Key Findings
Exploit success against a known set of Firefox vulnerabilities increased roughly 90-fold between consecutive model generations on Anthropic's benchmark.
Turning a known vulnerability into a working exploit can cost less than $2,000 and take under a day.
Of 27 vulnerabilities publicly disclosed by Anthropic, only one of the eight findings Mythos originally rates "Critical" holds up under independent review.
Among vulnerabilities that get exploited, roughly three in four are weaponized after their first day of public disclosure.
37% of security leaders cited "detecting more than we can fix" as their organization's single biggest obstacle to improving software supply chain security
Only 11% of security leaders said additional detection or scanning would be their next investment priority.
Fewer than 10% of the model's 23,019 candidate findings have undergone any external validation.
89% of known vulnerabilities have a fix available.
Roughly 40% of fixable vulnerabilities remain unresolved for more than six months.