For thirty years, vulnerability management ran on a buffer: the months between when a vulnerability was found and when someone could figure out how to weaponize it. The solution was straightforward enough; triage by severity, schedule the fix, validate, and move on. The buffer was what made that work.
Today, that buffer is gone.
AI didn't make your team slower. It changed the other side of the equation, compressing discovery-to-exploit from months to hours. And the sad truth for defenders is that a process built for breathing room can't survive without it.
AI Turned Vulnerability Discovery Into a Volume Game
In its May 2026 update, Anthropic reported that it and approximately 50 partners used Claude Mythos Preview to find more than 10,000 high- or critical-severity vulnerabilities in systemically important software in a single month.
Earlier figures were just as stark.
Pointed at Firefox, the gated Mythos model wrote 181 working exploits, against just 2 from the previous frontier model. It surfaced vulnerabilities across every major OS and browser, including an OpenBSD bug that had sat undetected for 27 years.
At the time of writing, more than 99% of what it found was still unpatched.
![]() |
| Figure 1. February 2026, FortiGate Campaign |
An AWS threat-intelligence report from February 2026 shows the flip side: no zero-days needed, just weak credentials, industrialized through a custom MCP server running offensive tools autonomously. AWS confirmed 600+ devices across 55+ countries; the actor's logs, according to independent researchers, queued 2,516 devices across 106 countries.

