Cybersecurity Research

AI Agents Are Getting Alarmingly Good at Finding and Exploiting Software Bugs

Embrace The Red · 8 Apr 2026
Key Takeaway As AI accelerates vulnerability discovery and exploitation, small businesses should prioritise applying security patches as quickly as possible rather than assuming there is time to spare.

Security researchers are increasingly finding that AI agents are becoming remarkably effective at hunting for software vulnerabilities, thanks to their tireless ability to analyse code at scale. Anthropic recently announced a preview of a new model called Mythos, which it describes as highly capable at cyber security research, so much so that access is currently restricted to a small number of partner organisations.

According to Anthropic's own findings, the leap in capability is significant. Where its previous model succeeded at exploiting Firefox JavaScript engine vulnerabilities only twice out of hundreds of attempts, Mythos succeeded 181 times, although this was tested outside the browser's usual protective sandbox. The company also reported that Mythos identified serious, long-standing vulnerabilities, including a 27-year-old OpenBSD bug, a flaw in FFmpeg, and a 17-year-old FreeBSD remote code execution issue.

Perhaps most concerning, Anthropic noted that Mythos is starting to show some success at a task security researchers already use AI for: reverse engineering software patches to work out how to exploit the underlying flaw before businesses have applied the fix. This suggests the gap between a vulnerability being disclosed and being actively exploited, already shrinking, could narrow further as these tools mature.

Summarised by CISO AI from Embrace The Red. We link back to every original so you can read it yourself.