Dawn of AI-Automated Vulnerability Discovery and Cybersecurity Industry Response
AI 안전 | Sun Jun 28 2026 00:00:00 GMT+0000 (Coordinated Universal Time) | 2 sources
Mass disclosure of 0-days via AI-based fuzzing and the emergence of Claude Mythos sparked discussions on cybersecurity industry response.
Analysis
[Anonymous GitHub Researcher (ashdfrkl)] mass-disclosed numerous 0-day vulnerabilities discovered via AI fuzzing [1]
- Automated fuzzing harness leveraging GPT-5.5-3-Codex-Spark
- Targeted major open-source projects including Ghidra
- libssh2
- FFmpeg
- and c-ares
- PoCs written manually
- READMEs generated by AI
- Demonstrated that effective discovery is possible without SOTA models given proper harnesses
[Anthropic Claude Mythos] released a model with expert-level automated cyberattack capabilities under restricted access [2]
- Initial release to 50 organizations via Project Glasswing
- later expanded to 150
- Launched alongside Fable 5 and soon withdrawn
- First model to succeed at expert-level tasks in UK AI Security Institute evaluation
- Achieved 'The Last One' full attack chain from reconnaissance to network takeover
[AI Security Institute (UK)] pointed out Mythos's limitations in real-world environments [2]
- Performance gap with GPT-5.4 and Opus 4.6 is incremental
- Benchmarks lack active defenders and defensive tools
- No penalty for triggering security alerts
- Disconnect from real enterprise environments with mature SOCs
[Cephalosec] recommended maintaining established security principles even in the post-Mythos era [2]
- Criticized Anthropic's dramatic PR marketing pattern
- Re-evaluated the significance of finding vulnerabilities in 27-year-old OpenBSD and 16-year-old FFmpeg
- Exploitability matters more than vulnerability identification
- Recommended maintaining existing defense systems rather than being swayed by FUD