
New Echo research shows that the vulnerabilities attackers actually exploit are rarely the ones AI just found; they're the ones organizations already knew about. Echo's readiness framework maps how organizations can effectively prepare.
NEW YORK, Sept. 3, 2026 /PRNewswire/ -- Echo, the company securing the software supply chain at its source, today released its Mythos Readiness Report, a data-driven look at how AI is reshaping software supply chain risk and why the industry's defining bottleneck has quietly shifted from finding vulnerabilities to acting on them.
The report combines Echo's own platform telemetry, a year-long study of nearly 40,000 CVE lifecycles across 250 widely used open source container projects, and survey responses from more than 80 security leaders across the United States with an independent analysis of Anthropic's Claude Mythos, the frontier model whose vulnerability-discovery and exploit-development capabilities have drawn intense industry attention since its introduction earlier this year.
The findings suggest AI has clearly changed the economics of offensive security. On Anthropic's own benchmark, exploit success against a known set of Firefox vulnerabilities increased roughly 90-fold between consecutive model generations, and Anthropic has demonstrated that turning a known vulnerability into a working exploit can now cost less than $2,000 and take under a day. However, Echo researchers found that of the 27 vulnerabilities Anthropic has publicly disclosed, only one of the eight findings Mythos originally rated "Critical" held up under independent review, and fewer than 10% of the model's 23,019 candidate findings have undergone any external validation at all.
"AI hasn't just made it faster to find a vulnerability; it's made it faster to be wrong about one," said Eylam Milner, CTO of Echo. "The industry has spent years optimizing for detection. This report shows that detection is no longer the constraint. It's judgment, and it doesn't scale the way model inference does."
That imbalance shows up beyond Mythos itself. In fact, CVE counts have grown 145% in two years, and Echo's research found that 89% of known vulnerabilities already have a fix available, meaning the real gap is propagation. Roughly 40% of fixable vulnerabilities remain unresolved for more than six months, and most successful attacks don't exploit new disclosures at all. Among vulnerabilities that do get exploited, roughly three in four are weaponized after their first day of public disclosure – often weeks, months, or years later, against fixes that already existed.
Echo's survey of security leaders reinforces the same conclusion from the defender's side: 37% cited "detecting more than we can fix" as their organization's single biggest obstacle to improving software supply chain security, while only 11% said additional detection or scanning would be their next investment priority.
"The story everyone wants to tell about AI and security is about killer new exploits," said Mor Weinberger, Echo Architect. "But the more interesting story is that most of what gets exploited was never a mystery in the first place. Organizations already knew about it, they just hadn't addressed it yet."
The report introduces a four-stage readiness framework: Exposed, Aware, Responsive, and Proactive, which organizations can use to assess how far their security posture has actually progressed from detection toward protection, along with a short self-assessment. Echo's research suggests most organizations sit in the second stage, where visibility has outpaced the ability to act on what's found.
The full report, including Echo's independent analysis of Claude Mythos, the CISO survey results, and the readiness framework, is available now at echo.ai/link-to-report.
About Echo
Echo is creating the trusted source for agentic-ready software. Rather than scanning for vulnerabilities after they've entered an environment, Echo replaces the supply itself – providing continuously vetted, hardened, and maintained versions of the open-source containers, libraries, VMs, and OS packages organizations already rely on. Every artifact Echo delivers is screened for malicious code, patched against known vulnerabilities, and shipped as a drop-in replacement for what teams would otherwise pull directly from public registries. To date, Echo has screened more than 24 million package versions, blocked more than 3,000 malicious packages before they reached customers, and eliminated more than 1.5 million known vulnerabilities across the artifacts it maintains. Learn more at echo.ai.
SOURCE Echo Software Inc.
Share this article