As cited
Copy frozen at (site build).
vulnerabilities
AI code security with Claude Mythos Preview: Inside Tenable’s 500+ hours of testing for Project Glasswing
Tenable conducted over 500 hours of testing on Anthropic's Claude Mythos Preview as part of Project Glasswing, evaluating its capabilities in source code analysis, exploit creation, binary reverse engineering, threat modeling, and dynamic testing. The testing revealed that frontier AI can meaningfully enhance code security programs when combined with expert oversight and proper tooling, but cannot replace traditional deterministic security tools like SAST, DAST, and SCA. Human analysis proved essential to filter findings into actionable risks, as the model generated numerous results with varying reliability.
Why it matters: Security teams evaluating AI-assisted code scanning should understand that frontier AI complements rather than replaces existing tools, and that source code visibility gives defenders an asymmetric advantage that should inform repository access controls.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
AI code security with Claude Mythos Preview: Inside Tenable’s 500+ hours of testing for Project Glasswing
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
AI code security with Claude Mythos Preview: Inside Tenable’s 500+ hours of testing for Project Glasswing
Tenable conducted over 500 hours of testing on Anthropic's Claude Mythos Preview model for code security tasks including source analysis, exploit creation, and reverse engineering. The testing revealed that while frontier artificial intelligence (AI) dramatically scales security testing capabilities, human expertise is essential to validate findings and determine true exploitability. Tenable concluded that frontier AI functions best as a supplementary tool within a broader code security program rather than as a replacement for traditional deterministic tools.
Why it matters: Security teams evaluating large language models for code analysis should recognize that AI findings require expert validation to reduce false positives, and that source code access gives defenders a significant advantage over external attackers when integrated with proper oversight and testing frameworks.
- Source published
- First seen by Cybersecurity Tracker