Twitter/X

On 2026-06-28 @cramforce warned there is a short-time window where the defensive…

Brief

@cramforce (2026-06-28) says a brief window exists where defensive measures—sharing source code and using automated harnesses—outperform black-box pen testing. He urges teams to run deepsec (vercel-labs/deepsec) with frontier coding models immediately to harden applications. Guillermo Rauch warns Mythos/Sol-style tools can be weaponized by adversaries, threatening US firms.

Why it matters

On 2026-06-28 @cramforce warned there is a short-time window where the defensive play (making source code available) is superior to the offensive play (black-box pen testing).

Key details

  • He recommends running harnesses like deepsec (GitHub: vercel-labs/deepsec), a coding-agent-powered security harness, with available frontier models to harden apps now and reduce findings for future pen-test models.
  • Guillermo Rauch (@rauchg) stated Mythos/Sol capabilities are useful both offensively and defensively and cautioned that if adversaries obtain equivalent offensive capability it poses a serious threat to US companies.
Source evidence

Don't sleep on this. We are in a short-time window where the defensive play (source code available) is superior to the offensive play (blackbox pen testing).

Harnesses like deepsec can harden your app today, so that there are fewer things for future pen test models to find.

Guillermo Rauch (@rauchg)

Mythos / Sol cybersecurity capabilities are equally useful in an offensive as well a defensive capacity.

If adversaries get ahold of an equivalent offensive capability, it poses a serious threat to US companies that remain unaware of latent vulnerabilities.

In the meantime, I strongly recommend running deepsec[1] or similar harnesses with the available frontier models.

[1] github.com/vercel-labs/deeps…

Link

GitHub - vercel-labs/deepsec: Deepsec is a security harness for finding vulnerabilities in your...

Deepsec is a security harness for finding vulnerabilities in your codebase powered by coding agents - vercel-labs/deepsec
github.com

— https://nitter.net/rauchg/status/2071047674187714830#m