
Cybersecurity Today Jeff Williams CTO Cofounder of Contrast Security and OWASP co-founder on Mythos and AI Security
Apr 11, 2026
Jeff Williams, co-founder and CTO of Contrast Security and former OWASP chair, shaped early AppSec tools like WebGoat and the OWASP Top 10. He discusses Anthropic’s Mythos model for finding zero-days, why common vulnerabilities persist, the economics and limits of AI vulnerability discovery, and building AI-powered software factories with feedback, monitoring, and assurance.
AI Snips
Chapters
Transcript
Episode notes
OWASP Top 10 Persistence Reflects Slow AppSec Change
- The OWASP Top 10 has remained largely the same because AppSec changes very slowly despite growing awareness.
- Williams notes adding 'use of unsafe libraries' to the Top 10 in 2013 anticipated today's supply chain focus.
Mythos Shows Strong Zero-Day Discovery Potential
- Anthropic's Mythos model is trained to find vulnerabilities and reportedly discovered novel CVEs across major systems.
- Williams says Anthropic hasn't disclosed token costs or methodology, but results suggest strong vulnerability-finding capability.
Most Open Source Code Remains Largely Unseen
- The number of public CVEs understates latent vulnerabilities because most open source projects receive almost no systematic scrutiny.
- Williams compares undiscovered bugs to Bitcoin mining: many exist but require investment to unearth rare finds.
