Frontier AI Models Transform Vulnerability Discovery
Security teams are rethinking how they defend networks as AI tools compress the time and cost of finding flaws.

Key points
- Claude Mythos and OpenAI's GPT-5.5 have changed how quickly attackers can discover and chain vulnerabilities.
- Defenders should prioritise limiting blast radius through identity controls and internal segmentation over patching everything perfectly.
- Anthropic has released the Mythos-class Fable 5 model publicly, with added cybersecurity guardrails.
- Smaller open-weight models are already replicating the vulnerability-finding results of frontier systems.
- The economic shift matters more than the technical one: the cost of running a credible attack campaign has dropped sharply.
What has actually changed?
The arrival of Claude Mythos and GPT-5.5 hasn't invented new attack classes. It's made existing ones cheaper and faster to run. Experts told CSO Online that the real shift is economic: running a credible offensive campaign now costs a fraction of what it did. A junior researcher with API access can surface logic flaws that traditional scanners missed entirely, because, as Nik Kale of the Coalition for Secure AI put it, "a frontier LLM reads a hardcoded trust assumption like it's reading a paragraph."
Martin Roesch, who created the Snort intrusion-detection system and now leads cloud work at Vectra AI, told CSO that people are already trying to replicate Mythos-level results using open-source models they run locally. Will Barker, cybersecurity advisor at Huntress, agrees: smaller open-weight models are finding the same zero-days and exploit chains. We've tracked Mythos closely since our first report on 11 June, and the speed of capability diffusion keeps outpacing expectations.
Should you worry about the exploit gap?
Finding a flaw is no longer the hard part. Converting it into a working exploit still requires skill. Raphael Peyret, a former Google product manager now advising at SHA/RP, told CSO that novel zero-days in hardened targets still demand human expertise. Louis Leung, co-founder at InFlow Inventory, put it plainly: the hard part is a stable working exploit that survives real-world defences and monitoring. What AI does accelerate is chaining. Jon Yeoh, chief scientific officer at the Cloud Security Alliance, told a recent CSO conference that three or four low-severity CVEs (published vulnerability records) can now be chained into something rated high or critical far more quickly than before.
Noe Ramos, vice president of AI operations at Agiloft, told CSO that CISOs should plan on attackers reaching frontier-level capability within months. Fine-tuned open-weight models running locally are the likelier route, not jailbreaks.
What should organisations do?
Stop trying to patch everything perfectly. That's the consensus, and it's the right call. Identity controls, least-privilege access rules, and network segmentation limit how far an attacker can move once they're in. The patching bottleneck we flagged in our Project Glasswing piece on 3 June hasn't gone away; AI just makes it more painful to ignore.
Scrutiinise any enterprise AI tool for what happens when it's turned against the organisation that deployed it. Noah Kenney of Digital 520 told CSO that legitimate enterprise AI being weaponised internally is a bigger practical risk than black-hat forks of Mythos itself.



