Cybersecurity Today

Jeff Williams CTO Cofounder of Contrast Security and OWASP co-founder on Mythos and AI Security

Apr 11, 2026
Jeff Williams, co-founder and CTO of Contrast Security and former OWASP chair, shaped early AppSec tools like WebGoat and the OWASP Top 10. He discusses Anthropic’s Mythos model for finding zero-days, why common vulnerabilities persist, the economics and limits of AI vulnerability discovery, and building AI-powered software factories with feedback, monitoring, and assurance.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
INSIGHT

OWASP Top 10 Persistence Reflects Slow AppSec Change

  • The OWASP Top 10 has remained largely the same because AppSec changes very slowly despite growing awareness.
  • Williams notes adding 'use of unsafe libraries' to the Top 10 in 2013 anticipated today's supply chain focus.
INSIGHT

Mythos Shows Strong Zero-Day Discovery Potential

  • Anthropic's Mythos model is trained to find vulnerabilities and reportedly discovered novel CVEs across major systems.
  • Williams says Anthropic hasn't disclosed token costs or methodology, but results suggest strong vulnerability-finding capability.
INSIGHT

Most Open Source Code Remains Largely Unseen

  • The number of public CVEs understates latent vulnerabilities because most open source projects receive almost no systematic scrutiny.
  • Williams compares undiscovered bugs to Bitcoin mining: many exist but require investment to unearth rare finds.
Get the Snipd Podcast app to discover more snips from this episode
Get the app