N-day is Becoming N-Hour. Patching Faster Won't Save You.
The traditional playbook for patching security vulnerabilities is no longer effective due to the rapid advancement of AI-powered exploit tools. Researchers have found that they can now turn a patch into a working exploit in under an hour, making it difficult for defenders…
Intelligence analysis by Llama

The rapid advancement of AI-powered exploit tools has made it difficult for defenders to keep up with patching security vulnerabilities. The traditional playbook is no longer effective, and defenders must adapt to this new reality.
Imagine you're trying to fix a bug in a computer program. But instead of just fixing the bug, a special tool can use the fix to create a way to break into the computer. This is called an exploit. The problem is that this tool can now create an exploit in under an hour, which makes it hard for the people trying to fix the bug to keep up. It's like trying to catch a speeding bullet.
Analysis
The Rise of N-Hour Exploitation
The traditional playbook for patching security vulnerabilities has been turned on its head by the rapid advancement of AI-powered exploit tools. For the last thirty-odd years, defenders have usually been able to outpace attackers in the race to deploy patches and fix vulnerabilities. However, with the emergence of tools like Claude Mythos Preview, this is no longer the case.
Claude Mythos Preview is a model that can turn a patch into a working exploit in under an hour. This is a significant shift from the traditional approach, where reverse-engineering a patch into a reliable exploit was slow, specialized work that required weeks of expert-level effort. The gap between a patch and a working public exploit has shrunk from weeks to hours, making it difficult for defenders to keep up.
The impact of this shift is significant. With roughly 135 new CVEs a day, defenders are facing a backlog where everything scores 9.8, effectively prioritizing nothing. The question is no longer 'what's vulnerable?' but 'which exposures can an attacker actually exploit here, would our controls stop the attempt, and can we prove it?' Validation doesn't make you patch faster; it makes patch speed matter less.
The Post-Mythos Action Plan
So, what can defenders do to adapt to this new reality? The answer lies in validating exploitability, rather than assuming it. This can be done through three methods: firing a real exploit where it's safe to do so, proving against controls instead of firing an exploit, and testing each component against real conditions before a live launch. By taking these steps, defenders can close the gap between patching speed and exploitability, and stay ahead of the attackers.
Conclusion
The shift in the way exploits are created and used has significant implications for security defenders. By prioritizing validation over patching speed, defenders can stay ahead of the attackers and keep their systems secure. It's time to adapt to the new reality of N-hour exploitation and take the necessary steps to stay ahead of the game.
Key points
- The traditional playbook for patching security vulnerabilities is no longer effective due to the rapid advancement of AI-powered exploit tools.
- Claude Mythos Preview is a model that can turn a patch into a working exploit in under an hour.
- Defenders must prioritize validating exploitability over patching speed to stay ahead of the attackers.
- The shift in the way exploits are created and used has significant implications for security defenders.
- By prioritizing validation over patching speed, defenders can stay ahead of the attackers and keep their systems secure.
By prioritizing validation over patching speed, defenders can stay ahead of the attackers and keep their systems secure. This means that even if an exploit is created, defenders can be confident that their controls will stop the attempt and that they can prove it.
The shift in the way exploits are created and used has significant implications for security defenders. If they don't adapt to this new reality, they risk being left behind by the attackers, who will continue to find new ways to exploit vulnerabilities.



