Are You Mythos-Ready?
AI has permanently compressed the attack timeline. The window between vulnerability discovery and exploitation has collapsed to under 24 hours. Here is what that means — and what to do about it.
By Tom Brennan
On April 7, 2026, Anthropic announced Claude Mythos — an AI system that autonomously discovered thousands of zero-day vulnerabilities across every major operating system and browser, generated working exploits without human guidance, and achieved a 72% exploit success rate. Alongside it, Anthropic launched Project Glasswing, one of the largest coordinated vulnerability disclosure efforts in history. The threat landscape changed that day. Permanently.
The Structural Shift
For years, the implicit assumption behind every patch management program, every risk register, and every board-level security briefing was this: there is time. Time to assess, prioritize, patch, and verify. That assumption is no longer valid.
Mythos is distinguished by three specific capabilities that represent a step change from prior AI tools. First, it generates working exploits without scaffolding — internal Anthropic testing showed Mythos produced 181 working Firefox exploits under conditions where prior models succeeded only twice. Second, it identifies chained vulnerabilities — complex attack paths combining multiple memory corruption bugs into a single exploit. Third, it operates in a "one-shot" mode — accomplishing significantly more from a single prompt, with no elaborate agent configuration.
The window between discovery and weaponization has not narrowed — it has collapsed. Current patch cycles, incident response processes, and risk metrics were not built for this environment.
This creates structural asymmetry. Attackers benefit disproportionately from AI because exploitation is cheaper, faster, and requires less skill. Defenders face the same volume of vulnerabilities — but with far less time to respond before those vulnerabilities become active liabilities.
Project Glasswing granted approximately 40 vendors early access to Mythos so they could patch their own products. That is a critically important start. But the world's exploitable attack surface is vastly larger than any curated partner program can cover. Most organizations that build or maintain software will not have early warning. When comparable offensive capabilities emerge in open-weight models — estimated within six to twelve months — that defensive advantage disappears entirely.
How We Got Here: The AI Offensive Timeline
- June 2025 — XBOW tops HackerOne. An autonomous offensive AI became the #1 ranked researcher on HackerOne's US leaderboard — the first system to outperform all human hackers on the platform.
- August 2025 — Google Big Sleep: 20 real zero-days. Google's AI discovered 20 vulnerabilities in open-source projects including FFmpeg and ImageMagick — each found and reproduced autonomously, without human direction.
- November 2025 — First AI-orchestrated espionage campaign. Anthropic disclosed that a Chinese state-sponsored group used Claude Code to autonomously run full attack chains — reconnaissance through exfiltration — across approximately 30 global targets.
- February 2026 — 500+ vulnerabilities, 12 OpenSSL zero-days. Claude Opus 4.6 found over 500 high-severity vulnerabilities in open-source software. Separately, AISLE found 12 OpenSSL zero-days including a CVSS 9.8 flaw dating to 1998.
- March 2026 — Zero Day Clock launched. The Zero Day Clock was introduced, visually demonstrating the collapse in time-to-exploitation — now under one day in 2026.
- April 7, 2026 — Claude Mythos Preview + Project Glasswing. Anthropic announces Mythos: thousands of zero-days across every major OS and browser. 72% exploit success rate. A 27-year-old OpenBSD bug. The largest multi-party coordination effort in vulnerability disclosure history.
What This Means for Your Organization
The organizations most exposed right now are those still operating on pre-Mythos assumptions. If your risk register was last updated before April 2026, it is already outdated. If your incident response playbooks assume a single high-severity event per quarter, they need to be rewritten. If your patch SLAs are measured in weeks, they are no longer realistic.
The CSA CISO Community, SANS, and OWASP GenAI Security Project jointly identified six core assumptions that Mythos has invalidated:
- Time-to-exploitation is measured in weeks. It is now measured in hours. Adversary timelines have compressed beyond anything prior risk models accounted for.
- A patch will be ready before exploitation occurs. With AI-discovered vulnerabilities, the exploit may arrive before the vendor has finished drafting the advisory.
- Incident frequency is manageable. Expect multiple simultaneous high-severity incidents. Playbooks designed for sequential events will fail.
- The CVE system will keep pace. AI vulnerability discovery is outrunning the disclosure pipeline. Many organizations will face threats that have no CVE number yet.
- Your developers control what ships. Coding agents and citizen developers are spinning up infrastructure outside central security oversight. Your attack surface is growing faster than your inventory.
- Your third-party risk program reflects current exposure. Vendors in your supply chain are affected by Glasswing patches and AI-discovered vulnerabilities just as you are — and their exposure becomes yours.
The Mythos-Ready Program: Four Lines of Defense
Being Mythos-ready is not about reacting to one model announcement. It is about closing the gap — permanently — between how fast vulnerabilities are found and how fast your organization can respond. At Proactive Risk, our four service lines map directly to the defensive architecture the CSA brief calls for.
CATSCAN® — Offensive Security
Find your vulnerabilities before the adversary does.
- AI-augmented penetration testing across your full attack surface — apps, APIs, infrastructure
- Autonomous assessments to continuously benchmark your exposure
- Exploit chain analysis scoped to Mythos-class threat scenarios
- Red team exercises simulating supply chain and zero-day compound attacks
ManageIT℠ — Managed Detection & Response
24/7 MDR purpose-built to catch post-exploitation fast.
- Active detection of attacker behavior in your environment through 24/7 managed detection and response
- Tabletop exercises for simultaneous, multi-event incidents at scale
- Automated containment and segmentation enforcement to limit blast radius
- Microsoft 365 threat coverage with phishing-resistant MFA and identity monitoring
MeasureRISK℠ — CyberAdvisor℠ & Risk Advisory
Recalibrate your program for the current threat environment.
- Risk register and board reporting updated to reflect post-Mythos threat reality
- 90-day Mythos-ready roadmap with clear owners, metrics, and milestones
- Governance acceleration: faster vendor onboarding, AI security policy frameworks
- NIST CSF 2.0, CIS Controls v8.1, and ISO 27001 alignment
RISKWatch℠ — Third-Party Risk Management
Your vendors carry this risk into your environment.
- Continuous monitoring of your entire vendor ecosystem
- Supply chain risk triage aligned to Glasswing patch wave notifications
- Tiered vendor risk programs scaled to portfolio size and regulatory obligations
- Escalation workflows to engage critical third parties before a disclosed vuln becomes an incident
The Human Cost — and the Opportunity
It would be incomplete to discuss Mythos purely as a technical challenge. Security teams are being asked to absorb an exponential increase in workload — more patches, more incidents, faster timelines — without proportional investment in headcount, tooling, or support.
Burnout and attrition in security functions are a direct operational risk. The expertise needed to navigate this transition is scarce, takes years to develop, and cannot be replaced on short timescales. The CSA brief is direct on this point: security team resilience should be treated as a strategic priority with the same urgency as the technical challenges AI presents.
There is also a genuine opportunity here. AI tools that represent a threat in adversary hands are available to defenders too. Coding agents can accelerate incident response, automate audit data collection, triage and test patches, and red team your environment — all at machine speed. Every role in your security program is becoming an "AI builder" role. The organizations that adapt fastest will close the gap.
Teams beat stovepipes. Coalitions beat teams. Coalitions equipped with the right technology win.
Start Now: A 90-Day Plan
The CSA brief calls for a targeted, aggressive 90-day plan. We agree. Here is where to begin this week:
- Run an AI-powered security review of your own code today. Start with an agent-assisted code review of your most critical application. Build toward a full VulnOps capability over 90 days.
- Harden the basics — they matter more now, not less. Segmentation, Zero Trust architecture, phishing-resistant MFA, and egress filtering all increase attacker friction even when exploits are AI-generated.
- Update your incident response playbooks. Write scenarios for simultaneous, high-severity events. Pre-authorize containment decisions so your team can move at the speed the threat requires.
- Recalibrate risk metrics and board reporting. If your risk register or executive dashboards have not been updated since before April 2026, they may be actively misleading your stakeholders.
- Audit your third-party exposure. Map which vendors were in the Glasswing early-access cohort, which were not, and what patches are incoming. Your supply chain is a live attack surface.
- Plan for capacity — human and AI. Request headcount or contractor capacity for the anticipated surge in triage and remediation, while deploying AI agents to extend your existing team.
We have done this before. Y2K was a systemic threat with a hard deadline, and the industry met it through coordinated, disciplined effort. This is the same kind of problem — with more powerful tools available to defenders, and a shorter timeline to act.
Every action above can begin this week.
Free Threat Intelligence Resources
Track AI-driven threats, zero-day exploitation, and adversary disclosure activity with Proactive Risk's curated investigation toolkit, available free in the Downloads library:
- OSINT Browser Bookmarks — a comprehensive collection of open-source intelligence tools, search engines, and investigation resources for threat research and zero-day monitoring
Key Takeaways
- Claude Mythos achieved a 72% exploit success rate discovering thousands of zero-days across every major OS and browser — time-to-exploitation is now measured in hours, not weeks.
- Six foundational security assumptions — from patch SLAs to incident frequency — have been invalidated by AI-powered offensive capabilities.
- Proactive Risk's four service lines (CATSCAN®, ManageIT℠, MeasureRISK℠, RISKWatch℠) map directly to the defensive architecture the CSA CISO Community recommends.
- A 90-day Mythos-ready plan should begin this week — covering AI code review, incident response updates, risk metric recalibration, and third-party exposure audits.
Source: This post draws on the April 12, 2026 expedited strategy briefing published by the CSA CISO Community, SANS Institute, OWASP GenAI Security Project, and contributing authors including Jen Easterly, Bruce Schneier, Heather Adkins, and Rob Joyce.