Fable 5 Shipped. The Exploit Window Is Negative.

Table of contents

Launch Day

Anthropic shipped Claude Fable 5 today. It is the first Mythos-class model available to the public, state of the art on nearly every benchmark, priced at less than half of what Mythos Preview cost. Stripe used it to compress a two month migration of a 50 million line Ruby codebase into a single day. For a small circle of cyberdefenders, the unrestricted twin, Mythos 5, went live through Project Glasswing.

Full disclosure: this post was researched and drafted with Fable 5, on its launch day. The tool writing about the fork in the road is part of the fork in the road. Sit with that for a second.

Because that is what this is. Not another model release. A fork in the road, and not just for the AI industry. Before the launch celebration drowns it out, somebody needs to do the math out loud.

The Slowdown Ask

Five days before shipping its most capable model ever, Anthropic said it would be good for the world to have the option to slow or temporarily pause frontier AI development, so that societal structures and alignment research can catch up. The company flagged recursive self improvement as the risk that keeps it up at night. Claude now writes more than 80% of the code in Anthropic's own codebase. Engineers there absorb eight times as much merged code per day as they did two years ago.

Read those two sentences together. We may need the option to pause. Also, here is Fable 5, cheaper and stronger than anything that came before it.

I want to be fair about the logic, because it is not as hypocritical as it first sounds. Anthropic explicitly said a unilateral pause by one company does nothing. A credible slowdown needs every well resourced lab, across multiple countries, stopping under the same conditions, with mutual verification. That is true. It is also conveniently unfalsifiable. You get to keep shipping at full speed while holding the moral high ground of having asked for a pause you know cannot be coordinated. The ask costs nothing. The release pays the bills, with an IPO reportedly on the horizon.

Here is my brutal take: the slowdown request is directionally right and strategically free. Judge the company by what it ships, not by what it wishes for. And what it shipped today is the most capable exploit discovery engine ever made available to the public, wrapped in safeguards that trigger in less than 5% of sessions.

The Numbers That Should Keep You Up at Night

While we debate whether labs should slow down, the offense side already finished the race.

Google's M-Trends 2026 puts the mean time to exploit newly disclosed vulnerabilities at negative seven days. Negative. Exploitation now typically happens a week before a patch exists. I watched this dynamic up close at Pwn2Own Berlin, where AI assisted exploit chains were already outpacing every human timeline in the room. In 2018 defenders had 63 days. In 2024 the metric crossed zero. The median time from disclosure to first observed exploitation collapsed from 771 days in 2018 to single digit hours by 2024, and by 2025 the majority of exploits were weaponized before public disclosure. Sergej Epp's Zero Day Clock now puts average time to exploit under 20 hours. CISA is reportedly considering cutting its default KEV remediation window from two weeks to three days, an admission that the old patch cycle is dead.

Against that, the defensive reality: the average enterprise patch cycle is still measured in weeks or months. A high or critical severity bug found by Mythos Preview takes two weeks to patch on average, and that is with Anthropic and six security firms doing the triage. Attackers operate at machine speed. Defenders operate at calendar speed, with change windows, compliance reviews, and business continuity constraints. The asymmetry is not new. The magnitude is.

One documented case makes it concrete. A threat actor ran their own LLM behind a custom MCP server as part of an autonomous attack chain and compromised 2,500 organizations across 106 countries in under an hour. This is the same playbook I broke down in the supply chain worm teardown and the GitHub breach analysis: automation does the breaking in, humans just collect. Initial access, credential dumping, exfiltration, all autonomous. The only human involvement was checking the results afterward.

Bad Actors Already Have the Keys

The safeguards conversation has a quiet assumption baked in: that capability stays where it is put. It does not.

Cisco tested eight major open weight models with multi turn jailbreak attacks and succeeded 93% of the time. Safeguards on open weight models can be fine tuned away by anyone with a GPU and a weekend. Open weight models are closing the gap to the frontier, which means Mythos-grade vulnerability discovery is on a conveyor belt toward everyone, including the people Glasswing exists to defend against. Google's threat intelligence team has already documented a zero day exploit believed to be developed with AI, intended for a mass exploitation event, caught only because defenders found the same bug first.

Anthropic's own warning is the most honest sentence in this whole story: within 6 to 12 months, many other AI companies will have Mythos-class models, and they could release them without safeguards. That is the actual clock. Not the safety roadmap of the most careful lab. The release schedule of the least careful one.

Glasswing Does Not Cover You

Project Glasswing is genuinely impressive work and I will not pretend otherwise. Roughly 50 launch partners, expanded last week by about 150 organizations across more than 15 countries. Over 10,000 high or critical severity vulnerabilities found. Cloudflare found 2,000 bugs across critical path systems. Mozilla found 271 vulnerabilities in Firefox 150, over ten times what the previous model managed. The wolfSSL certificate forgery exploit alone probably protected billions of devices.

Now the other column of the ledger. Glasswing covers roughly 200 organizations. There are hundreds of millions of companies on Earth. The program is built around the most systemically important software, which is the right triage call, but it means everything below that line, the mid market ERP system, the regional hospital network, the municipal water utility running a ten year old SCADA stack, gets nothing except advice to patch faster.

And patching is exactly where the whole thing falls over. I tracked Anthropic's disclosure pipeline in detail in my teardown of the Mythos disclosure ledger, and the numbers have not improved since. According to Anthropic's own update, of the 530 high or critical open source bugs disclosed so far, 75 have been patched. Picus puts the overall figure at fewer than 1% of Mythos findings patched. Open source maintainers, the unpaid individuals whose code runs banks and hospitals, are so overloaded that some have asked Anthropic to slow down its disclosure rate. Sit with that irony: the company that asked the industry to slow down is itself being asked to slow down by the people drowning in its findings. The Open Source Security Foundation has questioned why discovery funding outweighs remediation funding 25 to 1, when remediation is the actual bottleneck.

Discovery is no longer the problem. Mythos made finding bugs nearly free. Fixing them still costs what it always cost: human attention, testing, deployment, and risk. Glasswing industrialized one half of the pipeline and left the other half running on volunteers and goodwill.

The Fork in the Road

So here is where we actually stand on June 9, 2026.

The exploit window is negative. The patch pipeline is saturated. The unrestricted model is in the hands of 200 defenders while jailbroken open weight equivalents are 6 to 12 months from being everywhere. The company leading the field says the world may need a pause, ships anyway, and is honest enough to admit its safeguards are a stopgap until competitors release without any.

The fork is not between safe AI and dangerous AI. That choice was never on the menu. The fork is between a world that rebuilds its defensive infrastructure at machine speed and a world that keeps running calendar speed processes against machine speed attackers.

If I ran a software company today, I would do three things this quarter, not this year. First, treat patch deployment as the metric that matters: time from advisory to deployed fix, measured in hours, because CISA's three day window will look generous soon, and as I covered in the June legislation update, regulators are moving toward mandating exactly this kind of operational discipline. Second, run frontier models against my own code before someone else does, because the scan is happening either way and the only variable is who reads the report first. Third, fund the open source dependencies my stack lives on, because the maintainer triaging my transitive dependency's RCE for free is the single most leveraged security spend that exists.

Fable 5 is a genuinely remarkable tool. It drafted this post and it could probably find a bug in your codebase before you finish reading it. That sentence should excite you and scare you in equal measure. The arrival is real. So is the math. And the math says most of the world is standing on the unprotected side of the fork.

Stay in the loop New teardowns and guides, straight to your inbox. No spam.
↓ Download carousel