By David Honour, Editor, Resilience Forward
The recent Claude Mythos Preview has sent a shockwave through the cyber security community – and for good reason. Anthropic’s disclosure – that the model identified thousands of high-severity vulnerabilities across every major operating system and browser – has raised fears that Mythos could blow cyber security wide open.
While concerns around ensuring that there is a controlled rollout of itscapabilities are legitimate, treating Mythos as the primary threat is a strategic error. Mythos isn’t the architect of our fragility; it is the auditor. It has simply identified the technical debt we’ve been accruing for decades through the human flaws inherent in software and system development.
For years, organizations have survived despite imperfect software simply because the attackers were no better at nosing out vulnerabilities than the developers were at identifying them in the first place. Mythos exposes the reality that protection due to extreme complexity can never be relied upon again.
However, while highlighting the problem, Mythos also offers a way out of the dilemma.
In a traditional conflict, the attacker only has to be right once, while the defender must be right 100% of the time. AI potentially flips this script:
- The attacker’s burden: attackers must find a vulnerability that hasn’t been closed by an automated defensive audit.
- The defender’s advantage: Once a defensive AI identifies and remediates a bug, that entire class of exploit can be neutralised across the ecosystem at machine speed.
Compressing the OODA loop
To win in the Mythos era, we must move beyond manual patching toward autonomous cyber resilience. This is about compressing the OODA Loop (Observe, Orient, Decide, Act):
- Observe and Orient: use models like Mythos to find flaws in seconds, not months, years, or never.
- Decide and Act: shift from ‘notifying the team’ to ‘autonomous remediation’ – where the AI not only finds the vulnerability or other security hole but suggests (or even deploys, depending on your risk appetite!) the code to plug it.
By turning AI into a high-speed digital immune system, we move from a reactive posture to a proactive one. We aren’t just ‘fixing bugs’; we are hardening the attack surface before an adversary even knows it exists.
The future belongs to the fast
The lesson of the Mythos moment is clear: we cannot protect critical systems by refusing to address the issues. Blocking the deployment of Mythos or holding back its deployment is not a solution. It might kick the can a very short distance down the road. But the attackers now know where to look and what is possible using similar capabilities – which will inevitably quickly emerge.
The real risk is not that AI is too good at finding flaws; the risk is that our response remains too human, too manual, too slow, and too afraid.
The strategic response is not to suppress the visibility that AI provides, but to embrace the velocity it enables. We cannot win a race we refuse to run. The only viable cyber strategy is to out-pace the threat by building security that acts at the same speed as the intelligence that challenges it.
The future is not less visibility; it is faster action.
Industry comments
Ansgar Dodt, VP Strategic Development at Thales
“We have been warning about this shift for a long time – AI is dramatically lowering the barrier to discovering and exploiting software weaknesses and accelerating it to a scale humans simply cannot match.
“The implication is clear: organizations now have to assume their software and applications will be continuously analysed, deconstructed, and stress-tested by adversarial AI.
“That demands a fundamental rethink of software protection. It is necessary not only to systematise the remediation of vulnerabilities after they are discovered, but also for developers to make it more difficult, from the design stage onward, for attackers to understand and exploit the code. That means protecting the application itself – through encrypting code and sensitive data, obfuscating logic, and embedding runtime defences that actively detect debugging, tracing, or tampering attempts and respond in real time, for example by preventing execution or invalidating access.”
“Critically, protection also needs to be resilient, ensuring the integrity of the application and removing the clear seams of vulnerability attackers can exploit to separate and analyse code. The goal is to deny adversaries, and increasingly their AI tools, the visibility they rely on.
“An industrialised cyber security approach is needed to combine AI-augmented SOCs, AI-driven DevSecOps, automated patching and response (SOAR), advanced testing, and legacy system protection within a trusted framework. Cloud Security Alliance’s recommendations and the upcoming Cyber Resilience Act (CRA) both emphasise integrating AI-based vulnerability analysis throughout the development lifecycle to prevent exploitation from the outset. “Mythos Preview might never become public, but it is only a matter of time before we see models with comparable hacking abilities released by competitors out in the wild. Organizations need to act now to harden their applications against AI-driven analysis, or risk being exposed at machine speed. The conversation needs to move quickly from awareness to implementation. With the obligations under the CRA, failing to protect software applications from vulnerabilities can lead to reputational damage, potential penalties, product recalls, and loss of market access.”






