Anthropic tests AI exploit development speed

Researchers at Anthropic evaluated how models automate N-day exploit development - vulnerabilities with patches out but systems unupdated. In tests, the Mythos Preview model created working exploits for 8 of 18 Firefox vulnerabilities and 8 privilege-escalation chains to SYSTEM on Windows.
For Firefox, the model generated PoCs in 12-40 minutes and full exploits in 12 hours. On Windows, where source code isn't available, it crafted exploit chains in 6 hours at around $2000 in API costs per case.
The authors note current patch cycles taking weeks no longer ensure protection. Models shrink exploit development from weeks of expert work to a few hours.
Related stories
- Alberta government scans 466 million lines of code with Claude
- Anthropic's 225 bug finds, one attack in the wild
- Claude Fable knocked 20 bits off most popular hashes
- A discount Claude reseller was neither cheap nor Claude
- Every operation in Anthropic's threat report was disrupted
- Reward hacking gaps may have fed Claude's July incidents
Comments
No comments yet. Be the first.
Join the conversation
Sign in with Google to leave a comment. Your name and avatar come from your Google profile, and the comment appears after moderation.
