When Claude Mythos was announced in April, it quickly became one of the biggest cybersecurity talking points of the AI era. Developed by Anthropic, the new LLM demonstrated unprecedented cyber capabilities and prompted reactions that classified it as a major technology breakthrough alongside warnings that cybersecurity may be entering a period of unprecedented disruption.
According to Anthropic, the model can autonomously discover large numbers of zero-day vulnerabilities, reportedly identifying flaws in major operating systems and browsers, including examples that had remained undiscovered for decades. It was also able to chain individual weaknesses into working multi-step exploits.
Its impact has been so dramatic that, by June 12th, the US government ordered Anthropic to suspend all access to the technology for any foreign national worldwide, including foreign-national Anthropic employees. This was widely viewed as a reaction to concerns that offensive AI capabilities may have reached a point where unrestricted access could create unacceptable, even uncontrollable risks.
Under Project Glasswing, Anthropic’s disclosure and remediation program, access is currently restricted to around 50 organizations, including AWS, Apple, Google, Microsoft, CrowdStrike, Cisco and the Linux Foundation, among others. These businesses have been given a window to patch critical systems before vulnerabilities identified by Mythos are publicly disclosed from July onwards. At that point, the industry genuinely enters new territory.
Crossing the Rubicon
Many would agree that the arrival of frontier AI models means the security Rubicon has been crossed. And let’s be clear: the core issue is not necessarily the emergence of a particular model, but the possibility (or even likelihood) that vulnerability discovery and exploit development itself may be entering a new era, with AI able to operate at a scale and speed beyond that of human researchers.
If that proves to be the case, the implications extend far beyond specific vulnerabilities; they affect the assumptions on which vulnerability management and remediation processes have traditionally been built. In particular, current vulnerability management processes were developed in an era when human researchers constrained the pace of discovery. AI has the potential to fundamentally change that equation.
One consequence is likely to be a sharp increase in the number of vulnerabilities entering the security ecosystem. CVE volumes have already risen dramatically in recent years, and security teams are already under growing pressure even before the full impact of frontier AI models is felt.
In this context, vulnerability discovery itself may no longer be the limiting factor. Instead, the bottleneck shifts to triage and remediation. The challenge is compounded by the fact that exploitation timelines have been shrinking for years, and in some cases, exploits now appear before patches become available, leaving organizations with little time to react.
Operational readiness becomes the priority
So, what does an updated, fit-for-purpose approach to vulnerability management actually look like? Firstly, it needs to be treated as a continuous operational capability because, as it stands, the window between discovery and patch deployment is often too slow. Security teams need to understand which vulnerabilities are actually exploitable and which systems are affected.
As the volume of findings increases and the time to exploit decreases, operationalizing AI for security will become essential. Teams that leverage advanced AI detection capabilities (while managing token costs) and automate detection, triaging, and remediation will be best positioned to minimize exposure windows and negative business impacts. This is not about discovering the most vulnerabilities; it’s about identifying and remediating the most important issues quickly.
Second and more important, frontier AI models) are tools for cyber defense. Members of Glasswing can use the models to detect and fix previously undetected vulnerabilities, ideally with advanced access to have a head start over attackers when they inevitably have access to frontier AI capabilities too. Frontier AI models are a valuable detection tool; however, they do not automatically solve the operational aspects of how to manage AI scans (what is needed to scan, when, how to orchestrate scanning, what to do with the findings, how to manage the token costs, etc.). No matter what model is being used (and they’ll get better over time), security teams need to be able to operationalize frontier AI capabilities for cybersecurity faster than attackers can leverage the capabilities for exploitation.
The long-term challenge facing organizations is therefore not preparing for a single model or a particular wave of disclosures, but whether existing operating models can adapt to a world in which vulnerabilities are discovered and weaponized at unprecedented speed. Get that wrong, and organizations are facing a world of trouble.