Here’s what Mythos is really exposing inside banking and financial services
In April, Anthropic disclosed that its new AI model, Claude Mythos, had found a vulnerability in OpenBSD that survived 27 years of human review. Mozilla used the same model to find 271 security flaws in Firefox in a single evaluation pass. Anthropic says Mythos has identified “thousands of high-severity vulnerabilities, including some in every major operating system and web browser.” Bank of England governor Andrew Bailey put it more bluntly: Anthropic “may have found a way to crack the whole cyber risk world open.
LATEST ARTICLES
Introducing Code Repositories in Kosli
Kosli gives your organization a complete picture of software delivery - every build, scan, deployment, and compliance event tracked. Until now that picture was most useful to the people managing …
Kosli and Adaptavist Partner to Automate Governance for AI driven Software Delivery
Today, Kosli and Adaptavist announce a strategic partnership to help regulated enterprises automate governance for AI driven software delivery - making it automated, continuous, and evidence-driven …
Introducing kosli evaluate: Rego Policy Evaluation for Your Compliance Data
If you’re evaluating compliance controls against your Kosli trail data today, there’s a good chance you’ve written some glue code to make it work. A script that pulls trail data from …
Governing AI Generated Code - A Hands-On Experiment with Entire and Kosli
Can you create an audit trail for what your AI agent actually did, and enforce rules about what it was allowed to do? Here’s what I found after spending a session wiring the two tools together. …
A Technical Guide to Controls Engineering
Why Software Delivery Governance Matters The modern world runs on mission-critical software. It moves our money, drives our cars, diagnoses our illnesses, and fundamentally improves our lives. But, …
Environment support in Terraform Provider for Kosli - v0.2.0
We’re excited to announce support of physical environments in the Terraform Provider for Kosli! What’s Included Environment Management: Full lifecycle support for creating, updating, and …
FEATURES
Here’s what Mythos is really exposing inside banking and financial services
In April, Anthropic disclosed that its new AI model, Claude Mythos, had found a vulnerability in OpenBSD that survived 27 years of human review. Mozilla used the same model to find 271 security flaws …
Building a Control Framework for the AI SDLC
Since November, Kosli’s own engineering team has been running a live experiment: what happens to code review when the thing generating the code - and increasingly, the thing reviewing it - is an …
How Norsk Tipping uses feature flags to govern their deployments
Norsk Tipping is Norway’s state-owned gaming operator, running 2,500 to 3,000 production releases a year across iOS, Android, web and backend systems. Like every regulated organisation at scale, …
NEWS
Kosli and Adaptavist Partner to Automate Governance for AI driven Software Delivery
Today, Kosli and Adaptavist announce a strategic partnership to help regulated enterprises automate governance for AI driven software delivery - making it automated, continuous, and evidence-driven …
Kosli and Team Topologies - A Strategic Partnership for SDLC Governance
We’re delighted to announce a strategic partnership between Kosli and TeamTopologies - a collaboration that brings together SDLC Governance automation with the world’s leading framework …
Enhanced Environment Compliance with Environment Policies
We’re excited to announce an important enhancement to Kosli that will improve how environment compliance is managed across your organization. Starting with our next release, all compliance …
TECHNOLOGY
How Norsk Tipping uses feature flags to govern their deployments
Norsk Tipping is Norway’s state-owned gaming operator, running 2,500 to 3,000 production releases a year across iOS, Android, web and backend systems. Like every regulated organisation at scale, …
Diff-erent Perspectives: How Specialized LLM Personas Catch More Bugs
We’ve built a multi-LLM PR reviewer that runs on every pull request in a couple of our own repos. Two independent models look at each change in parallel, each wearing a set of “persona …
Governing AI Generated Code - A Hands-On Experiment with Entire and Kosli
Can you create an audit trail for what your AI agent actually did, and enforce rules about what it was allowed to do? Here’s what I found after spending a session wiring the two tools together. …