Two weeks ago, Anthropic announced Claude Mythos Preview, an AI model that autonomously discovers thousands of zero-day vulnerabilities across every major operating system and browser. It generates working exploits on its own. No human guidance needed.
This week, OpenAI followed with GPT-5.4-Cyber, a “cyber-permissive” variant of its flagship model designed to do the same kind of work with fewer safety guardrails.
The cybersecurity industry has a name for what’s happening right now: the AI Vulnerability Storm.
What Claude Mythos and GPT-5.4-Cyber Actually Do
Let’s cut through the noise.
Claude Mythos is not just a smarter chatbot. In Anthropic’s internal testing, it generated 181 working exploits on Firefox. The previous best model, Claude Opus 4.6, managed two under the same conditions. That’s not incremental progress. It’s a different category of capability.
Three things make Mythos different from anything before it. First, it builds exploits without scaffolding, meaning no elaborate setup or multi-step agent configuration. One prompt, one result. Second, it chains complex vulnerabilities together, combining multiple bugs into a single exploit path the way an experienced red team operator would. Third, it does all of this at machine speed, across every major OS and browser simultaneously.
Anthropic paired the release with Project Glasswing, giving roughly 40 critical infrastructure providers and open source maintainers early access so they could patch before public disclosure. But as the Cloud Security Alliance noted in their expedited strategy briefing, the world’s exploitable attack surface is “vastly larger than what any curated partner ecosystem can cover.”
OpenAI’s GPT-5.4-Cyber takes a different approach but arrives at the same destination. It’s a version of GPT-5.4 with lowered safety boundaries specifically for cybersecurity work. Access is restricted to members of OpenAI’s Trusted Access for Cyber program, which requires government ID verification and vetting. The message is clear: both frontier AI labs are now building and releasing offensive-capable models, and controlling access through trust programs rather than technical limitations.
Why This Hits SMBs Hardest
If you’re running a company with 50, 200 or even 500 employees, you probably don’t have a dedicated security operations team monitoring vulnerabilities around the clock. You might run quarterly pen tests. You patch when your CTO or a managed service provider flags something urgent.
That cadence worked when the average time between a vulnerability being disclosed and an attacker exploiting it was measured in months or years. According to the Zero Day Clock, that window was 2.3 years in 2018. In 2026, it’s under one day.
Read that again. Under one day.
Here’s what that means in practice. When Glasswing’s 40 early-access vendors start releasing patches, which they will in rapid succession, attackers will use AI to reverse-engineer those patches and generate exploits for every organization that hasn’t updated yet. The patch itself becomes the blueprint. And AI makes the reverse-engineering nearly instant.
The CSA, SANS, and OWASP jointly published an expedited strategy briefing calling this moment a “step change” and urging every organization to build what they call a “Mythos-ready” security program. Their timeline of AI offensive capabilities over the past year reads like an escalation ladder: AI systems topping the HackerOne leaderboard, Google’s Big Sleep finding 20 real zero-days in open source projects, a Chinese state-sponsored group running fully autonomous attack chains across 30 global targets, and Sysdig documenting an AI-based attack that reached admin-level access in eight minutes.
This is not a future problem. It’s an April 2026 problem.
What You Can Do Right Now
The CSA briefing provides detailed recommendations for enterprise security teams. Most SMBs don’t have the bandwidth to implement all of them. But there are four things you can start this week that will meaningfully reduce your exposure.
Get your patching house in order.
If you don’t have a system for triaging and deploying critical patches within 24 hours, build one now. The volume of critical vulnerabilities is about to spike, and your current cycle probably assumes you have weeks, not hours.
Know what you’re running.
You can’t patch what you can’t see. Build a real inventory of your internet-facing systems, your dependencies, and your third-party software. AI-accelerated attackers can enumerate your attack surface faster than you can inventory it, so start closing that gap.
Harden the basics.
Segmentation, multifactor authentication (phishing-resistant), egress filtering, and zero trust architecture. These controls work regardless of whether the attacker is human or AI. The CSA briefing is direct on this: “The basics remain valid and can be prioritized for risks that cannot otherwise be mitigated.”
Don’t try to do it alone.
The best approach is to build a collective defense. That means working with partners who see threats across hundreds of environments, not just yours. A single company’s visibility is a single data point. A managed security partner sees patterns across their entire client base before those threats reach you.
The Window Is Closing
AI is not making cybersecurity slightly harder. It’s restructuring the economics of attack and defense. Attackers gain disproportionate benefit because AI lowers the cost and skill floor for finding and exploiting vulnerabilities faster than organizations can patch them.
The companies that come through this well will be the ones that treated this month as the inflection point it is. Not next quarter. Not after the first incident.
We’re hosting a live webinar to break down exactly what the AI vulnerability storm means for businesses like yours, what the new threat models look like, and what practical steps you can take to get ahead of it.


