Ryan and Luca tackle the hot topic of AI-driven security research, sparked by the release (and brief containment) of Anthropic's Mythos tool. Ryan, drawing on his 20+ years in cybersecurity, delivers a surprisingly reassuring message: if you've been doing proper engineering, AI-found vulnerabilities aren't the existential threat the hype suggests. We explore how Mythos and similar tools are flooding the CVE database with thousands of new vulnerabilities, but discuss why this doesn't automatically mean more successful attacks. Ryan explains the crucial difference between finding a bug and actually exploiting it, and why embedded systems developers shouldn't panic—but should definitely have their update processes sorted. The conversation covers everything from botnet refrigerators to Ukrainian security cameras, threat modeling with AI assistance, and why AI makes such a relentlessly effective hacker (spoiler: it doesn't get bored). Bottom line: the weapons haven't changed, you just need to install the bulletproof glass you should have had all along. Key Topics: [02:30] Introducing Mythos: AI tool for finding software vulnerabilities, its May release, US containment, and recent re-release[05:15] The flood of AI-generated bug reports: distinguishing real vulnerabilities from noise, and the burden on maintainers[08:45] Mythos by the numbers: 6,000+ critical vulnerabilities found, 90% true positive rate, but does it matter for your system?[12:00] The reachability problem: having a bug vs. being able to exploit it, and why solid engineering processes matter more than bug counts[16:30] Embedded systems challenges: BSP version conflicts, regulatory approval nightmares, and the CRA/FDA compliance push[21:00] No uptick in actual attacks: why more CVEs doesn't equal more breaches, and what motivates attackers (hint: money, not bugs)[28:45] Embedded systems' blessing and curse: air-gapped devices vs. internet-connected vulnerabilities, and the botnet refrigerator story[35:20] Using AI for defense: network analysis, threat modeling, traffic pattern recognition, and why AI is the best grep you've ever seen[42:00] AI as the relentless attacker: no social norms, no contracts, just pure problem-solving—and why that's both powerful and concerning[47:30] The offensive vs. defensive mindset: why AI bridges both motivational patterns and what that means for security teamsNotable Quotes: "Just because there's more CVEs doesn't really change the defensive posturing that you need to do. If you have a solid engineering process to provide updates to your system and test and verify those updates actually work, it doesn't matter how many bugs you find. You can find two. You can find 6,000." — Ryan Torvik "AI doesn't have social norms. AI will just go and do things. And yes, there are guardrails that they're trying to put on, but like, I don't know if you've seen AI just ignore parts of your prompt before." — Ryan Torvik "There's not a death star. This is not an existential crisis. This is not something new. It changes the game but not in a way that we can't handle. The weapons haven't changed, you just need to install the bulletproof glass." — Ryan Torvik Resources Mentioned: Anthropic's Mythos - AI tool for automated vulnerability discovery in software, released in May 2024, briefly restricted by US authorities, then re-releasedCVE Database - Common Vulnerabilities and Exposures database, currently experiencing significant growth due to AI-assisted vulnerability discoveryAgile Embedded Podcast Slack - Community Slack channel where Ryan participates, sister podcast to Embedded AITulip Tree Tech - Ryan's company focused on improving embedded development processes, including emulator-in-the-loop solutionsluca.engineer - Luca's website with links to training courses, LinkedIn, and other professional activities