In six weeks, Claude Mythos found vulnerabilities in Palo Alto Networks' code that would have taken five to seven years to find using traditional methods, at a cost in the low millions.
Nikesh Arora reveals that Palo Alto Networks tested Anthropic's Claude Mythos on their codebase and found vulnerabilities in six weeks that would normally take five to seven years, at a cost of just a few million dollars.
transcript
Nikesh Arora: Mythos has shown us that all the bad code that humans have written over the last 50 years can be assessed by AI and shown. The vulnerabilities can be shown. We tested for six weeks, and in six weeks we found what would have taken us five to seven years. ... In 6 weeks, we found vulnerabilities which would have normally taken us five to seven years to find. ... If you put it on ultra mode, which is persistent thinking, so it keeps trying until it gets an answer, you can actually daisy chain vulnerabilities, i.e. finding a new attack path into your vulnerabilities. Now, we pride ourselves as a top percentile of companies that test our code because we're in cybersecurity business. If you take that and compound that across all the companies that exist in the world that write their own code or the 10 million developers write code, this thing is going to find stuff which would have taken us 10 years to find. ... No, it was in the low millions.
extends · 1