N-days \ red.anthropic.com
Winnie Xiao, Tim Abbott, Nicholas Carlini, Newton Cheng, David Forsythe, Keane Lucas, Milad Nasr, and Shikhar Sakhuja For the last few months, we’ve been writing about large language models’ cybersecurity capabilities. For the most part, we’ve focused on zero-days—vulnerabilities that are unknown to the software’s maintainers. But a large fraction of real-world harm comes from N-days: vulnerabilities that have already been publicly disclosed, but only patched on some devices. Attackers exploit the many systems that haven't yet applied the patch, during what’s known as the “patch gap.” In some ways, N-days are the more dangerous of the two, because the patch itself provides a roadmap to the bug. Once software vendors publish their security updates, attackers can “patch diff”: compare the pre-patched source code or binary against the new one to locate exactly what changed, and then reverse-engineer the vulnerability that the patch was meant to fix. This means that a working exploit is of
Frontier Red Team Measuring LLMs’ impact on N-day exploits Jun 8, 2026 Winnie Xiao, Tim Abbott, Nicholas Carlini, Newton Cheng, David Forsythe, Keane Lucas, Milad Nasr, and Shikhar Sakhuja For the last few months, we’ve been writing about large language models’ cybersecurity capabilities. For the most part, we’ve focused on zero-days—vulnerabilities that are unknown to the software’s maintainers. But a large fraction of real-world harm comes from N-days : vulnerabilities that have already been publicly disclosed, but only patched on some devices. Attackers exploit the many systems that haven't
Explore this link on the map →saved by
related reading
- Assessing Claude Mythos Preview’s cybersecurity capabilities \ Anthropicred.anthropic.com
- Project Glasswing: Securing critical software for the AI era \ Anthropicanthropic.com
- Nicholas Carlininicholas.carlini.com
- Measuring LLMs’ ability to develop exploits \ Anthropicred.anthropic.com
- Vulnerability Research Is Cooked - Quarrelsomesockpuppet.org
- Claude Mythos Preview System Cardwww-cdn.anthropic.com
- LLM-discovered 0 days \ Anthropicred.anthropic.com
- Security incident disclosure — July 2026huggingface.co
- Cybersecurity Looks Like Proof of Work Nowdbreunig.com
- What I learned this week - Can distillation be stopped, Mythos and the cybersecurity equilibrium, Pipeline RLdwarkesh.com
- Mythos finds a curl vulnerability | daniel.haxx.sedaniel.haxx.se
- From Naptime to Big Sleep: Using Large Language Models To Catch Vulnerabilities In Real-World Code - Project Zerogoogleprojectzero.blogspot.com