Mythos has made 2026 patching hell. It might make 2027 a breeze
Gartner analyst Craig Lawson argues AI bug-hunters like Anthropic's Mythos have audited major codebases so thoroughly that 2027 could see fewer severe vulnerabilities.
Speaking at Gartner's IT Symposium in Australia, research VP Craig Lawson said AI-driven bug hunting, exemplified by Anthropic's Mythos, is uncovering flaws at unprecedented scale, citing Microsoft shipping over 970 patches in one week and a recent series of CVEs in historically secure OpenBSD. He argued vendors are also using AI to find bugs before release, retiring technical debt and shrinking future zero-day avenues. Lawson predicts 2027 may be the first year with a net drop in vulnerability severity, if not aggregate counts. He also expects AI to enable near-continuous red-teaming and faster fixes, such as generating F5 iRule syntax for virtual patches via Gemini.
- Microsoft shipped over 970 patches in a single week, illustrating record 2026 vulnerability volume.
- Lawson cites recent OpenBSD CVEs as evidence AI finds flaws in historically secure codebases.
- He predicts 2027 could bring the first net drop in vulnerability severity as vendors adopt AI testing.
- AI could enable daily red-team exercises and faster virtual patching, such as F5 iRule generation.
- He urges SOC metric changes, celebrating defended outcomes instead of ticket counts.
Full article464 words · extracted from theregister.com · click to collapse
Security
Gartner sees huge amounts of technical debt paid down, and better scanning that could make software safer sooner
When Microsoft delivered over 970 patches last week, many saw a nightmare for beleaguered security staff. Gartner research vice president Craig Lawson thinks infosec workers might soon see sunlit uplands as their workloads ease.
Lawson outlined that scenario at Gartner’s IT Symposium in Australia today and explained it by theorising that the increased volume of vulnerability discoveries made possible by Anthropic’s Mythos and other bug-hunting AI might be getting close to finding most of the flaws in established codebases.
“We've never had a situation where massive codebases have been audited to that level before,” he told The Register, and offered the recent series of CVEs found in OpenBSD – which has historically been an unusually secure and stable OS – as evidence that AI bug-hunters are cleaning up.
REG AD
“Think about how much technical debt has been retired in products just in the last six months,” he said. Lawson pointed to the fact security vendors, who in theory know what it takes to create secure products, are also using AI to find flaws in their wares. Those discoveries, he suggested, again indicate AI is taking out potential avenues for zero-day attacks.
REG AD
The high number of CVEs reported in 2026 is a positive signal. Lawson thinks Mythos and its ilk may also create an invisible signal as vendors use the AI to detect more bugs in their future releases.
He therefore thinks that 2027 might see CVE numbers fall as vendors finish cleaning up old codebases, and because they use AI to more thoroughly test their next releases.
“2027 could be the first year we see a net drop, maybe not in aggregate vulnerabilities, but definitely in severity of flaws,” he told The Register.
He thinks AI will also make defenders happy by giving them better tools. Today, he said, a red-teaming exercise is an infrequent and costly event that usually involves hiring an external provider. AI bug-hunters could mean organizations can effectively run a red team every day.
And if a red team exercise produces tickets that need solving, he thinks AI will help analysts to identify fixes more quickly.
“What if I could spend three minutes going to Gemini and saying ‘Write syntax for an F5 IRule’ that becomes a virtual patch? Everyone can do threat intelligence, enrichment, some of those harder tasks.”
When infosec staff make those fixes, Lawson wants organizations to celebrate the impact of their work.
Today, Lawson said, security operations centers measure staff by the number of tickets they process and close. He thinks a better approach is to celebrate the fact that cyber-defenders kept a hospital open or stopped a ransomware raid. ®
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.theregister.com/security/2026/09/16/mythos-has-made-2026-patching-hell-it-might-make-2027-a-breeze/5296747