Unpacking the 'Son of Mythos': AI's Role in Vulnerability Discovery
As Anthropic and OpenAI expand AI tool access, organizations face both risks and opportunities.

Security teams are on alert as Anthropic and OpenAI broaden access to advanced AI models designed for vulnerability discovery. Anthropic's Project Glasswing, initially restricted to 50 organizations, now welcomes 150 more to its AI-powered vulnerability tool, Claude Mythos. This expansion signals a significant shift in cybersecurity, according to industry experts. Concurrently, OpenAI extends its GPT-5.5 Cyber tool to nine major UK banks.
At Infosecurity Europe, Gunter Ollmann, CTO of Cobalt, emphasized that other AI models from Google and China are catching up. "These frontier AI tools will only become more accessible," Ollmann noted, foreseeing a future where AI reduces costs and democratizes security testing.
Paul Chichester from the UK's National Cyber Security Centre warns of potential misuse but sees AI as a double-edged sword. He suggests organizations should use AI to enhance code quality and vulnerability detection, while reinforcing access controls and conducting incident response drills.
Daniel Wilcock of Talion adds that ignoring AI advancements could leave organizations vulnerable, as cybercriminals already exploit these technologies. AI's role in vulnerability chaining—linking medium-risk flaws to create significant threats—was highlighted at the CSO Cybersecurity Awards by Jim Reavis of the Cloud Security Alliance.
Reavis points out that conventional CVSS scoring may become obsolete with these new AI capabilities. Jon Yeoh, also from the CSA, agrees, noting that the 'son of Mythos' marks a pivotal change in AI's impact on cybersecurity.
Organizations embracing AI should focus on rapid validation, prioritization, and remediation of vulnerabilities, leveraging AI's analysis alongside human expertise for optimal protection.



