Jonathan Rende at Checkmarx considers why application security teams must rethink their approach in the age of AI-driven vulnerability discovery

In early June, Anthropic announced a significant expansion to the Project Glasswing programme assessing its Mythos model. One hundred and fifty new organisations joined the Glasswing consortium to pool discoveries, coordinate disclosures, and harden the software the world runs on.
Sounds like progress, but the expansion didn’t happen because things were going well. It expanded it because Mythos is the most capable LLM ever built, and it keeps finding vulnerabilities in code that everyone believed was sound.
The AppSec world, meanwhile, needs to wake up to a new reality. Our recent research found some big contradictions at the heart of AppSec as we know it.
Almost all (90%) of organisations admitted to a recent breach tied to their own applications, yet at the same time 73% of CISOs and AppSec managers still describe their security posture as "advanced" or "highly mature."
One of those numbers is lying. Nearly universal breaches, yet high confidence? It’s always been a dangerous combination, but Mythos just made the gap between bigger and a lot more expensive.
Most organisations were exposed before Mythos
What used to be innocuous items in backlogs have morphed into loaded weapons thanks to the latest models: known vulnerabilities can be exploited in minutes, not months.
So, what does the security industry do now?
First, we need to throw out the old playbook entirely. It’s time to rethink the fundamentals of security as we know it.
This means organisations must embed security into every layer, workflow, sprint and development cycle. Tool sprawl is eliminated, dependencies are reduced, and systems are streamlined. Accountability is built into the work of everyone who creates code – developer or not.
This is a change management exercise that requires humans in the loop, governance at the helm, and a security strategy that brings together the best of probabilistic, deterministic, agentic, and independent capabilities.
We also need to see a shift in the way organisations are managing and securing vulnerabilities. AI-driven development creates two distinct vulnerability problems, and they need different responses.
First, we have unknown vulnerabilities, where probabilistic frontier models shine, surfacing subtle, context-dependent flaws that rule-based scanning would miss. On the other hand, we have known vulnerabilities where deterministic models shine and frontier models miss the mark. We see this in our current testing. The comprehensive picture is a venn diagram and the overlap is very small. The catch is the inconsistency with different answers and outputs in probabilistic models. One model catches what the other misses. This creates a new type of risk that requires a new blended approach.
Known vulnerabilities, meanwhile, are those already in backlogs, deprioritised due to noise, resourcing constraints, or unclear exploitability. Mythos hasn’t changed what they are; it has changed what they cost to ignore.
Teams need to embed security in the AI development lifecycle with the right tooling in a seamless approach. AI-driven discovery needs to be paired with deterministic, context-aware validation that confirms exploitability and gives teams the best signals to address.
1.The right tools. Based on this, the first shift that needs to happen quickly, is to go hybrid. Probabilistic AI works by inference, scanning broadly across patterns and behaviours to surface risks that no rule has yet been written to catch. Deterministic analysis, meanwhile, works by logic, applying fixed, rules-based verdicts to known vulnerabilities with precision and repeatability.
Use probabilistic AI for breadth and speed across unknown vulnerabilities, and deterministic analysis to ensure precision that makes known vulnerabilities actionable rather than overwhelming. Neither works alone.
2. Security embedded into AI. Alongside having the right tools, teams need to embed security into the AI development lifecycle. Security must live where developers and agents actually work - in the IDE, outside the IDE via CLI, in the workflow, at the point of code creation. Catching issues before they enter the pipeline removes the downstream remediation burden before it accumulates.
3. Cut complexity. The third shift is about cutting complexity. Between 70% and 90% of modern software is open-source code from outside the organisation. Sprawling toolchains and inconsistent usage make that exposure worse, not better so it’s time to streamline the stack
4. Better governance. We also need to see more governance and accountability around AI tools and their output. We found only 22% of organisations have a formal approval or policy-based process for governing AI components in their applications. The majority don’t even govern the shadow AI that’s quietly writing tomorrow’s breach report. That’s not a policy gap. That’s a welcome mat.
5. Developer accountability. Finally, we need to make developers accountable again. Developers used to know and own every line of their code. In an era where anyone can generate a working feature in seconds, ownership and accountability need to be built back into the model. Bad code at AI speed is still bad code.
Keeping pace with Mythos and what comes after it requires putting the same speed and automation to work on the defensive side. It needs a hybrid engine running both probabilistic and deterministic analysis for the most comprehensive coverage at the highest fidelity, with agentic triage and remediation that doesn’t wait on a human in the loop. The answer lies in automation, but with governance attached.
And, ironically, this is a human exercise. The organisations that come through this well will be the ones that empower people to own the complexity and the process, not as a threat to be absorbed within existing frameworks.
The question was never whether AppSec needed to change. Mythos just removed the last excuse for not starting.
Jonathan Rende is CPO at Checkmarx
Main image courtesy of iStockPhoto.com and Thinkhubstudio
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543