The Mythos Moment: What AI-Driven Vulnerability Discovery Means for Your Security Program

The Mythos Moment: What AI-Driven Vulnerability Discovery Means for Your Security Program

The Mythos Moment: What AI-Driven Vulnerability Discovery Means for Your Security Program

Blackwire Labs

Cybersecurity

Research Methodology


This analysis draws on two primary sources: the Cloud Security Alliance's April 2026 draft report, "AI Vulnerability Storm: Building a Mythos-ready Security Program" (CSA, 2026), and VulnCheck's 2026 Exploit Intelligence Report, built from more than 500 sources and two dozen internal indices tracking exploitation activity across 2025. The fusion of CSA's forward-looking assessment of AI-driven vulnerability discovery with VulnCheck's empirical exploitation data helps to identify where theoretical risk becomes operational reality. Supporting context comes from Carnegie Mellon's SEI Cyber Intelligence Tradecraft Report (CMU SEI, 2019), the DARPA AIxCC 2025 findings published through OODA Loop, and Veracode research on AI-assisted application security. Together, these sources provide a grounded, data-first view of how the vulnerability management landscape is shifting and what security leaders need to do about it. VulnCheck's research serves as the pre-Mythos baseline: a high-confidence, longitudinal view of exploitation activity spanning 2024 through 2025, covering a period when earlier AI capabilities were beginning to influence discovery and weaponization velocity, but before Mythos-class models entered wide deployment.


Executive Summary


Anthropic's Mythos preview work, as summarized in the Cloud Security Alliance's "AI Vulnerability Storm: Building a Mythos-ready Security Program" (CSA, 2026), demonstrates that AI can autonomously discover thousands of critical vulnerabilities across major operating systems and browsers and generate working exploits with a 72% success rate, including a 27-year-old OpenBSD flaw. VulnCheck's 2026 report, based on over 500 sources and more than two dozen internal indices, shows that in 2025:

  • More than 48,000 CVEs were published, yet only approximately 1% of 2025 CVEs were exploited in the wild.

  • VulnCheck still recorded 884 new Known Exploited Vulnerabilities (KEVs), and 28.96% of those were exploited on or before CVE publication day.

  • 56.4% of 2025 ransomware CVEs were discovered because threat actors were already exploiting them as zero-days, and a third of those still have no public or commercial exploit code.

These numbers reflect the exploitation landscape before Mythos reached wide deployment. Earlier AI capabilities were already leaving fingerprints on 2025 data: faster vulnerability reporting, noisier exploit signal, and incremental compression of exploitation timelines.

So we're moving into a world where attackers can find and weaponize bugs at machine speed, but only a small fraction ever become operationally important. The challenge for leaders is no longer just prioritizing what to patch. It's building a VulnOps capability that operates on those high-impact vulnerabilities the way we treat live incidents: fast, coordinated, aligned to business risk and now with AI in the loop.

Our analysis focuses on these key questions: What is the strategic risk Mythos creates for my business? How does it reshape third-party and supply chain risk? How does it change our exposure to open-source vulnerabilities? And then: what does a Mythos-ready VulnOps function look like in practice?


Strategic Risk: Exposure Windows, Not Just More Bugs


According to CSA, Mythos-class models collapse the window between vulnerability discovery and exploitation into hours, not weeks. Anthropic's internal testing, cited in the CSA report, showed Mythos generating 181 working Firefox exploits where Claude Opus 4.6 managed only two under the same conditions, in single-prompt, "one-shot" fashion without complex scaffolding (CSA, 2026).

VulnCheck's 2026 data shows how that plays out in the real world. In 2025:

  • VulnCheck tracked 14,400+ exploits targeting 10,480 unique 2025 CVEs, a 16.5% year-over-year increase in same-year exploit coverage.

  • They added 884 KEVs in 2025, drawing on exploitation evidence from 118 sources; nearly 48% had 2025 identifiers, underscoring how quickly new bugs become operational.

  • Almost 29% of those KEVs were exploited on or before the day the CVE was published, up from 23.6% the year before.

These figures are the pre-Mythos baseline: exploitation velocity in an environment where AI-assisted discovery was emerging but not yet dominant. The trajectory was already moving in the wrong direction. Mythos accelerates that compression by an order of magnitude.

The React2Shell vulnerability (CVE-2025-55182) is the poster child. A critical RCE in React Server Components disclosed in early December 2025, it accumulated 236 valid public exploits in four weeks, more than any vulnerability in history, and rocketed into the top 1% of exploited vulnerabilities of all time. VulnCheck's Canary Intelligence observed more than 26,000 exploit attempts by January 2026, across Chinese, North Korean, and Iranian actors; botnets like Mirai, Gafgyt, and RondoDox; and at least one ransomware family (VulnCheck, 2026).

From an attacker's perspective, React2Shell is ideal: a single HTTP request manipulates in-memory runtime state, allows arbitrary JavaScript actions, and leaves almost no artifacts on disk. It is the type of vulnerability Mythos-class models are designed to find and weaponize at scale (CSA, 2026; VulnCheck, 2026).

The strategic implication: our risk is no longer proportional to how many vulnerabilities exist. It's driven by how quickly we can detect, contain, and compensate for the small subset of bugs that adversaries actually use. CSA frames the goal of a Mythos-ready program as increasing the cost of exploitation through segmentation, Zero Trust, strong identity, and egress controls; enabling early detection of compromise; and containing blast radius when that 1% is exploited.

We would also add that predictive classification at scale is now more feasible than ever. This means focusing on identifying which vulnerabilities are likely to make it into that one percent exploitable category before the attackers do. Traditional vulnerability management, with quarterly scans, risk ratings, and 30-60-day patch SLAs, wasn't designed for an environment where nearly a third of exploited vulnerabilities are already in play on day zero. This is a shift in approach whereby a VulnOps team treats high-risk vulnerabilities as operational events, not backlog items.


Third-Party and Supply Chain Risk: Your Vendors' Exposure Windows Are Now Yours (more than ever)


Project Glasswing is Anthropic's attempt to get ahead of this curve. As the CSA paper describes, Anthropic gave roughly 40 critical infrastructure providers and major vendors early access to Mythos so they could scan and patch their own products before public disclosure, in what the CSA calls the largest multi-party vulnerability coordination effort in history (CSA, 2026).

But VulnCheck's data shows how far Glasswing may have to stretch:

  • The 2025 KEV list spans 518 vendors and 672 unique products, from hyperscale enterprise platforms to small web apps and WordPress plugins (VulnCheck, 2026).

  • Network edge devices remain at the top of the KEV target list for 2025, with Fortinet, SonicWall, Ivanti, and others heavily represented.

  • The Routinely Targeted Vulnerabilities (RTV) list for 2025 reads like a who's-who of third-party risk: Microsoft SharePoint ("ToolShell" chain), SAP NetWeaver, Oracle E-Business Suite, Citrix NetScaler, SimpleHelp, GoAnywhere MFT, VMware ESXi, and more.

Consider the SharePoint ToolShell chain (CVE-2025-49704, -49706, -53770, -53771). Microsoft initially patched two flaws in July 2025, then acknowledged the fixes were incomplete and issued two more CVEs when patch bypasses were discovered amid active exploitation. CVE-2025-53770 alone ended 2025 with 10 different threat actors and at least six ransomware families associated with it (VulnCheck, 2026).

Or the Oracle E-Business Suite zero-days (CVE-2025-61882 and CVE-2025-61884), which Cl0p leveraged in a high-impact extortion campaign. Exploitation likely started months before public disclosure, and confusion over patch completeness and exploit chains led to muddled remediation guidance and a second CVE for an incomplete fix (VulnCheck, 2026). For executives, the supply chain implications are straightforward. You inherit your vendors' exposure windows. When complex platforms like SharePoint or EBS are under active exploitation before patches are complete, your own resilience hinges on their patch and mitigation cadence and your ability to put compensating controls in place quickly. Patch waves will come in clusters. Glasswing-style programs will likely drive bursts of urgent advisories from multiple vendors at once, especially in network edge, identity, and data-plane products. Your change management, testing, and rollback processes need to be prepared for "multi-vendor Patch Tuesday" scenarios, not one-off emergencies.

CSA's guidance is to tighten governance and procurement so you can onboard defensive tech faster and pressure vendors on their own Mythos-readiness:

  1. Do they use AI-assisted discovery on their code?

  2. How quickly can they roll out mitigations when Mythos-class disclosures land?

  3. And how quickly can you safely consume those changes?


Open-Source Risk: Shared Code, Shared Blast Radius


Open source has always been a leverage play: you get enormous capability for minimal cost, at the price of shared exposure when something goes wrong.

According to VulnCheck, eight of the ten most-researched CVEs of 2025 by exploit count are in open-source projects: sudo, XWiki, Apache Tomcat, Langflow, Erlang/OTP, Git, Next.js, and React. React2Shell again dominates the list with 236 exploits (VulnCheck, 2026).

On the signal quality side, VulnCheck calls out what they term "ensloppification": a surge of AI-generated, non-functional, or outright fabricated exploits polluting GitHub and other repos. The first widely circulated React2Shell PoC claimed to be a working exploit but never exercised the vulnerable code path. It still consumed significant time across many organizations and found its way into public write-ups. In some cases, AI systems then ingested those bogus repos and amplified them as authoritative results, creating self-reinforcing loops of bad technical intelligence (VulnCheck, 2026).

This creates a dual risk for open-source consumers. First, higher real vulnerability volume in the components you rely on most. Projects like Linux and curl are seeing vulnerability report volumes spike, initially from AI "slop," but now increasingly from high-quality, AI-assisted reports, many of which turn out to be real bugs (CSA, 2026). Second, a noisier signal environment at exactly the moment you most need clarity. Public PoCs have historically been a decent risk indicator, but VulnCheck's data shows that in 2025 more than 98% of tracked exploits were PoCs, not weaponized tools, and "public PoC exists" is a poor predictor of in-the-wild exploitation. In React2Shell's case, the early PoC was wrong, but the real risk was enormous (VulnCheck, 2026).

For a Mythos-ready VulnOps capability, that means treating key open-source dependencies as first-class assets, not transitive afterthoughts. SBOMs, dependency provenance, and hot-swap patterns become mandatory. Anchor prioritization on exploit intelligence, not just PoC availability. VulnCheck's KEV and RTV datasets are examples of how to separate the one percent that matters from the ninety-nine percent that doesn't. And validate exploit artifacts before you react. AI can help here too: agents that cross-check exploit behavior against real code paths will save time and reduce both false positives and false negatives.


What a Mythos-Ready VulnOps Capability Could Look Like


Operational response to vulnerabilities. Build playbooks that treat a new KEV-grade vulnerability like an incident: pre-approved containment steps, compensating controls (WAF rules, feature flags, segmentation moves), and communication plans. React2Shell and ToolShell were not "patch-within-30-days" problems. They were live fires.

Exploit-centric metrics. Start reporting "Mean Time to Compensating Control," "Mean Time to Contain," and "percentage of KEV/RTV vulnerabilities with effective mitigation in 24-72 hours," not just patch SLAs. Those are the numbers that will matter when boards and regulators ask how you responded to Mythos-class risk.

Human resilience as a first-class concern. Both CSA and VulnCheck point to the human cost: more vulnerabilities, higher tempo, and more confusing signals. If you try to absorb this with manual heroics, burnout and attrition are highly likely. CSA recommends additional headcount (yes humans), reserve capacity, and systematic AI augmentation across security roles so your team can operate at Mythos speed without breaking.

VulnCheck's exploit telemetry is the measurement framework for tracking what comes next. Organizations that establish their baseline now, mapping KEV coverage, time-to-exploitation, and ransomware zero-day rates against their own environment, will have the data to quantify Mythos-era impact as it materializes.

The key is to recognize that these trends are not a temporary spike. They mark a structural shift in how fast offense can move. A VulnOps enabled by predictive analytics, operational rigor and focused on addressing true business risk is how to turn AI and high confidence exploit intelligence into a competitive advantage, not just another source of anxiety.


Citations

  1. Cloud Security Alliance. "AI Vulnerability Storm: Building a Mythos-ready Security Program." CSA, 2026.

  2. VulnCheck. "2026 Exploit Intelligence Report." VulnCheck, 2026.

  3. Carnegie Mellon University Software Engineering Institute. "Cyber Intelligence Tradecraft Report." CMU SEI, 2019. https://www.sei.cmu.edu/documents/1589/2019_011_001_546699.pdf

  4. OODA Loop. "Lessons Learned about Offensive AI: The DARPA AI Cyber Challenge (AIxCC) and Team Atlanta's Victory." 2025. https://oodaloop.com/analysis/disruptive-technology/lessons-learned-about-offensive-ai-the-darpa-ai-cyber-challenge-aixcc-and-team-atlantas-victory/

  5. OODA Loop. "Defending Your Digital Frontier: Chris Wysopal on Reducing Attack Surface in the Age of AI." OODAcast, 2025. https://oodaloop.com/oodacasts/business/defending-your-digital-frontier-chris-wysopal-on-reducing-attack-surface-in-the-age-of-ai/

Share On:

Human Cybersecurity Expertise at Trusted AI Scale

Trust Center

© 2024 Blackwire Labs. All rights reserved.

The Blackwire Labs logo®, TRUSTWIRE®, and related indicia are © and registered trademarks of Blackwire Labs, Inc.

Human Cybersecurity Expertise at Trusted AI Scale

Trust Center

© 2024 Blackwire Labs. All rights reserved.

The Blackwire Labs logo®, TRUSTWIRE®, and related indicia are © and registered trademarks of Blackwire Labs, Inc.

Human Cybersecurity Expertise at Trusted AI Scale

Trust Center

© 2024 Blackwire Labs. All rights reserved.

The Blackwire Labs logo®, TRUSTWIRE®, and related indicia are © and registered trademarks of Blackwire Labs, Inc.