AI Can Find Your Vulnerabilities. It Still Can’t Own What Happens Next.
August 28, 2026 – Published on Coder Legion
Earlier this year, Anthropic gave Apple, Microsoft, Google, Amazon and a handful of other companies access to an AI agent called Mythos and turned it loose on their code. Project Glasswing, as the initiative became known, found bugs that had survived decades of human audits and fuzzing, including one flaw that had been sitting in OpenBSD for 27 years. It also found a lot more than anyone could fix. Fewer than 1% of the vulnerabilities Mythos discovered ever got patched.
That gap is the story Victor Wieczorek keeps coming back to. Wieczorek is SVP of Offensive Security at GuidePoint Security, where his teams run penetration tests and red team engagements across application security, cloud, infrastructure and operational technology. When I asked him where AI still falls short against a human pen tester, he pushed back on the question itself.
“It’s really a human versus a steam engine kind of idea,” Wieczorek said. “AI [is] so good at finding needles in a haystack. What I prefer to focus on is everything downstream of that. After you find the bug, after you identify the remediation, then what do you do about it?” Glasswing, he said, “talks to a lot of complexity” in that narrative. Finding the flaw was never really the bottleneck. Getting an organization to understand it, trust it and act on it always was.
Read More HERE.