Anthropic Warns N-Day Vulnerabilities Become N-Hour Threats With Claude Mythos Preview
The speed at which Claude Mythos Preview can weaponize known vulnerabilities compresses the patch window for defenders from days to hours, fundamentally changing the risk calculus for software maintenance and incident response.
Key Facts
- Anthropic's Claude Mythos Preview AI created its first proof-of-concept exploit from a publicly disclosed vulnerability in about 12 minutes and produced 13 PoCs within 40 minutes.
- For blue-screen exploits targeting Windows vulnerabilities, Claude Mythos Preview completed 18 out of 21 within six hours, with the first exploit finished in 31 minutes.
- Anthropic stated that the term 'N-day' has become dangerously misleading and that 'N-hour' is more appropriate for the current reality.
- Anthropic and about 50 partners used Claude Mythos Preview to discover over 10,000 vulnerabilities rated 'High' or 'Critical' severity in globally important software.
- On June 9, Anthropic also released the production versions Claude Mythos 5 and Claude Fable 5, both priced at $10 per million input tokens and $50 per million output tokens.
Reporting from 5 sources: ASCII.jp, GameBusiness.jp, GIGAZINE, Inside, and 1 more.
Anthropic released a report on June 9 showing that its Claude Mythos Preview AI can develop working exploits from publicly disclosed vulnerabilities, known as N-days, in hours rather than the days or weeks traditionally required. In tests, Claude Mythos Preview created its first proof-of-concept exploit in about 12 minutes and produced 13 PoCs within 40 minutes. For blue-screen exploits targeting Windows vulnerabilities, it completed 18 out of 21 within six hours, with the first exploit finished in 31 minutes. The company stated that the term N-day has become dangerously misleading and that N-hour is more appropriate for the current reality. Separately, on June 9, Anthropic also released the production versions Claude Mythos 5 and Claude Fable 5, both priced at $10 per million input tokens and $50 per million output tokens. Claude Fable 5 includes safety restrictions that block cyberattack-related instructions, while Claude Mythos 5 is limited to approved organizations through Project Glasswing. Claude Fable 5 also demonstrated the ability to clear Pokémon FireRed using only visual input, completing the game in 50 hours and 9 minutes.
Anthropic published the report through its research blog, red.anthropic.com, in May 2026. The company and about 50 partners used Claude Mythos Preview to discover over 10,000 vulnerabilities rated "High" or "Critical" severity in globally important software. Independent security research firms re-verified the vulnerabilities, finding 90.6% were genuine and 62.4% were actually rated "High" or "Critical."
The report focused on N-day vulnerabilities, which are publicly disclosed with patches released or in development but for which no exploit may yet exist. Anthropic noted that while most of its prior cybersecurity research covered zero-days, the majority of real-world damage comes from N-days. Attackers reverse-engineer patches through source code and patch diff analysis, a process that traditionally takes days to weeks.
In tests comparing Claude Mythos Preview against Claude Opus 4.8, Claude Opus 4.6, and Claude Sonnet 4.6 on 18 vulnerabilities, Claude Mythos Preview created its first proof-of-concept in about 12 minutes and 13 PoCs within 40 minutes. It took roughly 3 hours to complete the 14th. When tasked with 50 PoC developments per vulnerability, Claude Opus 4.8 and Claude Opus 4.6 consistently solved only one vulnerability each, while Claude Mythos Preview consistently solved seven.
For blue-screen exploits targeting Windows vulnerabilities, Claude Sonnet 4.6 and Claude Opus 4.7 each developed PoCs for 13 out of 21 vulnerabilities, Claude Opus 4.8 for 15, and Claude Mythos Preview for 18. Claude Mythos Preview's first PoC was completed in 31 minutes, and all 18 were achieved within six hours.
Anthropic stated: "This suggests that users currently in the patch gap face a much greater threat than before, and the risk only increases as model capabilities improve. The term 'N-day' has now become dangerously misleading; 'N-hour' is more appropriate for the reality we face." The company proposed that defenders accelerate patch deployment speed as a countermeasure.
Synthesized by Yomimono from the 5 cited sources below, including Japanese-language reporting where cited, then editorially reviewed before publishing.
Sources
- ASCII.jp わずか3日で停止された新AI「Claude Fable 5」は何がすごかったのか
- GameBusiness.jp Claudeのエージェント別枠化が撤回、Anthropicが当日発表―今後のプラン変更に向け再検討中
- GIGAZINE トランプ政権がClaude Mythos 5へのG7諸国のアクセスを認めない方針、イギリスは例外措置を要求
- Inside 高性能AIが『ポケモンFR』をクリア!? 視覚情報だけでやり遂げた最新モデル「Claude Fable 5」公開
- Game Spark 『ポケモンFR』を高性能AIがクリア!視覚情報だけでやり遂げた最新モデル「Claude Fable 5」公開―『Factorio』もプレイできる