← Google News

Anthropic points out that the AI 'Claude Mythos Preview,' which has extremely high cyberattack capabilities, can develop attacks within hours of a publicly disclosed vulnerability called 'N-day,' meaning 'the norm will change from N-day to N-hour.' - GIGAZINE

Google News · June 9, 2026
Anthropic identified that Claude Mythos Preview, an AI system, possesses advanced cyberattack capabilities and can develop attacks within hours of a publicly disclosed vulnerability. This capability represents a shift in vulnerability response timelines from the traditional N-day standard to an N-hour timeframe.

Detailed Analysis

Anthropic has disclosed findings regarding a model identified as Claude Mythos Preview that demonstrates substantially elevated offensive cybersecurity capabilities, particularly in the domain of exploiting publicly disclosed software vulnerabilities. The company's research indicates that this model can develop functional cyberattacks within hours of a vulnerability being publicly announced — a category of flaw traditionally referred to as an "N-day" vulnerability, where "N" denotes the number of days elapsed since public disclosure. Anthropic's conclusion is that this capability compression fundamentally alters the threat landscape: the operative unit of time for exploitation windows may shift from days to hours, effectively transforming "N-day" into what researchers are characterizing as "N-hour" exploitation.

The significance of this development lies in how it challenges a foundational assumption of enterprise and institutional cybersecurity: that organizations retain a meaningful remediation window after a vulnerability becomes publicly known. Current patch management frameworks, vulnerability disclosure timelines, and incident response protocols are largely calibrated around the expectation that defenders have days or weeks to act before sophisticated exploitation becomes widespread. If AI systems can reliably generate working exploit code within hours of a CVE or similar public disclosure, that assumption is no longer operationally valid, and the gap between disclosure and active exploitation — which defenders depend upon — effectively collapses.

This finding reflects a broader pattern in AI safety and capability research where frontier models are being rigorously evaluated against offensive security benchmarks before and after deployment. Anthropic, like other leading AI developers, has invested heavily in what it calls responsible scaling policies, which include pre-deployment evaluations of dangerous capabilities across categories such as biological threats, chemical weapons, and cyberattacks. The disclosure of Claude Mythos Preview's N-day capabilities suggests that Anthropic is internally identifying and publicly communicating capability thresholds that cross into high-risk territory, consistent with its stated commitment to transparency around dangerous model behaviors.

The broader implication for the cybersecurity industry is substantial. Vulnerability disclosure ecosystems — including coordinated disclosure programs, bug bounty platforms, and government databases like the National Vulnerability Database — operate on the premise that controlled information release benefits defenders more than attackers. AI-accelerated exploitation erodes this calculus by dramatically lowering the technical barrier and time cost for malicious actors to translate disclosed vulnerability information into deployable attack tools. Security teams would need to move toward near-real-time patch deployment, continuous automated patching pipelines, and potentially rethinking how and when vulnerability details are publicly released.

Anthropic's willingness to surface these findings publicly, even while they reflect capabilities of its own models, signals an evolving norm in the AI industry around proactive risk disclosure. Rather than waiting for adversarial misuse to materialize, the company appears to be using internal red-teaming and capability evaluations to map offensive potential before deployment and inform the security community of emerging threat vectors. This positions AI developers not merely as technology providers but as participants in shaping cybersecurity norms — a role that carries significant institutional responsibility as models grow more capable of autonomously conducting complex technical tasks across offensive and defensive domains alike.

Read original article →