Greg Kroah-Hartman – Security in the LLM Age [video]

268 points · 96 comments on HN · read original →

Points and comments are a snapshot, not live.

Greg Kroah-Hartman dissects Anthropic's Mythos security claims, finding only 10 of 79 reported vulnerabilities were genuine bugs.

In this Kernel Recipes 2026 talk, Greg Kroah-Hartman analyzes Anthropic's LLM-powered security tool Mythos, which claimed to find 79 Linux kernel vulnerabilities. After review, he categorizes them into 24 with no detail, 14 not actual bugs, 3 with fabricated data, 15 already fixed (11 by others), and 20 requiring fixes. Of those 20, many assume unlikely scenarios like malicious filesystem images or network packet injection. Only 10 are considered real bugs. The talk highlights inflated AI security claims and the need for expert validation.

What commenters are saying

Top commenters widely agree with Kroah-Hartman's assessment, sharing similar experiences with LLM-generated security reports requiring significant human expertise to vet. One commenter describes the reports as akin to "eager, bright 20ish year old interns", gung ho but lacking real-world context. Others note that Mythos did find real bugs in FreeBSD and OpenBSD, though not in Linux. A related blog post (curl) calls Mythos "exactly the marketing stunt it smelled like." Some question whether bias influences what counts as a "real" bug, given tools like USB storage devices can enable malicious filesystem attacks.