Subscribe Sign in

Mythos has made 2026 patching hell. It might make 2027 a breeze

2 min read Rewritten in plain language

Security

Show what we removed Rules applied: A1 A3 A4×2 A9 C1 C2 D2×7 D3×6 F2×2 all 30 rules
  • Gartner sees large amounts of technical debt paid down, and better scanning that could make software safer sooner
  • Lawson outlined that scenario at Gartner’s IT Symposium in Australia today and explained it by theorising that the increased volume of vulnerability discoveries made possible by Anthropic’s Mythos and other bug-hunting AI might be getting close to finding most of the flaws in established codebases.
  • Lawson pointed to the fact security vendors, who in theory know what it takes to create secure products, are also using AI to find flaws in their wares.
  • The high number of CVEs reported in 2026 is a positive signal.
  • Today, Lawson said, security operations centers measure staff by the number of tickets they process and close.

5 sentences from our version of the report, chosen to cover it. Nothing here is written; every line is in the article below. How

Lawson pointed to the fact security vendors are also using AI to find flaws in their wares.

Headline check

There is nothing in this headline a machine can check against the report: no figure, no name and no quotation.

Nothing was measured here, so nothing is claimed. How this is checked

Read the full reportHide the full report2 min

Gartner sees large amounts of technical debt paid down, and better scanning that could make software safer sooner

When Microsoft delivered over 970 patches last week, many saw a situation for security staff. Gartner research vice president Craig Lawson thinks infosec workers might soon see sunlit uplands as their workloads ease.

Lawson outlined that scenario at Gartner’s IT Symposium in Australia today and explained it by theorising that the increased volume of vulnerability discoveries made possible by Anthropic’s Mythos and other bug-hunting AI might be getting close to finding most of the flaws in established codebases.

“We've never had a situation where massive codebases have been audited to that level before,” he told The Register, and offered the recent series of CVEs found in OpenBSD – which has been a secure and stable OS – as evidence that AI bug-hunters are cleaning up.

“Think about how much technical debt has been retired in products just in the last six months,” he said. Lawson pointed to the fact security vendors, who in theory know what it takes to create secure products, are also using AI to find flaws in their wares. Those discoveries, he said, again indicate AI is taking out potential avenues for zero-day attacks.

The high number of CVEs reported in 2026 is a positive signal. Lawson thinks Mythos and its ilk may also create an invisible signal as vendors use the AI to detect more bugs in their future releases.

He therefore thinks that 2027 might see CVE numbers fall as vendors finish cleaning up old codebases, and because they use AI to more test their next releases.

“2027 could be the first year we see a net drop, maybe not in aggregate vulnerabilities, but definitely in severity of flaws,” he told The Register.

He thinks AI will also make defenders happy by giving them better tools. Today, he said, a red-teaming exercise is an infrequent and costly event that usually involves hiring an external provider. AI bug-hunters could mean organizations can effectively run a red team every day.

And if a red team exercise produces tickets that need solving, he thinks AI will help analysts to identify fixes more quickly.

“What if I could spend three minutes going to Gemini and saying ‘Write syntax for a F5 IRule’ that becomes a virtual patch? Everyone can do threat intelligence, enrichment, some of those harder tasks.”

When infosec staff make those fixes, Lawson wants organizations to celebrate the impact of their work.

Today, Lawson said, security operations centers measure staff by the number of tickets they process and close. He thinks a better approach is to celebrate the fact that cyber-defenders kept a hospital open or stopped a ransomware raid. ®

You are reading our version, not theirs. This is The Register's report with its verdicts and loaded words taken out. Plain description stays, and so do adjectives that carry a fact, such as "former" or "federal". The reporting, the facts and the quotations are theirs — quotations are never edited — and the indicators beside it measure this version. Hover or tap Adjectives to see every one left in the text.

How this outlet filed it, and how we rewrote it

No other newsroom we read has filed on this event, so there is nothing to compare it with yet.

Outlet Niral ScoreAdjectivesSourcingSentimentHappiness
The Registeras they published this story 18.5 17 37 -0.3 39.2
Mundane Readneutralized from The Register 10.5 16 37 0.2 51.5

Sign in to react.

Comments

Nothing here yet.

Sign in to comment.

Questions

Readers can ask a question about this story here. Questions and answers are for subscribers. Sign in to read them.

Comments are read before they appear where anything in them needs a person to look. Nothing posted here is ever deleted; a comment taken down keeps its text and the reason, so the decision can be looked at again. How this works