Anthropic published research this week showing that Mythos Preview can turn a newly disclosed software patch into a working exploit in as little as 31 minutes. Across 21 Windows kernel vulnerabilities disclosed after the model’s knowledge cutoff, Mythos caused a blue screen of death in 18 cases and generated 8 distinct working exploits. On Firefox, it built 8 working code-execution exploits across 18 security patches. The cost per exploit: approximately $2,000 in API credits.¹
The panic this has generated is understandable. It is also producing the wrong response.
Most organisations are concluding that they need to patch faster, scan more aggressively, and add more detection layers. Those are all legitimate controls. They are also all downstream of execution. And Mythos has just demonstrated that the window between vulnerability disclosure and working exploit is now 31 minutes. You cannot patch an enterprise estate in 31 minutes. You cannot deploy a detection rule in 31 minutes. The downstream controls cannot keep pace with this threat.
Anthropic’s own research notes the broader implication. It is not just Mythos. Open-source models are already operating at comparable capability levels. GPT-5.5-Cyber performs similarly. The $2,000-per-exploit cost is accessible to a wide range of threat actors, not just well-funded nation states. The 31-minute window is not a ceiling. It is an early benchmark that will compress further.
Against this backdrop, the question is not how to win the patching race. Charlie Hosner from Accenture said it plainly in a recent podcast: you are not going to out-patch Mythos. The question is what control remains effective when the exploit has already worked and the attacker is inside the network.
GoFirm answers that question. An exploit that gains access through an unpatched vulnerability still faces the execution boundary. A privileged action, a credential change, a bulk data export, a configuration modification, still requires confirmed human authority before it proceeds. The named authority’s registered device. Their biometric. The out-of-band channel the attacker cannot reach through the compromised session. The attacker is inside. The exploit worked. The consequential action does not execute.
This also reinforces the patching argument made elsewhere in this blog. GoFirm does not eliminate the need to patch. It changes which vulnerabilities are genuinely urgent. A vulnerability that leads to a consequential action execution is now lower priority because the execution boundary is protected. The security team can focus emergency patching effort on the vulnerabilities GoFirm does not cover, OS-level ransomware, denial of service, availability attacks, and manage the rest on a rational schedule rather than in permanent crisis mode.
Put simply: protecting the execution boundary buys back time. The security team’s patch backlog is not just a technical problem. It is a business cost: emergency maintenance windows, weekend deployments, consultant spend, operational disruption, and the constant pressure of knowing that every unpatched vulnerability is a potential catastrophic event. When the execution boundary is protected, that pressure changes. A vulnerability that could lead to a consequential action execution is no longer an emergency. The attacker can exploit it and still cannot execute the action that causes the irreversible damage. The patch still needs to happen, but it happens on a rational schedule rather than in crisis mode.
For a CFO the argument is direct. GoFirm reduces the frequency and cost of emergency patching cycles, which are among the most expensive and disruptive activities a technology organisation undertakes. The subscription pays for itself before you get to the breach prevention argument.
The 31-minute exploit window is alarming. It does not have to be catastrophic. The execution boundary holds regardless of how fast the exploit was generated, regardless of how the attacker got in, and regardless of how long the vulnerability existed before it was patched. That is the control the current security stack does not have and the one that matters most when the patch window has collapsed to half an hour.
GoFirm is The Authority Platform. Stop unauthorised action. Every time.
In association with Osinto.ai, the collective intelligence platform for Security, Resilience & Defence. Osinto’s AI-enabled open-source network and governed collaborative operational environment help mitigate the growing security, resilience and governance obligation in seconds, not days.
References
1. Sam Sabin, Exclusive: Anthropic’s Mythos can exploit new flaws in hours, Axios, June 2026, https://www.axios.com/2026/06/08/exclusive-anthropics-mythos-can-exploit-new-flaws-in-hours
