Greatly appreciated the candor. I've included a few slides into text that i thought were eye-opening to me:
From his Kernel Recipes 2026 slide on Mythos
```
Mythos's 79 vulnerabilities:
24 - no detail at all "something crashed"
14 - not a bug at all
3 - totally made up data
15 - already fixed in latest release
- 11 by others
- 4 by anthropic
20 - fixes were needed
- 7 "assume a malicious filesystem image"
- 2 "assume you can inject a malicious network packet into the middle of the stack"
- 2 "NOMMU"
- 6 sctp networking issues for untrusted devices
- 2 ipv6 minor network issues
- 1 gpu driver for local malicious user
```
GHK called this "10 'real' bugfixes", which to me sounds like there's a wild hype machine around these companies and uncritical parroting of every press release they make that falls apart when you engage the affected real experts.
The Linux Kernel is not necessarily the most interesting target for LLMs, since it gets a huge amount of attention. I would be interested to hear what people find in less prominent projects. For completeness that includes proprietary code stored in GitHub.
In our company we found real security issues in proprietary code using Opus 4.6/4.7. Obviously typical attackers might have difficulty finding these without code access but Claude was finding real CVEs, which we fixed.
p.s., This is an argument for not trying to deal with security problems by neutering the LLMs. To the extent LLMs are effective it weakens security.
usernomdeguerre · · focus · HN ↗
From his Kernel Recipes 2026 slide on Mythos
```
```GHK called this "10 'real' bugfixes", which to me sounds like there's a wild hype machine around these companies and uncritical parroting of every press release they make that falls apart when you engage the affected real experts.
hodgesrm · · focus · HN ↗
In our company we found real security issues in proprietary code using Opus 4.6/4.7. Obviously typical attackers might have difficulty finding these without code access but Claude was finding real CVEs, which we fixed.
p.s., This is an argument for not trying to deal with security problems by neutering the LLMs. To the extent LLMs are effective it weakens security.
Edit: added p.s.