Cybersecurity vendors ride Mythos-inspired spending wave
Anthropic CEO Dario Amodei may be the best marketer for cybersecurity software in the industry's history. You simply can't have a cybersecurity earnings call without talking about the "Mythos moment" and the reality that AI agents can wreak havoc on enterprise infrastructure.
The Mythos moment refers to Anthropic's Mythos model, which could find vulnerabilities at AI speed. Anthropic limited the release of Mythos, now on Mythos 5.1, to vetted partners and customers. Since the Mythos launch, OpenAI agents attacked Hugging Face and frontier labs are scrambling to come up with better safeguards to keep their creations in check. Toss in new models that are open to everyone and the cybersecurity landscape has shifted in a hurry.
- Fable 5 and the Shift From Model Capability to Capability Governance
- Claude Mythos and the New Cybersecurity Operating Model
Turns out that havoc, which has now evolved to include a disparate large language model landscape featuring open-weight models, is good for business.
Palo Alto Networks CEO Nikesh Arora summed it up:
"I've strived for 8 years to try and get CEOs interest in cybersecurity. I couldn't, but Dario did a phenomenal job by having Mythos. Because every CEO now wants to talk about what does this mean to us. How do we get access to it? How do we test ourselves from a vulnerability perspective?"
Arora said enterprises are looking to shed cybersecurity tech debt. Not surprisingly, this shift plays into Palo Alto Networks platformization pitch. Mythos started the urgency push for security and open models are just accelerating it. Indeed, OpenAI recently published a technical report on the Hugging Face attack and what its plans are to prevent it from happening again.
- OpenAI: We'll hit pause on model reinforcement learning for safety
- UK's AISI finds 19 instances where Anthropic's Mythos, OpenAI's GPT-5.6 Sol tried attacks
- Anthropic said Claude hacked three companies: Real worry or marketing?
- Hugging Face OpenAI attack postmortem points to lack of AI agent visibility
- OpenAI details how its models went rogue, attacked Hugging Face
- Hugging Face defends agentic AI attack with Z.ai's GLM 5.2
"Open source models are now already able to compete with the capabilities of Mythos. And this thing is going to get better, not worse. If that happens, and this capability becomes commonplace, we have a short window by when to get all the cybersecurity technical debt which hasn't been paid over many years back to -- up to the mark," said Arora, who even included a handy slide to note the shifts.
But Arora is just the latest CEO of a cybersecurity company basking in the Mythos marketing moment.
CrowdStrike CEO George Kurtz mentioned Mythos 11 times on the company's second quarter earnings call. "When we last spoke, we were just weeks after what we called the Mythos moment, an inflection point in cybersecurity. The world came to understand that cybersecurity is a necessity for AI adoption. New models created a new risk environment with no turning back. Recently, this realization became even clearer with the market's newest adversary, AI agents themselves," said Kurtz. "We told you this was the future, and this future is now a reality."
Kurtz added that Mythos has juiced CrowdStrike's annual recurring revenue. AI transformation requires a new platform, presumably CrowdStrike's Falcon, which creates the data flywheel needed to handle all the cybersecurity workflows.
Cybersecurity has now become a CEO discussion and first quarter urgency about Mythos has turned into more spending. "Customers want to deploy more AI, but they're being held back because of security, compliance, privacy, data protection type issues. So every customer that we talk to is concerned about the agentic threats," said Kurtz.
Other cybersecurity CEO quotes to note:
Rubrik CEO Bipul Sinha: "What is fascinating to us is that the scale of productivity that AI create is matched only by the scale of new risks that AI spawns. Mythos and Frontier AI models are proving it every day," said Sinha. "If you have yesterday's cybersecurity tools with human speed response, you have a huge mismatch. And at the same time, AI agents are increasingly running business processes, workflows that assume identities, access sensitive data and take autonomous action. Both threat actors and business operators are now agentic."
Elastic CEO Ashutosh Kulkarni: "People are really worried about what it means to protect your environment, protect your agencies and so on in a post-Mythos world. And it's not just Mythos. There are so many very, very capable models out there, not just commercial models, but open source models that give you the ability to really discover vulnerabilities and then act upon them. You have to assume that people who are trying to do harm now have the ability to access these models. So defenders are having to move faster."
Cisco CEO Chuck Robbins: "When we think about Mythos, we think about customers doing analysis right now on their LDOS or their last day of support footprint, products that can't be patched. We believe this is going to drive this super cycle for a while to come."
While cybersecurity executives are talking Mythos, they are also emphasizing that demand is sustainable over time. Retooling cybersecurity architecture for agentic AI will take time. Wall Street analysts frequently questioned whether the Mythos cybersecurity pop was sustainable.
"Recent market shifts, or what many are calling cybersecurity's Mythos moment, are refocusing enterprise boardrooms on systemic AI security. While these structural shifts create tailwinds for our business, it's important to note that modernizing cybersecurity infrastructure and enterprise budget deployments are multi-quarter and multi-year shifts that materialize over time," said SentinelOne CFO Sonalee Parekh.