You have 29 minutes. You are already losing 20 of them. And Mythos is not the problem
You are a CISO. It is 9:14 on a Tuesday morning. Your SIEM has just flagged a lateral movement alert. Twenty minutes later, you launch your first containment action. The attacker, meanwhile, needed only 29 minutes to move across your network.

You are a CISO. It is 9:14 on a Tuesday morning. Your SIEM has just flagged a lateral movement alert on a domain controller. You open the ticket. You look for context. You call the tier-2 analyst. You reread the logs. You waver between false positive and escalation. At 9:34, twenty minutes later, you finally launch the first containment action. Except the attacker needed only 29 minutes to go from initial access to lateral movement. Twenty-nine minutes is the average measured by CrowdStrike in 2025. The record observed: 27 seconds. In one documented case, data exfiltration began four minutes after the initial compromise. Four minutes. Your first reflex was to open a ticket. His was to steal your data.
This gap is not a technical problem, nor is it Mythos's fault. It is a decision problem.
Why is defense losing the speed race?
Twenty-nine minutes is the average breakout time published by CrowdStrike in its Global Threat Report of 24 February 2026. The year before, the same measurement gave 48 minutes. In twelve months, the attacker gained 65% in speed. The fastest case observed came down to 27 seconds, activity from AI-assisted adversaries rose by 89%, and intrusions specifically targeting the cloud by 37%.
Now look at the standard your team still applies. The 1-10-60 rule, one minute to detect, ten to investigate, sixty to remediate, has been the industry benchmark for years. It was formulated by CrowdStrike at a time when the vendor measured an average breakout time of 1 hour 58 minutes. That time budget no longer exists. The ten minutes of investigation now consume a third of the total window, and the sixty-minute remediation phase has no arithmetic basis left.
This is not a sensor problem. Yours saw the alert at 9:14. It is the twenty minutes that followed that cost you the incident, and they were taken up by human operations: looking for context, calling the tier-2 analyst, rereading the logs, hesitating. The gap is not in your tools. It is in your decision chain.
What Mythos reveals about you
On 7 April 2026, Anthropic unveiled the results of its Claude Mythos Preview model. The model autonomously identified thousands of unknown vulnerabilities, of high or critical severity, across every major operating system, Linux, FreeBSD, OpenBSD, across every major browser, and even inside closed-source software analysed through reverse engineering.
One of them, referenced CVE-2026-4747, had been sleeping for seventeen years in the FreeBSD NFS server: a buffer overflow in RPCSEC_GSS authentication that gives anyone on the network root access without authentication. The model found it, built a ROP chain spread across several network requests, and validated the exploitation. Without a human intervening after the initial request.
The figure that should stop you, though, is not that one. Anthropic writes that fewer than 1% of the potential vulnerabilities discovered have been fully fixed by their maintainers. The model did not only find flaws faster. It built up a stock of identified, unpatched flaws.
And Mythos is not public. Anthropic has restricted it to a small circle of industrial partners and open source developers, under the Project Glasswing programme, with a stated goal: to let defenders secure the most important systems before models with comparable capabilities become widely available. The company gives no date. It writes only that the transition period will be difficult.
Do you need a lab-grade model to find a critical flaw?
No. And that is exactly what should keep you awake at night.
The organisation AISLE took the flagship FreeBSD flaw from Mythos and submitted it to eight open-weight models. Eight out of eight detected it, in a single API call, with no staging. The smallest of the batch, 3.6 billion active parameters billed at 0.11 dollars per million tokens, identified the stack overflow, computed the remaining buffer space and rated the flaw critical with remote code execution.
One nuance, because it is honest: detecting is not exploiting. AISLE measures detection, not the construction of a working exploitation chain, and its analysis insists on how jagged that frontier is, with rankings reshuffling completely from one task to the next. But for a defender, detection is precisely the job. And today it costs a few cents.
Meanwhile, the commercial equivalent is already on sale on your desk. OpenAI presented Aardvark, its vulnerability research agent, in October 2025. Since 6 March 2026 it has been integrated into Codex under the name Codex Security and rolled out to ChatGPT Enterprise, Business and Edu customers.
And you, in the meantime, what exactly are you waiting for?
The real wall is not technological. It is in your head.
Back in January, I wrote in Siècle Digital that AI is above all a cognitive wave to absorb. That it changes not only what we do, but how we decide, how we delegate, and how we get things wrong. Mythos has just made that claim brutally concrete.
The problem is not that you lack access to Mythos. The problem is that you are not even using the tools already sitting on your desk. You have a coding agent. You have a subscription. You have code to audit. And yet you do not do it. Not because it is complex. Not because it is expensive. Because you have not yet decided that it was your job.
This is exactly the mechanism I have observed in the field across forty NIS2 assignments throughout Europe: identifying a risk and deciding to act are two radically different mental operations. The first is analytical. The second is existential. It engages your professional identity, your relationship to competence, your comfort with uncertainty. And that is precisely where the majority of defenders stay stuck.
You know these tools find things your commercial scanners miss. You have read it. You may even have tested it once, on a Friday afternoon, in exploratory mode. Then you went back to your usual processes. Because the usual process does not ask you to change who you are. It just asks you to keep doing what you already do.
That is human. That is understandable. And that is exactly what the attacker is counting on.
The comfort of process against the urgency of the real
There is a word to describe what most security teams do in the face of AI: they procrastinate structurally. Not out of laziness. Out of protection. Integrating a tool that challenges your way of working means accepting that your way of working was perhaps not good enough. It means admitting, implicitly, that flaws had been slipping through your nets for years. Nobody wants to make that admission. Least of all a CISO whose legitimacy rests on the idea that he controls the perimeter.
Except the perimeter has ceased to exist. Attackers no longer force doors. 82% of the detections in 2025 involved no malicious code, against 79% the year before and 51% in 2020. Attackers log in with valid credentials and use your own administration tools. They come in through the front door with your key. And while you look for a malicious signature that does not exist, they are already in your Active Directory.
The French picture is identical. In its Panorama de la cybermenace 2025, published on 11 March 2026, ANSSI describes attackers, state-sponsored as much as criminal, repurposing perfectly legitimate software: remote access tools such as AnyDesk or ScreenConnect, storage services such as Dropbox or Google Drive. The agency handled 1,366 incidents in 2025, against 1,361 in 2024. Ransomware is receding slightly, with 128 confirmed compromises, but simple data exfiltrations rose from 130 to 196 in one year. Small and medium-sized businesses alone account for 48% of ransomware victims.
On AI, ANSSI is in fact more measured than Anthropic: generative AI is a potential accelerator of offensive capabilities, but it does not make possible attacks that were not possible before. I fully agree, and that is precisely my point. Nothing new becomes possible. Everything becomes faster. And it is speed, not novelty, that breaks a defensive posture built around human deliberation.
The question is no longer whether your tools are up to date. The question is whether your defensive reflex is still suited to the speed of the attack. And the answer, for the vast majority of the organizations I work with, is no.
Where do you start concretely?
I am not going to give you a five-point checklist. That is not my register, and if you need a list to get started, the problem runs deeper than a list can solve.
What I will tell you is this: take a coding agent. Point it at a file you own. Ask it to look for exploitable vulnerabilities and write you a report. Read the report. Challenge it. Start again. That is all. One file. One question. One report.
Then compare the results with what your commercial tool found on the same scope. Look at the gaps. I guarantee there are some. Not because the agent is better. Because it is different. And because the combination of the two produces something that neither produces on its own.
This is not magic. This is not advanced research. It is professional hygiene in 2026. You do not need to understand the code to do it. You need to understand that your job has just changed.
The question nobody is asking you
AI will not replace you. But a defender who uses it will make you invisible. In cybersecurity, invisibility has a measurable cost: exfiltrated data, compromised systems, paralyzed organizations. This is not a career metaphor. It is an operational consequence.
So the question is not: do you have access to the right tools? You do. The question is not: do you have the budget? A subscription is enough to get started, and the smallest model tested by AISLE bills 0.11 dollars per million tokens. The question is not even: do you have the technical skills? You need to know how to phrase a request in English.
The question is: are you capable of governing a system that moves faster than your usual reflexes?
If the answer is no, you have 29 minutes to think about it. The attacker needs only 27 seconds.
Sources
- Average breakout time of 29 minutes over 2025 against 48 minutes in 2024, record of 27 seconds, exfiltration starting four minutes after initial access, AI-assisted adversaries up 89%: CrowdStrike, 2026 Global Threat Report, 24 February 2026.
- 82% of the detections in 2025 with no malicious code, against 79% in 2024 and 51% in 2020: CrowdStrike, key findings of the 2026 Global Threat Report.
- The 1-10-60 rule and the average breakout time of 1 hour 58 minutes: CrowdStrike, What is Lateral Movement.
- Results of Claude Mythos Preview, CVE-2026-4747 in FreeBSD, fewer than 1% of vulnerabilities fixed, Project Glasswing programme: Anthropic, Mythos Preview, 7 April 2026.
- Eight open-weight models out of eight detecting the FreeBSD flaw, including a model with 3.6 billion active parameters at 0.11 dollars per million tokens: AISLE, AI Cybersecurity After Mythos: The Jagged Frontier.
- OpenAI's vulnerability research agent, presented in October 2025 and integrated into Codex under the name Codex Security: OpenAI, Introducing Aardvark.
- 1,366 incidents handled in 2025, 128 ransomware cases, exfiltrations rising from 130 to 196, small and medium-sized businesses accounting for 48% of ransomware victims, repurposing of legitimate tools and position on generative AI: ANSSI, Panorama de la cybermenace 2025, 11 March 2026.
- AI as a cognitive wave and a mental shock before a technological one: Christophe Mazzola, Siècle Digital, 14 January 2026.
Frequently asked questions
What is breakout time and where does it stand?
It is the time between initial access and the first lateral movement, in other words the window a defender has before the attacker spreads. In its Global Threat Report published on 24 February 2026, CrowdStrike measures an average of 29 minutes over 2025, against 48 minutes in 2024. The fastest case observed is 27 seconds, and in one documented intrusion exfiltration started four minutes after initial access.
Is the 1-10-60 rule still valid?
One minute to detect, ten to investigate, sixty to remediate: that benchmark was formulated by CrowdStrike at a time when the average breakout time measured was 1 hour 58 minutes. With the window down to 29 minutes, the ten minutes of investigation absorb a third of the total budget, and the sixty-minute remediation phase no longer has any arithmetic basis.
What did Claude Mythos Preview actually find?
On 7 April 2026, Anthropic published the results of this model, which autonomously identified thousands of high and critical severity vulnerabilities in the major operating systems, in browsers, and in closed-source software analysed through reverse engineering. The most emblematic one, CVE-2026-4747, is a seventeen-year-old buffer overflow in the RPCSEC_GSS authentication of the FreeBSD NFS server, giving unauthenticated remote root access. Anthropic notes that fewer than 1% of the potential vulnerabilities discovered have been fully fixed by their maintainers.
Do you need a lab-grade model to find a critical flaw?
No. The organisation AISLE submitted the flagship FreeBSD flaw from Mythos to eight open-weight models: all eight detected it in a single API call. The smallest one, 3.6 billion active parameters billed at 0.11 dollars per million tokens, identified the stack overflow, computed the remaining buffer space and rated the flaw critical with remote code execution. The nuance to keep in mind is that detecting is not exploiting.
Are these tools already available to companies?
Yes. Mythos Preview remains restricted to a small circle of partners through Anthropic's Project Glasswing programme, but OpenAI presented Aardvark, its vulnerability research agent, in October 2025: since 6 March 2026 it has been integrated into Codex under the name Codex Security and rolled out to ChatGPT Enterprise, Business and Edu customers.
What does ANSSI say about offensive AI?
In its Panorama de la cybermenace 2025, published on 11 March 2026, the French agency considers generative AI a potential accelerator of the offensive capabilities of attackers, but judges that it does not make possible attacks that were not possible before. That is exactly the point: nothing new becomes possible, everything becomes faster.
Where do you start concretely?
Take a coding agent, point it at a file you own, ask it to look for exploitable vulnerabilities and write a report, challenge that report, then compare the gaps against those of the commercial tool on the same scope.
Sources & methodology
- Anthropic, Claude Mythos Preview, 7 April 2026,
- CrowdStrike, 2026 Global Threat Report, 24 February 2026,
- CrowdStrike, key findings of the 2026 Global Threat Report (82% of detections malware-free),
- CrowdStrike, What is Lateral Movement (1-10-60 rule and average breakout time),
- AISLE, AI Cybersecurity After Mythos: The Jagged Frontier,
- OpenAI, Introducing Aardvark: OpenAI's agentic security researcher,
- ANSSI, Panorama de la cybermenace 2025, 11 March 2026,
- Christophe Mazzola, Siècle Digital, 14.01.2026,

Être en cybersécurité
A cyber roadmap in plain language, for everyone, not just the experts.
