Bontchev · GitLab

    Computer anti-virus researcher

    favicon

    GitLab (gitlab.com)

    (Basically, any repo there that has "honey" or "pot" in the name.)

    1 Reply Last reply
    0
    • bplein@bvp.meB bplein@bvp.me

      @GossiTheDog My first hot take to “We are not releasing Mythos because it’s too good” was that they were hiding something. Or they needed to convince large companies that it was sooooo good that they better pony up. “You’ve never had coke this pure, not sure it’s safe to sell it to you.”

      ozu@infosec.exchangeO This user is from outside of this forum
      ozu@infosec.exchangeO This user is from outside of this forum
      ozu@infosec.exchange
      wrote last edited by
      #28

      @bplein @GossiTheDog CISOs suched it up like no tomorrow. Every day I have to listen my bosses how utterly powerful Mythos is and we need some AI tool to counter it.
      On the other hand they're surprised that all sorts of low level shit walks through our perimeter. I have to keep repeating we need zero-trust but nothing gets done.

      ✅ Spending money on shiny expensive AI tool
      ❌ Implementing free zero-trust policies

      1 Reply Last reply
      0
      • R relay@relay.an.exchange shared this topic
      • zzt@mas.toZ zzt@mas.to

        @GossiTheDog mythos has found at least one critical vulnerability: the infosec industry is utterly vulnerable to hype, and extremely unlikely to examine the origins or methodology behind vulnerability disclosures that authorities (regardless of their poor reputation) claim are earth-shatteringly critical

        drew@social.freebitcoin.gayD This user is from outside of this forum
        drew@social.freebitcoin.gayD This user is from outside of this forum
        drew@social.freebitcoin.gay
        wrote last edited by
        #29

        @zzt @GossiTheDog anyone who was paying attention already knew that, though. The security circus is nothing new, it's the inevitable result of the primary talent pool for infosec being obnoxious teenage skiddies swapping 31337 h4x0r reputation points in exchange for vulnerabilities of widely varying credibility

        drew@social.freebitcoin.gayD gossithedog@cyberplace.socialG 2 Replies Last reply
        0
        • drew@social.freebitcoin.gayD drew@social.freebitcoin.gay

          @zzt @GossiTheDog anyone who was paying attention already knew that, though. The security circus is nothing new, it's the inevitable result of the primary talent pool for infosec being obnoxious teenage skiddies swapping 31337 h4x0r reputation points in exchange for vulnerabilities of widely varying credibility

          drew@social.freebitcoin.gayD This user is from outside of this forum
          drew@social.freebitcoin.gayD This user is from outside of this forum
          drew@social.freebitcoin.gay
          wrote last edited by
          #30

          @zzt @GossiTheDog see also heartbleed and the endless circus brand-and-logo vulnerabilities afterwards, stuff like the grsec nonsense, etc, going back as far as you care to look.

          1 Reply Last reply
          0
          • drew@social.freebitcoin.gayD drew@social.freebitcoin.gay

            @zzt @GossiTheDog anyone who was paying attention already knew that, though. The security circus is nothing new, it's the inevitable result of the primary talent pool for infosec being obnoxious teenage skiddies swapping 31337 h4x0r reputation points in exchange for vulnerabilities of widely varying credibility

            gossithedog@cyberplace.socialG This user is from outside of this forum
            gossithedog@cyberplace.socialG This user is from outside of this forum
            gossithedog@cyberplace.social
            wrote last edited by
            #31

            @drew @zzt the scale of this is new, though. It's gone from annoying people to annoying corporations hijacking governments.

            1 Reply Last reply
            0
            • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

              Mythos is not great btw. Running it over a bunch of code, it’s similar findings to tools from a few years ago. It’s marketing, essentially. Viral marketing as people doing the marketing are companies and governments.

              It’s really good at finding vulns in vibe coded stuff from Claude.. because apparently AI must be both the cause and solution to all life’s problems, like beer.

              erraggy@hachyderm.ioE This user is from outside of this forum
              erraggy@hachyderm.ioE This user is from outside of this forum
              erraggy@hachyderm.io
              wrote last edited by
              #32

              @GossiTheDog
              Really not fair to beer 🍻

              1 Reply Last reply
              0
              • krutonium@social.treehouse.systemsK krutonium@social.treehouse.systems

                @GossiTheDog Beer, and Super Glue.

                nihilistic_capybara@layer8.spaceN This user is from outside of this forum
                nihilistic_capybara@layer8.spaceN This user is from outside of this forum
                nihilistic_capybara@layer8.space
                wrote last edited by
                #33

                @krutonium @GossiTheDog but never together

                1 Reply Last reply
                0
                • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                  Mythos is not great btw. Running it over a bunch of code, it’s similar findings to tools from a few years ago. It’s marketing, essentially. Viral marketing as people doing the marketing are companies and governments.

                  It’s really good at finding vulns in vibe coded stuff from Claude.. because apparently AI must be both the cause and solution to all life’s problems, like beer.

                  se38@nrw.socialS This user is from outside of this forum
                  se38@nrw.socialS This user is from outside of this forum
                  se38@nrw.social
                  wrote last edited by
                  #34

                  @GossiTheDog

                  Link Preview Image
                  1 Reply Last reply
                  0
                  • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                    Mythos is not great btw. Running it over a bunch of code, it’s similar findings to tools from a few years ago. It’s marketing, essentially. Viral marketing as people doing the marketing are companies and governments.

                    It’s really good at finding vulns in vibe coded stuff from Claude.. because apparently AI must be both the cause and solution to all life’s problems, like beer.

                    d0gb3r7@mastodon.socialD This user is from outside of this forum
                    d0gb3r7@mastodon.socialD This user is from outside of this forum
                    d0gb3r7@mastodon.social
                    wrote last edited by
                    #35

                    @GossiTheDog found the beer baron!

                    1 Reply Last reply
                    0
                    • em0nm4stodon@infosec.exchangeE em0nm4stodon@infosec.exchange shared this topic
                    • skydotbit@sharkey.skydevs.meS skydotbit@sharkey.skydevs.me

                      @GossiTheDog@cyberplace.social @Standard_Phil@infosec.exchange @zzt@mas.to Mythos did find that recent ActivityPub vulnerability which is interesting. I’m not trying to shill it or anything I just think it’s interesting

                      https://w.on-t.work/activitypub/may-2026-vulnerability#the-ellephamt-in-the-room

                      womble@infosec.exchangeW This user is from outside of this forum
                      womble@infosec.exchangeW This user is from outside of this forum
                      womble@infosec.exchange
                      wrote last edited by
                      #36

                      @skydotbit in order for that to be interesting or useful information, there'd need to be some indication that other models, or similarly resourced humans, would be incapable of finding the same vulnerability. All credible evidence so far is akin to my being able to find things in my kid's bedroom that they couldn't: it's not that I'm a magical finding things machine, it's just that they never looked.

                      @GossiTheDog @Standard_Phil @zzt

                      1 Reply Last reply
                      1
                      0
                      • R relay@relay.infosec.exchange shared this topic
                        R relay@relay.mycrowd.ca shared this topic
                      • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                        Mythos is not great btw. Running it over a bunch of code, it’s similar findings to tools from a few years ago. It’s marketing, essentially. Viral marketing as people doing the marketing are companies and governments.

                        It’s really good at finding vulns in vibe coded stuff from Claude.. because apparently AI must be both the cause and solution to all life’s problems, like beer.

                        freddy@social.security.plumbingF This user is from outside of this forum
                        freddy@social.security.plumbingF This user is from outside of this forum
                        freddy@social.security.plumbing
                        wrote last edited by
                        #37

                        @GossiTheDog We found it really really capable when running in our harness with deterministic bug validation. Did you run it from within claude code?

                        1 Reply Last reply
                        0
                        Reply
                        • Reply as topic
                        Log in to reply
                        • Oldest to Newest
                        • Newest to Oldest
                        • Most Votes


                        • Login

                        • Login or register to search.
                        • First post
                          Last post
                        0
                        • Categories
                        • Recent
                        • Tags
                        • Popular
                        • World
                        • Users
                        • Groups