← The State of Tech RSS Feed

24 mei 2026 · 13:41

Claude Mythos AI Finds 10,000 Critical Software Bugs

Anthropic's unreleased Claude Mythos model has flagged more than ten thousand high and critical software vulnerabilities across real-world code, including a working exploit targeting the wolfSSL encryption library used in systems worldwide. In this episode of The State of Tech, The European Edition, we unpack what AI-driven vulnerability hunting at industrial scale means for European critical infrastructure, NIS2 compliance, and open-source maintainers. We also cover Iran's fake-recruiter espionage campaign, Google's no-code Android app builder, and Trump's plan to move half of global chip production to the US by 2029.

Anthropic Cybersecurity Google Android Iran Semiconductors

Beluister deze aflevering:

Transcript

Samantha: Welcome to The State of Tech, The European Edition, Sunday May twenty-fourth, 2026. I'm Samantha Lawrence.

Bob: And I'm Bob Russell. Today: Anthropic's new AI uncovers ten thousand serious software bugs, Google lets you build Android apps without writing any code, Iranian hackers running a fake-jobs spy campaign, Trump's plan to drag half the world's chip production to the US, plus two things you can actually try yourself this afternoon. Let's start with the big one.

Anthropic's secret Claude Mythos AI uncovers more than ten thousand critical software bugs in real-world code.

Samantha: So Anthropic has been quietly testing an unreleased model called Claude Mythos, codenamed Project Glasswing, with about fifty hand-picked partners. And the results are, frankly, a little unsettling. The AI has flagged more than ten thousand high or critical severity vulnerabilities in software that is used all over the world. Six thousand two hundred of those sit inside a thousand open-source projects, the kind of code that quietly runs banks, hospitals, and government systems across Europe.

Bob: Cloudflare, the company that handles a huge slice of global web traffic, was one of those partners. They reported the AI found two thousand bugs in their own systems, with four hundred classed as high or critical. And the false-positive rate was lower than what human testers normally deliver. So it's not just spitting out noise, it's actually finding real problems faster and cleaner than people.

Samantha: And here's the part that should make every security team sit up. The model didn't just spot a weakness in wolfSSL, which is a widely used encryption library, it actually built a working exploit. As in, it wrote the attack code that could let someone forge security certificates and impersonate trusted websites.

Bob: Which is the double-edged sword everyone has been warning about. The same AI that finds the hole can write the burglary tool. Anthropic is framing this as defensive work, partners patching things before attackers find them. But the capability itself is the story. If a controlled model can do this, less scrupulous versions trained by other groups can do it too.

Samantha: For European companies and regulators this lands at an awkward moment. Brussels is still working through how the AI Act applies to high-capability models, and cybersecurity rules under NIS2 are now in force. A tool that can autonomously generate exploits doesn't fit neatly into either box.

Bob: And open source is the soft underbelly here. A lot of European critical infrastructure runs on libraries maintained by tiny volunteer teams. If Anthropic's partners found six thousand bugs in a thousand projects, the maintainers now face a flood of disclosures they may not have the people to fix quickly.

Samantha: The bottom line: AI-driven vulnerability hunting has crossed from research demo into industrial scale. Defenders just got a powerful new tool. So did attackers, eventually.

Google launches AI tools that let anyone build Android apps without writing a single line of code.

Bob: Moving on, Google has rolled out a new set of tools inside Google AI Studio that let you build an actual Android app just by describing it in plain English. Type something like, "build me an app that tracks my dog's walks and shows them on a map", and Gemini, Google's AI, turns it into a working app.

Samantha: And it's not a toy. The platform hooks into real phone features, GPS, Bluetooth, the camera. You can preview the app in your browser, then install it straight onto your phone. Google is aiming this at two crowds at once: experienced developers who want to test an idea in an afternoon, and complete beginners who've always wanted to make something but couldn't face learning Java or Kotlin.

Bob: There's also a discovery side to this. Google is adding an "Ask Play" feature inside the Play Store, where you describe what you need and the AI recommends apps. Which, if it works well, could shake up how apps get found. Right now ranking in the Play Store is a dark art involving keywords and reviews. If users start asking an AI instead, the whole app marketing playbook changes.

Samantha: For Europe this is interesting on two fronts. First, it lowers the barrier for small developers, students, hobbyists, small businesses, to ship something local and specific. A bakery in Lyon could build its own loyalty app over a weekend. Second, the Digital Markets Act has been pushing Google to open up the Play Store. An AI-driven recommendation layer raises fresh questions about how that ranking actually works and whether Google's own apps get a quiet nudge upward.

Bob: And there's the quality question. If anyone can ship an app in an afternoon, the Play Store fills up with half-baked stuff, security holes, privacy issues. Google's review process is going to get tested.

Samantha: True. But the direction of travel is clear: building software is becoming a conversation, not a craft. Whether that's liberating or alarming depends on which side of the keyboard you're on.

Samantha: Quick interruption. If you listen to The State of Tech regularly, hit that like button and subscribe, that way you'll never miss an episode. Okay, moving on.

Iranian state-backed hackers use fake job offers and infected video apps to spy on aviation and energy firms.

Bob: Researchers at Palo Alto Networks, specifically their threat team Unit 42, have uncovered an Iranian state-backed espionage campaign with a clever twist. The hackers are posing as job recruiters on professional networks, reaching out to software engineers with attractive-sounding offers. As part of the "interview process", the target is asked to download a video application. That app is infected.

Samantha: And once it's installed, the attackers get deep access to whatever network that engineer is connected to. The targets so far include software engineers in the aviation industry, a US oil and gas firm, and organisations in Israel and several Gulf states. So critical infrastructure and energy, the usual high-value targets.

Bob: What makes this campaign nasty is the social engineering. You're not clicking a dodgy link in a spam email, you're talking for days or weeks with someone who seems like a legitimate recruiter, building trust, before they ever send you anything. By the time the malware lands, your guard is completely down.

Samantha: European companies in aerospace, defence, and energy should treat this as a direct warning. Iran has been escalating cyber activity, and European firms in those sectors share supply chains and engineering talent with the US and Israeli companies already being targeted. There's no reason to assume Frankfurt or Toulouse engineers aren't next on the list.

Bob: And it's a reminder that the weakest link is rarely the firewall. It's the person on LinkedIn who really wants that new job. Security teams can patch every server in the building, but if an engineer downloads a "coding test" from a fake recruiter, none of that matters.

Samantha: The practical fix is boring but works: separate the work laptop from anything you download for a recruitment process, verify recruiters through the company's official channels, and assume any unsolicited approach with a file attached is hostile until proven otherwise.

Trump administration vows to relocate half of global chip production to the US within three years.

Bob: The Trump administration has put a number on its semiconductor ambition: forty to fifty percent of the world's chip manufacturing capacity moved to US soil by January 2029, the end of the president's term. That is a staggering target, given Taiwan currently makes the lion's share of advanced chips.

Samantha: Trump pinned Taiwan's dominance on past US trade policy and said publicly he wants Taiwanese chipmakers to build in America. TSMC, the world's biggest contract chipmaker, has already committed to expanding its Arizona operations. The question is whether the rest of the industry follows, and on what timeline.

Bob: The honest answer is that two to three years is extremely tight for an industry where a single new factory takes four to five years to build and qualify. So "forty to fifty percent" is more political ambition than engineering plan. But even partial movement reshapes global supply chains for AI hardware, defence systems, and consumer electronics.

Samantha: For Europe this is uncomfortable. The European Chips Act is trying to pull a slice of manufacturing here too, with Intel projects in Germany and expansions in Ireland. If the US sucks up the bulk of new Taiwanese investment, Europe's share gets smaller. And European carmakers, who got hammered during the last chip shortage, are watching closely.

Bob: There's also the geopolitical layer. Taiwan's chip dominance has been described as its "silicon shield", the reason the world has a stake in defending it from China. If a meaningful slice of that production moves to Arizona, the calculus around Taiwan shifts. That's a much bigger conversation than just supply chains.

Samantha: Whether Trump hits his number or not, the direction is clear. Chips are now treated as strategic national assets, not just commercial products. Europe needs to decide quickly whether it's competing for that capacity or settling for being a customer.

Bob: Right, to close out, two things you can actually use today, starting with something fun for the smart home crowd.

LG's Cloid home robot is making breakfast, and it signals what's coming to European kitchens.

Samantha: LG has been showing off its AI home robot, called Cloid, and the demo at CES this year had it preparing breakfast. Yes, an actual robot doing kitchen tasks. It's not in shops yet, but LG is signalling this is a serious product line, not a one-off concept.

Bob: What you can do today is have a proper look at it. LG has released demo videos and product information you can find through their official channels. It gives you a realistic sense of where consumer robotics actually is in 2026, beyond the hype.

Samantha: And it's worth understanding what Cloid actually does. It's not a humanoid in an apron. It's a mobile AI assistant on wheels that can interact with smart home appliances, your oven, fridge, lights, and coordinate small tasks. The "making breakfast" demo is really about orchestration: telling the coffee machine to start, the toaster to warm up, and reminding you to grab the milk.

Bob: For European households this matters because the smart home market here is fragmented. Lots of different standards, Bosch, Siemens, Miele, Philips Hue, all speaking slightly different languages. A robot that can act as a central coordinator could finally make the smart home feel coordinated rather than chaotic. Assuming LG plays nicely with other brands, which is a big assumption.

Samantha: Pricing isn't confirmed for Europe yet, but if you're curious about where this category is going, spending fifteen minutes with LG's demo material is genuinely useful. It tells you what to expect when these things start landing in shops over the next year or two.

Bob: And it's a reminder that AI isn't just chatbots in a browser. It's increasingly going to walk around your house carrying a cup of coffee.

The UAE's mainframe-to-AI shift offers a free blueprint European public sector teams can study today.

Samantha: And the second one is more for the curious-professional crowd. The United Arab Emirates is going through a rapid shift, replacing old mainframe systems, the big legacy computers that have run government and finance for decades, with AI, cloud, and modern digital infrastructure. It covers education, healthcare, energy, cybersecurity, and government services.

Bob: What you can do today is read up on how they're doing it. The UAE publishes a lot of its digital strategy openly, the documents are in English, and they're surprisingly readable. If you work in any kind of public sector or large enterprise IT role in Europe, it's a useful free reference.

Samantha: Because here's the thing. A lot of European governments and big institutions still run on mainframes. Tax offices, banks, social security systems. Replacing them is hard, expensive, and politically painful. The UAE is doing it at speed because they have central direction and money to spend. Europe doesn't have either of those, but the technical playbook still translates.

Bob: Specifically, look at how they sequence things, healthcare and education first, then critical infrastructure, with cybersecurity wrapped around all of it. That order matters. Doing it the other way round, modernising power grids before you've got AI security in place, is how you create vulnerabilities at national scale.

Samantha: It's also an interesting contrast with the European approach, which is more regulation-first. The UAE moves fast and figures out the rules later. Europe debates the rules for years and then moves. Neither is obviously right, but seeing a different model in action is genuinely useful if you're trying to push a project through your own organisation.

Bob: So that's your weekend reading sorted. Free, in English, and directly relevant if you work anywhere near public sector technology.

Samantha: Today we covered: Anthropic's AI finding ten thousand software bugs, Google's no-code Android apps, the Iranian fake-recruiter spy campaign, Trump's chip relocation plan, LG's breakfast-making home robot, and the UAE's mainframe-to-AI overhaul.

Bob: Want to know more or react? Visit stateoftech.eu or email us at info@doorzetters.net.

Bob: State of Tech, the tech world in 15 minutes.