Human Tech Tree
Unsolvedopen · Research Frontier · Today (unsolved as of Oct 2026)

Information / Communication & Networks

Robust Cybersecurity

Software and networks that withstand attacks even though flaws are everywhere, while AI speeds up both attack and defense.

Open in the interactive tree →

Modern software has millions of lines of code in which bugs are unavoidable. Microsoft (2019) and the Chromium project (2020) each found that roughly 70% of their serious vulnerabilities were memory-safety errors that safe programming languages can prevent, yet legacy systems remain. At the same time AI makes finding and exploiting flaws cheaper.

As of October 2026

According to Anthropic (April 2026), Claude Mythos Preview found thousands of zero-day vulnerabilities in major operating systems and web browsers, including a 27-year-old OpenBSD flaw and a 16-year-old FFmpeg flaw. The model was not released publicly; selected defenders got access through Project Glasswing (11 founding members plus over 40 further organizations). Its successor Claude Mythos 5 is available only to organizations verified through Anthropic’s programs such as the Cyber Verification Program. The migration to post-quantum cryptography is only starting.

What is missing

  • Verified or memory-safe software at large scale (instead of patching)
  • Patch speed of hours instead of weeks, especially for devices in the field
  • Secure supply chains for software and components
  • Liability, incentives and skilled staff
  • Defense against AI-driven attacks at machine speed

Becomes possible once solved

  • Critical infrastructure without permanent emergency operation
  • Trust in connected medical and vehicle systems
  • Secure government and financial systems

Open steps

  • Finding flaws at scale High AI leverageFind exploitable bugs, including logic flaws, in old and new code faster than fuzzers and manual audits, and triage them.
  • Safe automatic patching High AI leverageWrite patches that fix a flaw without breaking the program, validated by tests and proofs, so maintainers can approve quickly.
  • C and C++ to memory-safe code High AI leverageTranslate large legacy C and C++ codebases into Rust or other safe languages with the same behavior, and show equivalence.
  • Verified critical code at scale Medium AI leverageProve properties of operating-system, browser and protocol code with machine-checked proofs at a cost projects can afford.
  • Defense at machine speed Medium AI leverageDetect and contain AI-driven intrusion campaigns in minutes across networks and cloud, with few false alarms.

Where AI could help

High AI leverage. Finding and fixing flaws is code analysis at scale where AI already works; patch rollout, liability and AI-equipped attackers limit the gain.

  • Scan large codebases for memory-safety and logic flaws faster than fuzzers and manual audits
  • Draft and test patches automatically for maintainers to review
  • Translate C/C++ into memory-safe languages and generate proofs for critical code
  • Triage alerts and detect attacks at machine speed in networks

Shown so far

  • In October 2024 Google's Big Sleep agent found an exploitable stack buffer underflow in SQLite that OSS-Fuzz had missed; it was patched the same day, before release. source
  • In August 2025 finalists of DARPA's AI Cyber Challenge found 54 of 63 planted vulnerabilities, patched 43, and found 18 real ones with 11 patches submitted. source
  • In April 2026 Anthropic said (company claim) its Claude Mythos Preview found thousands of high-severity vulnerabilities, including a 27-year-old OpenBSD flaw, and shared them with defenders. source

Prerequisites

Unlocks

Sources

More in Communication & Networks · Research Frontier · Today

All 38 points in Communication & Networks →

Open in the interactive tree →