Discussion about this post

User's avatar
Pawel Jozefiak's avatar

The coordinated disclosure framing is useful. Security researchers have been doing this for decades and the norms are established: find it, notify, give time to patch, publish. What's new is the scale.

Mythos finding thousands of zero-days simultaneously across operating systems and browsers isn't a standard bug report workflow - it's a remediation program that needs organizational infrastructure to process at all. The 50 organizations aren't just getting model access, they're becoming the response capacity for a new category of vulnerability discovery. That's a meaningful structural shift in how software security gets maintained, and it's not obvious it was designed to be that from the start.

Sol Hando's avatar

Any recommendations for a company that holds sensitive information in the face of tech like this? We just upped our cyber insurance limit a few million because of it.

1 more comment...

No posts

Ready for more?