Apple spent five years and, by some accounts, enormous amounts of money building a security system called Memory Integrity Enforcement into its newest Mac chips. A small team at a firm called Calif broke through it in five days, with significant help from Anthropic's AI model, Claude Mythos. They then flew to Apple Park and delivered a 55-page report in person.
The actual exploit requires a skilled human to assemble. Mythos found the underlying weaknesses quickly because they belonged to known categories of bugs, but a human expert was still needed to build the final attack chain. This distinction matters. The AI is not replacing attackers. It is removing the slow, expensive parts of their job: finding where to look, and figuring out how pieces connect.
That shift in speed is the real story. The time from when a software flaw becomes known to when attackers are using it in the wild dropped from over 700 days in 2020 to 44 days in 2025. Today, according to Google's own threat data, the average is now negative: exploits routinely arrive before patches do. Anthropic's Mythos had already found thousands of serious flaws across every major operating system and browser before the macOS story broke publicly. One of those flaws had been sitting undetected for 27 years inside OpenBSD, a system specifically built for security.
The volume is becoming a structural problem. Microsoft has already patched more than 500 vulnerabilities in the first five months of 2026, on pace to break its own annual record. Its security team said directly that AI tools are driving the surge. Oracle, also a Glasswing participant, switched from quarterly to monthly patch cycles for critical issues. HackerOne, which runs one of the world's largest bug bounty programs, paused its open-source program this year, citing a worsening gap between how fast flaws are being found and how fast they can be fixed.
Both Anthropic and OpenAI have responded by building formal programs to direct these capabilities toward defense. Anthropic's Project Glasswing, launched in April with $100 million in committed resources, gives around 40 organizations controlled access to Mythos for defensive scanning. OpenAI's Daybreak, launched four days ago, uses its GPT-5.5 models and a security tool called Codex to help organizations find and fix vulnerabilities before attackers do.
The participants in both programs overlap significantly and include companies that run core financial, cloud, and communications infrastructure globally. The fact that both programs exist as closed, tightly controlled initiatives rather than public tools is itself an acknowledgment of the risk. Anthropic has explicitly said Mythos will not be released to the public in its current form.
For any organization that runs software, manages customer data, or relies on vendor platforms, the practical implication is this: the patch windows that IT teams have planned around for years are no longer realistic. A flaw discovered today may be weaponized before a fix is tested and deployed. The question is no longer whether your vendors will find and fix issues. It is whether they can do it fast enough, and whether your own systems are positioned to absorb updates quickly when those fixes arrive.
Calif called the Apple exploit a glimpse of what is coming. That framing is accurate. The tools that broke a five-year security effort in five days are not staying restricted for long.