VFF - The signal in the noise
News

AI Can Now Find Zero-Days. Your Patch Process Isn't Ready.

Read original
Share
AI Can Now Find Zero-Days. Your Patch Process Isn't Ready.

Anthropic's Claude Mythos model can autonomously discover zero-day vulnerabilities, closing a critical safety margin that previously existed because AI could only exploit known CVEs. Exploitation timelines have collapsed to hours rather than days, rendering traditional patch windows ineffective. Organizations must overhaul vulnerability prioritization and authorization controls to account for AI-driven attack speeds.

  • Claude Mythos discovered thousands of zero-day vulnerabilities across major operating systems and browsers, achieving 83.1% on vulnerability reproduction benchmarks
  • Recent exploits occurred in under 10 hours post-disclosure, before patches were available, invalidating assumptions about safe patch windows
  • CVSS-only prioritization is insufficient; a three-layer filter using CISA KEV status, EPSS scores, and CVSS achieved 18x efficiency gains and 85.6% coverage of exploited vulnerabilities
  • Authorization policies for privileged agent credentials have not been tested against AI behavior, creating measurable security gaps like Docker's CVE-2026-34040

The discovery that AI can autonomously find zero-days eliminates the assumption that enterprises have time to patch vulnerabilities before exploitation. Exploitation is now happening faster than patches can be developed and deployed, fundamentally breaking the traditional vulnerability management timeline. This requires immediate changes to how organizations prioritize and respond to security threats.

Enterprises cannot rely on their existing patch management processes to protect against AI-driven exploitation. The cost of discovering and exploiting vulnerabilities has dropped dramatically (under $20,000 for some campaigns), making attacks more economically feasible. Organizations that do not restructure their vulnerability prioritization and authorization controls face significantly elevated breach risk.

  • Vulnerability prioritization must shift from CVSS scores alone to a three-layer model incorporating active exploitation status, predicted exploitation likelihood, and severity baseline
  • Patch windows are no longer a reliable defensive assumption; organizations must assume exploitation can occur within hours of disclosure
  • Authorization systems and privileged access controls must be audited and redesigned to account for AI agent behavior, not just human operators

Monitor whether organizations adopt the three-layer prioritization framework and how quickly they can operationalize it. Track whether authorization bypass vulnerabilities in common platforms (Docker, Kubernetes, cloud providers) become more prevalent. Watch for industry guidance on AI-aware security architecture and whether vendors update their authorization plugins to account for AI agent behavior patterns.

Share

Subscribe to the newsletter

The latest stories and analysis, delivered to your inbox.

Free. No spam. Unsubscribe any time.

Related stories

AWS Embeds Security in Rival AI Models, Betting on Control Plane

AWS Embeds Security in Rival AI Models, Betting on Control Plane

AWS announced at Black Hat USA 2026 that its Continuum vulnerability platform will integrate directly into Anthropic's Claude Code and OpenAI's Codex, embedding AWS security tooling at the point where developers write code regardless of which AI model they use. The move positions AWS as a security control plane for enterprise software development and reflects an urgent industry response to frontier AI models like Claude Mythos Preview, which identified thousands of previously unknown zero-day vulnerabilities during testing. AWS also expanded its Security Hub Extended marketplace with a 10th category focused on supply chain protection, adding Chainguard and Socket as partners.

by michael.nunez@venturebeat.com (Michael Nuñez)· VentureBeat AI
OpenAI Launches GPT-5.6-Cyber for Authorized Security Research
TrendingModel Release

OpenAI Launches GPT-5.6-Cyber for Authorized Security Research

OpenAI has released GPT-5.6-Cyber, a cybersecurity-focused model available through Daybreak Red for authorized vulnerability research, exploit validation, and security testing. The model is designed to support authorized security professionals in identifying and validating vulnerabilities. The release reflects growing demand for AI tools tailored to defensive security work.

· OpenAI
Valve Steam hardware breach exposes European customer data

Valve Steam hardware breach exposes European customer data

Valve's European shipping partner CEVA Logistics suffered a data breach between July 29th and August 1st that may have exposed customer names, addresses, phone numbers, and email addresses for Steam hardware orders. The breach occurred weeks after Valve began taking reservations for its new Steam Machine and Steam Controller. CEVA stores delivery-related information for up to 90 days after orders, making European customer data vulnerable during that window.

by Emma Roth· The Verge AI
Browser Security Gap Widens as Enterprise Work Shifts Online
TrendingNews

Browser Security Gap Widens as Enterprise Work Shifts Online

Enterprise security architecture remains focused on endpoint protection even as business-critical work has shifted into the browser, creating a significant gap in defense strategy. Browser-based attacks have surged over the past two years, with Gartner projecting that over 85% of enterprise workloads will be accessed through browsers by 2027. Traditional detection-first security approaches fail against modern threats because malicious code can execute and complete its objective before security teams can respond, while AI-generated malware variants overwhelm signature-based detection tools.

· VentureBeat AI