Skip to content
Tiatra, LLCTiatra, LLC
Tiatra, LLC
Information Technology Solutions for Washington, DC Government Agencies
  • Home
  • About Us
  • Services
    • IT Engineering and Support
    • Software Development
    • Information Assurance and Testing
    • Project and Program Management
  • Clients & Partners
  • Careers
  • News
  • Contact
 
  • Home
  • About Us
  • Services
    • IT Engineering and Support
    • Software Development
    • Information Assurance and Testing
    • Project and Program Management
  • Clients & Partners
  • Careers
  • News
  • Contact

AI found 2,000 vulnerabilities in 7 weeks. We’ve patched almost none of them

There used to be an unspoken rule in cybersecurity: when a researcher found a vulnerability, everyone kept quiet long enough for the affected companies to patch it. The exploit would eventually be logged in the CVE channels, and the security community would respond — but there was a window to fix it. Time to defend.

That window is gone. Mythos closed it.

Anthropic’s new frontier model discovered more than 2,000 previously unknown software vulnerabilities across every major operating system in seven weeks — including flaws that had survived decades of human-led review. It didn’t just find them. It developed working exploits, autonomously, without human instruction.

And during internal testing, an early version escaped a controlled sandbox, gained unsanctioned internet access and emailed the supervising researcher to let them know. Nobody asked Mythos to do that.

The same threat, now unrecognizable

I’ve been watching the fraud landscape for 25 years, and my honest read is this: the negative potential of Mythos and similar tools isn’t a new breed of threat. It’s the existing threat, reborn at a speed that makes our current defenses structurally obsolete.

Meanwhile, the fraud we’ve always fought hasn’t changed in kind — we still face synthetic identities, account takeovers and injection attacks on liveness verification, among others. What has changed is velocity.

An attack that used to spread across financial institutions over weeks, giving defenders time to correlate signals and respond, can now happen across a thousand institutions in five minutes. Each one becomes its own zero-day. The consortium model — where shared intelligence lets the industry catch repeat attacks — breaks down completely at machine speed. There isn’t time for it to work.

That’s not an incremental problem. That’s a structural one.

What Mythos means for identity infrastructure

Here’s what makes the challenges introduced by Mythos particularly dangerous for identity verification: identity is software.

A mobile driver’s license is code. A biometric certificate is code. A KYC workflow is code. When an autonomous reasoning system is finding individual flaws and connecting them into working attack sequences across operating systems and financial rails, the logic of trust itself becomes the attack surface.

Another detail that deserves more attention is that over 99% of the vulnerabilities Mythos found remain unpatched. The model has outpaced remediation by an enormous margin. Faster vulnerability detection is only helpful if the remediation can keep up, and right now, it can’t.

In the wrong hands, this makes Mythos an offensive AI capability operating at rocket speed against a defensive infrastructure operating at airplane speed. Fast, but nowhere near fast enough.

The two-tier problem everyone hopes to avoid

Anthropic’s response to the extraordinary capabilities of Mythos was Project Glasswing — a controlled coalition of roughly 50 partners given early access to find and patch their vulnerabilities before adversaries develop equivalent capability. The list includes Microsoft, Apple, AWS, JPMorgan, Google, Nvidia and Palo Alto Networks.

It’s a reasonable approach. It’s also creating a two-tier security world.

Glasswing is a good idea with a serious blind spot. The coalition gets the biggest players patched before adversaries catch up, at least in theory. But the mid-market enterprise is working with the same vulnerable infrastructure, only without the patch runway or engineering capacity to move at that speed.

The right approach for anyone outside the chosen coalition isn’t to wait for guidance from the big companies. It’s to assume the vulnerability already exists, audit accordingly and build identity infrastructure resilient enough to absorb an attack you didn’t see coming — because that’s the scenario you’re actually in.

Additionally, what’s to stop a bad actor from creating a “Mythos” level attack capability on their own, leveraging readily available tools and intelligence already in the wild?  Now that Mythos has shown them the way, they’ll start experimenting with their own tech.

The KYA problem, accelerated

I’ve written before about Know Your Agent — the argument that we need the same upstream verification for agents that we apply to people and companies, especially as autonomous AI agents begin executing transactions on behalf of people and businesses. Who created this agent? Who is it acting for? Has it changed since we last trusted it?

Mythos sharpens that argument considerably. The question is no longer theoretical.

Anthropic’s agents are already running inside JPMorgan, Goldman and Citi. When a KYC workflow is AI-native end-to-end, the trust chain looks fundamentally different. An AI that can autonomously discover vulnerabilities and develop exploits is operating in the same environment as an AI that’s deciding whether to onboard a customer.

Any time an agent makes the verification call — not assisting a human who makes it — you need to know exactly where accountability and liability live before the first mistake happens. That means the agent’s origins, its permissions, who the real person is running it now and any changes to its behavior since it was last verified all need to be legible in real time.

Without that upstream verification logic, you don’t have a KYC workflow. You have a black box making compliance decisions.

The new shape of defensibility

Considering what companies need to defend against these new attacks is challenging because most organizations haven’t built it yet.

We need deepfake fraud detection across every modality, from document verification and liveness checks to device intelligence and data verification. This needs to be a unified system that correlates signals in real time, not merely a layered add-on.

The consortium model worked when attacks moved slowly enough to share intelligence and respond. At machine speed, you must defend at the point of contact. By the time the alert travels through a shared network, the attack is already done.

We also need to change the feedback loop. A system that updates its models every six months based on industry news isn’t a defense against Mythos-era attacks — it’s a slow-moving rulebook that’s likely outdated the first day it’s published.

Real resilience means continuously learning from what you see and updating before the next wave arrives. We’ve known for years that this moment was coming. Mythos didn’t change how we need to defend; it just radically accelerated the timeline.

This article is published as part of the Foundry Expert Contributor Network.
Want to join?


Read More from This Article: AI found 2,000 vulnerabilities in 7 weeks. We’ve patched almost none of them
Source: News

Category: NewsJune 16, 2026
Tags: art

Post navigation

PreviousPrevious post:SpaceX’s planned $60 billion deal for Cursor raises questions for CIOsNextNext post:Beyond the ERP system: The autonomous value chain

Related posts

Una mirada al futuro del liderazgo en TI: la visión del CIO Executive
June 19, 2026
Solving an ARD problem in AI: Agentic Resource Discovery
June 19, 2026
Google, Microsoft offer specs to help you prove your AI is behaving nicely
June 19, 2026
OpenAI adds spend controls and usage analytics to ChatGPT Enterprise
June 19, 2026
La carrera por abaratar la IA: así intentan las empresas bajar el coste de los ‘tokens’
June 19, 2026
Gracia Sánchez-Vizcaíno (Securitas): “El CIO que solo gestiona sistemas va a perder relevancia frente al que lidera la transformación del modelo operativo completo”
June 19, 2026
Recent Posts
  • Una mirada al futuro del liderazgo en TI: la visión del CIO Executive
  • Solving an ARD problem in AI: Agentic Resource Discovery
  • Google, Microsoft offer specs to help you prove your AI is behaving nicely
  • OpenAI adds spend controls and usage analytics to ChatGPT Enterprise
  • La carrera por abaratar la IA: así intentan las empresas bajar el coste de los ‘tokens’
Recent Comments
    Archives
    • June 2026
    • May 2026
    • April 2026
    • March 2026
    • February 2026
    • January 2026
    • December 2025
    • November 2025
    • October 2025
    • September 2025
    • August 2025
    • July 2025
    • June 2025
    • May 2025
    • April 2025
    • March 2025
    • February 2025
    • January 2025
    • December 2024
    • November 2024
    • October 2024
    • September 2024
    • August 2024
    • July 2024
    • June 2024
    • May 2024
    • April 2024
    • March 2024
    • February 2024
    • January 2024
    • December 2023
    • November 2023
    • October 2023
    • September 2023
    • August 2023
    • July 2023
    • June 2023
    • May 2023
    • April 2023
    • March 2023
    • February 2023
    • January 2023
    • December 2022
    • November 2022
    • October 2022
    • September 2022
    • August 2022
    • July 2022
    • June 2022
    • May 2022
    • April 2022
    • March 2022
    • February 2022
    • January 2022
    • December 2021
    • November 2021
    • October 2021
    • September 2021
    • August 2021
    • July 2021
    • June 2021
    • May 2021
    • April 2021
    • March 2021
    • February 2021
    • January 2021
    • December 2020
    • November 2020
    • October 2020
    • September 2020
    • August 2020
    • July 2020
    • June 2020
    • May 2020
    • April 2020
    • January 2020
    • December 2019
    • November 2019
    • October 2019
    • September 2019
    • August 2019
    • July 2019
    • June 2019
    • May 2019
    • April 2019
    • March 2019
    • February 2019
    • January 2019
    • December 2018
    • November 2018
    • October 2018
    • September 2018
    • August 2018
    • July 2018
    • June 2018
    • May 2018
    • April 2018
    • March 2018
    • February 2018
    • January 2018
    • December 2017
    • November 2017
    • October 2017
    • September 2017
    • August 2017
    • July 2017
    • June 2017
    • May 2017
    • April 2017
    • March 2017
    • February 2017
    • January 2017
    Categories
    • News
    Meta
    • Log in
    • Entries feed
    • Comments feed
    • WordPress.org
    Tiatra LLC.

    Tiatra, LLC, based in the Washington, DC metropolitan area, proudly serves federal government agencies, organizations that work with the government and other commercial businesses and organizations. Tiatra specializes in a broad range of information technology (IT) development and management services incorporating solid engineering, attention to client needs, and meeting or exceeding any security parameters required. Our small yet innovative company is structured with a full complement of the necessary technical experts, working with hands-on management, to provide a high level of service and competitive pricing for your systems and engineering requirements.

    Find us on:

    FacebookTwitterLinkedin

    Submitclear

    Tiatra, LLC
    Copyright 2016. All rights reserved.