While a massive overhaul is underway for the process of finding and fixing vulnerabilities in the wake of Anthropic’s Claude Mythos being revealed, the progress has been far from even around the industry, solution provider executives and security experts tell CRN.
The arrival of ultra-powerful AI models for vulnerability discovery that began with Anthropic’s Claude Mythos earlier this year has jolted the industry into making widespread changes in exposure management practices in just six months—though the challenges remain steep for many organizations, cybersecurity experts told CRN.
The April 7 disclosure of details about the proficiency of Mythos for discovering and exploiting software vulnerabilities at unheard-of speeds led to an immediate mobilization within many businesses around the issue.
Given that many companies can take weeks or months to patch vulnerabilities after disclosure, the prospect of a monumental surge in new software bugs was met with attention—and even panic—within the highest levels of industry and government.
[Related: CRN Global Cybersecurity Week 2026]
Indeed, the six months since Mythos came to light—which has also included a cascade of other frontier AI advancements in the area, including from OpenAI and open-weight models—have seen massive changes sweep the industry on vulnerability and exposure management.
Still, when it comes to the processes for finding and fixing vulnerabilities, the progress has been far from even around the industry, solution provider executives and security experts told CRN.
Without a doubt, the arrival of Mythos and other frontier models for vulnerability discovery “has really created an opportunity for our clients to push their threat exposure management agenda into the board—because boardrooms are now listening,” said Kathryn Hall, senior vice president of services at Leawood, Kansas-based Optiv, No. 29 on CRN’s Solution Provider 500 for 2026.
The result has been “a lot of really meaningful momentum” in a relatively short span of time, Hall said—though there’s no question that the degree of progress “has significantly varied by organization.”
Key changes that have come to the industry include a notable shift in how businesses decide which vulnerabilities to fix and how continuously they assess their exposure—as well as an evolution in how leaders make the case for expanded security investments to the board, according to experts.
At the same time, as new capabilities boost visibility in vulnerabilities and help with identifying the most important exposures to address, many businesses are still running into the old familiar obstacles getting in the way of rapidly fixing vulnerable software.
A Shift In The Conversation
For consulting giant Accenture, there’s no question that the typical customer conversation has changed dramatically since the initial alarm over AI-powered vulnerability discovery sparked by Mythos, according to Accenture’s Jason Lewkowicz.
Initially, calls from concerned clients had largely centered around how to patch vulnerabilities more rapidly as a way to address the fact that the models were identifying software flaws so much faster, said Lewkowicz, global lead for cyber resiliency and defense at Dublin, Ireland-based Accenture, No. 1 on CRN’s 2026 Solution Provider 500.
“I was finding more clients spending time on wanting to patch faster, versus rethink their broad-stroke program,” he said. “In the beginning, it was probably 80 percent, ‘Let’s go patch faster and play whack-a-mole.’”
However, as time went on—and with the help of Accenture—many customers have eventually come to see the limitations of that approach and recognize the need for a broader update to their strategy, Lewkowicz noted.
“Now it’s probably 80 percent in the bucket of, ‘Let’s really rethink our approach to this,’” he said.
That is translating, for instance, into heightened interest among customers in methods such as continuous threat exposure management (CTEM) and attack surface identification, as well as penetration testing and offensive security, Lewkowicz said.
Without a doubt, Mythos has accelerated a transition in the direction of CTEM that was already underway, according to GuidePoint Security’s Gary Brickhouse.
“Mythos is fast tracking it, frankly—and organizations probably are having to deal with it at a faster clip than they were originally planning to,” said Brickhouse, CISO at Herndon, Va.-based GuidePoint Security, No. 32 on CRN’s 2026 Solution Provider 500.
Previously, “I think maybe everybody felt like, ‘Hey, we can sort of ease into this,’” he said.
The truth is that CTEM is more of an ongoing approach to understanding and reducing exposure, as opposed to a particular goalpost that an organization reaches, Brickhouse said. The idea is for businesses to be continually assessing their attack surface and identifying new routes an attacker could take, he said.
“Probably the biggest, most important piece of CTEM is the ‘C’—which is continuous,” Brickhouse said.
The ultimate purpose is to give businesses an ongoing process for pinpointing which vulnerabilities and exposures truly matter most, according to Brickhouse.
Six months in after Mythos, the advancement toward better prioritization of exposures is “where we see most of the maturity happening,” he said.
Chaining Of Vulnerabilities
Another critical aspect of responding to the frontier AI shift has been the recognition that these models bring a proficiency to connecting vulnerabilities together, which just was not possible in the past, experts told CRN.
“The reality is, yes, AI is being used to find new vulnerabilities,” said Rocky Giglio, founder and CEO at Columbia, S.C.-based Cloud Security Pros. “But simultaneously, AI is also being used to chain vulnerabilities together.”
That has been highly relevant for businesses looking to adapt their vulnerability management for the Mythos era, according to Giglio.
The reason, he said, is simple: Fixing only the vulnerabilities with the highest severity scores can leave a backlog of bugs that threat actors may now be able to chain together to carry out cyberattacks.
Addressing that challenge requires a much more complete view into the potential attack path—and AI can help defenders with that, too, Giglio said.
For instance, an organization may have a vulnerability on a web server that is already protected by a web application firewall rule—whereas another bug, on a virtual machine with a public IP address, could actually warrant the most immediate attention, he said. New AI-powered capabilities can make that distinction very effectively, he said.
The idea is “applying AI to the whole attack path rather than just, ‘You have this vulnerability on this system,’” Giglio said.
Faster Patching
Alongside deploying new capabilities for prioritizing and fixing vulnerabilities, many businesses still need to update their practices around vulnerability management to enable faster responses, Giglio noted.
Without a doubt, in the Mythos era, “you can’t have a monthly patch cycle,” Giglio said. “That’s too long.”
Many customers are, in fact, revisiting restrictions that in the past allowed for potentially disruptive updates to software to take place only once a month, according to GuidePoint’s Brickhouse.
Even with adoption of new policies around patching, however, many businesses still must be willing to make difficult decisions about where to direct their limited resources, he said.
New AI capabilities can help in that regard, as well. The approach involves using AI to connect signals from different security tools—with the context included that is necessary to determine which exposures are the top priority for the business, Brickhouse said.
One way that Troy, Mich.-based Logicalis is working with clients to accelerate patching processes for customers is to agree up front on an expedited “emergency change process,” said Troy Saunders, CISO at Logicalis U.S., No. 79 on CRN’s 2026 Solution Provider 500.
“It’s about setting up all the parameters and [having an] agreement up front around what can we go ahead and patch without approval,” Saunders said.
That process can enable the solution provider to establish what changes can proceed without another round of approvals while also making sure that the actions are documented, he noted.
Communication Is Key
At cybersecurity powerhouse Optiv, many customer engagements are demonstrating both the progress being made as well as the importance of addressing key organizational issues surrounding remediation processes, according to Hall.
For one manufacturing customer, for instance, Optiv developed a new vulnerability management program and implemented the tools needed to improve visibility, she said.
But Optiv’s largest contribution has actually been around helping different business units communicate and take responsibility for addressing exposures, Hall said.
“This is not just a security problem,” she said. “This touches every business unit and infrastructure—and it takes a lot of stakeholder communication, education and change management.”
Uneven Progress
Still, greater awareness—and helpful new capabilities leveraging AI—have not universally translated into dramatic improvements on vulnerability management, according to security experts.
“I think people have been very interested in moving [to a new approach],” said Rob Lefferts, corporate vice president for threat protection at Microsoft. “I’m not sure they are moving fast enough in practice yet. And that’s especially true for the organizations that don’t have a strong security focus.”
Another issue certainly is that the constant arrival of new tools and competing claims can actually make it harder to decide what to do next, said Giglio of Cloud Security Pros.
“There’s a little bit of the analysis-paralysis. There are so many choices,” he said. “There’s a new cybersecurity tool every day that’s promising to solve some element of this.”
Meanwhile, although customers are becoming more willing to fund the necessary investments for updating their vulnerability and exposure management programs in the wake of Mythos, that investment does not appear to be happening fast enough across the board, according to Optiv’s Hall.
And in any case, funding alone will not entirely resolve the challenges posed by AI-accelerated vulnerability discovery, she noted.
“That money can buy you some tooling—but someone has to implement it and run it, and still drive all that stakeholder communication and connectivity,” Hall said.
The bottom line is that while the heightened attention from boards and C-level executives has provided greater support for making necessary security changes, turning that support into a lasting improvement is a work in progress for many businesses, she said.
“Yes, I’m optimistic,” Hall said, “but there’s a lot of work to be done.”





