Anthropic’s bug-hunting Mythos was greatest marketing stunt ever, says cURL creator

2026-05-11T19:23:58Z6655c4d8284241abd11a6765fe5042a5c01502de8eff744aaf293b3c4c246d5d
AI-securityAnthropicCopyFailDDoSDirty FragLinux root exploitMD5Mythosagentic-AIcPanelcredential theftencryption rollbacknation-state espionagenpmphishingpublic exploitsupply-chainvishingzero-day

What happened

Weekly security roundup: AI-powered bug-hunting and scanners produced mixed results (Anthropic Mythos credited with finding only a low-severity cURL issue), while multiple real-world threats escalated. Threat actors are actively exploiting high-impact vulnerabilities — notably a critical cPanel 0‑day under active exploitation and several Linux flaws (CopyFail, 'Dirty Frag') with public/root exploits and limited or no patches. Supply-chain compromises (npm/SAP), credential theft campaigns, AI-enabled phishing and vishing, MD5 password weaknesses, targeted espionage activity, and large-scale DDo

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
theregister_security
Record identifier
6655c4d8284241abd11a6765fe5042a5c01502de8eff744aaf293b3c4c246d5d
Enrichment time
2026-05-11T19:23:58Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.