Detecting Mythos-enabled intrusions when exploits outpace patches
Anthropic’s launch of Fable 5 and Mythos 5 marked a shift in the economics of offensive cyber operations. The two configurations share the same underlying model, with safeguards distinguishing how their capabilities can be used. For defenders, the larger issue is not whether one named model becomes the next attack tool. It is that autonomous vulnerability analysis and exploit development are moving closer to machine speed.
That changes what organizations can reasonably expect from the traditional scan, prioritize, patch, and verify cycle. Patching remains essential, but it cannot be the only control during the interval between exposure and remediation. Defenders also need runtime detection capable of identifying and disrupting attacker activity inside the environment when the entry technique is new, the exploit is unfamiliar, or remediation is still underway.
For a deeper examination of why model guardrails do not secure enterprise networks, see AI Guardrails vs. Enterprise Defense.[1]
At a glance
- Mythos-class AI can compress vulnerability analysis and exploit development, reducing the time defenders have to remediate newly disclosed vulnerabilities.
- Exploit lag is collapsing while enterprise patch lag remains constrained by testing, approvals, deployment windows, and operational risk.
- Cyber deception is attack-tool and vulnerability independent, producing high-confidence signals when an adversary interacts with assets that have no legitimate business use.
- During U.S. Navy ANTX FY25, every alert Acalvio generated was tied to confirmed malicious activity, and the deception layer denied approximately 80% of attacker objectives within the exercise
One security lag collapsed. The others did not.
Enterprise defense has traditionally operated within three time intervals:
- Disclosure lag: the time between private discovery of a vulnerability and public disclosure through a Common Vulnerabilities and Exposures (CVE) advisory.
- Patch lag: the time between disclosure and an organization’s testing, approval, and deployment of the fix across production systems.
- Exploit lag: the time between public disclosure and the availability of a reliable working exploit.
Historically, exploit lag often gave defenders a usable window. Organizations could identify exposed systems and deploy remediation before reliable exploit code became broadly available. That window made patch-first strategies viable even when patch deployment itself took time.
Mythos-class capabilities change one part of that equation. Autonomous systems can analyze a newly disclosed vulnerability, generate and test code, and assemble attack paths far faster than a human-led process. Exploit lag can therefore approach zero while patch lag remains bounded by production realities. N-day vulnerabilities begin to behave more like near-zero-days because exploit development is no longer the limiting factor.
The operating question is no longer only whether a vulnerability can be patched before an exploit exists. It is whether malicious behavior can be detected and disrupted before the attacker reaches an objective while remediation is still underway.
What fills the gap while remediation is underway
Runtime detection provides a control layer during the period when exposure is known but remediation is incomplete. It does not reduce the urgency of patching. It reduces dependence on the assumption that remediation will arrive before exploitation.
In this context, AI runtime security means detecting AI-accelerated attacker activity as it unfolds inside identity, cloud, network, and endpoint environments. It is distinct from model guardrails, which govern what an AI system is allowed to produce, and from agentic AI runtime protection, which protects enterprise agents, their tools, and their infrastructure while they operate. Those controls address related risks, but they do not solve the same problem.
For Mythos-enabled intrusions, the requirement is runtime threat detection that remains effective without prior knowledge of the exploit, the malware, or the automation framework behind the attack.
Why cyber deception works against machine-speed attack automation
Signatures, behavioral analytics, and event correlation remain important, but each asks defenders to interpret evidence generated by activity that may also be legitimate. Deception changes the quality of that evidence. A deceptive credential, honeytoken, HoneyPath, decoy service, or intentionally suspicious artifact has no legitimate business purpose. Interaction with it can therefore produce a high-confidence signal of malicious intent without depending on the vulnerability used for entry.
When initial access does not deliver the objective, an attacker typically needs to discover the environment, obtain additional access, test trust relationships, or move toward higher-value systems. Those post-compromise actions create opportunities for deception-based runtime detection regardless of whether entry came through a known vulnerability, a zero-day, a Mythos-generated exploit chain, or stolen credentials. Detection does not depend on a prior signature or a completed patch.
Acalvio 360 Deception extends this beyond isolated decoys across three vectors: fake assets that look real, real assets made to appear deceptive, and intentionally suspicious artifacts an attacker cannot safely ignore. Together, they make the environment harder for autonomous attack systems to interpret with confidence.
That matters because attack automation depends on stable ground truth. When the environment returns competing signals, the attacker must verify, branch, spend additional time, or proceed with greater uncertainty. Each interaction can convert ambiguous behavior into verified attacker intent. This is preemptive cybersecurity in practice: trusted-path disruption changes the terrain before the attacker reaches the objective rather than waiting to reconstruct intent after damage occurs.
Modern deception also has to operate at enterprise scale. Automated deployment, continuous refresh, and realistic coverage across identity, cloud, endpoint, network, and operational technology reduce the fingerprinting risk of static decoys and allow deceptive paths to evolve with the environment.
Deception-based runtime detection does not replace SIEM, EDR, XDR, IAM, or PAM. It adds a high-confidence layer that can feed those systems when authenticated or apparently authorized activity is still pursuing the wrong objective.
What the Navy ANTX FY25 results demonstrate
During the U.S. Navy NIWC Pacific Cyber Resilient Systems ANTX FY25, Acalvio’s ShadowPlex deployment was evaluated against a sophisticated red team in a live adversarial exercise. Acalvio achieved 100% true-positive alerts and denied approximately 80% of attacker objectives within the exercise environment.
The two measures should not be conflated. One hundred percent true-positive alerts means every alert generated corresponded to confirmed malicious activity. It is a measure of alert fidelity, not a claim that every possible intrusion was detected. Denial of approximately 80% of attacker objectives measures operational effect: the deception layer degraded the red team’s ability to complete its mission.
Detections spanned initial enumeration, credential access, lateral movement, privilege escalation, and data exfiltration. Within the scope of the exercise, the results demonstrate why deception is relevant to machine-speed intrusion: it can produce high-confidence detection while also diverting and disrupting the attack path.
Turning the CSA's 90-day guidance into an operating plan
The Cloud Security Alliance’s Mythos strategy briefing identifies deception as a high-priority control and recommends building the capability within 90 days. It also calls for behavioral monitoring, pre-authorized containment actions, and response playbooks that can execute at machine speed.
For security leaders, that guidance translates into four operating priorities:
- Map where unresolved exposure intersects with privileged identities, critical systems, and likely post-compromise routes.
- Instrument those paths with deceptive assets that have no legitimate business use and can produce high-confidence signals when touched.
- Integrate deception events into existing detection and incident response workflows, with pre-authorized containment actions for well-defined conditions.
- Validate time to signal and time to response through adversary emulation, including AI-assisted attack scenarios that operate faster than conventional exercises.
The goal is not to replace vulnerability management with detection. It is to remove the unprotected interval between the two.
Detection that does not wait for the patch
Machine-speed exploitation does not make vulnerability management obsolete. It removes the assumption that remediation will arrive first. Effective defense now requires both rapid patching and an environment instrumented to detect and disrupt malicious activity before the attacker reaches an objective.
The defensive objective is straightforward: shorten the remediation window while making the environment less reliable for the attacker and more revealing for the defender. Organizations should not ask analysts to infer intent from weak behavioral evidence when the environment itself can be designed to make malicious intent observable.
See which of your lateral movement and credential attack paths would expose a Mythos-speed intrusion today.
The 360 Deception Attack Path Assessment maps credential attack paths, lateral movement routes, and runtime blind spots to identify where deception-based detection can generate a high-confidence signal before attacker objectives are achieved.
FAQs about Mythos-enabled intrusion detection
Mythos-class models are highly capable systems designed for long-horizon autonomous work. Anthropic’s Fable 5 and Mythos 5 use the same underlying model, with safeguards distinguishing the two configurations. Their ability to analyze complex code, use tools, and sustain autonomous work can accelerate legitimate cyber defense and, if misused, offensive vulnerability research.
Mythos-class AI can automate vulnerability analysis, code generation, testing, retry, and attack-path assembly. Tasks that previously required multiple specialists and extended manual effort can be completed or iterated far faster, reducing the time between vulnerability disclosure and a usable exploit.
Patching remains essential, but production remediation is constrained by testing, approval, deployment, and availability requirements. If exploit generation moves faster than that process, organizations also need runtime detection during the interval between disclosure and completed remediation.
Deception technology detects interaction with assets that legitimate users and applications should not access. Honeytokens, deceptive credentials, HoneyPaths, decoys, and other deceptive assets can therefore reveal credential abuse, discovery, and lateral movement without relying on a known exploit signature.
No. Deception-based runtime detection identifies malicious activity in the enterprise environment, including activity accelerated by offensive AI. Agentic AI runtime protection safeguards enterprise agents, their tools, and their supporting infrastructure. Acalvio addresses that adjacent requirement through the Deception Guardrails capability in ShadowPlex, delivered as part of its Agentic AI Security solution. The two controls are related, but they protect different runtime surfaces.
No. Cyber deception adds an exploit-independent, high-confidence signal to the existing security stack. Its value is greatest when its alerts feed investigation, containment, and response workflows already operating through SIEM, EDR, XDR, IAM, PAM, and incident response platforms.
During U.S. Navy ANTX FY25, Acalvio’s ShadowPlex deployment generated 100% true-positive alerts, meaning every alert corresponded to confirmed malicious activity. It also denied approximately 80% of attacker objectives within the exercise environment, demonstrating both alert fidelity and meaningful operational disruption.