{"id":44168,"date":"2026-05-19T15:20:10","date_gmt":"2026-05-19T15:20:10","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/44168\/"},"modified":"2026-05-19T15:20:10","modified_gmt":"2026-05-19T15:20:10","slug":"analysis-amid-claude-mythos-fud-dont-forget-about-identity","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/44168\/","title":{"rendered":"Analysis: Amid Claude Mythos FUD, Don\u2019t Forget About Identity"},"content":{"rendered":"<p>While updating your patching practices will be essential, preventing attackers from fully utilizing vulnerabilities will require identity hardening as well.<\/p>\n<p>            <img decoding=\"async\" loading=\"lazy\" alt=\"\" src=\".\/media_19951db4020933cdf05c40076bf5f723788049e12.png?width=750&amp;format=png&amp;optimize=medium\" width=\"611\" height=\"458\"\/><\/p>\n<p>In all likelihood, the security conversation will continue for some time to be dominated by the rise of AI-discovered vulnerabilities and exploits, and the near-panic-level responses that have ensued.<\/p>\n<p>But the existence of powerful AI vulnerability discovery technologies such as Anthropic\u2019s <a href=\"https:\/\/www.crn.com\/news\/security\/2026\/how-cisos-need-to-prepare-for-the-claude-mythos-era-of-cyberattacks-experts\" rel=\"nofollow noopener\" target=\"_blank\">Claude Mythos<\/a> doesn\u2019t mean that patching will be the whole answer\u2014far from it.<\/p>\n<p>[Related: <a href=\"https:\/\/www.crn.com\/news\/security\/2026\/the-20-hottest-ai-cybersecurity-companies-the-2026-crn-ai-100\" rel=\"nofollow noopener\" target=\"_blank\">The 20 Hottest AI Cybersecurity Companies: The 2026 CRN AI 100<\/a>]<\/p>\n<p>From my recent conversations with security experts and solution providers, it\u2019s clear that updating your organization\u2019s practices will be essential, obviously. But that\u2019s only as a first step.<\/p>\n<p>However, preventing attackers from fully utilizing vulnerabilities will require identity hardening as well, among other measures.<\/p>\n<p>Even though AI-discovered vulnerabilities have already been increasing for years, exploitation of software flaws is \u201cstill not the most accessed ingress vector for an attack,\u201d Darktrace\u2019s Nicole Carignan told me. \u201cThat really still lies in identity.\u201d<\/p>\n<p>In particular, identity is still a crucial area of concern due to the fact that, with modern IT architectures, \u201cwe\u2019re tying so much to the identity control plane,\u201d said Carignan, senior vice president of security and AI strategy at Darktrace, which is based in Cambridge, U.K., but has numerous office in the U.S. and Canada.<\/p>\n<p>In other words: Don\u2019t forget about identity.<\/p>\n<p>Without a doubt, for many companies, patching has long been one of the most vexing security challenges. And there is little reason to doubt that AI is going to make that problem much more urgent.<\/p>\n<p>But even with all the FUD (fear, uncertainty and doubt) around Mythos and similar technologies, de-prioritizing identity would be a shortsighted move, according to solution and service providers.<\/p>\n<p>That is, the increase in cyber risk from the widespread adoption of AI\u2014including by threat actors looking to exploit vulnerabilities\u2014is unquestionably going to be about more than just exposure management.<\/p>\n<p>\u201cIt\u2019s one of the more robust cross-domain narratives that we\u2019ve seen,\u201d Blackwood\u2019s Chris Ebley told me.<\/p>\n<p>Organizations are trying to figure out how to take action to counter the rise in risk, but \u201caction for a lot of these things is going to be an identity conversation\u2014the permissioning and provisioning side of things, removal of entitlements\u2014making sure that you don\u2019t have [identity] risk that is exposed,\u201d said Ebley, CTO at Annapolis, Md.-based Blackwood, No. 93 on CRN\u2019s <a href=\"https:\/\/www.crn.com\/sp-500\/sp2025\" rel=\"nofollow noopener\" target=\"_blank\">Solution Provider 500<\/a> for 2025.<\/p>\n<p>The bottom line is that identity remains one of the most important areas for organizations to modernize in the Claude Mythos era, especially as they simultaneously adopt agentic AI systems.<\/p>\n<p>For solution and service providers, that means the opportunity is not just helping customers respond faster to vulnerabilities. It also means helping organizations to harden their identity systems and improve access controls, as well as to implement zero-trust segmentation and other compensating controls.<\/p>\n<p>Without a doubt, the channel opportunity ahead is massive in identity, as it has been for a number of years now, according to GuidePoint Security\u2019s Mark Thornberry.<\/p>\n<p>\u201cIdentity has been one of our biggest areas of focus and growth as a company. It\u2019s our largest single practice that we have at GuidePoint,\u201d said Thornberry, senior vice president for partnerships at Herndon, Va.-based GuidePoint, No. 37 on CRN\u2019s 2025 Solution Provider 500.<\/p>\n<p>Even before the advent of LLMs, identity was already a highly convoluted and confusing space for many customers, he noted.<\/p>\n<p>Ultimately, \u201ccustomers just have to do something there\u2014they\u2019ve had to do it for years,\u201d Thornberry said.<\/p>\n<p>GuidePoint kicked off its identity practice in 2020 and, given the surging needs among customers, \u201cit just continues to expand,\u201d he said. \u201cThere\u2019s a huge opportunity there. Obviously AI is [top of mind]. But identity keeps us really busy.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"While updating your patching practices will be essential, preventing attackers from fully utilizing vulnerabilities will require identity hardening&hellip;\n","protected":false},"author":2,"featured_media":44169,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[8],"tags":[24,405,408,53,3154,399,25,182,313,9954,223,400,401],"class_list":["post-44168","post","type-post","status-publish","format-standard","has-post-thumbnail","category-anthropic","tag-ai","tag-ai-agents","tag-ai-applications","tag-anthropic","tag-anthropic-claude","tag-application-and-platform-security","tag-artificial-intelligence","tag-claude","tag-cybersecurity","tag-endpoint-security","tag-generative-ai","tag-managed-security","tag-managed-service-providers"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/44168","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=44168"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/44168\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/44169"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=44168"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=44168"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=44168"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}