# Jeff Williams CTO Cofounder of Contrast Security and OWASP co-founder on Mythos and AI Security Page: https://stenobird.com/podcast/cybersecurity-today-65508/jeff-williams-cto-cofounder-of-contrast-security-and-owasp-co-founder-on-mythos-and-ai-security Text version: https://stenobird.com/podcast/cybersecurity-today-65508/jeff-williams-cto-cofounder-of-contrast-security-and-owasp-co-founder-on-mythos-and-ai-security.md Podcast: [Cybersecurity Today](https://stenobird.com/podcast/cybersecurity-today-65508) Published: 2026-04-11T04:10:00+00:00 Episode link: https://cybersecuritytoday.libsyn.com/jeff-williams-cto-cofounder-of-contrast-security-and-owasp-co-founder-on-mythos-and-ai-security Audio file: https://traffic.libsyn.com/secure/cybersecuritytoday/Jeff_Williams_OWASP_and_CTO_Cofounder_of_Contrast_Security.mp3?dest-id=679928 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/cybersecurity-today-65508/episodes/jeff-williams-cto-cofounder-of-contrast-security-and-owasp-co-founder-on-mythos-and-ai-security Duration seconds: 2143 ## Resource AI-Powered AppSec, OWASP Origins, and Anthropic's "Mythos" Model: Jeff Williams on What Changes Next Cybersecurity Today would like to thank Meter for their support in bringing you this podcast. Meter delivers a complete networking stack, wired, wireless and cellular in one integrated solution that's built for performance and scale. You can find them at Meter.com/cst Jim hosts Jeff Williams (Contrast Security co-founder/CTO and former OWASP global chair) for a wide-ranging discussion that begins with Anthropic's new "Mythos" model, described as powerful for finding zero-day vulnerabilities, and expands into how AppSec must evolve. Williams explains Contrast's runtime instrumentation approach, recounts OWASP's early days, the creation of WebGoat and the OWASP Top 10, and notes that many common vulnerabilities persist despite years of maturity models. They debate open source versus commercial security scrutiny, the likely high cost and scalability limits of advanced AI vulnerability discovery, and why finding more bugs matters only if remediation improves too. Williams argues for AI-powered "software factories" with feedback loops, assurance evidence, and runtime monitoring, and flags the EU Product Liability Directive treating software as a product with no-fault liability for security defects, including those from embedded open source. 00:00 AppSec Stuck in Ruts 00:42 Show Intro and Sponsor 01:40 What Contrast Security Does 02:35 OWASP Origins and WebGoat 04:33 Why the Top 10 Persists 06:28 Mythos Model Overview 08:05 Open Source Scrutiny Myth 11:31 Cost and Adoption Barriers 15:04 Finding vs Fixing Bugs 15:55 AI Code Quality Reality 17:46 AI Powered Software Factory 23:11 Building with AI in Practice 25:18 AppSec Metrics and New Approaches 26:42 Staying Optimistic as a… ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/cybersecurity-today-65508/episodes/jeff-williams-cto-cofounder-of-contrast-security-and-owasp-co-founder-on-mythos-and-ai-security/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/cybersecurity-today-65508/jeff-williams-cto-cofounder-of-contrast-security-and-owasp-co-founder-on-mythos-and-ai-security.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.