- Mythos can turn newly disclosed software vulnerabilities into working exploits in hours instead of weeks, according to shared first with Axios.
- Within 31 minutes, Mythos generated its first proof-of-concept exploit for a Windows kernel vulnerability.
- In 18 out of the 21 kernel bugs tested, Mythos was able to cause a 'blue screen of death'.
- Mythos also created 8 distinct exploits, with the longest exploit taking about 5.7 hours to create.
- Across 18 security patches, Mythos built 8 working code-execution exploits.
- Anthropic estimates Mythos generated its Windows privilege-escalation exploits for about $15,700 in API credits — roughly $2,000 per exploit.
Anthropic's Mythos can swiftly convert newly disclosed software vulnerabilities into effective exploits, a process that previously took weeks. In a remarkable demonstration, it generated its first proof-of-concept exploit for a Windows kernel vulnerability in just 31 minutes.12
According to shared insights with Axios, Mythos performed exceptionally well, producing 8 distinct exploits across 18 tested vulnerabilities. Out of the 21 kernel bugs examined, Mythos caused a 'blue screen of death' in 18 instances, showcasing its potential for significant disruption.34
The creation time for the exploits varied, with the longest exploit requiring about 5.7 hours to develop. Cumulatively, Anthropic estimates that Mythos generated its Windows privilege-escalation exploits at a cost of roughly $15,700 in API credits, averaging about $2,000 per exploit. This technological leap raises crucial questions regarding cybersecurity, demonstrating how AI can both enhance software development and present new challenges for security measures.6
The implications of such advancements in AI-driven exploit creation warrant further examination, as organizations must now prioritize cybersecurity to guard against rapidly evolving threats.
“Anthropic's Mythos can generate working exploits from software vulnerabilities in a matter of minutes. For example, it produced a proof-of-concept exploit for a Windows kernel vulnerability within just 31 minutes.”
