One Identity on Mythos, Fable and what they mean for your identity controls

Mythos changes the speed of attack. Identity controls decide what happens after. 

The shift underway 

For the first time in 19 years, vulnerability exploitation now leads the Verizon Data Breach Investigations Report as the breach entry point. It accounts for 31 percent of incidents, ahead of stolen credentials. Threat actors are using AI to exploit known vulnerabilities in hours rather than months. The Verizon data predates the latest frontier AI advancements.  

Anthropic launched Mythos in April through Project Glasswing. Access went to a small group of customers. In June, Anthropic unveiled Claude Fable 5, a general release version with safeguards, available to enterprise customers. 

Both defenders and attackers benefit. Defenders move at organizational speed. Attackers move at the speed of the tooling. Most security operations are still running on the old clock. 

What this means for your environment 

Mythos and Fable shorten the window between a vulnerability being discovered and being weaponized. Standing privilege is the multiplier that turns that compressed timeline into a blast radius. What an attacker inherits when they get in determines how much damage they can do. 

The threat is hard to escape. Fable 5 has safeguards that block cybersecurity prompts. Mythos is the same model without those safeguards and is already in more than 150 Glasswing organizations. Direct adoption is not the only exposure path either. Any vendor in your ecosystem can deploy Fable 5 or a similar model overnight. You inherit the risk whether you adopt it or not. 

The work with the highest returns is the work that most organizations shortchange: reducing standing privilege, governing non-human and AI-agent identities, and tightening privileged access controls. 

What One Identity is doing 

We treat Mythos and Fable as priorities. Our work falls into two areas. 

Product readiness 

Safeguard by One Identity supports just-in-time privileged access by design. It vaults your most sensitive credentials. It grants session-recorded access only when needed. Customers operate with less standing privilege from the start. The lower your standing privilege footprint, the less an attacker inherits if they get in. 

Active Roles by One Identity governs your Microsoft directory environments, including Active Directory, Entra ID and AD LDS. It enforces delegation policy, automates provisioning and deprovisioning, and produces a clean audit trail. It works across multiple forests and tenants. 

Identity Manager by One Identity provides governance and visibility across human and non-human identities. That includes AI agents and service accounts. Certifications and lifecycle controls help prevent your attack surface from growing quietly. We also apply predictive AI to detect risk in agentic AI and automated systems. 

Our customers depend on our products. We are testing each product against the threat models Mythos enables. We are prioritizing what matters most for containment. 

We are also reviewing and adjusting all our internal processes to make us more responsive and agile. Our engineers use AI to keep delivery speed in step with the threat. That work affects our security engineering, release pipelines and customer communications.  

Engagement with Mythos and Glasswing 

One Identity has requested participation in Project Glasswing for direct access to Mythos. More than 150 organizations across 15+ countries participate, including the US government. In June, Anthropic released Claude Fable 5 with the same capabilities. Any enterprise customer can buy Fable 5 directly. We are using it now. We work with AI partners, including Anthropic and Microsoft, and regularly use their models across our R&D operations. Our goal is to stay ahead of what Mythos changes. 

Where this goes next 

No vendor can predict how Mythos and Fable will play out. But the controls that mattered before now matter more: less standing privilege, cleaner identity hygiene, faster containment when something goes wrong. That work is what we have helped customers build for years. 

One Identity covers Active Directory, Entra ID, Unix, Linux and SaaS from one platform. Privileged access management, identity governance and Microsoft directory governance are built in. When the next vulnerability surfaces, that breadth is the difference between a coordinated response and a scramble across vendors. 

Reach out to your One Identity account team if you want to go deeper on what this looks like in your environment. 
 
 
 
 
 
 
 
 
All trademarks are the property of their respective owners. 

Anonymous
Related Content