Skip to content
Blog
August 20, 2026

Mythos one month later: What we saw after the exploit window closed

Author:
John Bruggeman – Consulting CISO
Mythos one month later The new reality of patch management
7:56

Summertime is when many people hit the beach to swim and surf. This summer, IT operations teams found themselves facing a different kind of wave: an influx of security patches.

In the spring, Anthropic’s Project Glasswing gave about 50 partners early access to Claude Mythos so their defenders could find and patch vulnerabilities before attackers could strike. I was very happy to see that because it gave the folks on the blue team time to assess the risks that Mythos exposed. A lot happens behind the scenes in IT operations that very few people see, and Glasswing gave teams time to gear up for the wave of patches that would be coming.

In another blog, my colleague Brian Quinn wrote about the Mythos Preview and proposed four questions for security leaders to tackle before July, when the coordinated-disclosure clock on those early findings started running out. It’s now August, and the fixes and the exploits derived from the vulnerabilities are landing in the IT ops team’s inbox in waves, just as everyone predicted.

I want you to think of this blog as part field report and part analysis of how Brian’s four questions are playing out across our client environments.

Newsflash (not!): Patch volume has surged

If you’re responsible for patching, you probably have firsthand knowledge of the patch tsunami that we have all experienced since May. You may know that Microsoft is on pace to patch a record number of vulnerabilities in 2026, with the total number deployed by June of this year exceeding all patches for 2025. And you may have experienced something like one CBTS Managed Services client, which had 570 vulnerabilities patched by our team last month alone. That’s a record high and a 285% increase compared to 200 patches in June 2026.

So what? Patching holes is what IT does. But that work is more urgent than ever when there’s no longer a lag between a vendor shipping a patch and a working exploit appearing. An IT ops team used to have days or weeks to patch. Now they have hours.

The dynamics of AI-accelerated exploits are also changing how teams triage. Because of Mythos, vulnerabilities that we would normally classify as mediums and handle at a comfortable (i.e., slow) cadence now require nearly the same response that’s reserved for criticals. The reason is that the old timelines assumed a human would be writing the exploit, an assumption that no longer holds. Criminals and threat actors (think: nation states like North Korea, China, and Iran) are using AI tools to automate the development of exploit code and attacks.

When the tide goes out, you can tell who was skinny-dipping

Brian’s blog posed an overarching question: In a threat environment where the window between disclosure and exploitation is measured in hours, does your current program assume that you have time that you really don’t have now? He also had four key questions for security leaders. Here’s a quick recap of the questions and how they’re coming to life this summer.

Runbooks built for hours, not weeks

  1. When was the last time your incident response runbook was pressure-tested against an hour, not a week-long timeline?

Brian’s first question asked when a team’s incident response runbook had last been pressure-tested (for example, in a tabletop exercise) against a one-hour patch window rather than a week patch window. Over the summer, that hour vs. week distinction separated the organizations that stayed ahead of attackers from the ones that fell behind.

In one Managed Services environment, CBTS had already drilled an emergency, out-of-cycle patch path against a same-day timeline. That “rehearsal” paid off when a fix hit a flaw that was already under active exploitation. The team ran the emergency path and closed the exposure in hours; organizations without a rehearsed route waited for their next scheduled window. That wait time is your risk window. How long do you want to keep it open?

Authority on a Friday night

  1. If a critical flaw is confirmed as actively exploited at 9 pm on a Friday, who has the authority to push a patch before Monday — and do they know it?

This is where we are seeing the most avoidable failures. The capability is often present. Companies do appropriate scanning and report generation to track vulnerabilities. Sometimes they have automation in place. What’s missing is knowing who is in charge. You need a name, someone with authority to act outside the normal change window at virtually any hour. Where that authority is ambiguous, the patch will wait until Monday, and Monday might be too late.

Reporting risk on outdated assumptions

  1. Are you reporting risk to your board using metrics built for human-speed attacks?

Many organizations are still relying on outdated metrics, and that’s not a surprise given that Mythos was released to the public in June. CIOs and CTOs are not reporting this way out of any desire to mislead. The problem is that the underlying assumptions simply haven’t been revised. Patch timelines, incident-frequency models, and an assumption that writing an exploit is difficult all reflect a threat environment that no longer exists. The leaders who have updated those assumptions this summer gave their boards an honest picture; the rest reported an artificially comfortable posture, which exposes those organizations and companies to much higher risk.

Defensive AI past the planning stage

  1. Have you deployed AI-based tools on the defensive side, or only thought about it?

Attackers are already using AI, all the time and often for free! On our side, the defender side, the CBTS SOC now runs what we describe as “SOAR on steroids.” Our SOC has agentic capability handling a large share of level one and level two analyst work. That’s how we are decreasing our time to detect, acknowledge, and triage even as volume keeps rising.

Finding the sweet spot in patch waves

Some organizations were already well-positioned for what happened this summer. That includes a financial services client that came to CBTS a few years ago after their previous provider had missed SLAs for PCI and PII patching.

We corrected the cadence in 45 days and have held full compliance since, with 95%+ SLA patching compliance maintained across every vulnerability tier, over six clean audits across three years, and sub-one-hour disaster recovery/business continuity failover. This client’s reporting has shown the risk needle moving from red to green, and that’s not a “watermelon” report, green on the outside but red in the middle. It reflects real progress and real risk reduction. It’s a great example of how the right operational model helps teams do the boring and rote work that gets an organization from missed SLAs to sustained compliance, especially when in-house resources are strapped for time.

What to do now? #PatchYourStuff

As summer and the initial patch waves draw to a close, the fundamentals still matter: Segment networks. Enforce access controls. Confirm that multi-factor authentication is deployed and enforced, not just configured. Disable services no one is using. And implement egress filtering, the outbound control the CSA CISO Community brief credited with blocking the public Log4j exploits it evaluated.

Basic hygiene compounds in value precisely as the threat environment accelerates; a breach that stays contained is a far smaller event than one that spreads.

Whether you’re reworking your patch cadence, response authority, or risk reporting, we are ready to talk. #PatchYourStuff

Straight talk from a trusted partner

Clear thinking on AI, security, cloud, infrastructure, and the decisions that determine whether technology delivers or disappoints.

Let’s build something that lasts.

If you’re looking for a technology partner that will stay invested in your success, we’d like to talk.