@YafahEdelman: I continue to be surprised about how big of a deal Mythos (and co) have been to cybersecurity. Here's critical vulns fo…

X AI KOLs Following News

Summary

The article highlights the significant role of AI models like Mythos in cybersecurity, revealing a surge in critical vulnerabilities at Oracle and detailing AI-driven discovery efforts by Anthropic and OpenAI.

I continue to be surprised about how big of a deal Mythos (and co) have been to cybersecurity. Here's critical vulns found at Oracle over the past few years: https://epoch.ai/data/cve?view=graph&source=Oracle…
Original Article
View Cached Full Text

Cached at: 08/22/26, 09:29 AM

I continue to be surprised about how big of a deal Mythos (and co) have been to cybersecurity. Here’s critical vulns found at Oracle over the past few years: https://epoch.ai/data/cve?view=graph&source=Oracle…


Cyber Vulnerabilities

Source: https://epoch.ai/data/cve?view=graph&source=Oracle Data: CVE records come from the CVE Program’scvelistV5 repository. We process every published record from 2020 onward. The dates visualized on our explorer represent vulnerability publication dates, not discovery dates.

Severity: CVE severities are based on theCommon Vulnerability Scoring System(CVSS). CVSS assigns a score between 0 and 10, according to factors like the attack complexity, required privileges, the scope of the vulnerability, and more. These numeric scores are then assigned to severity categories as follows:

  • None: 0.0
  • Low: 0.1 - 3.9
  • Medium: 4.0 - 6.9
  • High: 7.0 - 8.9
  • Critical: 9.0 - 10.0

We default to using a CNA’s own assessment first, and fill in gaps with assessments from third parties (known as Authorized Data Publishers, or ADPs). If multiple CVSS versions are given, we default to v4.0, with fallback to v3.1, then v3.0. Records without one of these CVSS scores are counted as “Unknown.”

Reporting organizations (CNAs): Every CVE record is assigned by a CNA (CVE Numbering Authority) — typically the vendor of the affected product or a third-party security research organization. We count CVEs across all CNAs, but to keep the underlying data manageable we only break down individual counts for notable CNAs, with non-notable CNAs grouped into an “Other” category.

We consider a CNA notable if it is a vendor of widely-deployed software or hardware, or a major open-source project or foundation, and it maintains an active CVE program (we require at least 50 CVEs published since 2020). We include the following organizations in our list of notable CNAs:

  • Major vendors (17): Microsoft · Google · Apple · Adobe · Oracle · Cisco · IBM · Red Hat · Intel · AMD · NVIDIA · Qualcomm · Samsung · SAP · Amazon (AWS) · VMware (Broadcom) · GitHub (own products)
  • Open source (4): Linux · Mozilla · Apache · OpenSSL

Reporting practices vary substantially across organizations, creating noise. For instance, Linux became a CNA in February 2024 and subsequently began assigning CVEs for thousands of backported bug fixes, leading to a high number of reports in 2024 and 2025.

Individual records: Alongside the aggregates, we surface individual High and Critical severity CVEs from notable CNAs, each linking back to its official CVE record. See the “Table” view in the explorer above, or download our data at the link below.

Our explorer visualizes the announcement date ofClaude Mythos Preview(April 7, 2026), which coincided with a large jump in the number of new vulnerability reports. Anthropic claimed that Claude Mythos was capable of autonomous vulnerability discovery, andgave trusted partners access to the modelin order to harden their software. Mythos Preview was used to find bugs in software before the April 7th announcement, which may have contributed to an increased number of reports in the month before the announcement. As of May 22nd, Anthropic claimed that Mythos Preview had been used to identifymore than ten thousand high- or critical-severity bugs(not all of which had been publicly reported). Additionally, OpenAI has claimed that GPT-5.5 (released April 23) and GPT-5.5-cyber (May 7) are also capable of advanced cybersecurity tasks, and launched a similartrusted-partner programon May 7th, 2026.

Similar Articles

Mythos finds a curl vulnerability

Lobsters Hottest

Daniel Stenberg reports that Anthropic's Mythos AI model identified a vulnerability in curl, highlighting the growing role of advanced AI in security auditing while noting initial access hurdles via the Linux Foundation.