The Best Vulnerability-Hunting AI Is Now Something You Buy
Anthropic has opened Claude Mythos 5 to enterprise teams for hunting vulnerabilities in code. That is the same model that turned up in an accidental disclosure earlier this year, described internally as far ahead on cyber capabilities. It has gone from a rumour about something powerful sitting inside a lab to a product with an access process. If your business does not write software, that still matters to you, just not in the way the headline suggests.
From rumour to product
Earlier this year, internal material about this model became public and described capabilities well ahead of anything on the market for finding software flaws. We wrote about it at the time in what the Claude Mythos leak meant, and the honest position then was that a leaked description is not a product and nobody outside could evaluate it.
That is no longer the situation. It is now something enterprise teams can get access to and point at their own code. Which makes the question less philosophical: what does it mean when the strongest available flaw-finder becomes purchasable?
Good news and bad news, in the same week
The defensive case is strong and worth stating first. A system that reads code the way a patient attacker would, at a speed no human team can match, is exactly the capability most organisations have never been able to afford. Serious security review has always been expensive and scarce. Making it cheaper genuinely helps, and the software you depend on gets better as a result.
The uncomfortable half is that the same class of capability lowers the effort needed to find flaws for other reasons. Access controls and enterprise gating slow that down. They do not settle it, and nobody serious claims otherwise. This week does not create that tension, it just makes it concrete enough to plan around.
What it means if you do not write software
Most Canadian small businesses do not employ developers. You still run a lot of other people's code: your website and its plugins, a booking system, accounting software, point of sale, whatever sits on the office server that nobody has looked at since it was installed.
Faster flaw discovery across the industry produces two effects at once. More problems get found and fixed, which is good for you. And the window between a patch appearing and the flaw being exploited compresses, which is only good for you if you install patches. That is the whole practical translation. Your exposure is mostly a function of how quickly you update, and it always was. The clock just runs faster.
| Do this | Why it matters more now |
|---|---|
| Automatic updates on, and verified | The patch window is shrinking |
| List your internet-facing software | You cannot patch what nobody wrote down |
| Ask vendors about patch speed | Their timeline is now your exposure |
| Multi-factor authentication everywhere | Still the highest-value hour you can spend |
None of that is new advice, and there is no clever AI answer hiding behind it. What changed is the cost of being slow.
Push the question to your suppliers
Buying a scanner for software you did not write and cannot change mostly produces a list nobody can act on. The higher-value move is to ask the people who do control the code.
Do you use automated security review on your product? How quickly do you ship a fix once a serious flaw is confirmed? How will we hear about an incident that affects us, and how fast? Those three questions take a minute to ask and the quality of the answers separates suppliers quickly. They belong alongside the rest of the questions in using the emerging AI security standard as a buyer checklist.
If you do build software
Then this is straightforwardly useful and you should be evaluating it, with one caution. A tool that surfaces a hundred findings is only valuable if someone triages them, and an unread backlog of security findings is arguably worse than no scan, because you can no longer claim you did not know.
Decide who owns the output before you turn it on. And if you are letting an agent run scans across your systems, the containment principles in giving an agent its own limits apply with force here, because a tool with permission to read all your code is a significant thing to hand out.
The honest summary
This is a real improvement for defenders and a real acceleration of the whole game. Both. Anyone telling you it is purely one or the other is selling something.
For a business without developers, the response is unglamorous and it works: know what you run, keep it updated, turn on multi-factor authentication, and make your suppliers answer for their patch speed. That was good advice last year. It is worth more now, because the interval between a flaw being found and being used has quietly shortened, and nobody is going to send you a notice when it does.
Frequently Asked Questions
What happened?
Anthropic opened Claude Mythos 5, the model it has described as its strongest on cyber capabilities, to enterprise teams for finding vulnerabilities in code. That is notable mainly because the same model was the subject of an accidental disclosure earlier this year, when internal material described it as far ahead on offensive security. Whatever you thought about that at the time, the capability is now a product with an access process attached, which is a meaningfully different situation from a rumour about an internal model.
Is this good news or bad news?
Both, and the balance depends on who moves faster. Defenders get a genuinely useful tool: a system that reads code the way a determined attacker would, at a speed no security team can match, is exactly what most organisations have never been able to afford. The same class of capability also lowers the effort required to find flaws for less friendly purposes. Nothing about this week changes that dynamic, it just makes it concrete, and access controls slow that down rather than preventing it.
We do not write software. Does this affect us?
Yes, indirectly, and the indirect route is the one that reaches you. You run software written by other people: your website, your booking system, your accounting package, your point of sale. When flaw discovery gets faster across the industry, two things follow. More vulnerabilities get found and patched, which is good. And the window between a fix being published and being exploited gets shorter, which is only good if you actually apply patches. Your exposure is mostly a function of how quickly you update.
What should a small business actually do?
Boring things, done consistently. Turn on automatic updates everywhere you can and check that they are working rather than assuming. Know what internet-facing software you run, because you cannot patch what nobody has listed. Ask any vendor who builds or hosts software for you how quickly they apply security patches and how they tell you about incidents. Make sure multi-factor authentication is on everywhere. None of that is new advice. What changed is that the cost of being slow went up.
Should we be running AI security scanning ourselves?
Only if you build or maintain your own software, and even then it complements rather than replaces the basics. For most small businesses the higher-value question is directed at suppliers rather than internal tooling: ask whether they use automated security review, how fast they ship fixes, and what their disclosure process looks like. That pushes the capability to where the code actually lives. Buying a scanner for software you did not write and cannot change mostly produces a list nobody can act on.
Shorten your exposure window
We help Canadian businesses inventory the software they depend on, fix update practices, and hold suppliers to a real security standard.
Related Articles
Ottawa Is Drafting AI Transparency Rules. Speak Now.
The Next Laptop You Buy Ships With AI Already On It
AI Is Now Your Cyber-Defender, Too
Ajan leads the ChatGPT.ca team: 200+ custom GPT builds and automation projects for 50+ businesses across 20+ industries. Based in Markham, Ontario. PIPEDA-compliant solutions.