Safety2 min read

AI Now Finds Security Holes Faster Than Anyone Can Fix Them

May 8, 2026Synthesized from 1 source: The Guardian

Anthropic's new AI model found tens of thousands of hidden flaws in the world's most used software before anyone else did, and the gap between how fast these holes are now being discovered and how fast organizations can actually fix them is the real danger facing every business.

On April 7, Anthropic announced that its new AI model, Claude Mythos, had found thousands of previously unknown security flaws in every major operating system and web browser on earth. One flaw had been sitting undetected in a widely used piece of software for 27 years. Another survived 16 years and five million automated tests before Mythos found it. Anthropic decided it was too dangerous to release the model publicly and instead gave access to roughly 40 companies, including Microsoft, Apple, Google, and JPMorgan, under a program called Project Glasswing.

The capabilities are real, even if the marketing around them is loud. An earlier Anthropic model found about 20 vulnerabilities in the Firefox browser. Mythos found nearly 300, and was able to turn 181 of them into working attack tools. Two years ago, the best AI models could barely complete beginner-level security tasks. Now Mythos completes expert-level ones 73% of the time, tasks that previously no model could attempt at all. The UK government's AI Security Institute confirmed independently that Mythos can execute multi-stage attacks on vulnerable networks in the time it takes a human specialist days to complete.

But the more important story is not what Mythos can find. It is what no one can fix fast enough. Anthropic's own figures show that over 99% of what Mythos discovered remains unpatched. Fixing software is still a slow, human process: file a ticket, test a patch, roll it out, make sure it does not break the system it runs on. AI has collapsed the time it takes to find a problem from months to hours. The time it takes to fix one has not changed at all.

This gap hits hardest in places that run older equipment. Industrial control systems in energy, water, manufacturing, and transportation are often decades old and cannot receive patches at all, either because the manufacturer no longer supports them or because applying a patch would risk shutting down an operation. These systems were built to be reliable, not to be updated continuously. They are now the softest targets on the network.

There is also a geopolitical dimension that is not theoretical. Anthropic's CEO says Chinese AI is six to twelve months behind Mythos in these capabilities. Chinese law already requires private security researchers to hand discovered vulnerabilities to government agencies before anyone else is told, which means China's best security research feeds directly into state intelligence programs. A Chinese cybersecurity firm has already claimed its own AI found close to a thousand vulnerabilities, including serious flaws in Windows and Android. Whether that claim is fully accurate or not, the direction of travel is clear.

The precedent Anthropic has set also deserves attention. A private company has unilaterally decided which organizations get access to a capability with national security implications, with no democratic oversight and no regulatory framework. OpenAI has now released a comparable model to vetted defenders under a different, somewhat more open approach. Neither approach was designed by governments. Both were designed by the companies themselves.

What this means practically: the organizations who got access to Mythos first are quietly scanning and patching their systems right now. The organizations who did not are not standing still either. They are simply unaware of the specific flaws in their software that AI can already find. That asymmetry between the informed and the uninformed will define the next wave of serious cyberattacks. The attackers need to find only one way in. The defenders have to close all of them.

Stay informed

Get AI intelligence like this delivered to your inbox.


You May Also Find Valuable