When a new CVE drops, getting notified is the easy part. The real challenge comes right after. Depending on how your organization is set up, different teams have to scramble to figure out if you're actually using the affected product, which specific versions are exposed, whether it's lurking anywhere in your subsidiaries or vendor ecosystem, and how urgently you need to patch it. At the same time, attackers are running through the exact same math, except their job is much simpler: they just need to find one viable path that gets them closer to their target. In the post-Mythos era, AI is helping threat actors find those entry points at a high scale.
While Mythos Preview isn't widely available yet, it clearly demonstrated how quickly frontier AI can bridge the gap from vulnerability discovery to working exploits. But Mythos is not the only platform capable of exploiting vulnerabilities. Other models have already caught up and, on some vulnerability research and exploitation tasks, surpassed what Mythos has demonstrated. Anthropic’s September 2026 threat intelligence report shows that attackers are already doing this without access to Mythos-class models. Anthropic observed threat actors using Claude Haiku, Sonnet, and Opus to run vulnerability research and exploit development workflows in parallel. The risk isn’t limited to what the newest models may eventually enable. Attackers are already using existing models to expand the speed and scale of attacks.
For attackers, that can mean faster software analysis, patch comparison, reconnaissance, and part of exploit development. Mythos and similar models can help attackers pursue several possible attack paths at once and change the scale of the problem for defenders. It still does not make every CVE a drop-everything crisis; it heavily depends on whether threat actors are actively exploiting it, whether you use the affected product, and how the vendor prioritizes it.
Attackers still weigh the pros and cons, balancing ease of exploitation and expected payoff against their chances of getting caught. But when they do decide to act, AI gives them a serious speed boost. That means defenders need to shrink their own response times, too.
For Bitsight, part of the solution is using AI to accelerate product fingerprinting. Product fingerprinting means identifying the product (and where possible the version) behind an internet-facing service using the technical clues it exposes. We can then apply those fingerprints across our internet-wide observations to uncover likely exposure across your own footprint and extended ecosystem.
Bitsight and AI fingerprinting
BItsight is using AI to create product fingerprints faster and at scale. These fingerprints give defenders a head start when a new vulnerability is disclosed. Creating a vulnerability-specific detection signature in as little as 31 minutes is impressive, but it only starts the process. That test still has to be run across potentially affected systems at internet scale. The results then need to be analyzed and connected back to the organizations, subsidiaries, and suppliers that may be exposed. Understanding the internet-wide supply chain impact takes longer than generating the test itself. With attackers moving faster, defenders cannot afford to wait for that entire process before they begin looking for exposure.
This is where continuous fingerprinting comes into play. Bitsight continuously looks for products and versions across the public internet. If one of those products is later found to be vulnerable, we can use the observations we already have to quickly identify where it may be exposed. When the CVE drops, the product search is already underway. Some systems may appear to be running an affected product or version but turn out to not be vulnerable because of a backported patch, a different configuration, or other security controls. Even so, the fingerprint gives SOC and GRC teams a fast way to understand the likely scope of the problem and immediately investigate the most critical internet-facing systems.
Bitsight also runs vulnerability-specific scans that can look more closely at whether the vulnerable condition is present and appears exploitable. These scans raise confidence, filter out some of the initial noise, and turn a broad exposure list into a manageable set of findings. Fingerprinting provides the speed and coverage needed to get ahead of the problem, while vulnerability scans provide the additional confidence needed to narrow it down. As frontier AI enables threat actors to move faster, defenders need to move faster too.