top of page

The rules just changed

May 22
2 min read

Updated: Aug 15

Over the weekend, I listened to an interesting cyber security podcast (Steve Gibson’s ‘Security Now!’), discussing Anthropic’s new AI model “Mythos” and its ability to identify previously unknown software vulnerabilities at a scale and speed we simply haven’t seen before.


What struck me wasn’t the usual “AI will change everything” narrative, which is probably a bit of a boring read for people here now. This was something that really needs everyone's attention.


For years, much of the technology industry, and their customers, has operated with a degree of accepted imperfection:

  • Software gets shipped quickly to meet demand

  • Humans are expected to uncover issues

  • Vulnerabilities get patched later


Now imagine what happens when AI becomes exceptionally good at reviewing software code, identifying weaknesses and developing exploits faster than humans can respond.


One example discussed in the podcast was a critical vulnerability that Mythos reportedly identified in a widely used encryption library called wolfSSL, which is said to protect BILLIONS of devices worldwide. The concern wasn’t just the vulnerability itself. It was that something quite fundamental, related to certificate validation checks, had remained undiscovered for so long.


I think many organisations may still be underestimating what’s coming.


The real issue is not simply that AI can help attackers. It’s that AI may expose just how much hidden technical debt, weak governance and operational fragility exists beneath the surface.


In many organisations today:

  • Legacy systems are often unsupported

  • Patch cycles are still fairly inconsistent

  • Supplier assurance remains weak

  • AI governance is still fairly immature (I’m personally trying to change that!)

  • Cyber security still competes with short term delivery pressures


One of the most sobering examples discussed was how rapidly the gap between vulnerability disclosure and active exploitation is collapsing. In 2018, organisations typically had an average of 2.3 YEARS before newly disclosed vulnerabilities were actively exploited. Today, that window has reportedly fallen to around 10 HOURS.


That fundamentally changes the operating model for those responsible for cyber security. Patching cycles, governance processes and risk management approaches haven’t been designed for a world where machine-speed attacks can emerge within hours of disclosure.  That needs to change …. and fast.


Ironically, while this may ultimately improve security standards across the industry, the transition period could be uncomfortable for organisations that havent invested sufficiently in resilience, governance and operational discipline.


We are entering a world where the gap between vulnerability discovery and catastrophic business impact may be measured in hours, not months. That should trigger serious discussion and meaningful action to reduce the risk.


 
 
 

Recent Posts

See All
AI is changing the economics of cyber extortion

Much of the discussion around AI and cyber-crime has focused on how it enables attackers write malware, create more convincing phishing campaigns, or identify and exploit software vulnerabilities. My

 
 
 
The advantage might just be shifting

For quite some time, much of the discussion around AI and cybersecurity has focused on the risks. What happens when attackers use AI to find vulnerabilities faster? My previous post on Claude Mythos f

 
 
 
Experience can't be prompted

I had an interesting conversation this week with a few fellow fractional CIOs and CTOs that genuinely made me stop and think. A couple shared situations where business leaders had recently compared th

 
 
 

Comments


bottom of page