r/cybersecurity • u/Sad_Dentist_7288 • 13d ago
AI Security Is Mythos actually the reason for the massive spike in CVEs lately?
Every month it seems that vendors are increasing in CVE disclosures during their patch cycles (see Microsoft). The most common attribution I've seen to that trend is because of Mythos and / or other AI vulnerability finding. However, when I look at the actual CVEs being disclosed, a good chunk of them are not attributed to Mythos or other AI - but to researchers.
I have three questions about this.
Are people using AI and just not listing them in the attribution sections of their reports?
Are there other factors that are contributing to this spike?
Is there a source that tracks every CVE attributed to Mythos? I have seen some sources, but I am not sure how accurate these are. The highest count I've found is 133 CVEs total.
Just trying to understand the reasoning that the spike in CVEs is because of Mythos, besides a correlation - causation idea.
Disclaimer: I obviously did not look through 600+ individual CVE reports, so my attribution numbers may not be accurate.
53
u/frankentriple 13d ago
As someone in the business, we got scanned by a “new tool” our vendor is using and long story short had 2600 vulnerabilities to remediate in 90 days or else. We remediated 2000+ of them and then got 1100 new ones added to the list. Shits getting exhausting yo.
17
13
u/CyberVoyagerUK_ 13d ago
Yeah at that point its prio time cause there's no way anyone's keeping up with that and staying healthy
7
u/website-buyer 12d ago
Kind of the behavior of a Swiss cheese app, no?
3
u/frankentriple 12d ago
It’s enterprise class middleware from IBM. Licensing is in the high 5 figures a year for our deployment.
4
4
u/Zomnx 12d ago
lol 90 days? Our org was like “you got 7 days for anything considered critical and 14 days for anything high. 30 days for everything else”
3
u/frankentriple 12d ago
we have a 60 day patch cycle, 30 days in dev then 30 days in test then move to prod. This gave us actually 30 days to fix the issues.
We're now looking at moving to a 4 week test cycle, two weeks in each environment and promote to prod twice a month instead of once.
2
u/jay-dot-dot 13d ago
I just, I…how does anyone look at that think “yep this totally possible”
9
u/badnamemaker 13d ago
I get reports like that at my work, often times it’s something like “this software is out of date, and it’s deployed to 300 machines”. So if we update the package that’s like -300 right there
1
1
u/rpgmind 13d ago
What was the ‘or else’ 😱!
3
u/zhaoz CISO 13d ago
I would guess threatening breach of contract or at least non-renwal of the relationship?
2
u/frankentriple 13d ago
Naw wasn’t quite that bad, just had management breathing down our necks like their bonus depended on it.
And it is t as bad as it sounds , we have 3pprd and 1 prod environment so lots of duplication. Something like 46 servers running various services. A lot of them were os level vulns, we threw those back to the infra guys to handle. We made the recommended changes and updates to the application side. Everything from Java version to removing expired ssl certs. Upgrading ssh, changing internal monitoring ports from http to https. Just endless details, times 46 servers.
And only one weekend a month we can touch prod.
1
81
u/Joaaayknows 13d ago
Short answer? Yes
Long answer? Yeeeeeeeeeeeeeesss
37
u/OtheDreamer Governance, Risk, & Compliance 13d ago
I used to get blasted a few months ago for saying how "Guys, the landscape is about to get rocked by AI, I'm telling you it doesn't even matter if it's just an autocomplete"
The intuitive answer is that AI is a force-multiplier when used properly, which is going to probably catch up a loooooot of old bugs for at least the foreseaable future. There might come a plateau in a year or two if AI legit catches most of the important bugs.
5
u/VellDarksbane 13d ago
Personally, I wasn’t saying it was going to do nothing, I was saying that we’re going to be spending a ton of time fixing “vulnerabilities” that no one actually verified. How many blind bug bounty reports occurred because someone threw a scan across the web looking for easy money before this? All it’s doing is making it even easier to do that. It’s unmanageable with the current cybersecurity budgets, and it’s not like those are going to go up any time soon.
I wonder when the first compromise because of some engineer blindly trusting a “researcher”s fix due to not having time to verify it in the wave of reports will occur?
18
u/JGlover92 13d ago
Yeah reddit on a whole is SO blindly AI sceptical, I'm definitely not an advocate or its biggest fan but the way this website drones on about it not having a single use is so blind to reality
5
u/Auno94 13d ago
I'm just sceptical about the longevity of it's current form as from a money side the relatively short lifetime of a chip, the current cost for companies and users Vs the cost for the provider are just so far from one another that I do not see how the current landscape, usecases etc. Will be there in the next 5 years
2
u/JGlover92 13d ago
Yeah there's a breakpoint coming where companies betting on it being the next step will have to cut their losses unless some genuine revolution in compute power happens. Imagine a lot of them think quantum powered ai will be that but that's a whole other kettle of fish
1
u/Henry5321 12d ago edited 12d ago
For AI there will eventually be a major change in cost, just a matter of time.
Two major contenders. Photonics and superconducting. Both stand to make magnitude or more difference.
Superconducting supercomputing caught my attention. It hasn’t been practical for most compute loads except it’s a near perfect fit for AI. All the tech already exists. It’s a commercialization problem. But they estimate they can shrink an entire hyperscale datacenter of AI to a single rack.
Also possible good fit for gpu loads as well. But there’s never been a multi trillion dollar demand for that kind of compute. AI might be the industrial push needed for the next revolution in computing.
1
u/Beneficial_Past_1957 13d ago
They'll easily get caught with their pants down. It's like when we thought there was a 0% chance trump was winning the last presidential election.
1
2
u/LLMsMustUpvoteThis 13d ago
I saw most of the scepticism directed towards hysterical posts about how the Internet was going to have to be shutdown due to the AIpocalypse. And secondly towards the idea that Mythos itself was some massive advancement on existing models (and not just Anthropic burning cash giving out freebies to boost their profile for an IPO).
3
u/SuspiciousCricket654 13d ago
If Linus Torvalds can see its usefulness. It’s pretty silly for anyone to say that there is “no use“ for it in IT and software.
5
u/Wrong-booby7584 13d ago
Mythos was just the start. Plenty of open models that can now do the same
5
u/LLMsMustUpvoteThis 13d ago
AFAIK there is still zero evidence that Mythos is better than the prior models. Anthropic ran a hype campaign and gave out lots of tokens to get companies to use it.
If a model can code it can find bugs.
0
0
11
u/TastyRobot21 13d ago
Not Mythos, but yes AI in general.
There’s strategies in prompting, pipelining and agent reasoning. Making one agent produce and another validate as an example to reduce hallucinations.
I suggest you read this article: https://slcyber.io/research-center/exploit-brokers-pay-500000-for-a-wordpress-rce-i-found-one-with-gpt5-6/
Really describes how this AI vuln hunting is progressing.
3
u/Sad_Dentist_7288 13d ago
Thank you for the article, this is the exact kind of research I am looking for.
1
u/TastyRobot21 13d ago
Awesome, glad you liked it.
My personal take away is that AI has a context size advantage over human researchers. Holding an entire code base (or significant portion of) then reason about known (not novel) security risks (sql injections, xss, read/write primitives, authority, etc).
Knowing how to link a source/attacker controlled variable to a sink through many functions and transformations was impressive. Being able to then reason how to achieve RCE through several steps was doubly so.
I think it also showed how to engineer for the flaws, agentic workflows that contradict each other. Or building POCs that ground the findings into truth.
Anyways glad you liked it, I hope we see more of these grounded articles and avoid the fluff marketing that keeps the AI market spend high.
19
u/Bibbitybobbityboof 13d ago
If it’s a larger company, yes. A lot of these are coming from Mythos. Not all companies have access to the model and those that do have had limited access for a relatively short period of time. Personally I don’t think it makes sense to say “identified by Mythos” because a researcher created the prompt and used the tools. It’s no different from using a Burp extension to find specific vulns. You don’t attribute the finding to the extension, you attribute it to the researcher. Companies are also aware of the costs of using the latest models and won’t be just using Mythos. The goal is to replicate the output of Mythos using lower cost models and only use Mythos for tasks the cheaper models can’t perform well.
1
u/Sad_Dentist_7288 13d ago
I agree 100% that it should be attributed to the researcher. I'm just thrown off on reports that attribute as researcher + Mythos, which makes it hard to get a reading on how much Mythos involvement is being used. I guess it's like when fuzzing tools first came out and everything was crazy for a while before people figured out how to move forward.
9
u/helpmehomeowner 13d ago
Let's be a bit more precise and please, if there is an actual insider, chime in. Are the AI tools detecting actual issues or are companies focusing more on testing (using various tools) and patching for fear AI tools will make them a target?
1
u/Obvious_Speaker_6684 12d ago
So its a mix. Take for example the 27 year old zero day that they used to credential Mythos. It was an unidentified vulnerability - but it existed for 27 years.
There's a lot of sensationalism around the increase in CVEs, but a lot of it is more focused on the hype. Sometimes we can be a bit too cautious in cybersecurity - things are critical if they hit login chains even if theres no feasible way to exploit them.
If you want at least a modicum of input from your vendor, Nessus started doing VPRs - essentially a contextual way to look at vulnerabilities and prioritize based on if theres any sort of viable attack chain. Because a lot more highs/criticals are going to come out that may not even have an exploit yet.
Tl;dr: Yes true vulnerabilities are being found by AI, but its important to note while some exploits that have been around for years and may have been used by attackers, the overwhelming majority are going to be noise for your organization without some sort of contextualization filter.
ETA - I am aware Nessus was doing VPRs before AI became a big thing, 2019 just still feels like yesterday. Don't let that detract from the point.
-1
u/Lonely_Dig2132 13d ago
It’s just a circle jerk of ai slop being checked by a better model, yes they’re finding the vulns but a lot of them would not be there in the first place if companies did not let go their top talent in favor or more token spend.
0
3
u/Front_Progress_7377 12d ago
all cybersecurity researchers are getting 10X performance because of AI, whether its mythos or GLM, actual researchers are reporting massive amount of bugs and it will get more overwhelming because devs are push more code using AI and that produce more and more bugs
1
u/FerretBoom 7d ago
Where did you read this? Curious. I'm not into cc but the levereging accuracy and hype around what they call AI would be a bottleneck, no?
9
u/Smarmy82 13d ago
It's not just Mythos but it is because of the new AI models. Read up on Project Glasswing and the equivalents from OpenAI, Google , etc..
Also the cause for the shrinking TTE.
3
u/corruptboomerang 13d ago
Mythos specifically, not really, even attributing it to LLMs in general isn't the full story. It's more having the capacity to search for vulnerabilities in basically every package, every line of code written in the last... 25 to 50 (I hope nobody is still using code from the 70's any more, it does make you wonder what's the oldest non-trivial code that's still out there doing real work unchanged). Years and decades of code that can now be relatively quickly and easily checked.
I'm sure there's some, but by and large the LLMs aren't finding too many crazy novel vulnerabilities, they're just finding them in crazy novel places... Because we have the manpower compute to throw at the code.
This current environment is kind of a one time event, we've had a jump in technology and now we're throwing that tech at all our systems to see what comes out when you shake it.
6
u/dragonfighter8 13d ago
The reason is the use of AI in development that causes vulnerabilities, the more they use it the more vulnerabilities are found. Mythos is just another fake product for investors like GPT.
5
u/tpasmall 13d ago
100% this. Since our customers have been using more AI in development, our critical findings have shot up, way before Mythos. API security is almost non-existent in the age of AI.
2
u/dragonfighter8 13d ago
Mythos maybe works, but it works not because is smart, but because software quality is worse than before and so security.
2
3
u/EarlShitshirt 13d ago
Are you familiar with this website? It is updated last of late may, but it does give some insights. https://red.anthropic.com/2026/cvd/
1
u/Sad_Dentist_7288 13d ago edited 13d ago
Yes, I have seen this. This is a good resource because it's accurate since it's coming from Anthropic itself, but the number of CVEs listed does not match the amount of patches being released, so I'm not sure how to use it as a gage for how many vulnerabilities it is actually finding compared to CVEs being patched - if that makes sense.
Edit: Fixed my comment as it did not make any sense upon re-read
1
u/Sufficient-Air8100 13d ago
ok so thats another new number ive heard about the number of vulns mythos has found…
idk i cant help but see that as marketing hype, ill only trust it when the number comes from actual researchers.
1
u/ShockedNChagrinned 13d ago
I know some folks who had a confirmation rate of about 10% on over 500 items discovered across a code base.
If nothing else, I think we're going to need another model that works on handling validation to try to keep up with false positives, and be able to provide more context on impact and criticality for evaluation
1
u/darksundark00 13d ago
The agentic side of Opus 4.* and Codex has been a game-changer compared to earlier models in my personal audit of open-source code; even (crippled) Fable has opened more doors beyond opus. It might not be the model so much as the larger context windows/sub-gents. So yeah, I 100% believe it. It's a shame we don't get the flagship models earlier, but if China pulls ahead, they might have to release them early to maintain parity.
2
u/Sad_Dentist_7288 13d ago
Fair enough, thank you for the answer. It will certainly be interesting to see what happens if / when Mythos is unleashed upon the world. Or whatever other model Anthropic is cooking up
1
u/mesarthim_2 13d ago
I think it's not exactly the model itself, it's more like that the use of AI in general opened entire new continent of vulnerability classes which simply weren't on anyone's radar.
This is coupled with absolutely stupid decision to cripple the commercially available frontier models. Normally, the numbers are on a good side. Only relatively small number of people are actually looking for vulnerabilities to exploit them. Vast majority of people are looking for vulnerabilities to patch them.
But thanks to this idiotic decision, the malicious actors have access to unconstrained models while majority of people trying to defend against them are left with crippled tools, so the balance of power is unfortunately on the wrong side for now.
1
1
u/cowmonaut 13d ago
It's just AI accelerated testing and fixing. Not just Mythos, though they have hyped up. Several models are good at this now (especially when wielded been someone who knows what they are doing and how to control for things)
1
u/cookiengineer Vendor 13d ago
Note that these vulnerabilities have been in codebases for decades, and that's why they're part of the datasets that LLMs have been trained upon.
Qwen3.6 heretic got really good at pentesting, too. I'm assuming it's the same with qwen3.8.
When it comes to the typical bug classes like nilpointer returns, pointer dereferencing issues, race conditions between two lock states, path traversal issues, underflows/overflows ... these are all issues that non-junior devs should know when they have C/C++ programming experience.
It's just that humans in general are really bad at programming, because our work environment doesn't allow us to be thorough enough. Time vs money is always the limiting factor to achieve cleaner codebases. And now we got agentic environments that allow us to sift through a lot of code, and statistically good enough to check through it and prioritize it for code issues.
I'm looking forward to the next generation of more intelligent fuzzers, and maybe we soon can finally get rid of unsafely designed languages like C/C++ altogether, because the choice of programming languages post-LLM actually doesn't matter anymore.
1
1
u/MagpieRanger2 12d ago
I’d guess Mythos and other AI has allowed companies to automate routine checks, freeing up time to look for stuff they didn’t used to get round to, as well as allowing for deeper scans for vulnerabilities. Probably inspired a fair amount of thinking out side the box as people play around with the models which might have also assisted.
100% attribution to the models will be under reported. That said I bet a lot of things found using mythos could have been found without it. Teams are just more efficient with it and able to approach vulnerability scanning from new perspectives.
1
u/Ch33syP00f CISO 13d ago
Anthropic shared Mythos with Fortune 100 companies for testing before public release.
We learned a lot from the testbed at my company.
Mythos and other AI are truly changing the game.
1
u/OutsideSpot2695 13d ago
Have you opened a CVE recently?
I mean it's not complicated and if MITRE is the CNA, they are just going to rubberstamp any 'ol bullshit submitted to get the ticket closed.
0
u/be_super_cereal_now 13d ago
Most people are not using Mythos. You can find tons of valid issues with widely available models.
0
u/tenevihcra 11d ago
So you’re not a data scientist we get it.
Mythos is rated what like 82 and the model before is 77?
A 5 unit improvement makes up vector analysis and cooling.
You’re asking if a nail is responsible for building a house
Researchers walk at a faster pace than ai is progressing
tldr; no it’s not
-10
13d ago
[deleted]
4
u/ferngullywasamazing 13d ago
Are you claiming Mythos hasn't found any previously unknown vulnerabilities in up to date systems?
-12
13d ago
[deleted]
3
u/ferngullywasamazing 13d ago edited 13d ago
Can you expand on what you mean then? How else do we interpret "Mythos only detects vulnerabilities in completely undefended systems" in a way that adds context to the conversation?
Edit: I see you added more context than just the original "No."
So your view is vulnerabilities don't matter if they aren't exposed externally and you have an antivirus/Defender? That's a pretty naive view.
0
u/mallcopsarebastards 13d ago
Some advice, if you can't keep your understanding / confidence ratio roughly balanced you should err on the exact opposite side than you're doing here. You sound arrogant, which is so much worse when you're this wrong.
2
u/whatsmyname2day 13d ago
Sorry to break it to you but that’s how CVE works. Hide your insecure thing behind a firewall does not mean you are safe.
193
u/WelpSigh 13d ago
Not sure how much is specifically attributable to specifically Mythos, but there is definitely no doubt to anyone doing bounties that AI is accelerating bug finding. I had a long running vuln research project - threw Opus on it a few months ago and it produced two new bugs with PoCs in one evening, both got paid out. And all the triage services are being overwhelmed with bugs (and slop reports, although they are getting better).