Every time a frontier AI model finds a real vulnerability before a human does, someone in cybersecurity treats it as proof the arms race is tilting toward defenders. It isn’t that simple. This week, Anthropic’s Mythos model reportedly caught a flaw in a small stretch of Linux kernel code, the epoll subsystem, and got credit for it. Sitting right next to that flaw, in the same code, was a separate bug the model missed entirely: CVE-2026-46242, nicknamed “Bad Epoll,” which lets an ordinary user with zero special access become root on Linux desktops, servers, and Android devices. Same neighborhood, same model, one catch and one miss. That’s not a defender’s scoreboard. That’s a coin flip with better production values, and it landed the same week two Chinese labs shipped models that go head-to-head with the top US frontier systems, and a critical flaw in an AI code editor showed that the tools defenders are adopting can become the blast radius themselves.
Cybersecurity Bought The AI Bug-Hunting Story Early
The pitch has been consistent for two years: point a capable enough model at a codebase and it will surface the vulnerabilities humans miss, at a scale humans can’t match. Bad Epoll is a useful reality check on that pitch. Mythos found a bug in the epoll code. It didn’t find the bug. An unprivileged local user exploiting CVE-2026-46242 gets full root, no special access required, on any unpatched machine running that kernel version, which includes a meaningful slice of the Android install base. If a model with genuine code-reasoning capability can walk right past a root-level privilege escalation sitting a few functions away from the one it did catch, then “the AI already checked this” is not a sentence any security team should be comfortable saying out loud.
None of this means AI-assisted vulnerability research is worthless. It means it’s probabilistic, not exhaustive, and attackers only need the one bug it misses. Treat AI-assisted code review the way you’d treat a very fast junior analyst: useful for triage and first-pass coverage, not a substitute for the patch cycle, and definitely not a reason to slow down on kernel and OS updates. If Bad Epoll affects anything in your fleet, that patch goes out on emergency timelines, not the next maintenance window.

Your AI Code Editor Is Now Part Of The Blast Radius
Separately, and in the same week, researchers disclosed a set of flaws in the Cursor AI code editor, tracked as DuneSlide, that enable zero-click prompt injection attacks capable of escaping the editor’s sandbox and executing arbitrary code on the underlying operating system. Read that again: zero-click. A developer doesn’t have to run anything malicious or approve a suspicious suggestion. The exploit rides in through content the editor’s AI assistant reads, like a file, a comment, or a piece of retrieved context, and turns that into OS-level remote code execution.
Sandboxes Assume The Model Behaves. That’s The Whole Problem.
The sandbox around an AI coding assistant is designed to contain what the assistant does, not to account for the assistant being manipulated into doing something else entirely by text it was never supposed to trust. Prompt injection breaks that assumption at the root. Every AI-integrated developer tool your org has adopted, code editors, IDE plugins, CI copilots, inherits this same weakness by default unless someone has deliberately hardened it. If your security team hasn’t inventoried which developer tools embed an LLM with tool-calling or file-system access, that inventory is now overdue, not optional.
Chinese Model Releases Mean Attackers Don’t Need Your Vendor’s AI
The third piece of this week’s picture: two new large language models out of Chinese firms now compete directly with top-tier US frontier and mainstream models. That matters for defenders less because of who built them and more because of what it does to the gap. When frontier-level reasoning stops being scarce and expensive to access, attackers no longer need to be inside a well-funded lab to get AI-assisted vulnerability discovery, phishing generation, or exploit chaining. The capability that used to be a defender’s edge, or at minimum a slow-moving advantage, becomes ambient. Threat detection built around the assumption that sophisticated, AI-assisted attacks are rare and well-resourced needs to retire that assumption. It’s cheaper for attackers to get that capability than it’s ever been.
What Actually Reduces Risk While The AI Race Plays Out
None of the three stories above have a product fix. They have an operational one. Here’s the practical version:
- Patch on exploit timelines, not maintenance windows. Bad Epoll is a local privilege escalation, which means it’s a serious follow-on for any initial-access foothold. Confirm your kernel and Android fleet versions against CVE-2026-46242 and push the fix ahead of the normal cycle.
- Inventory every AI-integrated developer tool. Code editors, IDE extensions, CI/CD copilots. If it embeds an LLM with file access or tool-calling, it’s part of your attack surface, and it needs the same patch and configuration scrutiny as any other privileged software.
- Scope what those tools can touch. Least-privilege isn’t just for service accounts anymore. An AI coding assistant that can read arbitrary repo content and execute local commands should not also have unrestricted OS-level access. Segment it.
- Don’t retire signature-based threat protection, but stop trusting it alone. As AI-assisted attacks get cheaper to produce, behavior-based threat detection, anomalous process spawning, unexpected privilege escalation, unusual outbound connections from developer machines, catches what signatures were never built for.
- Keep the boring stuff boring. Firewall rules, brute-force lockouts on exposed services, and basic security hardening on endpoints still stop the majority of opportunistic attacks, AI-assisted or not. Defense in depth doesn’t become obsolete because the top layer of the stack got more interesting.
- Rehearse incident response for a faster attacker. If AI shortens the time between vulnerability disclosure and working exploit, your response plan needs to assume less lead time, not the same lead time with better tooling bolted on.
Frequently Asked Questions
- Does AI-assisted vulnerability discovery actually make software safer?
- It helps at the margins by catching bugs faster in some cases, but it’s not exhaustive. The Bad Epoll case shows a capable model can miss a serious flaw sitting next to the one it found, so patch cycles and manual review still matter.
- What makes zero-click prompt injection different from a normal exploit?
- It requires no user action beyond the AI tool processing untrusted content, like a file or piece of retrieved text. There’s no malicious link to click or file to open, which makes it harder to catch with user-awareness training alone.
- Should we stop using AI coding assistants until these flaws are fixed?
- Not necessarily, but you should confirm patches are applied, restrict what the tool can access on the host system, and treat it as privileged software requiring the same scrutiny as any other tool with file and execution access.
Sources
- New “Bad Epoll” Linux Kernel Flaw Lets Unprivileged Users Gain Root, Hits Android
- Critical Cursor AI Code Editor Flaws Could Lead to OS-Level Remote Code Execution
- Chinese LLMs Broaden the Gap Between Attackers & Defenders
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
