05-08-2026

Mythos finds 271 Firefox bugs humans missed

PLUS: Fitbit is dead, Google Health and Gemini launch, and Moonshot AI hits $20B

Good morning, AI enthusiasts. Anthropic's Mythos model spent two months working through Firefox's codebase and surfaced 271 high-severity security vulnerabilities — bugs that human reviewers had missed, some for as long as 15 years.

The scale of the results is hard to ignore: Firefox shipped 423 bug fixes in April 2026 alone, compared to just 31 in the same month a year prior. The question now is whether AI-assisted security review moves from an impressive case study to a standard part of how development teams protect their software.

In today's AI recap:

  • Anthropic's Mythos finds 271 Firefox bugs humans missed
  • Google retires Fitbit, launches Gemini-powered Health app
  • Moonshot AI hits $20B valuation as Kimi gains global traction
  • OpenAI's new voice API brings GPT-5-class reasoning to real-time conversation

AI Uncovers 271 Firefox Bugs Humans Missed

From Larry Bruce: "Anthropic's Mythos model just delivered one of the most concrete proofs yet that AI agents can do serious, high-stakes security work at scale. For developers and builders in our audience, this is a clear signal that AI-assisted code review is moving from experiment to essential workflow. — Larry Bruce, Editor, BDCbox"

The Recap: Anthropic's Mythos AI model, working alongside Mozilla's engineering team, found 271 high-severity security vulnerabilities in Firefox over just two months — with almost no false positives.

Unpacked:

  • Mythos used a specialized setup called a 'harness' that mimics exactly how human Mozilla developers work, letting it find real bugs instead of flooding engineers with useless noise.
  • The results show clear scale: Firefox shipped 423 bug fixes in April 2026, compared to just 31 in the same month a year earlier.
  • Among the most alarming findings were bugs that had been sitting undetected in Firefox's code for up to 15 years, including sandbox vulnerabilities that qualify for Mozilla's top $20,000 bug bounty.

Bottom line: AI-assisted bug hunting is becoming an essential layer in software security, catching vulnerabilities that have quietly slipped past human reviewers for years. For developers and security teams, this signals a shift toward using AI not just to write code, but to actively defend it.

Fitbit Is Dead. Google Health's AI Coach Is Here.

From Larry Bruce:
"Google's decision to retire the Fitbit app signals something bigger — AI is now moving into the center of personal health management. For professionals and early adopters already leaning on AI to streamline their work, this same shift is now coming for how you track and manage your body. — Larry Bruce, BDCbox"

The Recap: Google is officially retiring the Fitbit app on May 26 and replacing it with the new Google Health app — a Gemini-powered platform that can ingest your medical records and act as a personalized AI health coach.

Unpacked:

  • The Google Health app connects directly to your medical records, letting the Gemini-powered Health Coach give you personalized guidance based on your actual health history — not just your activity data.
  • Google validated its Health Coach with health experts and Steph Curry's performance team, lending real-world credibility to the coaching recommendations users will receive.
  • The new Fitbit Air is a screenless $99 wearable with a full week of battery life, targeting users who want continuous health monitoring without a bulky smartwatch — positioning it as a direct Whoop competitor.

Bottom line: Google is consolidating its entire health and fitness ecosystem into one AI-powered app, and the Google Fit app is also shutting down later this year as part of that transition. The ability to feed your actual medical history into an AI coach is a meaningful step forward for personalized health guidance.

Moonshot AI Hits $20B as Open-Weight Models Go Global

From Larry Bruce: Moonshot AI's latest funding round is one of the clearest signals yet that the global AI race has real competitors beyond the usual Silicon Valley names. For developers and builders in our audience, this is a story worth watching closely — the tools you reach for tomorrow may look very different from the ones you use today. — Larry Bruce, Editor, BDCbox

The Recap: Beijing-based Moonshot AI — the company behind the Kimi open-weight model series — just raised $2 billion at a $20 billion valuation, up from just $4.3 billion at the end of 2025, making it one of the fastest valuation climbs in recent AI history.

Unpacked:

  • Moonshot's valuation jumped from $4.3 billion to $10 billion and then to $20 billion in roughly six months, with the latest round led by Meituan's VC arm and backed by investors including Tsinghua Capital, China Mobile, and CPE Yuanfeng.
  • Kimi K2.6 is now the second-most-used LLM on OpenRouter globally, showing that developers worldwide are actively choosing open-weight models built outside the US for real projects.
  • Moonshot crossed $200 million in annual recurring revenue as of April 2026, putting it in the same competitive conversation as other Chinese AI challengers like DeepSeek, Zhipu AI, and MiniMax.

Bottom line: The open-weight AI model market is no longer a US-dominated story — Chinese labs are earning genuine developer adoption at a global scale. Professionals building AI-powered products now have a wider, more competitive set of capable models to choose from than ever before.

OpenAI's New Voice API Can Listen, Translate, and Reason

From Larry Bruce:
"OpenAI just made a big move for anyone building voice-driven products, and the implications go well beyond basic voice commands. For developers and entrepreneurs on the cutting edge, this is a signal that real-time voice AI is quickly becoming a serious layer of the modern tech stack." — Larry Bruce, BDCbox

The Recap: OpenAI launched three new voice intelligence models inside its Realtime API — GPT-Realtime-2, GPT-Realtime-Translate, and GPT-Realtime-Whisper — designed to push voice interfaces well beyond simple question-and-answer interactions and into territory where AI can actively listen, reason, translate, and act during a live conversation.

Unpacked:

  • The newest model, GPT-Realtime-2, brings GPT-5-class reasoning to voice conversations, meaning it can handle complex, multi-step requests that the previous version couldn't — a meaningful upgrade for customer service tools where conversations rarely follow a straight line.
  • GPT-Realtime-Translate supports over 70 input languages and 13 output languages in real time, giving development teams a practical way to build voice products that work for a global audience without patching together separate translation services.
  • Pricing is structured around how you use each model — Translate and Whisper are billed by the minute, while Realtime-2 is billed by token consumption, so developers can match costs to the type of voice experience they're building.

Bottom line: Voice AI that can reason, translate, and act mid-conversation puts a powerful new tool directly in the hands of developers building the next generation of customer and communication products. The practical pricing structure makes it easier to experiment and scale without committing to a one-size-fits-all cost model.

The Shortlist

Anthropic taught Claude to 'dream' between active sessions — a new scheduled background process that reviews past tasks, spots recurring mistakes, and locks those learnings into memory so every new session starts smarter, with the company also launching Outcomes (a quality-grading system) and Multiagent Orchestration to let multiple Claude agents tackle complex workflows in parallel.

Google killed Project Mariner, its screenshot-based autonomous web browsing agent debuted at I/O 2025, with the shutdown date listed as May 4 — the visual processing approach couldn't keep up with faster, code-level agentic systems, and Mariner's core technology is now being absorbed into the Gemini API and Gemini Agent.

Perplexity opened its Personal Computer AI agent to all Mac users, giving Pro and Max subscribers autonomous agents that can access local files, native Mac apps, and 400+ connectors to handle multi-step personal workflows — positioning it as a security-focused alternative to OpenClaw, with tasks processed on Perplexity's servers rather than with elevated local device permissions.

Researchers found over 5,000 AI-built 'vibe-coded' apps — built with platforms like Lovable, Replit, and Base44 — sitting openly accessible on the web with almost no authentication, with nearly half exposing sensitive data including medical records, financial documents, and corporate strategy files to anyone who lands on the right URL.

Get AI, CDP (Customer Data Platform) & SPA (Sales Process Automation) Tips

Get updates delivered
directly to your inbox.
2026 BDCbox© - All rights reserved

15-Minutes to 15 additional Sales a Month—Guaranteed.

Our conversational AI doesn’t just manage leads—it creates sales from your entire customer base. Let us show you how to squeeze more sales from your existing customer with a 15 minute, demo .

From Data to Deals: The Power of DIAA

Learn how Beatrix.ai transforms dealership data into personalized conversations that grow sales and service revenue. Schedule a 15 minute demo now.

15-Minutes to 15 additional Sales a Month—Guaranteed.

Our conversational AI doesn’t just manage leads—it creates sales from your entire customer base. Let us show you how to squeeze more sales from your existing customer with a 15 minute, demo.
  • Cass
  • NCOA
  • EmailValidation
  • EmailAppend
  • Mobile Phone Indicator
  • Mobile Phone Validation
  • Mobile Phone Append
  • VIN still owned and maintained by the customer