Slashdot

News for nerds, stuff that matters

Anthropic's Bug-Hunting Mythos Was Greatest Marketing Stunt Ever, Says cURL Creator

cURL creator Daniel Stenberg says Anthropic's hyped Mythos bug-hunting model found only one confirmed low-severity vulnerability in cURL, plus a few non-security bugs, after he expected a much longer list. He argues Mythos may be useful, but not meaningfully beyond other modern AI code-analysis tools. "My personal conclusion can however not end up with anything else than that the big hype around this model so far was primarily marketing," Stenberg said a blog post. "I see no evidence that this setup finds issues to any particular higher or more advanced degree than the other tools have done before Mythos." He went on to call Mythos "an amazingly successful marketing stunt for sure." The Register reports: Stenberg explained in a Monday blog post that he was promised access to Anthropic's Mythos model - sort of - through the AI biz's Project Glasswing program. Part of Glasswing involves giving high-profile open source projects access via the Linux Foundation, but while Stenberg signed up to try Mythos, he said he never actually received direct access to the model. Instead, someone else with access ran Mythos against curl's codebase and later sent him a report. "It's not that I would have a lot of time to explore lots of different prompts and doing deep dive adventures anyway," Stenberg explained. "Getting the tool to generate a first proper scan and analysis would be great, whoever did it."

That scan, which analyzed curl's git repository at a recent master-branch commit, was sent back to him earlier this month, and it found just five things that it claimed were "confirmed security vulnerabilities" in cURL. Saying he had expected an extensive list of vulnerabilities, Stenberg wrote that the report "felt like nothing," and that feeling was further validated by a review of Mythos' findings. "Once my curl security team fellows and I had poked on this short list for a number of hours and dug into the details, we had trimmed the list down and were left with one confirmed vulnerability," Stenberg said, bringing us back to the aforementioned number.

As for the other four, three turned out to be false positives that pointed out cURL shortcomings already noted in API documentation, while the team deemed the fourth to be just a simple bug. "The single confirmed vulnerability is going to end up a severity low CVE planned to get published in sync with our pending next curl release 8.21.0 in late June," the cURL meister noted. "The flaw is not going to make anyone grasp for breath."

Read more of this story at Slashdot.

Into the Storm

Greg Adams Photography posted a photo:

Into the Storm

But I Guess It Was Just Someone Who Felt a Lot Like I Remember You

Thomas Hawk posted a photo:

But I Guess It Was Just Someone Who Felt a Lot Like I Remember You

The Hugh Stevens Bell Collection

Thomas Hawk posted a photo:

The Hugh Stevens Bell Collection

slides from an undated SVE box by photographer Hugh Stevens Bell

Kool & The Gang

Thomas Hawk posted a photo:

Kool & The Gang

Construction on the Baja Coast

Thomas Hawk posted a photo:

Construction on the Baja Coast

20260512_075252

iain.davidson100 has added a photo to the pool:

20260512_075252

My birthday. Two pieces of wrapping paper, a hand painted card and two books about Hockney

20260511_105239

iain.davidson100 has added a photo to the pool:

20260511_105239

20260510_123344

iain.davidson100 has added a photo to the pool:

20260510_123344

Behance Featured Projects

The latest projects featured on the Behance

myaize-??????-??????