According to a new analysis by Anthropic’s red team, the traditional patch-to-exploit window has collapsed from weeks to under an hour, driven by AI models like Claude Mythos Preview. In controlled tests, the model turned 18 Firefox patches into 8 working code-execution exploits, with the first exploit landing within 60 minutes of Mozilla shipping the fix—while the actual Firefox release carrying that patch was still 18 days away. For Windows kernel bugs, the model built proof-of-concept crashes for 18 out of 21 CVEs (fastest in 31 minutes) and chained 8 to full SYSTEM compromise at roughly $2,000 per exploit chain. Notably, one chain targeted a bug Microsoft had rated ‘Exploitation Unlikely,’ a calibration that no longer holds against AI-driven reverse engineering.
The article argues that the old playbook of ‘patch faster’ is no longer viable. Verizon’s 2026 DBIR reports median fix time for known-exploited flaws at 43 days, up from 32 days the prior year, with only 26% ever fully patched. The Zero Day Clock shows average time-to-exploit dropping to under 24 hours in 2026, down from ~53 days in 2024. With roughly 135 new CVEs per day (up 40% year-over-year), security teams cannot clear the backlog. The author, Sıla Özeren Hacıoğlu of Picus Security, proposes a shift from vulnerability prioritization to adversarial exposure validation—proving exploitability through three methods: safe live exploit testing (covers 10-15% of assets), TTP-chaining against controls (covers the remaining 85-90%), and continuous breach and attack simulation. Picus Security’s platform, Picus Swarm, operationalizes this loop with AI agents, reporting 92% fewer SLA violations, 89% lower MTTR, and 2x control effectiveness in three months.
CVEs: CVE-2026-XXXX, CVE-2026-YYYY, CVE-2026-ZZZZ, CVE-2026-WWWW, CVE-2026-VVVV, CVE-2026-UUUU, CVE-2026-TTTT, CVE-2026-SSSS, CVE-2026-RRRR, CVE-2026-QQQQ, CVE-2026-PPPP, CVE-2026-OOOO
Companies: Anthropic, Mozilla, Microsoft, Picus Security, Verizon
Products: Claude Mythos Preview, Picus Autonomous Penetration Testing, Picus Exposure Validation, Picus Breach and Attack Simulation, Picus Swarm
Original source: thehackernews.com