Anthropic Built an AI That Can Hack Your Business

Anthropic just revealed Claude Mythos Preview, an AI so capable at finding and exploiting software vulnerabilities that they decided the world isn't ready for it.

Not a research paper. Not a proof of concept. A working system that autonomously found thousands of previously unknown vulnerabilities in the world's most critical software, operating systems, web browsers, cryptography libraries, and then wrote working exploits to prove it.

They're keeping it locked up. One of the most safety-conscious AI labs on the planet built something powerful enough to hack nearly everything and decided even they shouldn't release it.

That silence is the warning.


What Claude Mythos Actually Did

I want to be specific here, because the details matter.

Anthropic didn't just test Mythos in a controlled lab environment. They pointed it at real, production software that runs the internet and let it work.

Here's what it found and exploited, autonomously:

A 27-year-old bug in OpenBSD, a security-focused operating system used in firewalls and core internet infrastructure. The bug would allow a remote attacker to crash any machine running the system over the internet. It took the AI several hours and cost under $50 to find.

A 17-year-old remote code execution hole in FreeBSD's network file system. An attacker anywhere on the internet, with no credentials whatsoever, could gain complete root access to a server. Mythos didn't just find the vulnerability. It autonomously wrote a working exploit with no human involvement after the initial prompt.

In total, Anthropic's team identified thousands of high- and critical-severity vulnerabilities and is now working through responsible disclosure to get them patched.


Why This Is a Business Problem, Not a Security Team Problem

Here's what I've learned in 25 years of IT, cybersecurity, and risk management: the gap between "technically interesting" and "business-ending" is smaller than most executives think.

So let me translate what Mythos means for your business.

Speed has changed fundamentally. When a vulnerability is publicly disclosed today, attackers historically needed days or weeks to turn that disclosure into a working exploit. That window is your organization's survival window. It's when your team patches, when your vendor releases a fix, when the risk goes from theoretical to real. Mythos compresses that window dramatically. Exploits that previously took expert researcher's weeks to build are now being generated autonomously in hours.

Scale has changed fundamentally. A skilled human attacker can meaningfully target a limited number of systems. An AI-driven tool can scan, probe, and exploit at a scale no human team can match, simultaneously, without breaks, without getting bored. The businesses that get hit won't necessarily be targeted specifically. They'll be the ones that happened to be reachable and unpatched when the scan swept through.

The skill barrier has collapsed. Anthropic's own paper notes that engineers with no formal security training were able to ask Mythos to find remote code execution vulnerabilities and wake up the next morning to a complete, working exploit. The tools that previously required elite expertise are becoming accessible. That means the population of people who can attack your business is growing.

What does this mean in business terms?

It means a breach isn't an IT inconvenience. It's a week of operations offline. It's your customer data on a dark web forum and the regulatory notifications that follow. It's the call to your cyber insurance carrier and the argument about what's covered. It's your clients asking hard questions. It's the conversation with your board that nobody wants to have.

I wrote about exactly this dynamic in Exposed to Secure. The businesses that don't survive breaches almost never failed because the attack was too sophisticated. They failed because their defenses were built for a threat environment that no longer exists.


The Uncomfortable Truth About "We're Probably Fine"

I hear some version of "we have antivirus and a firewall, we're probably fine" more often than I should.

That posture made sense in 2005. In 2026, it's a liability.

Most small and mid-sized businesses are sitting in the same position right now. Perimeter defenses designed before cloud infrastructure became standard. Patch cycles that run quarterly when vulnerabilities are now being weaponized in hours. No real-time visibility into what's happening on the network, just the assumption that silence equals safety.

Silence doesn't mean safe. It often means undetected.

What a post-Mythos threat environment actually requires:

Knowing your vulnerabilities before an attacker finds them, through regular penetration testing and vulnerability discovery that reflects the actual threat landscape, not an annual checkbox audit.

Network segmentation and perimeter architecture that limits what an attacker can reach even after they get in, because eventually, something gets in.

Intrusion detection that catches anomalous behavior in real time, not a report you review next quarter.

Advanced threat protection built for AI-driven attack patterns, not the playbooks from five years ago.

And increasingly, executive-level security leadership that translates risk into board-level decisions. Whether that's a vCSO, fractional support, or a trusted external partner, someone needs to be thinking about this at the level it actually operates.

This isn't about buying more software. It's about having a coherent security posture that matches the actual threat environment your business is operating in right now.


What Anthropic's Own Researchers Are Telling Defenders to Do

The team that built and tested Mythos published specific guidance for defenders. A few things worth highlighting:

Shorten your patch cycles, urgently. The time between a vulnerability being disclosed and a working exploit being available is shrinking fast. If your organization treats security patches as routine maintenance on a quarterly schedule, that needs to change now.

Assume your legacy software has unknown vulnerabilities. Mythos found a 27-year-old bug in OpenBSD and a 17-year-old bug in FreeBSD. These were among the most thoroughly audited software systems in the world. If those have undiscovered holes, so does your legacy infrastructure.

The exploitation window is closing. Anthropic's researchers were explicit: exploit development that used to take skilled researchers days or weeks now happens in hours, autonomously, at a cost of under $2,000 in some cases. Your incident response plan and patching enforcement need to reflect that reality.


What I Tell Clients After News Like This

When something like Claude Mythos surfaces, I don't use it to frighten people. I use it to focus them.

Fear without direction is just anxiety. And anxiety doesn't protect your business. Direction does.

After 25 years in this field, and after being featured in the documentary Cyber Crime Investigations, I've seen these threat cycles play out before. The pattern is always the same: new capability emerges, defensive tools catch up, a new equilibrium forms. Anthropic's own researchers said as much. They believe defenders will ultimately benefit more from AI than attackers will.

But they were also clear: the transitional period will be difficult. And the businesses that navigate it well will be the ones that got ahead of it, not the ones that waited until something went wrong.


Where to Start

If you're a business owner reading this and feeling uncertain about whether your current security posture is built for what's coming, that uncertainty is worth acting on.

Not with a massive emergency overhaul. Start with clarity.

At Netready, we work with businesses in financial services, construction, hospitality, and nonprofit sectors to do exactly that. We build security programs that match the actual risk environment, not the one from five years ago. From vulnerability discovery and penetration testing to perimeter defense, intrusion detection, and vCSO support, we help organizations move from exposed to secure in a way that fits how they actually operate.

The conversation doesn't have to be complicated. It just has to happen before the breach, not after.

If you want a straightforward, no-pressure conversation about where your business stands today, reach out. I'm happy to start there.


Zac Abdulkadir is President of Netready and has 25+ years of experience in IT, cybersecurity, and risk management. He is the author of the Amazon bestseller Exposed to Secure and has been featured in the documentary Cyber Crime Investigations. Netready serves clients across Southern California with services including perimeter defense, secure network design, vulnerability discovery, penetration testing, intrusion detection, advanced threat protection, insider threat management, and vCSO support.