When Anthropic unveiled its new Mythos mannequin in April, it additionally delivered a stern warning to anybody creating software program. The mannequin was so highly effective at sniffing out software program vulnerabilities, the lab claimed, that it had found hundreds of high-severity bugs that may have to be mounted earlier than it might be made public.
Now, safety researchers for Mozillaβs Firefox browser are offering a more in-depth take a look at what that course of has seemed like in follow, and what Mythosβ powers imply for software program safety at giant.
In a put up revealed on Thursday, Mozilla mentioned Mythos has unearthed a wealth of high-severity bugs, together with some that had lain dormant within the code for greater than a decade.
Thatβs a big enchancment from what AI safety instruments have been able to even six months in the past. Till now, AI bug-finding instruments have include extreme drawbacks, typically inundating safety groups with low high quality experiences and false positives. However Mozillaβs researchers say the most recent technology of instruments have turned a nook, notably now that agentic programs can assess their very own work and filter out unhealthy outcomes.
βIt’s tough to overstate how a lot this dynamic modified for us over a number of quick months,β the researchers wrote. βFirst, the fashions bought much more succesful. Second, we dramatically improved our methods for harnessing these fashions.β
The outcomes are hanging: In April 2026, Firefox shipped 423 bug fixes, in comparison with simply 31 precisely a yr earlier. The researchers have additionally revealed particulars on 12 of the bugs, which vary from a pair of surprising sandbox vulnerabilities, to a 15-year-old error in how the browser parses an HTML aspect.
βThis stuff are literally simply immediately excellent,β Brian Grinstead, a distinguished engineer at Mozilla, instructed Trendster. βWe see that on our personal inside scanning, we see that on exterior bug experiences, and we see that in all types of alerts throughout the trade.β
Techcrunch occasion
San Francisco, CA
|
October 13-15, 2026
The truth that the system helped reveal vulnerabilities in Firefoxβs βsandboxβ system is especially spectacular, given how intricate an assault that exploits it must be. To seek out sandbox vulnerabilities, the mannequin should write a compromised patch for the browser, then assault probably the most safe a part of the software program with the brand new code carried out. Discovering and demonstrating the bug is a fragile, multi-step course of, requiring each creativity and shut consideration.Β
To place this into context, Mozillaβs bug bounty program pays researchers who can discover a bug in Firefoxβs sandbox as much as $20,000 β the best reward obtainable. Regardless of the top-dollar bounty, nonetheless, Grinstead says Mythos is discovering extra sandbox points than human researchers ever did. βWe do get them,β he instructed Trendster, βhowever not on the quantity that we’re capable of finding with this system.β
Notably, the Firefox staff nonetheless isnβt utilizing AI to repair the bugs, regardless of well-documented progress in AI coding instruments. The staff does ask AI to code up patches for every bug, however the ensuing code normally canβt be deployed straight, and as an alternative serves as a mannequin for a human engineer.
βFor the bugs weβre speaking about on this put up, each single one is one engineer writing a patch and one engineer reviewing it,β Grinstead says. βWe’ve not discovered it to be automatable.β
Itβs nonetheless not clear how AIβs rising capabilities will change the broader stability of energy in cybersecurity. One month since Mythos was previewed, many of the bugs found possible havenβt been patched, which makes it exhausting to seize the total scope of their affect. Anthropic has been scrupulous about following accountable disclosure norms, nevertheless itβs possible unhealthy actors are utilizing comparable methods behind the scenes, even when the fashions theyβre utilizing arenβt fairly nearly as good.
Talking at a current occasion, Anthropic CEO Dario Amodei was optimistic that the brand new instruments would in the end favor defenders. βIf we deal with this proper, we might be in a greater place than we began, as a result of we mounted all these bugs. There are solely so many bugs to seek out,β Amodei mentioned. βSo I feel thereβs a greater world on the opposite aspect of this.β
Having handled the gritty particulars, Grinstead has a extra measured view: βItβs helpful for each attackers and defenders, however having the instrument obtainable shifts the benefit a bit bit to protection. Realistically, no person is aware of the reply to this but.β
If you buy by way of hyperlinks in our articles, we could earn a small fee. This doesnβt have an effect on our editorial independence.





