AI Safety

Mythos Preview's AI vulnerability discovery: offense now, defense later

Mythos found 70-80% of severe bugs – but expect a bumpy 2026-2027

Deep Dive

A new analysis by tchauvin on LessWrong examines the cybersecurity implications of Mythos Preview's vulnerability discovery capabilities, which represent a paradigm shift from sparse to dense sampling. Historically, both attackers and defenders only covered a small fraction of the software attack surface (sparse sampling), favoring attackers due to low overlap. AI tools like Mythos Preview change this by enabling broad, easy scanning of entire codebases, moving toward dense sampling where defenders find nearly all vulnerabilities. The post estimates Mythos Preview already discovered 70-80% of severe vulnerabilities in the codebases it reviewed, largely by exploiting low-hanging fruit that previous methods missed. However, this progress does not immediately benefit end users, because most discovered vulnerabilities exist in already-shipped software that requires slow patch rollouts and faces legacy system constraints. The transition period (2026-2027) will be offense-dominant as attackers exploit known vulnerabilities before patches are applied. In the long run, as AI vulnerability discovery is integrated earlier in the software lifecycle, new code will ship with far fewer flaws, tilting the balance back to defense. The analysis also notes that exploitation remains offense-dominant in both offline and online contexts, except for a narrow defensive use case where developing exploits helps test defenses. Ultimately, the journey toward a more secure ecosystem will involve a rough ride before the benefits materialize.

Key Points
  • Mythos Preview likely found 70-80% of severe vulnerabilities in reviewed codebases, picking low-hanging fruit missed by fuzzing.
  • Transition to dense AI-driven vulnerability discovery will create a 2026-2027 vulnerability window due to slow patch rollouts.
  • Long-term, AI integrated pre-release will make new software nearly vulnerability-free, favoring defense over offense.

Why It Matters

Organizations face a two-year window of elevated risk before AI-driven defense outpaces attackers in software security.

📬 Get the top 10 AI stories daily