Claude Mythos introduces new security threats and opportunities to defenders. (Photo Illustration by Pavlo Gonchar/SOPA Images/LightRocket via Getty Images)SOPA Images/LightRocket via Getty ImagesThe hype around Mythos isn’t going away. Ever since Anthropic announced Mythos had discovered thousands of high-severity vulnerabilities in major operating systems and web browsers in April, anxieties over the dangers of next-generation AI models have been heightened. On June 12, the U.S. government introduced export controls on Mythos and Fable 5 to restrict access to foreign nationals. Then on July 16, HuggingFace released a blog post claiming to have been breached by an autonomous agent, an incident which OpenAI later said was caused when GPT-5.6 Sol and an “even more capable pre-release model” exploited a zero-day to escape an isolated test environment. Across the security industry, there are concerns that the offensive capabilities of frontier AI models like Mythos will outpace the abilities of defenders if they’re misused, a risk that could potentially be amplified as more powerful open-source models come to market. In the short term, security teams will face a high degree of disruption, but there maybe a silver lining long term as they learn how to leverage these technologies to automate their operations.Just How Bad Is Mythos? At its core, Mythos represents a new generation of models that can discover and exploit vulnerabilities with a high level of speed. But how bad is the risk presented by Mythos exactly? “I think it’s very early days still, but the biggest thing at the moment is people are trying to understand how these models will potentially impact them in the future, and what this means from a vulnerability exposure perspective,” Michael Sentonas, president of CrowdStrike, told me in a video interview. Cloud-based AI security vendor CrowdStrike has been deeply involved in the effort to respond to the threats presented by frontier AI models like Mythos and GPT-5.5 Cyber, becoming the first pureplay cyber vendor to be included as part of both Project Glasswing and OpenAI’s Trusted Access for Cyber programs. “If vulnerabilities are found really quickly, are we entering a world where something that took, you know, days to weeks to weaponize now takes minutes?," Sentonas said. “The risk is that we wake up and we’re just always dealing with zero-day threats.”Right now, defenders are trying to understand what the risk is when these tools are openly available. For Sentonas, one of the main risks is that these tools can scan entire code bases and chain together exposures at a high speed. It’s worth noting that OpenAI claims its models identified and chained vulnerabilities to escape their testing environment and hack Hugging Face. Watch Out For Models That Code While Mythos has become an emblem of AI models with powerful offensive capabilities, it’s not the only model to have these capabilities. “Mythos is by no means unique in having the ability to find and chain together vulnerabilities to bigger effect,” Phil Venables, ex CISO of Google Cloud and Goldman Sachs, who joined the board of incident response management provider BreachRx in June, told me in a video interview. ”All models open and closed that are good at writing code are going to be good at finding and chaining vulnerabilities together, and so that backdrop means that the world is going to have to deal with finding and fixing vulnerabilities at an ever quicker pace," Venables said. Venables describes himself as “short-term pessimistic and long-term optimistic,” warning that it's going to be “wild” for the next 12 months, but he ultimately believes AI gives defenders an advantage over attackers if they’re using it aggressively enough and in the right ways.Beyond vulnerability exploitation, he warns that attackers may use these tools to “industrialize” their operations, adding that the “dirty secret” of cybersecurity is that there are always more vulnerabilities that go unexploited than have been exploited, due to attackers being resource-constrained. In this sense, AI could help threat actors to scale their operations.Brace For More Sophisticated Threats The challenge presented by these next-generation tools isn’t just that attackers can use them to scale more effectively, but that cybercrime itself is becoming more accessible. “We’ve gotten to the point where agents are now better than people at discovering these things, and they have infinite patience,” Dan Lorenc, co-founder and CEO of open source security provider Chainguard, told me in a video interview.Lorenc warned that defenders have to assume “every single company,” is “under the threat of a nation-state hacker all the time.” He added that we’ve got months before open models that can’t be restricted the same way as Mythos get into wider hands. When that happens, he predicts we’re going to see more Log4j style vulnerabilities than ever before. When asked about the risk presented by nation states like China working on similar cyber permissive models, Lorenc added that “it puts a timeline on defenders." While it doesn’t necessarily increase risk, it adds urgency to vulnerability patching, given that it's difficult to stop a user applying a jailbreak to a model running off their own device. The UpsideThe adjustment to Mythos-level threats appears to involve accelerating vulnerability discovery and building VulnOps as a permanent organizational capability, as the Cloud Security Alliance (CSA) recommended in a recent report.One of the biggest challenges will be getting to grips with the scale of vulnerabilities. According to NIST, cybersecurity vulnerabilities and exposures (CVE) submissions to the national vulnerability database (NVD) increased 263% between 2020 and 2025. If this trend continues or accelerates when Mythos-level models come to market, defenders could easily fall behind. In addition, Lorenc notes that locating exploitable software can be challenging, as it was back when Log4j was at the height of exploitation at the end of 2021. The good news is that defenders can use AI tools like Opus, Mythos, and GPT-5.5 Cyber to surface and patch vulnerabilities faster. For instance, in July, Microsoft released a record number of 570 security patches for Windows, Office and other products, almost triple the prior month’s total. Microsoft executive vice president Pavan Davuluri claimed in the announcement blog post that Windows users will see a higher volume of security updates as AI aids in vulnerability discovery.Similarly, Sentonas recommended companies begin using tools like Opus to scan for vulnerabilities, arguing that “good enough” AV scanning strategies and volume license software aren’t going to work anymore. “You’re going to need the best in the industry," Sentonas said.Venables also noted that Google was using AI models internally to find and fix vulnerabilities during his tenure. That being said, he added that you don’t need AI to fight AI if you have a strong level of baseline defences. Measures like multi-factor authentication, network segmentation and restricting privilege can all reduce the risks presented by autonomous threats. Considering these perspectives, Mythos and equivalent models present significant risks in the short term as they come to market, but in the long term, the upside is that security providers will be able to leverage these tools to help automate vulnerability scanning and other key security operations.