Exploit Window Collapses to 4 Hours: Mythos Kills Responsible Disclosure

Exploit Window Collapses to 4 Hours: Mythos Kills Responsible Disclosure

N
News Editor 01
2026-07-22 22:00:14
Bloomberg columnist warns that the window between vulnerability disclosure and weaponization has shrunk from 771 days to under 4 hours, driven by AI agents like Mythos, rendering responsible disclosure obsolete.
MythosAI securityresponsible disclosureexploit windowSMEs

The time it takes for a disclosed software vulnerability to become a working exploit has collapsed from 771 days in 2018 to less than four hours today. That’s a compression factor of over 4,600x — and it’s the opening salvo in Bloomberg Opinion tech columnist Parmy Olson’s latest piece, which declares the era of responsible disclosure effectively dead.

Olson uses Anthropic’s flagship model Mythos as a narrative hook, but she quickly shifts focus: Mythos is a symptom, not the cause. The real story is how AI capabilities have shattered the window between a bug going public and being weaponized. Data from zerodayclock.com shows the average time dropped from 771 days in 2018 to under four hours now.

Treasury Secretary Calls Wall Street, AISI Puts a Cap on Mythos

Days after Mythos’ release, U.S. Treasury Secretary Scott Bessent summoned Wall Street leaders to review system defenses. Olson views the move as “invaluable publicity” for Anthropic, but also notes the obvious question: who gets exclusive access to the threat intelligence? The UK AI Safety Institute (AISI) — which Olson calls “the world’s top neutral arbiter of what counts as safe and secure AI” — has already tested Mythos. Its assessment confirmed Mythos outperforms ChatGPT and Gemini on complex cyberattack tasks, but with a critical caveat: the model is most dangerous against “weakly defended” or “simplified” systems.

That caveat is the pivot point. Big banks aren’t the real problem.

Big Banks Can Defend; SMEs Are the Real Target

Olson points out that major banks have the world’s best IT security infrastructure. Bessent’s call to JPMorgan, Goldman Sachs, and others is routine. “The much broader array of small and medium-sized companies” is the soft underbelly. SMEs lack the resources to patch near-instantaneously, making them the primary playground for AI-driven agentic attacks.

Patch Tuesday Logic Is Broken, Responsible Disclosure Dead

The traditional responsible disclosure pipeline — researcher finds bug, notifies vendor, public disclosure, then users patch before hackers see details — assumed attackers needed time to turn public details into working exploits. Olson argues that assumption has been obsolete for two years: ChatGPT could already scan GitHub for similar patterns and generate attack tools near-instantly. With Mythos, the window collapses to hours. She asks directly: “Whether ‘responsible disclosure’ is such a smart idea in the first place” and “whether the process of patching flaws over weeks and months is now fruitless.”

Mythos Chains Vulnerabilities Like a Top Human Hacker

Olson emphasizes Mythos’ ability to “chain” multiple flaws into multi-step attacks — something previously achievable only by skilled human hackers. Her analogy: “Like a burglar planning a series of break-in steps — find the first unlocked window, unlock a door from inside, switch off the alarm. Each step alone is insufficient; together, they grant full access.” With agentic capabilities (Anthropic’s Claude Cowork can auto-send emails and manage calendars), AI-driven attack tools now autonomously probe different paths until they succeed.

Anthropic Has Its Own Agenda, but the Crisis Is Real

Olson doesn’t dodge Anthropic’s commercial interest: “Anthropic’s disclosure of Mythos certainly benefits its own publicity efforts ahead of an initial public offering, adding to the mystique around the potency of its technology.” Yet she insists that doesn’t negate the severity of the issue: the window between published flaws and their exploitation has “effectively vanished.” Wall Street at least has the money to push near-real-time patching. SMEs need the same speed but lack the technical and regulatory support. Olson’s conclusion: “The entire cybersecurity ecosystem built on the assumption that you have time needs to be redesigned.”

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
400

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.