this post was submitted on 23 Apr 2026
73 points (95.1% liked)
Programming
26625 readers
188 users here now
Welcome to the main community in programming.dev! Feel free to post anything relating to programming here!
Cross posting is strongly encouraged in the instance. If you feel your post or another person's post makes sense in another community cross post into it.
Hope you enjoy the instance!
Rules
Rules
- Follow the programming.dev instance rules
- Keep content related to programming in some way
- If you're posting long videos try to add in some form of tldr for those who don't want to watch videos
Wormhole
Follow the wormhole through a path of communities !webdev@programming.dev
founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
I'm a bit confused because the quotes do seem to do Mythos quite a bit of justice here. Saying it is essentially the equivalent of an elite security researcher seems... good, right?
Isn't the threat that's being discussed "what if anyone could point this at anything and then actively exploit the things it finds"?
Much of Lemmy is ideologically against AI, so it is difficult to have rational conversation about the topic here.
Yes, for many enterprises, an "automated security researcher" is likely to be quite useful... and by the same measure, likely to be dangerous in the wrong hands. People attempting to pounce on this as some sort of gotcha mostly havent engaged beyond the headline.
The article does not.
It states that logs indicate that the LLM was pointed at known bugs and reproduced known bug reports.
For FreeBSD, they state that the logs indicate that it was hand-guided to known issues.
For firefox, they ran it in a sandbox with most of Firefox's security disabled/stripped out.
It states that Mythos found no zero days.