Close Menu
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
More items
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
X (Twitter) LinkedIn
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
Login
LinkedIn Bluesky
Resilience Forward
Subscribe Now
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
Resilience Forward
You are at:Home»Cyber resilience»Claude Mythos Preview and the end of security through obscurity (Page 8)
Cyber resilience

Claude Mythos Preview and the end of security through obscurity

April 21, 20265 Mins Read
Digital Security Breach Concept of a Cracking Lock Representing Cyber Threats and Data Protection.

By David Honour, Editor, Resilience Forward

The recent Claude Mythos Preview has sent a shockwave through the cyber security community – and for good reason. Anthropic’s disclosure – that the model identified thousands of high-severity vulnerabilities across every major operating system and browser – has raised fears that Mythos could blow cyber security wide open.

While concerns around ensuring that there is a controlled rollout of itscapabilities are legitimate, treating Mythos as the primary threat is a strategic error. Mythos isn’t the architect of our fragility; it is the auditor. It has simply identified the technical debt we’ve been accruing for decades through the human flaws inherent in software and system development.

For years, organizations have survived despite imperfect software simply because the attackers were no better at nosing out vulnerabilities than the developers were at identifying them in the first place. Mythos exposes the reality that protection due to extreme complexity can never be relied upon again.

However, while highlighting the problem, Mythos also offers a way out of the dilemma.

In a traditional conflict, the attacker only has to be right once, while the defender must be right 100% of the time. AI potentially flips this script:

  • The attacker’s burden: attackers must find a vulnerability that hasn’t been closed by an automated defensive audit.
  • The defender’s advantage: Once a defensive AI identifies and remediates a bug, that entire class of exploit can be neutralised across the ecosystem at machine speed.

Compressing the OODA loop

To win in the Mythos era, we must move beyond manual patching toward autonomous cyber resilience. This is about compressing the OODA Loop (Observe, Orient, Decide, Act):

  1. Observe and Orient: use models like Mythos to find flaws in seconds, not months, years, or never.
  2. Decide and Act: shift from ‘notifying the team’ to ‘autonomous remediation’ – where the AI not only finds the vulnerability or other security hole but suggests (or even deploys, depending on your risk appetite!) the code to plug it.

By turning AI into a high-speed digital immune system, we move from a reactive posture to a proactive one. We aren’t just ‘fixing bugs’; we are hardening the attack surface before an adversary even knows it exists.

The future belongs to the fast

The lesson of the Mythos moment is clear: we cannot protect critical systems by refusing to address the issues. Blocking the deployment of Mythos or holding back its deployment is not a solution. It might kick the can a very short distance down the road. But the attackers now know where to look and what is possible using similar capabilities – which will inevitably quickly emerge.

The real risk is not that AI is too good at finding flaws; the risk is that our response remains too human, too manual, too slow, and too afraid.

The strategic response is not to suppress the visibility that AI provides, but to embrace the velocity it enables. We cannot win a race we refuse to run. The only viable cyber strategy is to out-pace the threat by building security that acts at the same speed as the intelligence that challenges it.

The future is not less visibility; it is faster action.

Make a comment

Industry comments

Ansgar Dodt, VP Strategic Development at Thales

“We have been warning about this shift for a long time – AI is dramatically lowering the barrier to discovering and exploiting software weaknesses and accelerating it to a scale humans simply cannot match.

“The implication is clear: organizations now have to assume their software and applications will be continuously analysed, deconstructed, and stress-tested by adversarial AI.

“That demands a fundamental rethink of software protection. It is necessary not only to systematise the remediation of vulnerabilities after they are discovered, but also for developers to make it more difficult, from the design stage onward, for attackers to understand and exploit the code. That means protecting the application itself – through encrypting code and sensitive data, obfuscating logic, and embedding runtime defences that actively detect debugging, tracing, or tampering attempts and respond in real time, for example by preventing execution or invalidating access.”

“Critically, protection also needs to be resilient, ensuring the integrity of the application and removing the clear seams of vulnerability attackers can exploit to separate and analyse code. The goal is to deny adversaries, and increasingly their AI tools, the visibility they rely on.

“An industrialised cyber security approach is needed to combine AI-augmented SOCs, AI-driven DevSecOps, automated patching and response (SOAR), advanced testing, and legacy system protection within a trusted framework. Cloud Security Alliance’s recommendations and the upcoming Cyber Resilience Act (CRA) both emphasise integrating AI-based vulnerability analysis throughout the development lifecycle to prevent exploitation from the outset. “Mythos Preview might never become public, but it is only a matter of time before we see models with comparable hacking abilities released by competitors out in the wild. Organizations need to act now to harden their applications against AI-driven analysis, or risk being exposed at machine speed. The conversation needs to move quickly from awareness to implementation. With the obligations under the CRA, failing to protect software applications from vulnerabilities can lead to reputational damage, potential penalties, product recalls, and loss of market access.”

Africa Asia Asia Pacific Australasia Europe Middle East North America UK
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email WhatsApp
Previous ArticleUK Resilience Academy to expand National Occupational Standards for resilience and emergencies
Next Article Attackers change tactics to target human behaviour and trusted relationships

Related Posts

An exploding digital padlock illustrates the requirement for post-quantum cryptography.

Research breakthrough brings reliable quantum computers and Q-day closer to reality

September 10, 2026
A danger sign on a digital background.

New blob URL phishing technique evades detection by using legitimate Microsoft services

September 10, 2026
AI risks

Unmanaged AI workflows expose EMEA organizations to rising compliance and data risks

September 9, 2026
City skyline at sunset with bright light trails and a translucent blue smart-city grid overlay and GPS pins indicating locations.

AI world models: future possibilities for organizational resilience?

September 7, 2026
DRJ and BCI logos

DRJ and BCI publish guidance for governing, managing, and using AI in resilience

September 7, 2026
Decision making with over whelming information.

AI can find the vulnerability. Accountability still sits with your crisis leadership

September 7, 2026
Advertisement
Resilience First
This week's most read articles
Logos of the Amazon cloud services AWS on a heap on a table.

New Level 1 DORA Workbook released for AWS customers regulated under DORA

November 26, 2024
Close-up of a green-brown iris peering through a jagged tear in dark paper or wall material.

The blind spots in business continuity

September 2, 2026
AI risks

Unmanaged AI workflows expose EMEA organizations to rising compliance and data risks

September 9, 2026
Latest resources
A cargo ship being loaded at a port.

UK Government report explores supply chain risk and resilience

June 24, 2026
Load More

Subscribe to Updates

Get our Resilience Updates newsletter.

Most Popular Feature Articles
Three dark coloured light bulbs on a black background illustrate the concept of The Dark Triad in Crisis Management.

The Dark Triad in crisis management

Five stage crisis management framework

A five stage framework for a crisis management process

Blue interconnected gears and network nodes symbolizing automation and complex machinery.

Agent zero – the 2028 digital pandemic

Latest Reports
A futuristic red warning alert icon with glowing exclamation mark.

Cloud Security Alliance publishes Hugging Face Incident Initial Post-Mortem

A person hold a building door open for a person behind who is tailgating to get unauthorised access.

Security Culture: A Strategic Capability That Builds Resilience in a Volatile World

An identity icon with a map marker on it, indicating the concept of identity as a target for attackers. The icon is on a generic IT background predominantly in black and orange.

Identity-based approaches dominate initial access for ransomware attacks

A promo box for an article about resilience governance.
© 2026 Resilience Forward
  • About Resilience Forward
  • Newsletter
  • Newsfeed
  • Advertise
  • Call for Papers
  • Contact
  • Privacy Policy and Cookie Use
  • AI Use Policy

Type above and press Enter to search. Press Esc to cancel.

Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Ad Blocker Enabled!
Ad Blocker Enabled!
Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.

Sign In or Register

Welcome Back!

Login to your account below.

Lost password?