Post
Dan Luu
danluu.com
did:plc:2mrgzk6xlemfv6yugn644xxy
Why didn't Anthropic do effective false positive rejection with their Mythos/Glasswing vuln reports? In https://danluu.com/ai-coding/#mythos, I mentioned a colleague finding that the reports we got were mostly false.
That seems common? E.g., gregkh on kernel reports and https://www.vulncheck.com/blog/anthropic-glasswing-receipts
2026-09-23T16:48:32.361Z