Defenders have always relied on one advantage: time.
A vulnerability is discovered, security teams investigate it, patches are tested, and systems are updated before attackers can exploit it at scale.
Claude Mythos suggests that advantage may be disappearing.
Earlier this year, Anthropic announced Claude Mythos and with that a report describing their findings. The results? Both impressive and unsettling. During testing, the model independently identified, chained together, and exploited software vulnerabilities. With skills matching but even surpassing human experts in a fraction of the time. Restricted early access revealed flaws in every major operating system and web browser. Anthropic reported more than 23.000 potential vulnerabilities.
What happens when the same machine that can help defenders find vulnerabilities can also help attackers exploit them?
Claude Mythos and Project Glasswing
Mythos AI, previously known as Claude Mythos Preview Mythos, is a generative AI model developed by Anthropic. Built to autonomously generate new, original content. A huge step beyond just analysing existing information. Earlier Claude models take the roles of back-and-forth conversational assistants. Mythos was designed to work autonomously on complex, multi-step problems.
Although cybersecurity was not its primary objective, the model quickly demonstrated exceptional capabilities in the field. During testing, Mythos analyzed large codebases, identified vulnerabilities, determined how those vulnerabilities could be exploited, and even proposed effective remediations.
Recognizing both opportunity and risk, Anthropic partnered with major tech firms like AWS, Google, Microsoft, Apple, Cisco, CrowdStrike, NVIDIA, and the Linux Foundation. This coalition was called Project Glasswing. The goal was to expose Mythos to real-world tools and technologies and see what it could find. And the results were impressive.
During the first weeks, AI identified over 10.000 potential security vulnerabilities. Many of which had been lying dormant and went unnoticed for years. Some vulnerabilities dated back as early as the 90’s. It surfaced flaws in every major operating system and every major web browser. Hidden away in plain sight in code that countless developers and security researchers had previously reviewed.
Should that be called success or concern?
Why Mythos isn’t made publicly available
The short answer is because it’s simply too powerful to be released as is. It requires significant restrictions before going public.
Finding vulnerabilities is not new. Security scanners and automated analysis tools have done that for decades. And even modern AI models and agents have been doing so for a couple of years. What makes Mythos fundamentally different is that it doesn’t stop at discovery.
It understands software behaviour, reasons about edge cases, chains multiple vulnerabilities together, and can generate realistic attack paths with minimal human direction.
That capability has enormous defensive value. Security teams can discover weaknesses earlier, prioritize remediation efforts more effectively, and strengthen software before attackers ever see those vulnerabilities.
Unfortunately, bad actors can use the exact same functionality to accelerate cyberattacks.
Anthropic has openly discussed risks observed during testing. Engineers with little security experience gain the capability to search for remote code execution vulnerabilities. And by the following morning, they receive fully functional exploits. All of this with minimal effort and limited knowledge.Â
The concern is no longer whether AI can assist vulnerability research. It is whether autonomous exploit development will become widely accessible. Whether Mythos is ever publicly released is almost beside the point. The capability now exists. Mythos-like tools, even open-source ones, are becoming a reality.
How can you tackle Mythos-based attacks?
Whether organizations are ready or not, Mythos is happening. The traditional assumption that attackers and defenders move at the same pace is disappearing. If autonomous systems can discover vulnerabilities in hours instead of weeks, the bottleneck is no longer identifying problems. The challenge shifts to how quickly organizations can respond.
This makes several cybersecurity disciplines more critical than ever:
Vulnerability Management
Even in a world with potentially new zero days every day, knowing your attack surface and its exposure is a critical step towards protection. Organizations cannot protect assets they do not know exist.
Maintaining a complete asset inventory, continuously assessing vulnerabilities, prioritizing remediation based on business risk, and deploying patches efficiently are becoming more than best practices. They are fundamental requirements. As AI accelerates vulnerability discovery, the window between discovery and exploitation will continue to shrink.
Managed Detection and Response (MDR) and Identity Threat Detection and Response (ITDR)
Attacks unfold faster than human analysts can manually respond. So rapid detection, investigation, and containment at machine speed become increasingly valuable. Organizations that detect threats faster and respond quicker will have a significant advantage.
Did you know? Leveraging Silverfort and MDR SOC services allows visibility into attack patterns that would otherwise blend into normal AD (Active Directory) noise. Deeper integration enables breach containment trough Silverfort’s Freeze mode. This instantly stops lateral movement in its tracks and allows security teams to tackle ransomware attacks before they spread. Read more
Microsegmentation
Modern security assumes that breaches will eventually occur.
Microsegmentation limits how far an attacker can move after compromising an initial system. A breach doesn’t equal gaining unrestricted access across the network. Instead, attackers are confined to small portions of the environment. This dramatically reduces the potential impact of a successful intrusion.
Zero-Trust
Trust can no longer be assumed simply because a user or device is already inside the network.
Continuous authentication and least-privilege access limit attacker opportunities. Just-in-time permissions add another layer of control. It’s plain and simple: every request should be verified, regardless of where it comes from.
The conclusion: Friend or foe?
Artificial intelligence is transforming cybersecurity at an unprecedented pace. Claude Mythos demonstrates both the immense potential and the inherent risks of generative AI in cybersecurity. It poses great opportunities, but it needs safeguards to be able to do so.
The future belongs to organizations that successfully combine AI’s speed, scale, and analytical capabilities with human expertise, judgment, and strategic thinking. Not humans against AI but empowered by AI.
Rather than replacing human security professionals, Mythos-like models will amplify and speed up their capabilities. Human expertise remains essential for providing the correct judgment, business context, and strategic decision-making.
At the same time, it serves as a warning. The capabilities that help defenders today may eventually become available to attackers tomorrow.
The organizations that succeed in this new reality will not be the ones with the most tools. They will be the ones that can adapt fastest and respond quickest. The biggest advantage and defense will be to have security built into every layer of their environment.
The earlier you start, the more chance you stand against these emerging zero-day threats.