AI Just Found Bugs Humans Missed for Decades
Something quietly big happened this week.
A new AI model — Claude Mythos — has been used to uncover thousands of high-severity software vulnerabilities, including some buried deep inside major operating systems and widely used tools.
Not small apps. Not niche projects. Core infrastructure.
One example stood out: a 27-year-old vulnerability in OpenBSD — an operating system known for being one of the most security-focused in the world. Another was a flaw in FFmpeg, software used everywhere for video processing, that had been hit millions of times in testing without being detected.
These weren’t obvious bugs. They were the kind that sit quietly for years, hidden in plain sight.
What’s Actually Changed
This isn’t about AI suddenly becoming “hackers”.
It’s about scale.
Finding serious vulnerabilities has always required a rare mix of skill, patience, and experience. Now, AI can scan massive codebases, test edge cases, and spot subtle patterns far faster than any individual human.
In simple terms: what used to take months — or never happen at all — can now happen quickly and repeatedly.
The Window Is Getting Smaller
There’s a shift happening that most people won’t notice straight away.
The time between a vulnerability being discovered and being exploited is shrinking.
What once took months can now take days — or less.
This matters because many systems we rely on every day aren’t actively monitored or updated. Old code, legacy systems, forgotten software — all of it becomes more exposed in a world where vulnerabilities are easier to find.
Why This Matters to You
You don’t need to be running a server or managing infrastructure for this to matter.
If you store anything online — conversations, files, personal data — you’re relying on software being secure.
And that assumption is changing.
AI isn’t just making things more powerful. It’s making weaknesses easier to uncover.
That doesn’t mean everything is suddenly unsafe — but it does mean the margin for error is getting thinner.
The Good Side (and Why This Isn’t All Bad)
There’s a positive side to this as well.
The same AI that can find vulnerabilities can also help fix them — faster than ever before.
That’s why companies are already using models like this defensively, scanning their own systems and patching issues before they’re exploited.
In many ways, security could actually improve — just at a much faster pace than we’re used to.
Where This Leaves Us
This feels like one of those quiet turning points.
Not dramatic, not sudden — but meaningful.
We’re moving into a world where software is constantly being tested, analysed, and probed at a level that simply wasn’t possible before.
And that changes the rules a bit.
Less assumption. More awareness.
Less “it’s probably fine”. More “let’s actually check”.
A Small Note from Me
This shift is one of the reasons I built Export Reader in the first place.
Not because everything is broken — but because understanding and having visibility over your own data is becoming more important.
As tools get more powerful, knowing what you have — and where it lives — starts to matter more than ever.
Conclusion
AI finding decades-old bugs isn’t just a technical milestone — it’s a signal.
Things are speeding up.
And while that brings new risks, it also brings better tools to deal with them.
The key is staying aware of the shift — because it’s already happening.