Claude Mythos: Faster Attackers Don’t Change Where the Line Is
Guest Author: Steve Carter, CEO & Co-founder @ Nucleus Security
Claude Mythos continues to make waves across the vulnerability management space. Predictions of doom, apocalyptic waves of new findings, are crushing security teams.
OK, maybe that’s an exaggeration, but you get the point.
The argument I keep hearing about Mythos goes like this:
“Attackers can produce exploits faster and cheaper now, so defenders have to automate more and accept more risk to keep up. Pull the humans out of the loop. Let the agents remediate. We don’t have time to be careful anymore.”
The first half is right. The conclusion doesn’t follow.
Mythos makes exploits cheaper to produce, thereby industrializing mass exploitation. It begets more attack campaigns and pushes them faster against more targets. That’s a real concern.
What doesn’t change is what an attacker does once an exploit lands, and it doesn’t change anything about how your own production environment behaves. The bottleneck moves downstream. It shifts to prioritizing and remediating what’s coming at you.
So yes, automate. Automate harder. But automate the things that were already safe to automate, not the things that weren’t.
Here’s where the “raise our risk tolerance” logic falls apart. It’s predicated on the fallacy that we had the luxury of time at one point. That’s not why we gated certain remediation actions “in the good old days.” The simple truth is that the cost of getting things wrong has no ceiling.
- We don’t auto-revoke permissions because a bad permission change can break a service account three dependencies down the line. If that happens, you won’t get a clean signal telling you why.
- We don’t auto-patch brittle production systems because the patch itself breaks things for reasons that have nothing to do with whether the decision to patch was correct.
We gate and monitor these kinds of actions because they’re irreversible and very often their blast radius is unbounded.
Just because attackers are moving faster doesn’t change any of these factors. A bad WAF rule doesn’t become self-correcting because the adversary moved quicker. A broken entitlement change can’t be reversed. Taking down production doesn’t get cheaper.
The constraint was always the blast radius. It wasn’t tempo. As we’ve learned, tempo is the one thing Mythos changes.
There’s a quieter problem hiding in the mindset of “tolerate more risk.” A small error rate that’s fine on a human-reviewed prioritization list becomes a major problem once you’ve removed the human to keep pace. You haven’t reduced the risk. You’ve moved it from a place where a mistake costs nothing to a place where it costs everything.
Speed pressure changes everything if you let it. It’s a force that pushes the error from cheap surfaces onto expensive ones. Calling that shift “higher risk tolerance” makes it sound like a strategy instead of the accident it is.
Here’s the real rub. When exploitation goes industrial, an autonomous agent with standing authority to change identity or push to prod stops being a convenience and starts being a target. You’d be standing up the highest-value attack surface in your environment at the exact moment the volume of attempts against it spikes.
That’s not keeping up with the threat. That’s building it a door, turning the light on, and handing the keys over to the attackers.
So here’s the line, and it doesn’t move:
Automate the deterministic work to the floor. Normalization, deduplication, correlation, applying your prioritization policy, and opening the ticket. None of that should run through a probabilistic model in the first place, and Mythos is a reason to do more of it, faster.
Automate the upstream remediation work aggressively. Match the finding to the fix, check whether it’s actually being exploited, scope the affected assets, and stage the change. That’s where agents earn their keep, and there’s no irreversible commit anywhere in it.
Let agents triage and prioritize with a human watching the output. Push additive, single-point, reversible controls like a WAF rule or a virtual patch, as long as you’ve built something that tells you when the rule is wrong instead of waiting for a support ticket.
Gate the rest. Control fixes like identity changes or irreversible patches to systems that can’t absorb them. Not because the models aren’t good enough. Because the action can’t be taken back, and the downside has no floor. No model-generation fixes will fix that, because it was never a model problem.
The honest version of “what do we do about faster attackers” isn’t braver. It’s more automation where mistakes are cheap, on a foundation solid enough that the cheap-mistake layer can’t corrupt the parts that have to be right. The line between what you automate and what you gate was drawn on reversibility and blast radius.
Mythos doesn’t redraw it. It just raises the stakes on getting it right.
![]() | This article was contributed by Steve Carter, CEO & Co-founder at Nucleus Security Steve Carter is co-founder and CEO of Nucleus Security. Steve has spent over 25 years in cybersecurity, helping organizations build, optimize and scale enterprise vulnerability management programs. Prior to founding Nucleus, Steve was a founding partner of Rampant Technologies, a defensive cybersecurity service provider for large federal agencies and private sector organizations. Steve holds a Master’s of Computer Science from Florida State University. |
