Skip to content

Security1 publisher3 min readPublished

Mythos's method, not its zero-day count, is what breaks CVE-keyed vuln management

Anthropic's model reasons its way to new bugs instead of matching known CVEs, and one vendor-sourced breakdown puts comparable capability in wider hands inside six to 24 months.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Photograph accompanying Mythos's method, not its zero-day count, is what breaks CVE-keyed vuln management
Photo: anthropic.com

What happened

  • Anthropic's Mythos AI model landed in April and shocked the cybersecurity industry with the number of zero-day vulnerabilities it can quickly discover; the article characterises that count only as a "frightening number" and does not state a figure.
  • Mythos does not scan for known CVEs or match signatures to vulnerability databases.
  • Mythos reasons its way through software, forms hypotheses about where vulnerabilities might lie, tests those hypotheses, and adapts its approach until it confirms exploitable weaknesses.
  • Anthropic is restricting use of Mythos to big-name software, banking and cybersecurity companies, deeming the model's abilities too dangerous for public use.
  • The article says most experts reckon it will be between six and 18 months before similar AI models become widely available to attackers and defenders alike.

Compiled by The WatchSomething wrong?How this is made

Why it matters

Anthropic's Mythos, per a technical breakdown published on scworld.com, landed in April and does not look for what scanners look for: it does not scan for known CVEs or match signatures against vulnerability databases [1][2]. Instead it reasons through software, forms hypotheses about where flaws are likely to sit, tests them, and adapts until it confirms something exploitable [3]. That distinction, not the bug count, is the operational problem, because a program whose intake is a feed of published identifiers has nothing to match when the finding does not have an identifier yet [1].

The loop the piece describes is mundane, and that is the point. Mythos is given an eight-word prompt: "Please find a security vulnerability in this program" [6]. It stands up an isolated container cut off from the internet to run the target and analyse source or inspect binaries [7], builds a map of the architecture, trust boundaries, authentication logic and data flows [8], generates hypotheses about where serious flaws are most likely, tests each by running the software, and backs up to the next candidate when a hypothesis returns nothing [9]. Confirmed bugs get a written report, often with a working proof-of-concept exploit [10]. A second AI agent then reviews the report and exploit and gives its own verdict on whether the bug is real, screening out likely false positives [11]. Instances can run simultaneously [12]. Brad Hibbert, Brinqa's COO and CSO and the only named expert in the article, calls it "a security researcher that never sleeps" [13][19].

The part that matters to anyone running a remediation queue is chaining. Hibbert says Mythos's most important ability is not individual bugs but linking low- and medium-severity flaws, including combinations human researchers lack time to investigate, into full compromise paths ending in privilege escalation, remote code execution or sandbox escape [14]. He also says low and medium items sit far down the queue and never get dealt with [16]. Those two statements cannot both be comfortable: ordering work by individual severity systematically defers exactly the components an automated chainer needs [2]. Hibbert frames the shift as economic, arguing that what used to require a highly skilled researcher and days or weeks of work is now a line item that fits a modest budget [17].

Access is still gated. Anthropic restricts Mythos to large software, banking and cybersecurity companies and deems its abilities too dangerous for public use [4]. The article says most experts put wide availability to attackers and defenders at six to 18 months [5], while Hibbert puts nation-state and well-funded criminal access at less than 12 months and broader availability at less than 24 [18]. Those windows do not line up, and the honest reading of the piece is a spread of six to 24 months [3].

Two caveats on the sourcing. This is one article, its sole named expert is a vendor executive, and it recommends exposure-management platforms that mimic Mythos's own reasoning, which is a product category [19][20]. And an article whose thesis is that the number is not the story never prints the number: the zero-day count appears only as a "frightening number" [1].

Watch for Anthropic publishing anything about Mythos findings that lets outsiders count and validate them, for restricted-access customers reporting chained paths rather than single bugs, and for agentic hypothesis-and-test loops appearing in open-weight releases. The internal test is narrower: whether a vulnerability programme can ingest a bug report with a working exploit and no identifier attached to it [1].

Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories