惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
博客园 - 聂微东
博客园 - 叶小钗
爱范儿
爱范儿
罗磊的独立博客
Hugging Face - Blog
Hugging Face - Blog
阮一峰的网络日志
阮一峰的网络日志
S
SegmentFault 最新的问题
Apple Machine Learning Research
Apple Machine Learning Research
美团技术团队
T
Tailwind CSS Blog
博客园 - 司徒正美
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
宝玉的分享
宝玉的分享
量子位
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
The Cloudflare Blog
人人都是产品经理
人人都是产品经理
小众软件
小众软件
博客园 - 【当耐特】
博客园 - 三生石上(FineUI控件)
V
Visual Studio Blog
雷峰网
雷峰网
酷 壳 – CoolShell
酷 壳 – CoolShell

Hacker News - Newest: "AI"

AI can't read an investor deck AI as an attorney? Student uses ChatGPT, Gemini to sue UW over alleged racial discrimination Hacking MCP Servers in AI Systems – The Rug Pull: Tool Changes After Approval GitHub - MeepCastana/KubeezCut: Free Web based video editor Can AI judge journalism? A Thiel-backed startup says yes, even if it risks chilling whistleblowers Coming soon: 10 Things That Matter in AI Right Now DARPA built an AI to fact-check enemy weapons claims What explains heterogeneity in AI adoption? When AI Meets Muscle: Context-Aware Electrical Stimulation Promises a New Way to Guide Human Movements - Department of Computer Science AI Changed How We Build. It Did Not Change What Matters. Linux rules on using AI-generated code - Copilot is OK, but humans must take 'full responsibility for the… Meta spins up AI version of Mark Zuckerberg to engage with employees Code Mode: Let Your AI Write Programs, Not Just Call Tools | TanStack Blog GitHub - Delavalom/graft: Go framework for building AI agents. Type-safe tools, multi-provider (OpenAI, Anthropic, Gemini, Bedrock), zero vendor SDKs. India's TCS tops estimates, says new AI models did not dent services demand Gen Z's fading AI hype Strong feeling: we are in a folded AI reality GitHub - machinarii/total-recall-catalog: A reference catalog of latest knowledge retrieval, memory & RAG systems GitHub - mensfeld/code-on-incus: Give each AI agent its own isolated machine with root, Docker, and systemd. Active defense detects and stops threats automatically.. Quantization, LoRA, and the 8% Problem: Benchmarking Local LLMs for Production AI Iran war: We spoke to the man making Lego-style AI videos that experts say are powerful propaganda Powell, Bessent discussed Anthropic's Mythos AI cyber threat with major U.S. banks GitHub - immartian/bellamem: Persistent belief-graph memory for AI agents. Retrieves decisive context by importance — not recency, not RAG, not /compact. recursive-mode: The Repo-Native Operating System for AI Engineering After the attack on Sam Altman's home, will AI CEO's go on the offensive? The biggest advance in AI since the LLM Opus 4.6 vs GPT 5.4 One Prompt Unity World Generation Test “AI polls” are fake polls Client Challenge Can AI be a 'child of God'? Inside Anthropic's meeting with Christian leaders
271 Firefox flaws closed thanks to Mythos AI: Breakthroug...
Prunkton · 2026-04-22 · via Hacker News - Newest: "AI"

In the latest Firefox update, 271 vulnerabilities were closed, which the browser's development team found using Anthropic's new AI model, Claude Mythos Preview. Mozilla has now announced this, stating that for a hardened product like its browser, each of these vulnerabilities would have justified a red alert. Nevertheless, working with the AI model – which only a few companies working in IT security officially have access to – has been a hopeful one, the team assures. In the eternal battle between attackers and defenders in the IT field, the latter finally have the opportunity to win thanks to the breakthrough in AI development – “decisively”.

Anthropic introduced Mythos two weeks ago and stated that the model is so dangerous that it is only made available to companies working in IT security. The AI model has already identified thousands of high-risk zero-day vulnerabilities. At the same time, the AI technology is significantly more likely to develop a working exploit for such vulnerabilities, sometimes even using several in conjunction. Therefore, only companies that can use the tool to improve IT security have been granted access. To what extent this is honest concern, clever PR, or even a limitation based on Anthropic's resources not being sufficient for a release, is currently being hotly debated.

Mozilla's Firefox team is now among the first to share experiences with Mythos publicly. They have been working with Anthropic since February 2026; searches with the Opus 4.6 model had already uncovered 22 security-relevant bugs in Firefox 148. In the blog post announcing the release of Firefox version 150, the group now writes that they have long recognized in silence that the number of exploitable security vulnerabilities could never be reduced to zero. However, they have tried to make zero-day exploits so expensive that only actors with unlimited resources have access to them and do not use them against “normal” users. They reached this conclusion because attackers have an asymmetric advantage. The attack surface, for example in a browser, is not infinite but large enough to make defense with existing tools very difficult.

Until now, only a few people have been able to find security vulnerabilities through time-consuming source code analysis. Computers have been “completely incapable” of this until a few months ago, and at Firefox, they have years of experience analyzing the work of these experts. Anthropic's Mythos Preview is now “every bit as capable” as these very few people: “So far, we haven't found any category or complexity of vulnerability that humans can uncover that this model can't uncover,” the team writes. While this sounds alarming, they also found that Mythos has not found any vulnerabilities that a top researcher couldn't have found.

Therefore, they do not share predictions that AI models will find entirely new forms of vulnerabilities in the future that exceed our current understanding: “The defects are finite, and we are entering a world where we can finally find them all.” While Firefox confirms Mythos's claimed capabilities with this, it is an initial indication of the possible consequences for IT security. At Mozilla, they actually assume that all vulnerabilities and all attack vectors can be found with the help of AI. This would be a huge gain for IT security. However, whether this will prove true remains to be seen. The update for Firefox is installed automatically, but it can also be initiated by clicking on “About Firefox” in the “Help” menu.

(mho)

Don't miss any news – follow us on Facebook, LinkedIn or Mastodon.

This article was originally published in German. It was translated with technical assistance and editorially reviewed before publication.