What are the impacts of Mythos and MDASH?
The claims around these new frontier models represent a meaningful shift in cybersecurity, with thousands of previously unknown vulnerabilities reportedly identified across major operating systems and browsers, including flaws that have existed for decades. If those claims prove out, we are at the start of a busy and challenging period for software engineering and cybersecurity teams, even for well-maintained products and organisations with strong cyber hygiene, because well-chained exploits drawing on combinations of newly surfaced flaws represent a particularly high risk.
The concern deepens for organisations running older systems. It is not practical for every business to move to the latest and greatest overnight, and this category sits squarely in the firing line of a rapid and capable vulnerability exploitation pipeline.
It is worth saying clearly: it remains an “if” for now. The headline figures are largely self-reported, with limited independent verification, and there is legitimate debate around the extreme compute cost required to make these models perform at the levels claimed. The trend, however, is obvious. Project Glasswing partners have begun corroborating elements of the work, and at least one privilege escalation chain on macOS has already been attributed to techniques surfaced during Mythos testing. The wider picture is still emerging, and we are treating the claims as credible enough to plan against rather than as established fact.
Even so, the direction of travel is clear. Capabilities like this lower the barrier to offensive activity, and it is only a matter of time before equivalent tooling reaches less benign hands. Attackers no longer need deep expertise if AI can automate large parts of discovery and exploit construction, which puts organisations with weak security posture directly in the firing line.
The short-term picture is uncomfortable. Organisations already struggle to prioritise and patch the vulnerabilities they know about, and a sustained increase in disclosed findings will not make that easier. Patch Tuesdays will get heavier. Vendor support queues will lengthen. Scanner outputs will balloon. Security teams will face a familiar problem at a less familiar scale, trying to fix everything at once with finite hands and finite change windows. The asymmetry sharpens the pain: defenders have to patch all of it, attackers only need one chain to work. In the near term, the realistic expectation is more exposure, not less.
The longer-term picture is genuinely more hopeful, and it is worth holding on to. If models of this class are run continuously against code as it is written, reviewed, and deployed, the volume of latent vulnerabilities in production software should fall over time. Bugs that have hidden for decades get found and fixed once, rather than waiting to be rediscovered by an attacker years later. Vendors bake this capability into their secure development lifecycles. The patch treadmill slows. We end up in a materially more secure place than we are today, with fewer surprises and a tighter loop between code being written and code being trusted.
The honest framing is that this better future sits on the other side of the disruption, not in place of it. The industry will have to work through a period of real pressure on engineering teams, patching programmes, and incident response capacity before the benefits start to show. Organisations that invest now in the fundamentals will be the ones still standing when that turn comes.