Rubrik、AIセキュリティツール「Mythos」の脆弱性検出能力に工程不足を認識
本文の状態
日本語全文を表示中
詳細モードで約5分の本文を読めます。
同じ出来事の情報源
この情報源を基点に整理
The New Stack AI
セキュリティ企業 Rubrik は Anthropic の Mythos Preview を利用し、AI が発見する脆弱性の規模が人間の処理能力を超えると判断し、人的対応から自動化基盤への転換を決定した。
Continue in AI NEW LAB
このニュースを、実務の判断につなげる
AI NEW LABで、試したことや先に確認したい条件を共有できます。まずはログインなしで読めます。
AI NEW LABで論点を見るAI深層分析を開く2026年8月14日 02:57
AI深層分析
キーポイント
AI 発見速度と人間処理能力のギャップ
Mythos が複雑な脆弱性チェーンを即座に特定する一方、既存の人的レビューでは対応が追いつかず、ボトルネックが発生した。
人的拡張から自動化基盤への転換
Rubrik は追加採用を検討したが、AI 速度には人間による修復が追いつかないと判断し、自動化されたハッチ(基盤)構築へ方針を転換した。
ターゲット型スキャンの導入
全リポジトリスキャンで初期発見を行い、その後段階的に絞り込むプロセスを導入してノイズを排除し、高品質な発見のみをエンジニアへ送信するワークフローを構築した。
Project Glasswing の役割
Rubrik は Anthropic が選定したプロジェクト参加企業として Mythos Preview にアクセスし、その限界と可能性を実証した。
自動化と人間判断のバランス
信頼性を維持するため、機械による修復は信頼性が高く定義された脆弱性のクラスに限定し、それ以外は人間の判断に委ねる。
重要な引用
We quickly abandoned the plan…as we realized there was no way human-driven remediation could keep pace with AI-speed discovery.
The focus was to build an effective harness that manages tool calls and checkpoints, adds business context, security context, and trust boundaries.
"Surprisingly, we ran into this question about what not to automate quite often," says Nithrakashyap, calling out the inherent conflict between "trustworthy automation" and "maximum automation."
"Mythos has shown us that AI actually increases the demand for engineering rigor in the systems that surround it."
編集コメントを表示
編集コメント
AI の能力が爆発的に向上する中で、セキュリティ運用のボトルネックが「発見」から「処理」へ移行した事例は極めて示唆に富む。Rubrik が示したような自動化基盤の構築は、今後多くの組織が直面する課題に対する重要な指針となるだろう。
Source Article
元記事を日本語で読む
本文に関係しない購読案内、埋め込み通知、サイト内プロモーションは除いています。

セキュリティと AI 企業である Rubrik が「Project Glasswing」に参加し、Mythos Preview の実験にアクセスできるようになったことで、同社は自社のエンジニアリングリソースが、このモデルの脆弱性探索能力に追いつくには不十分であることを学びました。
Rubrik の CTO 兼共同創業者である Arvind Nithrakashyap 氏は、Mythos が従来のセキュリティツールや手法では見逃していた複雑な脆弱性の連鎖を即座に見つけ出し、大規模なコードベースにまたがるコンポーネント間の関係性など、通常のスキャンや単一のエンジニアによるレビューでは捉えきれない問題も特定したと語ります。そして、こうした発見の急増により、既存のエンジニアリングチームが対応しきれていない優先順位付けのボトルネックが生じました。
「当初、潜在的な問題の報告を見たとき、私たちの直感的な反応はこれをリソース不足の問題だと捉えることでした」と Nithrakashyap 氏は The New Stack に語り、より多くの人間によるレビュー担当者を採用することを検討したことも明かしました。
しかし、この考えからの転換は迅速に行われました。「すぐにその計画を放棄しました」と彼は続けます。「AI の速度で発見される問題に対して、人間の主導による修正対応が追いつくことはないと悟ったからです」
AI 主導の発見には旧来のワークフローは通用しない
Mythos Preview にアクセスできるのは、Project Glasswing に招待された厳選されたパートナーのみです。Anthropic がこのプロジェクトを約 15 カ国にまたがる 150 組織程度に拡大した際、Rubrik は同年 6 月にそのリストに参加しました。
「人間による対応が AI の発見速度に追いつかないと気づいた瞬間、その計画はすぐに放棄しました。」
Rubrik はオンボーディング後、高忠実度の脅威検出と排除を実現するため、多機能なエンジニアリングチームと情報セキュリティ(infosec)チームを編成し、可能な限り人手のレビューを増やすのではなく自動化に頼りました。
「焦点は、ツール呼び出しやチェックポイントを管理し、ビジネスコンテキスト、セキュリティコンテキスト、信頼境界を追加する効果的なハッチを構築することでした」と Nithrakashyap 氏は語ります。同氏は The New Stack に対し、Mythos の周囲にソフトウェア層を構築し、最終的にエンジニアがレビューや対応を行うべき発見件数を削減することが目的だったと説明しました。
Nithrakashyap 氏の説明によると、Rubrik のチームはまず Mythos を使ってリポジトリ全体のスキャンを実行し、その初期の発見結果をもとに、よりターゲットを絞った次のスキャンへと進めます。これらの後続のスキャンでノイズを排除し、高品質な発見のみが適切なチームへルーティングされ、優先順位が付けられるようにしています。
Nithrakashyap 氏によれば、こうしたターゲットを絞ったスキャンを導入して初めて、エンジニアにとって対応しやすいよう Mythos から高優先度のアクション可能な発見結果を伝達するワークフローを構築できるようになったそうです。
より難しい問い:何を自動化しないか
Mythos が発見する脆弱性の速度は、人間が手動で対応できる範囲を超えていると Nithrakashyap は指摘します。この状況において、発見スピードに追いつける自動化システムの構築こそが唯一の前進策です。ただし、その実現には「どこまでを機械に任せるか」「どこでは人間の判断が必要か」という重要な決断が伴います。
「Mythos が示したのは、AI 自体だけでなく、それを支えるシステム全体に対して、より高いエンジニアリングの厳密性が求められるようになったという事実です」
「自動化すべき対象を限定する必要性について、意外にも頻繁に議論になりました」と Nithrakashyap は語ります。これは、「信頼性の高い自動化」と「最大限の自動化」の間にある本質的な対立によるものです。The New Stack への説明で彼はこう述べています。
「信頼性を維持するため、私たちは自動化による修正を、機械が確実かつ明確に処理できる脆弱性クラスの一部に限定しました。これにより、定義されたクラスの脆弱性のみが自動パスを進みます。それ以外の発見事項はすべてエンジニアリングチームへ転送され、最終的な対応は人間の判断に委ねられます」
新たな知見とボトルネックの出現
Anthropic が「最も能力の高いモデル」と称する Mythos を 1 ヶ月運用した Rubrik の経験から、既存の多くのエンジニアリングワークフローが、このモデルの発見スピードに対応しきれていないことが浮き彫りになりました。Nithrakashyap は The New Stack に対し、「Mythos が示したのは、AI 自体だけでなく、それを支えるシステム全体に対して、より高いエンジニアリングの厳密性が求められるようになったという事実です」と述べています。
適応には、ハネス内に構造的な文脈を直接統合し、Mythos の発見事項を修復のための実行可能なインサイトとして分類・フィルタリングするシステムを構築する必要があります。
本記事は The New Stack にて最初に公開された「Rubrik が Mythos Preview を 1 ヶ月利用して得た教訓」です。
原文を表示

After it joined Project Glasswing and gained access to experiment with Mythos Preview, security and AI company Rubrik learned it didn’t have the engineering capacity to keep up with the model’s vulnerability-hunting capabilities.
Arvind Nithrakashyap, CTO and co-founder, Rubrik, says Mythos was instantly finding complex vulnerability chains that slipped past Rubrik’s usual security tools and methodology, including identifying relationships between components across large codebases that a conventional scan or a single engineer’s review couldn’t catch. And that surge in findings created a prioritization bottleneck Rubrik’s existing engineering team wasn’t prepared to handle:
“When we first saw the readout of potential issues, our immediate instinct was to treat it as a capacity problem,” Nithrakashyap tells The New Stack, adding Rubrik was even considering hiring more human reviewers to accommodate the larger volume.
But the pivot away from this idea was swift. “We quickly abandoned the plan,” he continues, “as we realized there was no way human-driven remediation could keep pace with AI-speed discovery.”
Old workflows don’t work with AI-led discovery
Only vetted partners that are invited to Project Glasswing get access to Mythos Preview. Rubrik joined that list in June when Anthropic expanded the project to roughly 150 organizations across 15 countries.
“We quickly abandoned the plan…as we realized there was no way human-driven remediation could keep pace with AI-speed discovery.”
Once onboard, Rubrik assembled a multi-functional engineering and infosec team to enable high-fidelity threat discovery and elimination, leaning on automation whenever possible rather than scaling its base of human reviewers.
“The focus was to build an effective harness,” says Nithrakashyap, “that manages tool calls and checkpoints, adds business context, security context, and trust boundaries.” Specifically, he tells The New Stack the goal was to build a software layer around Mythos that could cut down the number of findings that ultimately make it to engineers for review and remediation.
As Nithrakashyap explains it, Rubrik’s team first uses Mythos to run a whole-repository scan, leveraging those initial findings to then inform progressively more targeted passes. These subsequent passes then weed out the noise to ensure only high-quality findings are routed to appropriate teams and prioritized accordingly.
According to Nithrakashyap, it was only after introducing those targeted passes that Rubrik’s engineering team was able to build a workflow that could relay high-priority, actionable findings from Mythos and make remediation more manageable for engineers.
The harder question: what not to automate
With Mythos flagging vulnerabilities at rates Nithrakashyap claims aren’t feasible for human-led remediation, he says building automation that can match the rate of discovery is the only way to move forward. But doing so comes with decisions about where to let machines handle remediation and where only human judgment will do.
“Mythos has shown us that AI actually increases the demand for engineering rigor in the systems that surround it.”
“Surprisingly, we ran into this question about what not to automate quite often,” says Nithrakashyap, calling out the inherent conflict between “trustworthy automation” and “maximum automation.” As he explains to The New Stack:
“To maintain trust, we chose to limit automated remediation to a deliberate, tightly-scoped subset of vulnerability classes where machine-driven fixes are highly reliable and well defined.” This way, only vulnerabilities within those predefined classes can move along the automated path. Everything else Mythos surfaces that doesn’t fall into those categories gets routed to engineering teams where human judgment can own the final fix.
More findings, new bottlenecks
Rubrik’s learnings after one month with what Anthropic calls its “most capable model” indicate that most existing engineering workflows likely aren’t ready to keep up with the model’s speed of discovery. As Nithrakashyap tells The New Stack, “Mythos has shown us that AI actually increases the demand for engineering rigor in the systems that surround it.”
Adapting requires integrating structural context directly within the harness and building systems to categorize and filter Mythos findings into actionable insights for remediation.
The post Rubrik’s lessons from one month with Mythos Preview appeared first on The New Stack.
関連記事
今日のまとめ
AIデイリーブリーフで今日の重要ニュースをまとめ読み