Post B6BSX3Cp5YBC9y3eQC by bagder@mastodon.social
 (DIR) More posts by bagder@mastodon.social
 (DIR) Post #B6BBjbuWBUle35tnxw by bagder@mastodon.social
       1 likes, 4 repeats
       
       #Mythos finds a #curl vulnerabilityyes, as in singular one.https://daniel.haxx.se/blog/2026/05/11/mythos-finds-a-curl-vulnerability/
       
 (DIR) Post #B6BBjcG8t6458A14fg by bagder@mastodon.social
       0 likes, 0 repeats
       
       "Zero memory-safety vulnerabilities found." šŸ’š
       
 (DIR) Post #B6BBjcOeNSs1YXzrvs by bagder@mastodon.social
       1 likes, 0 repeats
       
       My personal conclusion can however not end up with anything else than that the big hype around this model so far was primarily marketing. I see no evidence that this setup finds issues to any particular higher or more advanced degree than the other tools have done before Mythos. Maybe this model is a little bit better, but even if it is, it is not better to a degree that seems to make a significant dent in code analyzing.
       
 (DIR) Post #B6BSIbvViPXPV64ggC by johnnythan@tuebingen.network
       1 likes, 0 repeats
       
       @bagder Would it be a good idea to take an older version, where you already know you (as humans) found (and fixed) a certain number of vulnerabilities and see if AI can spot those correctly? The Idee beeing to really have a quality test? ("For Science" ;) ). Or are the all trained on your latest version already and that would invalidate that test?
       
 (DIR) Post #B6BSIc8GwxkK8g2sZU by bagder@mastodon.social
       1 likes, 0 repeats
       
       @johnnythan I agree that would be an interesting challenge for someone with time and tokens to burn
       
 (DIR) Post #B6BSK9kVRvmEglfFr6 by netresec@infosec.exchange
       1 likes, 0 repeats
       
       @bagder LOL!The report concluded it found five ā€œConfirmed security vulnerabilitiesā€. I think using the term confirmed is a little amusing when the AI says it confidently by itself. Yes, the AI thinks they are confirmed, but the curl security team has a slightly different take.
       
 (DIR) Post #B6BSLhS3d83rVLlsQa by quinn@social.circl.lu
       1 likes, 0 repeats
       
       @bagder I suspect the question is, will it still be a worthwhile tool when the actual price to use the tool, not subsidized by anyone's war chest or VC, is revealed?
       
 (DIR) Post #B6BSX33Ff8WVgHa0VE by gnirre@mastodon.social
       0 likes, 0 repeats
       
       @bagder How do you explain that Mythos found 271 bugs in Firefox, and counting, and only 1 in cURL. Is the Firefox code base 271  times larger?
       
 (DIR) Post #B6BSX3Cp5YBC9y3eQC by bagder@mastodon.social
       1 likes, 0 repeats
       
       @gnirre I do not explain that at all because I don't have enough knowledge to do so.
       
 (DIR) Post #B6BSXY7w7lgs3n0gbo by doragasu@mastodon.sdf.org
       1 likes, 0 repeats
       
       @bagder In line with what this blog post stated shortly after it was announced: the model is nothing special and much cheaper models can find the same bugs. Marketing BS turned to 11. https://www.flyingpenguin.com/the-boy-that-cried-mythos-verification-is-collapsing-trust-in-anthropic/