When Anthropic disclosed that Mythos generates a working exploit on its first attempt over 83% of the time, it wasn’t just publishing a benchmark, it was announcing an obituary for the patch window. Back in April 2026, Anthropic revealed that a preview version of its Claude Mythos model had autonomously found thousands of high-severity vulnerabilities across major software used by organizations including AWS, Apple, Cisco, Microsoft, and JPMorgan Chase. One flaw sat undetected for 27 years in OpenBSD, a system built specifically to resist this kind of discovery, before Mythos found it across roughly 1,000 automated test runs. Fortunately, no one is known to have exploited it; it was a true zero-day, uncovered by an AI model rather than an attacker. That’s what makes it a warning rather than a curiosity. This article is the first in a series on what that means for security strategy.
AI Vulnerability Discovery Just Broke the Patching Model
Security teams have long operated on a predictable rhythm: a vulnerability is disclosed, a patch is developed, and IT rolls it out over weeks or months. That rhythm assumed discovery was slow and rare enough for defenders to stay ahead of it, one flaw at a time.
The OpenBSD flaw breaks that assumption for a single vulnerability. Scale breaks it further. In the weeks after Mythos Preview’s disclosure, participants in Anthropic’s Project Glasswing initiative, including Cisco, Google, and the Linux Foundation, uncovered more than 10,000 high- and critical-severity vulnerabilities across critical infrastructure, software, and widely used open-source projects. As Anthropic put it, AI models have reached “a level of coding capability where they can surpass all but the most skilled humans at finding and exploiting software vulnerabilities.” That’s not a faster version of the old pace; it’s a different order of magnitude, and it means vulnerabilities now surface by the thousands instead of one at a time.
Takeaway: Patch cycles were built for a world where discovery was slow and vulnerabilities arrived one at a time. Neither is true anymore.
From Discovery to Exploit: The Gap Is Nearly Gone
Volume is only half the problem. The other half is what happens after a flaw is found. An 83% first-attempt success rate at building a working exploit means the step that used to take attackers’ side the longest, turning a known flaw into a usable attack, now takes almost no time at all, at least when a Mythos-class model is doing the work.
Cybersecurity has always run on an uncomfortable asymmetry: defenders have to be right every time, attackers only need to be right once. That math was survivable when both sides moved at roughly the same speed: a human researcher finding a flaw, a human attacker weaponizing it, a human defender responding. AI vulnerability discovery breaks that symmetry. One side can now move at machine speed while the other is still bound by change-management windows, testing cycles, and procurement timelines, even when aided by its own ML or AI tools.
Takeaway: The gap between “a vulnerability exists” and “a vulnerability is exploited” is compressing toward zero, and it’s compressing for attackers before defenders.
Why Remediation Alone Can’t Keep Up with AI Vulnerability Discovery
None of this means patching stops mattering. It means patching stops being sufficient, for three reasons.
• Speed: the race between disclosure and exploitation is no longer one defenders can count on winning.
• Coverage: not everything can be patched on demand. Legacy systems, industrial control systems, medical devices, and unmanaged BYOD hardware often can’t be updated the moment a fix ships, and some can’t be updated at all.
• Rollout gaps: even a well-run patch cycle leaves a window between “patch available” and “patch applied everywhere,” and that window is exactly where AI-accelerated exploitation does its damage.
Takeaway: Remediation answers the wrong question when the honest answer is that some devices won’t be patched in time, or ever. The right question is what that device can reach while it’s exposed.
The Real Fix: Knowing and Controlling Every Identity That Connects
Patching can’t always be guaranteed to happen before exploitation. In fact, when a vulnerability is discovered only because it was already being used in an attack, patching first is impossible by definition. That’s why the more durable control sits upstream of the vulnerability entirely. It starts with knowing exactly who and what is connecting to the network, whether that’s a laptop, a workload, a user, or an AI agent. It means verifying that identity and its posture before granting access, then limiting what it can reach once it’s on. An identity that’s never granted access to sensitive systems in the first place doesn’t need to be contained after the fact. The exposure never happens.
Takeaway: The organizations that adapt fastest won’t be the ones that patch quickest; they’ll be the ones that proactively and continuously seek which identities, human or not, can be trusted with access and which can’t.
Putting This Into Practice
Security leaders should stop equating a high patch-compliance score with strong security, and start treating real-time visibility, of devices and the identities behind them, as the true baseline. That means maintaining a real-time inventory of every device, user, workflow, and AI agent requesting access; continuously verifying identity and security posture for the life of the session; and making network access itself conditional on trust, so an unpatched device or non-compliant identity is restricted automatically rather than flagged for a follow-up ticket.
Conclusion
AI vulnerability discovery is eroding the one advantage defenders used to count on: time. The patch window isn’t disappearing because teams got worse at patching; it’s becoming a less reliable assumption because discovery-to-exploit time can now outpace any patch cycle, and because some systems were never going to be patched in time anyway. That doesn’t make remediation worthless, but relying on it more heavily than prevention, the kind zero trust frameworks are built to provide, is no longer a safe way to protect enterprise environments in the age of AI. The organizations that hold up best in this next phase won’t be the ones that patch fastest; they’ll be the ones that always know who and what is connecting to their environment, human or non-human, and can act on that trust in real time, patch or no patch.
That’s where Portnox comes in. Learn more about Portnox and how it forms an essential part of your zero trust security strategy, verifying and restricting access in real time for every identity, human or non-human, before a vulnerability ever becomes a breach.