
checkmarx
In April 2026, Anthropic gave a mini number of tech companies, banks, and information companies restricted entree to Claude Mythos Preview — an AI exemplary truthful effective astatine uncovering vulnerabilities that Anthropic wouldn't merchandise it publicly. It recovered vulnerabilities that years of accepted scanning had missed. Since then, different LLM models are besides proving to person akin capabilities. Word sewage to boardrooms fast, and concerned boards are asking their CEOs, CTOs, and CISOs the aforesaid question: What are we doing astir this information challenge?
The urgency is real. At Fortune 50 companies, AI-assisted developers now constitute codification 3 to 4 times faster than their peers — but present information findings 10 times arsenic often, according to a 2026 Cloud Security Alliance report. More codification intends much vulnerabilities, and the aforesaid AI acceleration has been a triumph for attackers too, collapsing the clip betwixt flaw find and progressive exploit.
So, what tin boards do to support their organizations some building and unafraid successful a post-Mythos world? Focus connected their firm’s information posture and whether the correct mechanisms are successful spot to supply a broad position of risk, prioritize what to hole first, and remediate vulnerabilities faster than they tin beryllium exploited.
How We Got Here
AI coding assistants person supercharged really overmuch codification gets written. But much codification isn’t the rumor — it’s that AI-generated codification carries much information vulnerabilities than human-generated code. A July 2026 study by Ilya Kabanov of The Weather Report tested really today's frontier models grip realistic, repository-scale coding tasks. The models were bully astatine producing codification that worked. They were acold worse astatine producing codification that was besides unafraid — astir of the codification that worked still shipped pinch information flaws.
That’s compounding a problem years successful the making, though it didn't commencement pinch AI.
For overmuch of my career, AppSec sat good beneath infrastructure connected the main information officer’s privilege list, while a decade of instrumentality sprawl and regularisation kept raising the stakes. Security teams ended up pinch much devices and much information than ever, but still lacked a unified appraisal of risk, and the devices to reside them astatine speed.
Fixing every vulnerability was ne'er realistic without slowing transportation to a crawl, truthful teams did the reasonable thing: scanned broadly, past invested a batch of quality labour successful triaging them truthful they could attraction their constricted hole capacity connected vulnerabilities astir apt to beryllium exploited. The problem is that what was reasonable earlier isn't capable anymore pinch the improvement of the Mythos people of AI models.
AI vulnerability reports person astir tripled since 2024, according to a 2026 HackerOne report. Discovery has outpaced remediation by an bid of magnitude — astir teams still spot 1 bug astatine a time, built for a world uncovering a captious flaw a week, not 1 an hour.
AI cuts some ways. The aforesaid reasoning that lets AI models find what information devices missed besides lets attackers weaponize those models — lowering the accomplishment and costs it takes to utilization a flaw. Vulnerabilities that utilized to beryllium safe because they were difficult to scope nary longer are. That's collapsed the spread betwixt a vulnerability becoming nationalist and an attacker exploiting it, from months to days. In fact, today, the stock of exploitations occurring connected aliases earlier the time of disclosure has risen to astir 80%, accourding to a study by J.P. Morgan Chase Private Bank. Fixing the astir evident flaws first was a safe stake erstwhile reaching the remainder required existent sophistication. That stake nary longer pays off.
Triage capacity isn't the full fix. The backlog needs to extremity increasing — which intends uncovering vulnerabilities accurately enough, and accelerated enough, to remediate astatine instrumentality speed.
AI Is Part of the Problem. It’s Also Part of the Fix.
As a information scanner, AI models tin logic done code, which lets them uncover caller threats nary rule-based scanner would catch. But that system besides makes them inconsistent. They tin hallucinate findings that aren't real, which only adds to the sound — and the backlog. And because they deficiency the rigor of a rule-based scanner, a ample number of vulnerabilities gaffe through.
Deterministic scanning, connected the different hand, runs connected well-tested, security-knowledge-based rules, which intends nary hallucinations. When you adhd AI reasoning connected apical of that foundation, you get a overmuch much broad position of risk.
But uncovering everything — done some deterministic and AI scans — is only the first step. Security teams besides request to spot what they find. By applying a third, independent study furniture that checks AI and deterministic findings against each other, we tin get an meticulous position of exploitable aliases attackable risk.
Independence present is essential: the aforesaid strategy that generated the codification aliases flagged a flaw can't besides beryllium the sole judge of whether the flaw is existent — nary much than a student should people their ain exam. Organizations besides request to spot that the tools’ findings are complete, leaving thing down that an adversary mightiness find and exploit.
When you tin trust what surfaces, it drives faster remediation, reliable governance, and a existent reply for the board.
The Path Forward
So what should boards really beryllium focused on? Not a azygous number, but 3 things: a broad appraisal of the exploitable risk, manageable processes to prioritize and hole the vulnerabilities, and auditable impervious that they are really fixed.
Getting location is simply a matter of order, not speed. The afloat image comes first — not a partial scan, not 1 tool's portion of the codebase, but everything connected to it. Only past does prioritization mean anything: which vulnerabilities are reachable and exploitable, not conscionable which ones a scanner branded critical. And erstwhile a vulnerability is prioritized, location needs to beryllium a system that gets it fixed fast, and pinch impervious it happened, not conscionable a summons marked closed. That subject has to clasp crossed each squad and each instrumentality — comprehensive, prioritized, auditable — because 1 spread is simply a doorway near open, and successful a post-Mythos world, thing will enactment hidden for long.
Your adjacent committee update should sound for illustration this: here's the afloat picture, here's what we're fixing first, and here's the impervious that the backlog is reducing.
English (US) ·
Indonesian (ID) ·