Skip to content
AI HOT (Curated Pool)

Anthropic study shows AI needs hours, not weeks, to build exploits from security patches

Anthropic 研究:AI 数小时内即可从安全补丁构建漏洞利用

Anthropic's security team measured how fast LLMs reverse-engineer vulnerabilities from patches. On Firefox's SpiderMonkey engine, the unreleased Mythos Preview model produced its first crash proof in 12 minutes, hit 14 of 18 CVEs within 40 minutes, and built 8 working remote-code-execution exploits—the first within an hour of the patch going live. On Windows kernel privilege-escalation bugs without source code, Mythos Preview found 18 of 21 vulnerabilities in under 6 hours for ~$2,200 in API credits, then assembled 8 full SYSTEM-level attack chains at ~$2,000 per exploit. Opus 4.8 built individual components but couldn't chain them. Microsoft had rated 14 of the 21 as 'less likely' or 'unlikely' to be exploited. The buffer that patch analysis used to give defenders is now mostly gone: a single operator can turn a month of patches into working exploits in an afternoon for a few thousand dollars.

Why it matters: Anthropic's security team tested their unreleased Mythos Preview on reverse-engineering Firefox patches: 12 min to first crash, 40 min to cover 14/18 bugs, 8 full RCE exploits. Shrinks patch-to-exploit from weeks to hours. Not 85+ because only the-decoder is reporting so far; ...

Read the original ↗Export Markdown