What Claude Mythos Means for Vulnerability Management Programs

Scott Kuffer
July 30, 2026
Industry Perspectives
Mythos vulnerability spread

If you've been following the cybersecurity conversation over the last several weeks, you've heard some version of the phrase “Claude Mythos changes everything.” It’s dominated the industry news cycles since early April.  

While the capabilities these stories tout are very much real, I have an issue with the framing being wrong when it comes to vulnerability management. There’s a narrative that Mythos and other frontier models will find too many vulnerabilities to deal with. That’s been happening for years now, though. The vulnerability volume equation’s been against us for a long time.  

To paraphrase Billy Joel, Mythos didn’t start the fire. Mythos made the problem impossible to ignore any longer. 

I wrote about this a few weeks ago, arguing that the NVD funding breakdown was actually a more structurally dangerous event than Mythos. My position hasn't changed. But after spending an hour on our recent webinar with Jerry Hoff, CEO of AppSec Training, Inc., and one of the sharpest AI security minds I know, I think there's more to say on the topic. 

We've Always Had More Vulnerabilities Than We Could Handle 

Let’s start with a number: roughly 150 vulnerabilities per asset.  

That's the average we see across the environments we work with at Nucleus. This number holds more or less steady over time because discovery and patching operate at about the same pace. What that means in practice is that, for every new microservice you spin up, you inherit a new maintenance burden of 120–170 open findings within six months. At 10,000 assets, that's a staggering number. At 100,000 assets, the math gets genuinely terrifying. 

"Finding vulnerabilities has never been the limiting factor,” Jerry shared during our conversation. “So as an example, I used to be a penetration tester back in the day. And ... I went to all the major banks and government agencies ... I would always tell them, okay, if you give me two weeks, I'll find two weeks of vulnerabilities. If you give me three weeks, I'll find three weeks of vulnerabilities. Give me a month, I'll find a month of... There was almost a never-ending fountain of vulnerabilities." 

The lesson here is that the vulnerability reservoir was never going to run dry, even pre-Mythos. But if your organization was already drowning in a backlog it couldn't close, the additional volume is almost beside the point. If you're already a million vulnerabilities behind on the vulns that matter, what's another million on top of it? 

The Adoption Gap Is Real, But Not the Way You Think 

One of the best questions we got from the webinar audience was about the adoption gap between attackers and defenders. The assumption embedded in the question is that attackers have no red tape, no procurement, and no legal review to deal with. They can just pick up any tool and go. 

That imbalance of power has always been there, the same as the backlogs. One of the underappreciated points right now is that defenders in the enterprise space (and likely elsewhere) have been adopting AI faster than I've ever seen any technology adopted.  

We’ve seen ‘blank-check’ AI spending in ways that have no historical precedent. That's unusual, and I have a feeling the trend will reverse itself as AI spend surpasses planned budgets. 

"From my point of view, from what I've seen, organizations are using AI to build a huge amount of new infrastructure and assets,” Jerry said. “But when it comes to doing not even just complex security work, even kind of more basic security work, it's a little bit uneven." 

That unevenness is where the real risk lives. Speed of adoption and quality of implementation are two very different things. I think we’re all seeing that at some level today. 

What Actually Breaks Down Under Pressure 

What would happen if you woke up tomorrow with five times the number of vulnerabilities you have today? What would be your biggest bottleneck? 

We asked the webinar audience these questions, and the top answer was prioritization (I could have guessed that would be top-3, easily). That tracks with what we see in the field, but what does the answer really tell us? 

Prioritization is step two of a very long pipeline that starts with discovery, aka ‘finding the stuff.’ Prioritization begins with triaging what's real and what's noise. Then you prioritize, and you triage again. If prioritization is already where the pipeline breaks down, before AI-generated volume hits, that's a signal that the entire operational layer underneath your vulnerability program needs attention. Vulnerability management programs struggle because findings aren’t reliably routed to the right team; tickets get created and never verified; and security and engineering don’t share a common workflow. 

The Asymmetry Problem and What To Do About It 

The concern about attackers moving faster than defenders is legitimate. But there's a silver lining that gets overlooked: defenders have a bounded problem. You know your environment. You have a finite set of assets, a finite set of owners, and a finite set of systems to protect.  

There's a real-time strategy game concept called 'turtling' that provides a useful analogy. In a gaming context, turtling involves creating a solid defense around your base and weathering the storm of attacks, all while building up your own strength.  

While the analogy isn’t perfect, it does have some valuable parallels to cybersecurity and vulnerability management. Defenders don't have to defend everywhere. They can choose what to turtle around and defend that territory well. 

Jerry extended that thought in a way I thought was exactly right: 

"You have to plan. You have to have your strategy up front ... I know the attack waves are going to be coming in at this time. So you start building up your defenses. I think this is where most organizations ... they are out there harvesting the resources, but they're not building up the defenses."  

That's the crux of it. The organizations that navigate this AI moment well will be the ones that quietly spent the last two or three years building the operational layer that converts findings into closed exposures: normalized data, clear ownership, and verified closure. 

So, What Does Mythos Actually Mean for VM? 

If you walk away from both the webinar and this article with one lesson learned, it’s this: 

Mythos increases the pressure on your remediation infrastructure.  

Coordination failures that were acceptable when you had 500,000 open findings are no longer acceptable when that number multiplies. Organizations that were coasting on discovery tooling alone are going to start feeling real consequences, and thanks to Mythos their boards and their stakeholders will be asking more questions about it. 

But it doesn't mean vulnerability discovery is the broken part of your program. It never was. If anything, what Mythos has done is turn an insider conversation that only people in the industry cared about into a public one. The heightened awareness will mean that budgets are moving, board members are paying attention, and the work that vulnerability management practitioners have been doing for years will finally be recognized as the mission-critical function we always knew it was. 

Now we must make sure that attention translates into fixing the right things, not just finding more of them to add to the backlog.

Scott Kuffer
Scott is the co-founder and Chief Product Officer of Nucleus Security, a leading provider of risk-based vulnerability management solutions. With a wealth of experience in cybersecurity, SaaS, and business strategy, he has been at the forefront of driving innovation in vulnerability management, helping some of the world’s most complex enterprises tackle their biggest security challenges.

See Nucleus in Action

Discover how unified, risk-based automation can transform your vulnerability management.