{"rewrite":{"id":"r_1721127f7943c15930c1cca4","clusterId":"c_9eeb0928a15720b54fb0bd9e","slug":"anthropic-s-claude-mythos-preview-can-exploit-known-vulnerabilities-in-hours","model":"deepseek-v4-flash","headline":"Anthropic Warns N-Day Vulnerabilities Become N-Hour Threats With Claude Mythos Preview","summary":"Anthropic released a report on June 9 showing that its Claude Mythos Preview AI can develop working exploits from publicly disclosed vulnerabilities, known as N-days, in hours rather than the days or weeks traditionally required. In tests, Claude Mythos Preview created its first proof-of-concept exploit in about 12 minutes and produced 13 PoCs within 40 minutes. For blue-screen exploits targeting Windows vulnerabilities, it completed 18 out of 21 within six hours, with the first exploit finished in 31 minutes. The company stated that the term N-day has become dangerously misleading and that N-hour is more appropriate for the current reality. Separately, on June 9, Anthropic also released the production versions Claude Mythos 5 and Claude Fable 5, both priced at $10 per million input tokens and $50 per million output tokens. Claude Fable 5 includes safety restrictions that block cyberattack-related instructions, while Claude Mythos 5 is limited to approved organizations through Project Glasswing. Claude Fable 5 also demonstrated the ability to clear Pokémon FireRed using only visual input, completing the game in 50 hours and 9 minutes.","whyItMatters":"The speed at which Claude Mythos Preview can weaponize known vulnerabilities compresses the patch window for defenders from days to hours, fundamentally changing the risk calculus for software maintenance and incident response.","webCardHtml":"\u003cp\u003eAnthropic published the report through its research blog, red.anthropic.com, in May 2026. The company and about 50 partners used Claude Mythos Preview to discover over 10,000 vulnerabilities rated \u0026#34;High\u0026#34; or \u0026#34;Critical\u0026#34; severity in globally important software. Independent security research firms re-verified the vulnerabilities, finding 90.6% were genuine and 62.4% were actually rated \u0026#34;High\u0026#34; or \u0026#34;Critical.\u0026#34;\u003c/p\u003e\n\n\u003cp\u003eThe report focused on N-day vulnerabilities, which are publicly disclosed with patches released or in development but for which no exploit may yet exist. Anthropic noted that while most of its prior cybersecurity research covered zero-days, the majority of real-world damage comes from N-days. Attackers reverse-engineer patches through source code and patch diff analysis, a process that traditionally takes days to weeks.\u003c/p\u003e\n\n\u003cp\u003eIn tests comparing Claude Mythos Preview against Claude Opus 4.8, Claude Opus 4.6, and Claude Sonnet 4.6 on 18 vulnerabilities, Claude Mythos Preview created its first proof-of-concept in about 12 minutes and 13 PoCs within 40 minutes. It took roughly 3 hours to complete the 14th. When tasked with 50 PoC developments per vulnerability, Claude Opus 4.8 and Claude Opus 4.6 consistently solved only one vulnerability each, while Claude Mythos Preview consistently solved seven.\u003c/p\u003e\n\n\u003cp\u003eFor blue-screen exploits targeting Windows vulnerabilities, Claude Sonnet 4.6 and Claude Opus 4.7 each developed PoCs for 13 out of 21 vulnerabilities, Claude Opus 4.8 for 15, and Claude Mythos Preview for 18. Claude Mythos Preview\u0026#39;s first PoC was completed in 31 minutes, and all 18 were achieved within six hours.\u003c/p\u003e\n\n\u003cp\u003eAnthropic stated: \u0026#34;This suggests that users currently in the patch gap face a much greater threat than before, and the risk only increases as model capabilities improve. The term \u0026#39;N-day\u0026#39; has now become dangerously misleading; \u0026#39;N-hour\u0026#39; is more appropriate for the reality we face.\u0026#34; The company proposed that defenders accelerate patch deployment speed as a countermeasure.\u003c/p\u003e","blueskyPost":"Claude Mythos Preview turned N-day vulnerabilities into N-hour threats, completing 18 out of 21 Windows blue-screen exploits within six hours. Anthropic's own report redefines the timeline defenders have to respond.","twitterPost":"Claude Mythos Preview exploits N-day vulnerabilities in minutes, not days. Anthropic says the term N-day is now dangerously misleading.","threadsPost":"Claude Mythos Preview produced 13 proof-of-concept exploits in 40 minutes from publicly disclosed vulnerabilities. Anthropic's report is a direct warning that the traditional N-day window for patching has collapsed to hours. The term N-hour is no longer hyperbole; it is a measurement.","newsletterBlurb":"Anthropic released a report showing its Claude Mythos Preview AI can develop exploits from publicly known vulnerabilities in hours, compressing the traditional patch window. The company also launched production models Claude Mythos 5 and Claude Fable 5, with the latter clearing Pokémon FireRed using only visual input.","attributionJson":"[{\"source\":\"ASCII.jp\",\"url\":\"https://ascii.jp/elem/000/004/409/4409569/?rss\",\"title\":\"Anthropic Finally Makes \\\"Mythos-Class\\\" Model Available to the Public\"},{\"source\":\"GIGAZINE\",\"url\":\"https://gigazine.net/news/20260609-anthropics-mythos-exploit/\",\"title\":\"Anthropic points out that the AI 'Claude Mythos Preview', which has excessively high cyberattack capabilities, can develop attacks from publicly disclosed vulnerabilities 'N-day' in hours, changing common sense from 'N-day' to 'N-hour'\"},{\"source\":\"GIGAZINE\",\"url\":\"https://gigazine.net/news/20260610-claude-mythos-fable/\",\"title\":\"Official version of 'Claude Mythos' finally released, and 'Claude Fable' with usage restrictions removed also released, making it available to everyone\"},{\"source\":\"Game Spark\",\"url\":\"http://www.gamespark.jp/article/2026/06/10/167798.html\",\"title\":\"High-Performance AI Clears Pokémon FireRed! Latest Model 'Claude Fable 5' Achieves It Using Only Visual Information - Can Also Play Factorio\"}]","lintFlagsJson":null,"lintHits":0,"costUsd":0,"inputTokens":12920,"outputTokens":1499,"status":"published","repairAttempts":0,"nextRepairAt":null,"factsAttemptedAt":1781009582,"createdAt":"2026-06-09T12:40:51.000Z","publishedAt":"2026-06-09T12:45:00.000Z","updatedAt":"2026-06-09T12:45:00.000Z"},"cluster":{"id":"c_9eeb0928a15720b54fb0bd9e","canonicalTitle":"サイバー攻撃性能が高すぎるAI「Claude Mythos Preview」は公開済みの脆弱性「N-day」から数時間で攻撃を開発できるため「N-dayからN-hourに常識が変わる」とAnthropicが指摘","representativeArticleId":"a_fce3d10c43ad41fc37f94787","sourceCount":5,"writtenSourceCount":3,"writeAttempts":0,"isSolo":false,"entitiesJson":"{\"anime_titles\":[],\"manga_titles\":[],\"work_titles\":[],\"studios\":[],\"people\":[],\"type\":\"news\",\"domain\":\"other\",\"is_roundup\":false}","contentType":"news","status":"written","firstSeenAt":"2026-06-09T12:00:00.000Z","lastSeenAt":"2026-06-17T03:00:03.000Z","updatedAt":"2026-06-17T03:10:30.000Z"},"attribution":[{"source":"ASCII.jp","url":"https://ascii.jp/elem/000/004/410/4410414/?rss","title":"わずか3日で停止された新AI「Claude Fable 5」は何がすごかったのか"},{"source":"GameBusiness.jp","url":"https://www.gamebusiness.jp/article/2026/06/17/27229.html","title":"Claudeのエージェント別枠化が撤回、Anthropicが当日発表―今後のプラン変更に向け再検討中"},{"source":"GIGAZINE","url":"https://gigazine.net/news/20260617-us-government-wont-allow-access-mythos/","title":"トランプ政権がClaude Mythos 5へのG7諸国のアクセスを認めない方針、イギリスは例外措置を要求"},{"source":"Inside","url":"https://www.inside-games.jp/article/2026/06/10/182765.html","title":"高性能AIが『ポケモンFR』をクリア!? 視覚情報だけでやり遂げた最新モデル「Claude Fable 5」公開"},{"source":"Game Spark","url":"http://www.gamespark.jp/article/2026/06/10/167798.html","title":"『ポケモンFR』を高性能AIがクリア！視覚情報だけでやり遂げた最新モデル「Claude Fable 5」公開―『Factorio』もプレイできる"}],"entities":{"anime_titles":[],"manga_titles":[],"work_titles":[],"studios":[],"people":[],"type":"news","domain":"other","is_roundup":false},"keyFacts":["Anthropic's Claude Mythos Preview AI created its first proof-of-concept exploit from a publicly disclosed vulnerability in about 12 minutes and produced 13 PoCs within 40 minutes.","For blue-screen exploits targeting Windows vulnerabilities, Claude Mythos Preview completed 18 out of 21 within six hours, with the first exploit finished in 31 minutes.","Anthropic stated that the term 'N-day' has become dangerously misleading and that 'N-hour' is more appropriate for the current reality.","Anthropic and about 50 partners used Claude Mythos Preview to discover over 10,000 vulnerabilities rated 'High' or 'Critical' severity in globally important software.","On June 9, Anthropic also released the production versions Claude Mythos 5 and Claude Fable 5, both priced at $10 per million input tokens and $50 per million output tokens."]}
