What he means is that the headline-grabbing mythos output amounted to 10 actual bugs out of 79^H6 (and all of those got CVEs because that's how linux does it). The other 1300 CVEs came from other sources (the big increase likely being everyone else running LLMs through the codebase and filtering through the false positives). The Mythos output is mainly meant as an example of how even the top-tier models still have a high false-positive rate and that can be pretty tiring to deal with.

I do think he repeats some myths in the video, or at least confidently states some things that are not demonstrated to be true, but his core point of 'you still gotta check these things' seems pretty solid.

> he repeats some myths in the video, or at least confidently states some things that are not demonstrated to be true

I am genuinely curious what the myths/unproven things he states - I watched the video and it's repetitive sure but not much felt controversial to me.