Discussion summary

Recent vulnerabilities surged around the release of Claude Mythos Preview, sparking debate on whether LLMs are better at finding bugs or if increased usage causes more vulnerabilities. Some see this as a positive for software quality, while others note it may be influenced by external factors like geopolitical events.

What the discussion says

  • LLMs may be better at finding vulnerabilities.
  • Increased use of LLMs could lead to more vulnerabilities.
  • Vulnerability patches also increased, indicating more bug discovery.
  • Some see this as a sign of improved software security.
  • Others suggest external factors like geopolitical tensions may influence these spikes.
“It's almost like... Finding bugs is a good thing.”
— nullbio
“Poor quality software gets outed and maybe fixed.”
— 6d7770

Join the discussion

Write your take first — we'll ask for email only when you're ready to publish.

  • Hacker News
  • So basically there are two plausible explanations:

    1. Someone with early access to Mythos leaked it to the bad guys.

    2. Cybercriminals are getting enough mileage out of alternatives to Mythos to create exploits far more quickly, even though they don't have access to Mythos.

    My own guess is that it's a combination of #2 plus vibe-coding degrading software quality at multiple layers, open the door to sophisticated exploits, but I have no insider access to Mythos so am just guessing. Maybe someone with Mythos access might say why they think this vulnerability spike happened when it did.

  • Maybe a bit of both Mythos helping find bugs and engineers relying on AI shipping more bugs. Both can be true.
  • I predict once the responsible disclosure period is up we will see a lot more
  • How are these reports verified to be valid? If there are too many some could be hallucinations too.
  • This is hardly news? We've known for months that a flood of AI-assisted vulnerabilities was coming; I posted on Twitter in March calling 2026 the year of a million CVEs: https://x.com/i/status/2035045573116789002
  • I do maintain dozens of C/C++/Perl projects. I got massive amounts of new good vulnerability reports, more than with the latest fuzzing waves. Fuzzing is still the majority overall, but Opus dominates now. Haven't got any Mythos/Fable vuln yet. And with the help of Sonnet/DeepSeek I can finally get around and weed out all the still existing fuzzing bugs. It has nothing to do with Mythos for me, just people getting Anthropic Max accounts.

    And CVE's: People actually do that now, which before they didn't. Github allowing it now, certainly does help massively. This is a good thing

  • One of the major differences between Amodei’s and Hagseth’s views is that Hagseth said that in their world they don’t distinguish between “defensive” and “offensive” capabilities.

    In other words, a weapons missle defense system is equivalent to an attack one.

    I think that applying this thinking to software is a mistake. A lot of commercial software uses open source libraries under the hood, and and while the large corporations might have access to Mythos/Fable/gpt 5.6, the open source library maintainers typically don’t. That leaves them vulnerable to foreign adversaries who do have access to AI models. Attackers don’t need Mythos-level capability then, they just need to outperform whatever the maintainers are using.

    Which means that Anthropic’s decision to restrict security research on even Sonnet makes that gap (and thus an attackers opportunity) even larger.

    I say this as a coder who wants to release some of my internal libraries to open source. The risk now is that I open up my own products (which use those libraries) to vulnerability scanners while not having those kinds of detection methods myself. This, it’s safer to not release and keep internal than to risk increasing my own attack risk.

    Hopefully we will come to see that software is not equivalent to missle defense — writing safe code is different than attacking others’.

Explore Birbla archives