
Anthropic’s Mythos announcement set off exactly the reaction you would expect: if models can now find serious bugs at scale, software security must be about to get much worse.
I think that reaction mixes up two things.
A bug is not automatically a vulnerability.
And even a vulnerability is not automatically exploitable.
That distinction matters even more in the agent era. AI is getting better at surfacing weird behavior in code. It can push edge cases, strange paths, and awkward combinations much faster than most human teams. That is not bad news. That is visibility.
[Read More]





