Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. #Mythos finds a #curl vulnerability

#Mythos finds a #curl vulnerability

Scheduled Pinned Locked Moved Uncategorized
mythoscurl
60 Posts 41 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • bagder@mastodon.socialB This user is from outside of this forum
    bagder@mastodon.socialB This user is from outside of this forum
    bagder@mastodon.social
    wrote last edited by
    #1

    #Mythos finds a #curl vulnerability

    yes, as in singular one.

    Link Preview Image
    Mythos finds a curl vulnerability

    yes, as in singular one. Back in April 2026 Anthropic caused a lot of media noise when they concluded that their new AI model Mythos is dangerously good at finding security flaws in source code. Apparently Mythos was so good at this that Anthropic would not release this model to the public yet but instead … Continue reading Mythos finds a curl vulnerability →

    favicon

    daniel.haxx.se (daniel.haxx.se)

    bagder@mastodon.socialB madduci@mastodon.socialM aristot73@infosec.exchangeA varpie@peculiar.floristV arcayr@gts.mischief.expertA 22 Replies Last reply
    0
    • bagder@mastodon.socialB bagder@mastodon.social

      #Mythos finds a #curl vulnerability

      yes, as in singular one.

      Link Preview Image
      Mythos finds a curl vulnerability

      yes, as in singular one. Back in April 2026 Anthropic caused a lot of media noise when they concluded that their new AI model Mythos is dangerously good at finding security flaws in source code. Apparently Mythos was so good at this that Anthropic would not release this model to the public yet but instead … Continue reading Mythos finds a curl vulnerability →

      favicon

      daniel.haxx.se (daniel.haxx.se)

      bagder@mastodon.socialB This user is from outside of this forum
      bagder@mastodon.socialB This user is from outside of this forum
      bagder@mastodon.social
      wrote last edited by
      #2

      My personal conclusion can however not end up with anything else than that the big hype around this model so far was primarily marketing. I see no evidence that this setup finds issues to any particular higher or more advanced degree than the other tools have done before Mythos. Maybe this model is a little bit better, but even if it is, it is not better to a degree that seems to make a significant dent in code analyzing.

      km@mastodon.babb.noK dotmavriq@social.dotmavriq.lifeD oots@infosec.exchangeO gnirre@mastodon.socialG redsakana@infosec.exchangeR 7 Replies Last reply
      0
      • bagder@mastodon.socialB bagder@mastodon.social

        #Mythos finds a #curl vulnerability

        yes, as in singular one.

        Link Preview Image
        Mythos finds a curl vulnerability

        yes, as in singular one. Back in April 2026 Anthropic caused a lot of media noise when they concluded that their new AI model Mythos is dangerously good at finding security flaws in source code. Apparently Mythos was so good at this that Anthropic would not release this model to the public yet but instead … Continue reading Mythos finds a curl vulnerability →

        favicon

        daniel.haxx.se (daniel.haxx.se)

        madduci@mastodon.socialM This user is from outside of this forum
        madduci@mastodon.socialM This user is from outside of this forum
        madduci@mastodon.social
        wrote last edited by
        #3

        @bagder thanks for this. It was really helpful to understand the hype around Mythos and also see that high quality in code matters a lot,especially if human driven

        1 Reply Last reply
        0
        • bagder@mastodon.socialB bagder@mastodon.social

          #Mythos finds a #curl vulnerability

          yes, as in singular one.

          Link Preview Image
          Mythos finds a curl vulnerability

          yes, as in singular one. Back in April 2026 Anthropic caused a lot of media noise when they concluded that their new AI model Mythos is dangerously good at finding security flaws in source code. Apparently Mythos was so good at this that Anthropic would not release this model to the public yet but instead … Continue reading Mythos finds a curl vulnerability →

          favicon

          daniel.haxx.se (daniel.haxx.se)

          aristot73@infosec.exchangeA This user is from outside of this forum
          aristot73@infosec.exchangeA This user is from outside of this forum
          aristot73@infosec.exchange
          wrote last edited by
          #4

          @bagder spectacular result! Huge congratulations to the entire team! Made my day 🙂

          1 Reply Last reply
          0
          • bagder@mastodon.socialB bagder@mastodon.social

            #Mythos finds a #curl vulnerability

            yes, as in singular one.

            Link Preview Image
            Mythos finds a curl vulnerability

            yes, as in singular one. Back in April 2026 Anthropic caused a lot of media noise when they concluded that their new AI model Mythos is dangerously good at finding security flaws in source code. Apparently Mythos was so good at this that Anthropic would not release this model to the public yet but instead … Continue reading Mythos finds a curl vulnerability →

            favicon

            daniel.haxx.se (daniel.haxx.se)

            varpie@peculiar.floristV This user is from outside of this forum
            varpie@peculiar.floristV This user is from outside of this forum
            varpie@peculiar.florist
            wrote last edited by
            #5

            @bagder That reinforces my suspicions that there was a breakthrough for security at the start of the year, and that the rest of the year will be more quiet.

            1 Reply Last reply
            0
            • bagder@mastodon.socialB bagder@mastodon.social

              My personal conclusion can however not end up with anything else than that the big hype around this model so far was primarily marketing. I see no evidence that this setup finds issues to any particular higher or more advanced degree than the other tools have done before Mythos. Maybe this model is a little bit better, but even if it is, it is not better to a degree that seems to make a significant dent in code analyzing.

              km@mastodon.babb.noK This user is from outside of this forum
              km@mastodon.babb.noK This user is from outside of this forum
              km@mastodon.babb.no
              wrote last edited by
              #6

              @bagder from my talks with people who had been given access to mythos in their org, they say it does find things which current tools miss, but also overlooks cases which current tools catch. so, yeah, to me it is "mostly marketing" combined with general FUD

              km@mastodon.babb.noK paco@infosec.exchangeP 2 Replies Last reply
              0
              • bagder@mastodon.socialB bagder@mastodon.social

                #Mythos finds a #curl vulnerability

                yes, as in singular one.

                Link Preview Image
                Mythos finds a curl vulnerability

                yes, as in singular one. Back in April 2026 Anthropic caused a lot of media noise when they concluded that their new AI model Mythos is dangerously good at finding security flaws in source code. Apparently Mythos was so good at this that Anthropic would not release this model to the public yet but instead … Continue reading Mythos finds a curl vulnerability →

                favicon

                daniel.haxx.se (daniel.haxx.se)

                arcayr@gts.mischief.expertA This user is from outside of this forum
                arcayr@gts.mischief.expertA This user is from outside of this forum
                arcayr@gts.mischief.expert
                wrote last edited by
                #7

                @bagder that "the size of curl" section is honestly incredible numbers.

                1 Reply Last reply
                0
                • km@mastodon.babb.noK km@mastodon.babb.no

                  @bagder from my talks with people who had been given access to mythos in their org, they say it does find things which current tools miss, but also overlooks cases which current tools catch. so, yeah, to me it is "mostly marketing" combined with general FUD

                  km@mastodon.babb.noK This user is from outside of this forum
                  km@mastodon.babb.noK This user is from outside of this forum
                  km@mastodon.babb.no
                  wrote last edited by
                  #8

                  @bagder but i have not asked them about exploit capabilities, though. there i cannot comment, and there it could be significantly better caps

                  1 Reply Last reply
                  0
                  • bagder@mastodon.socialB bagder@mastodon.social

                    #Mythos finds a #curl vulnerability

                    yes, as in singular one.

                    Link Preview Image
                    Mythos finds a curl vulnerability

                    yes, as in singular one. Back in April 2026 Anthropic caused a lot of media noise when they concluded that their new AI model Mythos is dangerously good at finding security flaws in source code. Apparently Mythos was so good at this that Anthropic would not release this model to the public yet but instead … Continue reading Mythos finds a curl vulnerability →

                    favicon

                    daniel.haxx.se (daniel.haxx.se)

                    viss@mastodon.socialV This user is from outside of this forum
                    viss@mastodon.socialV This user is from outside of this forum
                    viss@mastodon.social
                    wrote last edited by
                    #9

                    @bagder hah! i was right!

                    1 Reply Last reply
                    0
                    • bagder@mastodon.socialB bagder@mastodon.social

                      #Mythos finds a #curl vulnerability

                      yes, as in singular one.

                      Link Preview Image
                      Mythos finds a curl vulnerability

                      yes, as in singular one. Back in April 2026 Anthropic caused a lot of media noise when they concluded that their new AI model Mythos is dangerously good at finding security flaws in source code. Apparently Mythos was so good at this that Anthropic would not release this model to the public yet but instead … Continue reading Mythos finds a curl vulnerability →

                      favicon

                      daniel.haxx.se (daniel.haxx.se)

                      alterelefant@mastodontech.deA This user is from outside of this forum
                      alterelefant@mastodontech.deA This user is from outside of this forum
                      alterelefant@mastodontech.de
                      wrote last edited by
                      #10

                      @bagder
                      At least it works. It would have been quite a disaster if it found zero.

                      totoroot@ibe.socialT 1 Reply Last reply
                      0
                      • bagder@mastodon.socialB bagder@mastodon.social

                        #Mythos finds a #curl vulnerability

                        yes, as in singular one.

                        Link Preview Image
                        Mythos finds a curl vulnerability

                        yes, as in singular one. Back in April 2026 Anthropic caused a lot of media noise when they concluded that their new AI model Mythos is dangerously good at finding security flaws in source code. Apparently Mythos was so good at this that Anthropic would not release this model to the public yet but instead … Continue reading Mythos finds a curl vulnerability →

                        favicon

                        daniel.haxx.se (daniel.haxx.se)

                        johnnythan@tuebingen.networkJ This user is from outside of this forum
                        johnnythan@tuebingen.networkJ This user is from outside of this forum
                        johnnythan@tuebingen.network
                        wrote last edited by
                        #11

                        @bagder Would it be a good idea to take an older version, where you already know you (as humans) found (and fixed) a certain number of vulnerabilities and see if AI can spot those correctly?

                        The Idee beeing to really have a quality test? ("For Science" 😉 ).

                        Or are the all trained on your latest version already and that would invalidate that test?

                        bagder@mastodon.socialB 1 Reply Last reply
                        0
                        • johnnythan@tuebingen.networkJ johnnythan@tuebingen.network

                          @bagder Would it be a good idea to take an older version, where you already know you (as humans) found (and fixed) a certain number of vulnerabilities and see if AI can spot those correctly?

                          The Idee beeing to really have a quality test? ("For Science" 😉 ).

                          Or are the all trained on your latest version already and that would invalidate that test?

                          bagder@mastodon.socialB This user is from outside of this forum
                          bagder@mastodon.socialB This user is from outside of this forum
                          bagder@mastodon.social
                          wrote last edited by
                          #12

                          @johnnythan I agree that would be an interesting challenge for someone with time and tokens to burn

                          1 Reply Last reply
                          0
                          • bagder@mastodon.socialB bagder@mastodon.social

                            #Mythos finds a #curl vulnerability

                            yes, as in singular one.

                            Link Preview Image
                            Mythos finds a curl vulnerability

                            yes, as in singular one. Back in April 2026 Anthropic caused a lot of media noise when they concluded that their new AI model Mythos is dangerously good at finding security flaws in source code. Apparently Mythos was so good at this that Anthropic would not release this model to the public yet but instead … Continue reading Mythos finds a curl vulnerability →

                            favicon

                            daniel.haxx.se (daniel.haxx.se)

                            bagder@mastodon.socialB This user is from outside of this forum
                            bagder@mastodon.socialB This user is from outside of this forum
                            bagder@mastodon.social
                            wrote last edited by
                            #13

                            "Zero memory-safety vulnerabilities found." 💚

                            synlogic4242@social.vivaldi.netS 1 Reply Last reply
                            0
                            • bagder@mastodon.socialB bagder@mastodon.social

                              #Mythos finds a #curl vulnerability

                              yes, as in singular one.

                              Link Preview Image
                              Mythos finds a curl vulnerability

                              yes, as in singular one. Back in April 2026 Anthropic caused a lot of media noise when they concluded that their new AI model Mythos is dangerously good at finding security flaws in source code. Apparently Mythos was so good at this that Anthropic would not release this model to the public yet but instead … Continue reading Mythos finds a curl vulnerability →

                              favicon

                              daniel.haxx.se (daniel.haxx.se)

                              netresec@infosec.exchangeN This user is from outside of this forum
                              netresec@infosec.exchangeN This user is from outside of this forum
                              netresec@infosec.exchange
                              wrote last edited by
                              #14

                              @bagder LOL!

                              The report concluded it found five “Confirmed security vulnerabilities”. I think using the term confirmed is a little amusing when the AI says it confidently by itself. Yes, the AI thinks they are confirmed, but the curl security team has a slightly different take.

                              1 Reply Last reply
                              0
                              • bagder@mastodon.socialB bagder@mastodon.social

                                #Mythos finds a #curl vulnerability

                                yes, as in singular one.

                                Link Preview Image
                                Mythos finds a curl vulnerability

                                yes, as in singular one. Back in April 2026 Anthropic caused a lot of media noise when they concluded that their new AI model Mythos is dangerously good at finding security flaws in source code. Apparently Mythos was so good at this that Anthropic would not release this model to the public yet but instead … Continue reading Mythos finds a curl vulnerability →

                                favicon

                                daniel.haxx.se (daniel.haxx.se)

                                ireneista@adhd.irenes.spaceI This user is from outside of this forum
                                ireneista@adhd.irenes.spaceI This user is from outside of this forum
                                ireneista@adhd.irenes.space
                                wrote last edited by
                                #15

                                @bagder yessssssssss. we guessed right on the poll 😄

                                1 Reply Last reply
                                0
                                • bagder@mastodon.socialB bagder@mastodon.social

                                  #Mythos finds a #curl vulnerability

                                  yes, as in singular one.

                                  Link Preview Image
                                  Mythos finds a curl vulnerability

                                  yes, as in singular one. Back in April 2026 Anthropic caused a lot of media noise when they concluded that their new AI model Mythos is dangerously good at finding security flaws in source code. Apparently Mythos was so good at this that Anthropic would not release this model to the public yet but instead … Continue reading Mythos finds a curl vulnerability →

                                  favicon

                                  daniel.haxx.se (daniel.haxx.se)

                                  quinn@social.circl.luQ This user is from outside of this forum
                                  quinn@social.circl.luQ This user is from outside of this forum
                                  quinn@social.circl.lu
                                  wrote last edited by
                                  #16

                                  @bagder I suspect the question is, will it still be a worthwhile tool when the actual price to use the tool, not subsidized by anyone's war chest or VC, is revealed?

                                  kleisli@mastodon.socialK 1 Reply Last reply
                                  0
                                  • bagder@mastodon.socialB bagder@mastodon.social

                                    My personal conclusion can however not end up with anything else than that the big hype around this model so far was primarily marketing. I see no evidence that this setup finds issues to any particular higher or more advanced degree than the other tools have done before Mythos. Maybe this model is a little bit better, but even if it is, it is not better to a degree that seems to make a significant dent in code analyzing.

                                    dotmavriq@social.dotmavriq.lifeD This user is from outside of this forum
                                    dotmavriq@social.dotmavriq.lifeD This user is from outside of this forum
                                    dotmavriq@social.dotmavriq.life
                                    wrote last edited by
                                    #17
                                    @bagder Yes. While I can't prove it, it tracks with A stealing the playbook of O who already said that they will likely pivot from B2C into B2B. One last fear mongering push and tons of directed compute at reputable projects and suddenly your marketing far surpasses that of any benchmark.
                                    1 Reply Last reply
                                    0
                                    • bagder@mastodon.socialB bagder@mastodon.social

                                      #Mythos finds a #curl vulnerability

                                      yes, as in singular one.

                                      Link Preview Image
                                      Mythos finds a curl vulnerability

                                      yes, as in singular one. Back in April 2026 Anthropic caused a lot of media noise when they concluded that their new AI model Mythos is dangerously good at finding security flaws in source code. Apparently Mythos was so good at this that Anthropic would not release this model to the public yet but instead … Continue reading Mythos finds a curl vulnerability →

                                      favicon

                                      daniel.haxx.se (daniel.haxx.se)

                                      maniacata@mastodon.socialM This user is from outside of this forum
                                      maniacata@mastodon.socialM This user is from outside of this forum
                                      maniacata@mastodon.social
                                      wrote last edited by
                                      #18

                                      @bagder the power of rigorous software engineering 😄

                                      1 Reply Last reply
                                      0
                                      • bagder@mastodon.socialB bagder@mastodon.social

                                        #Mythos finds a #curl vulnerability

                                        yes, as in singular one.

                                        Link Preview Image
                                        Mythos finds a curl vulnerability

                                        yes, as in singular one. Back in April 2026 Anthropic caused a lot of media noise when they concluded that their new AI model Mythos is dangerously good at finding security flaws in source code. Apparently Mythos was so good at this that Anthropic would not release this model to the public yet but instead … Continue reading Mythos finds a curl vulnerability →

                                        favicon

                                        daniel.haxx.se (daniel.haxx.se)

                                        E This user is from outside of this forum
                                        E This user is from outside of this forum
                                        eskett@mstdn.social
                                        wrote last edited by
                                        #19

                                        @bagder not trying to buy into Anthropic's hype machine, but I wonder if curl is just a nonrepresentative code base. The average closed source / internal code base is probably worse in orders of magnitude when it comes to static checks, engineering principles, you name it.

                                        I suspect Mythos will be useful in making poor software a bit more secure. That could have been done without AI of course.

                                        bagder@mastodon.socialB 1 Reply Last reply
                                        0
                                        • E eskett@mstdn.social

                                          @bagder not trying to buy into Anthropic's hype machine, but I wonder if curl is just a nonrepresentative code base. The average closed source / internal code base is probably worse in orders of magnitude when it comes to static checks, engineering principles, you name it.

                                          I suspect Mythos will be useful in making poor software a bit more secure. That could have been done without AI of course.

                                          bagder@mastodon.socialB This user is from outside of this forum
                                          bagder@mastodon.socialB This user is from outside of this forum
                                          bagder@mastodon.social
                                          wrote last edited by
                                          #20

                                          @eskett I do emphasize that it is good at finding flaws. And so are many other models. So yes, they will certainly find many flaws in source code going forward. Mythos and the others.

                                          1 Reply Last reply
                                          0
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • World
                                          • Users
                                          • Groups