‘scraped the web and found the bugs’
https://www.youtube.com/watch?v=krayLBNiAx8&list=UU9rJrMVgcXTfa8xuMnbhAEA- video
https://pivottoai.libsyn.com/20261007-mythos-not-the-magical-ai-hacking-tool-after-all - podcast
time: 7 min 03 sec
The curl blog post claims that they fixed bunches of other vulnerabilities using AI before this.
Which is to say: even if you accept the questionable premise that AI is “good at finding software vulnerabilities” it doesn’t change anything. It’s not the end of the world. It’s essentially just another fuzzing technique. The low hanging fruit gets discovered and patched, and life goes on (just with more annoying chatbot spam than before).
I was trying to tell my coworkers this when Mythos was in the news but they were all freaking out about no software ever being secure ever again or something rather than at best a one time blip.
Exactly. People don’t understand how many webapp vulns there are out there, low hanging fruit that is pretty damn easy to find if you know how it works, because it’s fucking everywhere. Like reflected xss, once I figured it out, I checked random sites and it’s just fucking everywhere. Less so with good React apps these days, but even then, still everywhere.
It doesn’t mean the internet doesn’t work or that every app is immediately hacked. That XSS existed then, it exists now, and even if mythos finds it, doesn’t mean it gets exploited or even fixed for the next year.
People outside of directly knowing how xss works are super impressed by it, and the AI scam artists took advantage of that. It sells the product, makes it seem like some cyberpunk super hacker. It’s never been that huge of a deal or complex to find.
I mean, you might end up with some interesting ai boosted threat actors these days… But it’s not the end of the world. People were always doing weird shit. Things were always getting hacked. Nation state threat groups are probably just a bit more dangerous when they were already very dangerous in this respect.
Click the arrival link in the header if you skipped it. There are some great quotes in there and lots of sources.
Eleven of them were famously found and fixed by other people! In public, before this report even came out. They scraped the web and found the bugs.
I’m fucking shocked that it was just marketing! Shocked!





