AI company Anthropic’s new AI model, Claude Mythos, recently scanned the Firefox web browser for vulnerabilities. The AI tool uncovered 271 vulnerabilities in the software code. Some had gone undetected for decades. A team of human experts might take months or years to find the same flaws. Mythos did it in days.
Anthropic considered this capability powerful enough that they chose not to release the model publicly. Instead, they provided access to roughly 50 major organizations – including Microsoft, Apple, Google, and the Linux Foundation – to scan their own systems, along with $100 million in usage credits for this defensive security work.
Why Election Officials Should Pay Attention
This Mythos story isn’t really about AI. It’s about software quality and what happens when the cost and time of finding hidden flaws approach zero. In the wrong hands, these tools can be used by malicious actors to find and exploit existing vulnerabilities more quickly than before. Three things have changed:
- Asymmetric Speed: AI can find vulnerabilities – flaws that even the software’s creators don’t know exist – far faster than any human team. What once took skilled researchers weeks or months now takes AI only minutes or days.
- Massive Scale: Attackers can use AI to scan thousands of systems simultaneously, probing for opportunities into election technology, such as internet-facing voter portals, websites, or election returns portals.
- Obscurity: You can no longer rely on the idea that a flaw won’t be found because it’s buried deep in the code. AI tools have become very good at finding those hidden flaws.
The fundamentals of election security are strong, and the practices that protect against AI-enabled threats are the same ones you already know. But the urgency is higher. Here are concrete steps to consider:
Operations:
- Update your software (patching) to close security gaps. AI has narrowed the window between disclosure and exploitation.
- Train your staff on phishing and social engineering attacks. AI makes them more targeted and more convincing – referencing contacts by name, mimicking actual vendors.
- Have a backup plan so your office can keep operating even if the primary system is compromised.
Vendors and Procurement:
- Ask your vendors directly: “What are you doing to find and fix your own vulnerabilities?”
- Require your vendors to provide a current, machine-readable Software Bill of Materials (SBOM). A living SBOM, monitored for known vulnerabilities, can serve as an early warning system.
- Require security in your contracts – built-in multi-factor authentication, transparent vulnerability disclosure, and regular patching.
* In a full analysis, Election Security Consultant Spencer Wood breaks down exactly what election officials should be demanding from their vendors, starting with an SBOM.
AI is accelerating the discovery of problems that were always there. The solution is the same disciplined approach that has always mattered: rigorous software testing, strong vendor contracts, layered security, staff training, and clear public communication. AI makes those practices more necessary than ever before.
The Situation Room focuses on real security incidents and threats in the news relevant to election security. To review previous issues, see the newsletter archive.
