- Claude Mythos delivers working exploits targeting known vulnerabilities within hours, according to Anthropic.
- Put to the test, Claude Mythos Preview delivered 16 working exploits targeting Firefox and Windows within hours.
- The model wrote its first working exploit in just under one hour, and created eight different exploits in roughly 12 hours.
- Mythos Preview delivered its first PoC in 31 minutes and created working exploits leading to privilege escalation for eight vulnerabilities within 18 hours.
- In April and May, Anthropic touted its ability to find vulnerabilities across more than 1,000 open source software (OSS) projects.
- N-days are considered more dangerous than zero-days because attackers can patch diff and reverse-engineer them to build exploits.
- While exploit development is just one step in a real N-day campaign, historically it is the step most bottlenecked by a lack of reverse engineering expertise.
- The cost of building exploits is not high, as each model is given a three-million-token budget for creating PoCs and exploits.
- The company suggests an updated patching playbook that should rely on 'N-hour' rather than 'N-day', suggesting that weaponizing a patch does not take weeks.
Anthropic's Claude Mythos Preview model is changing the landscape of exploit creation by enabling developers to create working exploits within hours, sometimes even minutes, challenging existing timelines for vulnerability remediation.124
In tests, Mythos created 16 working exploits aimed at Firefox and Windows within hours, showcasing its efficiency.
The system notably generated its first Proof of Concept (PoC) in just 31 minutes, proving that N-days can indeed become N-hours with this advanced technology. Mythos Preview produced eight different exploits over approximately 12 hours, and led to privilege escalation for several vulnerabilities within 18 hours.6
According to Anthropic, N-days are especially critical as they allow attackers to reverse-engineer exploits. The company advocates for an urgent shift in patching protocols, now suggesting a response based on 'N-hour' timelines instead of 'N-day'. This change emphasizes the need for a rapid response to emerging threats. The cost of creating these exploits is relatively low, with each model operating under a three-million-token budget to construct the PoCs targeting Firefox.8
Overall, this progress suggests a pressing need for updates in cybersecurity practices to keep pace with these technological advancements.
“Anthropic's Claude Mythos model drastically reduces the time needed to create exploits for N-day vulnerabilities, achieving results in as little as 31 minutes. The company suggests a new approach to vulnerability patching that counters assumptions about exploit development timelines.”
