anthropics mythos has
|

How Anthropic’s Mythos has rewritten Firefox’s approach to cybersecurity

When Anthropic unveiled its new Mythos model in April, it also delivered a stern warning to anyone developing software. The model was so powerful at sniffing out software vulnerabilities, the lab claimed, that it had discovered thousands of high-severity bugs that would need to be fixed before it could be made public.

Now, security researchers for Mozilla’s Firefox browser are providing a closer look at what that process has looked like in practice, and what Mythos’ powers mean for software security at large.

In a post published on Thursday, Mozilla said Mythos has unearthed a wealth of high-severity bugs, including some that had lain dormant in the code for more than a decade.

That’s a significant improvement from what AI security tools were capable of even six months ago. Until now, AI bug-finding tools have come with severe drawbacks, often inundating security teams with low-quality reports and false positives. But Mozilla’s researchers say the latest generation of tools have turned a corner, particularly now that agentic systems can assess their own work and filter out bad results.

“It is difficult to overstate how much this dynamic changed for us over a few short months,” the researchers wrote. “First, the models got a lot more capable. Second, we dramatically improved our techniques for harnessing these models.”

Image Credits:Firefox

The results are striking: In April 2026, Firefox shipped 423 bug fixes, compared to just 31 exactly a year earlier. The researchers have also published details on 12 of the bugs, which range from a pair of unusual sandbox vulnerabilities, to a 15-year-old error in how the browser parses an HTML element.

“These things are actually just suddenly very good,” Brian Grinstead, a distinguished engineer at Mozilla, told TechCrunch. “We see that on our own internal scanning, we see that on external bug reports, and we see that in all sorts of signals across the industry.”


The fact that the system helped reveal vulnerabilities in Firefox’s “sandbox” system is particularly impressive, given how intricate an attack that exploits it needs to be. To find sandbox vulnerabilities, the model must write a compromised patch for the browser, then attack the most secure part of the software with the new code implemented. Finding and demonstrating the bug is a delicate, multi-step process, requiring both creativity and close attention. 

To put this into context, Mozilla’s bug bounty program pays researchers who can find a bug in Firefox’s sandbox up to $20,000 — the highest reward available. Despite the top-dollar bounty, however, Grinstead says Mythos is finding more sandbox issues than human researchers ever did. “We do get them,” he told TechCrunch, “but not at the volume that we are able to find with this technique.”

Notably, the Firefox team still isn’t using AI to fix the bugs, despite well-documented progress in AI coding tools. The team does ask AI to code up patches for each bug, but the resulting code usually can’t be deployed directly, and instead serves as a model for a human engineer.

“For the bugs we’re talking about in this post, every single one is one engineer writing a patch and one engineer reviewing it,” Grinstead says. “We have not found it to be automatable.”

It’s still not clear how AI’s emerging capabilities will change the broader balance of power in cybersecurity. One month since Mythos was previewed, most of the bugs discovered likely haven’t been patched, which makes it hard to capture the full scope of their impact. Anthropic has been scrupulous about following responsible disclosure norms, but it’s likely bad actors are using similar techniques behind the scenes, even if the models they’re using aren’t quite as good.

Speaking at a recent event, Anthropic CEO Dario Amodei was optimistic that the new tools would ultimately favor defenders. “If we handle this right, we could be in a better position than we started, because we fixed all these bugs. There are only so many bugs to find,” Amodei said. “So I think there’s a better world on the other side of this.”

Having dealt with the gritty details, Grinstead has a more measured view: “It’s useful for both attackers and defenders, but having the tool available shifts the advantage a little bit to defense. Realistically, nobody knows the answer to this yet.”

Similar Posts

  • | |

    The Sham Shaman

    In 1968, a graduate student in anthropology at the University of California, published a book that would reshape the publishing world. Titled The Teachings of Don Juan: A Yaqui Way of Knowledge. The book purported to be a faithful academic field report by Carlos Castaneda detailing his apprenticeship under an elderly Yaqui shaman named Don Juan Matus in the Mexican desert. Castaneda’s account became an overnight sensation as it blended desert mysticism, hallucinogenic plant rituals, and philosophical paradoxes. It sold millions of copies, earning him a doctorate from UCLA. This success made him a guru to icons like Bob Dylan, John Lennon, and Octavio Paz. A Life Built on Fabrications Long before he wrote about desert sorcery, Castaneda had mastered the art of reinventing himself. Born César Carlos Salvador Arana in Peru in 1925—the son of a humble watchmaker—he routinely rewrote his origin story. He claimed to have been born in Brazil, shaved years off his age, and concocted wild tales of fighting as a soldier in North Korea or working as a border spy. In reality, he fled Peru after fathering a child at thirteen, eventually making his way to Los Angeles in the 1950s. Ground-breaking Anthropological Discoveries. Yet beneath the celebrated field notes lay one of the most audacious literary fabrications in modern history. Don Juan Matus was not a real person. The desert apprenticeships never took place. Castaneda was not a devoted field researcher. He was a master illusionist who deceived prestigious academics and eager seekers alike. When Castaneda enrolled at UCLA, he found an academic environment eager for authentic indigenous wisdom and existential insight. Synthesizing disparate ideas into a singular narrative, he assembled Don Juan’s philosophical worldview by freely borrowing from European philosophy, Buddhist theology, ethnomethodology, and popular horror fiction. To his impressionable professors, the resulting texts appeared to be ground-breaking anthropological discoveries. Unraveling the Hoax While Castaneda’s books topped bestseller lists throughout the late 1960s and 1970s, critical cracks in his story soon began to widen into chasms. Skeptical researchers and anthropologists began scrutinizing the timeline and claims in his field notes. Archive Contradictions: UCLA library records revealed that on dates Castaneda claimed to be in the Sonoran desert learning shamanic secrets, he was actually signed into the university library reading room. Botanical and Cultural Errors: Experts on Yaqui culture noted that the spiritual concepts and language attributed to Don Juan bore almost no resemblance to authentic Yaqui traditions or language structures. Philosophical Echoes: Literary sleuths discovered that Don Juan’s most profound dialogues were near-verbatim adaptations of modern academic sociology and Western philosophical texts. Despite being systematically exposed by critics, Castaneda maintained his mystique. He avoided photo shoots, refused interviews, and cultivated an aura of secretive invulnerability. He also assured his devotees that any perceived discrepancies were simply part of a sorcerer’s duty to erase his personal history. The Guru’s Reclusive Cult and Legacy As public acclaim gave way to scholarly embarrassment, Castaneda retreated further into reclusiveness. In the 1990s, he launched a movement called Tensegrity. He promoted a series of physical movements he claimed were ancient Toltec magical passes. Critics quickly noted their striking resemblance to modern martial arts taught by a local Santa Monica instructor. Surrounding himself with a inner circle of devout disciples in Los Angeles, Castaneda governed his group with increasing paranoia until his death from cancer in 1998. Anthropology’s Ultimate Trickster Ultimately, Carlos Castaneda remains a complex figure in cultural history. His anthropological credentials were exposed as entirely fraudulent. His writings captured the yearning of an era desperate for spiritual transcendence beyond traditional structures. He stands as anthropology’s ultimate trickster. He’s a man who turned a fictional thesis into a million-dollar empire and proved that, given the right narrative, millions of people will gladly step through the looking glass.

Leave a Reply

Your email address will not be published. Required fields are marked *