‘scraped the web and found the bugs’
https://www.youtube.com/watch?v=krayLBNiAx8&list=UU9rJrMVgcXTfa8xuMnbhAEA- video
https://pivottoai.libsyn.com/20261007-mythos-not-the-magical-ai-hacking-tool-after-all - podcast
time: 7 min 03 sec
The curl blog post claims that they fixed bunches of other vulnerabilities using AI before this.
Which is to say: even if you accept the questionable premise that AI is “good at finding software vulnerabilities” it doesn’t change anything. It’s not the end of the world. It’s essentially just another fuzzing technique. The low hanging fruit gets discovered and patched, and life goes on (just with more annoying chatbot spam than before).
I was trying to tell my coworkers this when Mythos was in the news but they were all freaking out about no software ever being secure ever again or something rather than at best a one time blip.
I’m fucking shocked that it was just marketing! Shocked!
Click the arrival link in the header if you skipped it. There are some great quotes in there and lots of sources.
Eleven of them were famously found and fixed by other people! In public, before this report even came out. They scraped the web and found the bugs.





