Videos imFedndyXYQ
Using LLMs to Secure Source Code — Eugene Yan, Anthropic
Scene timeline
50 shot(s).
keyframes kept every frame deduplicated
What was stored
- cues
- 306
- whisperx 306
- chunks
- 37
- from 306 cues
- keyframes
- 20
- kept of 50 captured
- frames with text
- 20
- 387 lines read
- chapters
- 21
- from the source metadata
- keyframe bytes
- 6.1 MB
- word timings on 306 cues
Provenance
| stage | state | model | started | took |
|---|---|---|---|---|
fetch |
done | — | 2026-08-11 01:01 | 1m 14s |
stt |
done | — | 2026-08-11 01:02 | 25s |
chunk |
done | — | 2026-08-11 01:03 | 0s |
text_embed |
done | — | 2026-08-11 01:03 | 1s |
keyframe |
done | — | 2026-08-11 01:03 | 2m 03s |
ocr |
done | — | 2026-08-11 01:05 | 9s |
frame_embed |
done | — | 2026-08-11 01:05 | 4s |
Frames, and what the machine read
-
- AlEngineer0.96
- World's Fair1.00
-
- AIEngineer0.95
- World's Fair0.99
-
- LAB & PLATINUM SPONSORS0.99
- Amazon AGI Lab0.98
- ANTHROP\C1.00
- Google DeepMind1.00
- MINIMAX0.97
- OpenAI0.92
- Akamai1.00
- arize0.92
- aws1.00
- Braintrust bright data0.98
- B1.00
- Browserbase1.00
- docker1.00
- :neo4j0.93
- ORACLE1.00
- PayPal1.00
- qodo1.00
- reducto1.00
- Sonar1.00
- Makers of0.99
- togetherai1.00
- Unblocked1.00
- WorkOS1.00
- SonarQube1.00
-
- AlEngineer0.99
- World's Fair0.99
-
- AlEngineer0.99
- World's Fair0.97
- Working with Models1.00
- PRESENTED BY1.00
- to Secure Source Code0.99
- Microsoft1.00
- Eugene Yan·Anthropic1.00
- AI Engineer World's Fair ·20260.98
- ANTHROPIC1.00
- World's Fair0.89
- Engineering the future of Al0.99
-
- AlEngineer0.97
- What we'll cover0.97
- World'sFair1.00
- PRESENTED BY0.96
- Why now: the trends we're seeing1.00
- Microsoft1.00
- How to work with models for security, and potential bottlenecks0.99
- How to get started now + resources to help1.00
- ANTHROPIC1.00
- World'sFair1.00
- Engineering the future of Al1.00
-
- AlEngineer0.98
- World'sFair1.00
- PRESENTED BY0.99
- Sectionl0.93
- Whynow1.00
- Microsoft1.00
- Three trends: Model capability, Vulns found, Shifting bottleneck1.00
- ANTHROPIC1.00
- World'sFair1.00
- TRACK 5· JUNE 30, 20260.94
- Security1.00
-
- AlEngineer0.99
- Model capability on cyber tasks is doubling every ~5 months0.99
- World's Fair0.96
- AISI Cybersecurity Time Horizons0.99
- AISI IANSECUITY0.75
- AISI CTF suite, 80% rellability, 2.5M token cap, reasoning models only0.98
- INSTITUTE1.00
- Previous AISI estimate (Nov 2025): -8mo doubling0.98
- Frontier post-reasoning trend (pre-Mythos): -4.7mo doubiing0.98
- Caveats:1.00
- B% l le)0.65
- 4d:0.92
- - Models evaluated under a 2.5M token cap; uncapped time horizons would be0.98
- • Narrow cyber tasks only; no claim about generalization to other capability0.97
- significantly higher1.00
- PRESENTED BY1.00
- - Mythos Preview (new) and GPT-5.5 saturate the task suite, resulting in highly0.98
- uncertain time horizons0.98
- domains1.00
- Microsoft1.00
- 10.0h1.00
- Mythos Preview (new)1.00
- GPT-5.51.00
- 1.0h1.00
- Claude Opus 4.6*0.95
- GPT-5.3-Codex1.00
- Claude 4 Opus1.00
- GPT-51.00
- Claude Sonnet 4.51.00
- -Claude Opus 4.50.97
- 6m1.00
- Claude 3.7 Sonnet1.00
- Provider1.00
- Anthropic1.00
- OpenAl0.94
- 2025-011.00
- 2025-041.00
- 2025-071.00
- 2025-101.00
- 2026-011.00
- 2026-041.00
- 2026-071.00
- 2026-101.00
- Model Release Date1.00
- ANTHROPIC1.00
- UK AISI — How fast is autonomous Al cyber capability advancing?0.97
- World's Fair0.92
- TRACK 5·JUNE 30,20260.98
- Security1.00
-
- AlEngineer0.97
- Mozilla found more vulns in April 2026 than all of 20250.98
- World'sFair1.00
- Firefox Security Bug Fixes by Month1.00
- All Sources • All Severities0.96
- 4231.00
- 611.00
- 761.00
- 211.00
- 201.00
- 261.00
- 311.00
- 171.00
- 211.00
- 221.00
- 171.00
- 181.00
- 261.00
- 191.00
- 201.00
- 251.00
- 20251.00
- JAN1.00
- 20251.00
- FEB1.00
- 20251.00
- MAR1.00
- 20251.00
- APR1.00
- 20251.00
- MAY1.00
- 20251.00
- JUN1.00
- 20251.00
- JUL1.00
- 20251.00
- AUG1.00
- 20251.00
- SEP1.00
- 20251.00
- OCT1.00
- 20251.00
- NOV1.00
- 20251.00
- DEC1.00
- 20261.00
- JAN1.00
- 20261.00
- FEB1.00
- 20261.00
- MAR1.00
- 20261.00
- APR1.00
- ANTHROPIC1.00
- Mozilla Hacks — Behind the Scenes: Hardening Firefox0.99
- World'sFair0.97
- TRACK 5· JUNE 30, 20260.94
- Security1.00
-
- AlEngineer0.98
- What are some notable public vulns and exploits?0.99
- World'sFair1.00
- Log4Shell1.00
- Heartbleed1.00
- CVE-2021-44228· Dec 20210.99
- CVE-2014-0160· Apr 20140.99
- A bug in a Java logging library let attackers1.00
- A bug in OpenSSL — the encryption library0.99
- run code on your server just by getting it to0.98
- behind most of the internet's HTTPS traffic1.00
- log a string. Minecraft, iCloud, Steam, AWS0.99
- — let anyone read server memory, including0.99
- —all affected.0.97
- passwords and private keys.1.00
- 93% of enterprise cloud environments0.98
- Half a million HTTPS servers0.99
- were vulnerable. Belgium's Defence0.99
- vulnerable; 4.5M patient records0.97
- Ministry was breached within days; one0.97
- stolen in one breach. Sat undetected0.99
- fintech platform leaked 2M users' data.0.99
- in open-source code for two years.0.98
- ANTHROPIC1.00
- Log4Shell - Heartbleed - Wikipedia0.94
- World'sFair0.93
- TRACK 5· JUNE 30, 20260.96
- Security1.00
-
- AlEngineer0.98
- World'sFair1.00
- Section Il0.89
- Six simple steps1.00
- To building your own agentic harness for security1.00
- ANTHROPIC1.00
- World'sFair1.00
- TRACK 5• JUNE 30, 20260.94
- Security1.00
-
- AlEngineer1.00
- Distilling what we learned into six steps1.00
- World's Fair0.99
- Setup—invest once0.98
- Cycle — repeat until clean0.97
- Threat model0.98
- Sandbox1.00
- Discovery1.00
- Verification1.00
- Triage0.98
- Patching1.00
- Decide what counts1.00
- Build a runnable target0.99
- Surface candidates1.00
- Confirm what's real1.00
- Rank what matters0.97
- Fix and find varlants0.99
- Setup feeds every step0.97
- re-scan periodically, or with each new feature or commit1.00
- The threat model scopes the scan1.00
- and calibrates severity. The sandbox1.00
- is where every proof of concept fires.0.98
- ANTHROPIC1.00
- Using LLMs to secure source code — Anthropic0.97
- World's Fair0.98
- TRACK 5· JUNE 30, 20260.94
- Security1.00
-
- AlEngineer0.99
- RUNNING EXAMPLE1.00
- World's Fair0.98
- Meetorder-service1.00
- 0000.72
- shop.example.com/orders?id=ORD-24120.99
- Find your order1.00
- PRESENTED BY0.97
- Microsoft1.00
- 0RD-24120.97
- Look up0.96
- Order #ORD-2412 Dellvered0.97
- [email protected]·2items·$148.001.00
- 1234 Market St, San Francisco CA· Delivered Tue, Jun 230.97
- Track package0.98
- View invoice0.99
- Start a return0.99
- Report an issue0.98
- ANTHROPIC1.00
- World's Fair0.92
- TRACK 5· JUNE 30, 20260.94
- Security1.00
-
- AlEngineer0.99
- Sandbox: Isolate the agent, make runs reproducible0.99
- World's Fair0.97
- Why1.00
- What and how1.00
- One offensive-security team built a0.99
- Isolate1.00
- harness with a simple rule: it's only a0.99
- Target and PoCs in a microVM with egress locked down0.99
- true positive if the agent can build a0.99
- proof of concept and run it on the test0.97
- Never mount credentials, tokens, or prod secrets into the agent's context1.00
- bed. After six weeks, "the biggest0.96
- Enforce constraints via configuration, not in the prompt1.00
- efficacy lever has been giving the0.98
- model test beds, live systems, and0.98
- Reproducibility1.00
- running the PoCs."1.00
- Pin image tags, commit SHAs, and dependency versions1.00
- Snapshot the environment so every run sees the same code and deps0.99
- A reproducible sandbox lets a separate agent re-verify each vuln0.98
- 1· Threat model0.95
- 2·Sandbox0.99
- 3 · Discovery0.88
- 4·Verification0.99
- 5 · Triage0.91
- 6·Patching0.99
- ANTHROPIC1.00
- World's Fair0.98
- TRACK 5·JUNE 30,20260.98
- Security1.00
Transcript
306 cues· 3,765 words· 20,921 chars
- 0:12 Hi, I'm Eugene, member of Technical Staff at Anthropic.
- 0:16 I've spent the last several months working with security teams and Claude to find and fix vulnerabilities in codes and systems.
- 0:21 So I'll share with you what we've learned as much as we can.
- 0:24 Before I get started, quick show of hands.
- 0:26 How many of you here are security engineers in your day job?
- 0:31 OK, OK. How many of you here are engineers in your day job?
- 0:34 Oh, sweet.
- 0:35 OK, great.
- 0:36 I have a better understanding of how to give this talk now.
- 0:39 Security engineers in the room, please don't boo me if I oversimplify things.
- 0:42 I want to get this message out to as many people as I can.
- 0:45 So first I want to share with you three high-level trends that we are seeing in terms of model capabilities, right?
- 0:50 Number of vulnerabilities found and where the bottleneck is shifting to.
- 0:54 Then I want to distill the lessons we've learned from working with dozens of organizations to improve their security posture, as well as the bottleneck that you might encounter and how you can try to address it and prep for it.
- 1:03 And finally, I want to share how you can get started this week with links to resources.
- 1:09 So why do we care so much about cybersecurity now?
- 1:12 Time horizon benchmarks track the length of time an AI model can complete a task measured against an actual human doing the task.
- 1:23 So we all know about the meta eval task, how much knowledge one agent can do.
- 1:28 The UK AI Security Institute has a cybersecurity version of this.
- 1:32 These tasks require identifying exploiting security weaknesses in target systems and testing skills like reverse engineering and web exploitation.
- 1:40 So in this chart, we see that models are able to increasingly do longer cybersecurity tasks.
- 1:46 But what's also interesting is that you kind of see a step jump against the previous regression line.
- 1:51 So these models are a step improvement in capability.
- 1:55 And what does this step improvement in capability buy us?
- 1:58 Recently, Mozilla Firefox published a number of security bug fixes they made each month.
- 2:04 The average in 2025 was about 20, 20-ish.
- 2:08 And then you can see in February and March, it kind of 3x'd to about 60 and 70.
- 2:13 And then in April, it 7x'd to 400.
- 2:18 So what this means is that what's happened in April is 20x of last year's average.
- 2:25 They attributed about two-thirds of this to Mito's preview, about 271, which shows that frontier models can help defenders like yourself find and fix vulnerabilities at scale.
- 2:37 We also, one of some notable vulnerabilities, hands up, who here remembers log4shell?
- 2:43 Anyone?
- 2:43 Anyone was here over the December holidays like scrambling to patch this stuff too?
- 2:47 So log4shell,
- 2:50 It's a bug in the Java logging library.
- 2:51 If an attacker sends a string, you log it, the attacker can run code on your system.
- 2:57 The Belgium Defense Ministry was breached within days, and a fintech platform leaked 2 million users' data.
- 3:03 And then before that, we had Heartbleed, which is a bug in OpenSSL.
- 3:07 So much of the internet runs on OpenSSL, and we all know what impact it had.
- 3:13 This is entropic sharing of our own work, scanning more than 1,000 open source repos.
- 3:20 From 23,000 candidates, 6,200 of them were rated as high or critical.
- 3:25 And at the time of the update, 1,600 of them were reported to maintainers and about 100 patched upstream.
- 3:32 We shared our observation that finding vulnerabilities now is quite straightforward.
- 3:39 The bottleneck has now shifted to verification triage and patching.
- 3:43 And I want to share with you everything we've learned about that so you can get ahead of it.
- 3:48 So how do we do this in our own systems and code bases?
- 3:52 Two words, agentic harnesses.
- 3:54 I'm citing Mozilla again.
- 3:55 And this was even before they worked with Mito's preview.
- 3:58 I'm going to read off the screen here.
loading
Chapters
- 0:00 Working with security teams to find and fix vulnerabilities
- 0:49 Three trends in model security capability
- 1:16 Cybersecurity benchmarks and the step jump in capability
- 1:54 Mozilla's 20x jump in monthly security fixes
- 2:44 Log4Shell, Heartbleed, and why this matters
- 3:22 Anthropic's scan of a thousand open source repos
- 3:35 The bottleneck shifts to verify, triage, and patch
- 3:48 Why agentic harnesses changed the game
- 4:29 The six step workflow
- 5:31 A running example: the order service
- 5:45 Step 1: the threat model and 90% true positives
- 7:42 Step 2: the sandbox for isolation and reproducibility
- 9:24 Step 3: discovery and the five line SQL injection
- 11:44 Step 4: independent adversarial verification
- 13:36 Step 5: triage and the scarcity of engineer attention
- 15:52 Step 6: patching and closing the loop
- 17:19 It all looks like a machine learning pipeline
- 17:43 The non technical bottlenecks are harder
- 18:47 Organizational bottlenecks: routing, severity, bandwidth
- 20:05 Three takeaways and how to start this week
- 20:38 Scanning was never the bottleneck.