By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: Mythos only finds a vulnerability in curl
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Software > Mythos only finds a vulnerability in curl
Software

Mythos only finds a vulnerability in curl

News Room
Last updated: 2026/05/12 at 9:31 AM
News Room Published 12 May 2026
Share
Mythos only finds a vulnerability in curl
SHARE

Anthropic’s AI model Claude Mythos Preview is considered too dangerous for the public, at least that’s the reason the company gives as to why there is only limited access to this sophisticated AI vulnerability search. Selected users and projects were allowed to test Mythos – including Daniel Stenberg, maintainer of the download tool curl. Mythos found it exactly once.

Read more after the ad

The test run is surprising, because at the beginning of the year the curl maintainer was complaining about “shit reports” in the form of AI bug reports and was already “fed up” with them a year ago. In the meantime, he even discontinued the bug bounty program on HackerOne, only to eventually return there because bug management works better with it than with GitHub, for example.

As part of the Glasswing project, Stenberg was to be given access. After hiccups during setup, a third party took over the test using the curl sources, Stenberg writes in his blog.

curl: Well hung code

Stenberg points out that they have of course already examined curl with several different and capable AI tools – as an addition to “normal” static code analysis tools, setting very selective compiler options or using fuzzing for years. With these tools, around 200 to 300 bugs have been discovered in the past eight to ten months and associated bug fixes have been merged into curl. A bunch of these reports are confirmed vulnerabilities and have received CVE entries.

Developers also use tools like GitHub’s Copilot and Augment Code to review pull requests. Their comments and findings help to improve the code and avoid merging errors. This still happens, but the review bots would regularly highlight problems that the programmers would then fix. Stenberg’s point here is that AI reviews are used as an adjunct to human reviews; they only help and do not replace people. He now sees a high volume of high-quality security reports flooding the project, and IT security researchers are now using AI comprehensively and effectively.

The scan with Mythos spit out five findings in the report, Stenberg continues. They would have expected more. He and his security team then poked around the reported problems for a few hours and arrived at a confirmed vulnerability. Of the other four, three were false positives – these were already explained in the API documentation – and in the fourth the programmers came to the conclusion that it was just a bug.

Read more after the ad

Stenberg happily continues that the remaining security vulnerability will receive a CVE entry with a severity level of “low”. It will be closed in curl 8.21.0 at the end of June. Those interested can find further classifications and details as well as further information from the Mythos report in Stenberg’s blog entry. In the end, Stenberg remains conciliatory. The AI ​​has now become significantly better and is actually a helpful tool.


(dmk)



Unfortunately, this link is no longer valid.

Links to gifted items will be invalid if they are older than 7 days or have been accessed too often.


You need a heise+ package to read this article. Try it now for a week without obligation – without obligation!

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Science explains why your brain prefers paper to keyboard to learn Science explains why your brain prefers paper to keyboard to learn
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Science explains why your brain prefers paper to keyboard to learn
Science explains why your brain prefers paper to keyboard to learn
Gaming
This column is too dangerous to read
This column is too dangerous to read
News
Infostealer on AI platform Hugging Face disguises itself as an OpenAI repository
Infostealer on AI platform Hugging Face disguises itself as an OpenAI repository
Software
after 16 road accidents, this Tesla competitor is the target of an investigation
after 16 road accidents, this Tesla competitor is the target of an investigation
Mobile

You Might also Like

Infostealer on AI platform Hugging Face disguises itself as an OpenAI repository
Software

Infostealer on AI platform Hugging Face disguises itself as an OpenAI repository

4 Min Read
Supply chains in the spotlight: Shein and Temu litigation
Software

Supply chains in the spotlight: Shein and Temu litigation

4 Min Read
Swiss health data: Confederates against US cloud dominance
Software

Swiss health data: Confederates against US cloud dominance

4 Min Read
RCS catches up with iMessage: Apple provides iOS 26.5
Software

RCS catches up with iMessage: Apple provides iOS 26.5

4 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?