by

Claude takes a crowbar to 1986 Apple code

Microsoft Azure, CTO Mark Russinovich says AI is getting handy at decompiling machine code and sniffing out vulnerabilities in legacy architectures, using his own work as bait.

Russinovich wrote: “We are entering an era of automated, AI-accelerated vulnerability discovery that will be used by defenders and attackers.”

In May 1986, Russinovich wrote a utility called Enhancer for the Fruity Cargo Cult Apple II, with everything done in 6502 machine language.

Enhancer added the ability to use a variable or BASIC expression for the destination of a GOTO, GOSUB, or RESTORE command, because Applesoft BASIC normally demanded a line number.

Russinovich fed the code into Claude Opus 4.6, released in early February 2026, and watched it tear through the machine language as if it had built the thing.

Claude decompiled the code and flagged several security issues, including “silent incorrect behaviour” when a destination line was not found.

Instead of reporting an error, the program could set the pointer to the following line or past the end of the program, which is how you get “it works” right up to the moment it does not.

The proposed fix was boring and correct: check the carry flag when the line is not found, then branch to an error.

On Job’s Mob kit, that kind of flaw is mostly a giggle, because nobody is banking their pension on an Apple II type-in utility.

The nasty bit is what the demo implies for embedded systems, where the firmware is ancient, undocumented and running in places nobody can easily patch.

“Billions of legacy microcontrollers exist globally, many likely running fragile or poorly audited firmware like this,” said one comment to Russinovich’s post.

Anthropic has warned that models like Opus 4.6 can speed up vulnerability discovery, and the same capability is not reserved for the good guys.

The company’s Red Team, which is responsible for raising public awareness of AI risks, said: “When we pointed Opus 4.6 at some of the most well-tested codebases (projects that have had fuzzers running against them for years, accumulating millions of hours of CPU time), Opus 4.6 found high-severity vulnerabilities, some that had gone undetected for decades.”

The Red Team suggested, “This is a moment to move quickly… to secure as much code as possible while the window exists.”

That is plausible for high-profile projects like Mozilla’s Firefox, where AI reportedly uncovered 14 high-severity bugs.

Last month, Anthropic said: “We expect that a significant share of the world’s code will be scanned by AI in the near future, given how effective models have become at finding long-hidden bugs and security issues.”

The sales pitch says defenders get new power tools, while attackers get the same toys and do not bother with procurement forms.

 

Latest articles

Share

Featured articles

Hot topics

No results found.

Latest reviews