What if AI just found the biggest security risk in your old business system?

Rappit - Profile Picture _ Huibert de Vries
Written by Huibert de Vries - 31 July 2026

Why Claude Mythos is the end of the old way to deal with legacy 

For a long time, legacy enterprise systems have survived on a quiet assumption: they may not be perfect, but they are manageable. Let’s not touch them now.

They run critical business processes. They are optimized for unique operations. They’ve been tested over time. And while vulnerabilities exist, as they always do, the belief has been that with enough patching, monitoring, and control, the risk can be contained.

Claude Mythos disrupts that assumption.

What changed

AI company Anthropic recently unveiled Project Glasswing, an initiative centered on their unreleased AI model, Claude Mythos Preview. Mythos can identify vulnerabilities in software systems almost instantly and generate working exploits to take advantage of them without human input.

What makes this moment so significant is not just the capability itself, but also what it uncovered. The model found a 27-year-old bug in OpenBSD, an operating system,  despite 27 years long extensive testing and scrutiny of this system. 

It’s not that these bugs appeared out of thin air, they were always hiding in the woodwork. What changed is that they are now easy to find. Everyone will be handed a high-powered flashlight to find them.

The discussion around Anthropic’s Claude Mythos has mostly focused on whether the company did the right thing by not releasing it. With the press coverage being dominated by the technical detail of the zero-day exploits, and the vulnerabilities discovered. 

That’s the wrong discussion and the wrong question. For Business and IT leaders, the only question that matters is this:

What happens to our outdated business systems, and business, when AI models with these capabilities become widely available?

Because they will soon. And it has huge consequences. 

Moving at two different speeds

We witness humans and AI moving at a different speed. 

On one side, vulnerability discovery is accelerating rapidly. AI can now scan, reason about, and exploit enterprise software at machine speed. In controlled testing, Mythos was even able to complete complex multi-step cyberattack simulations, something no previous model could reliably achieve.

On the other side, enterprise reality hasn’t changed nearly as fast.

The average organization still takes over 250 days to fix a vulnerability, and many carry significant backlogs of unresolved issues, often referred to as security  or technical debt.

At the same time, fewer than 1% of vulnerabilities identified by Mythos had been patched early in testing, and the vast majority of organizations, around 82, are carrying security debt, with unresolved issues lingering for months or even years. Increasingly, many of these aren’t minor flaws but high-risk, exploitable vulnerabilities sitting in production environments.

This creates a widening gap. One side is operating at AI speed, increasing the speed at which vulnerabilities can be found and exploited. The other side is constrained by human speed, architecture, process, and complexity on how fast issues can be resolved. 

Legacy systems were not built for today’s reality

It is tempting to see this as a tooling problem, something that can be addressed with better security. But the issue runs deeper.

Legacy systems like your ERP, WMS, OMS or TMS were designed for a different environment. A world where change was slower, systems were more isolated, and threats evolved gradually. In that context, tightly coupled architectures and long release cycles were acceptable trade-offs.

Around 62% of organizations still run legacy enterprise applications in production, often at the core of their operations. Relying on systems that include end-of-life components, unsupported technology frameworks, or deeply embedded dependencies. Once support ends, any newly discovered vulnerability effectively becomes permanent, there is no patch coming.

The result is a growing accumulation of risk that cannot be easily reduced, not because teams don’t want to, but because the systems themselves resist change.

The old way has reached its limits

Enterprises managed legacy systems through incremental improvement for decades. They patched vulnerabilities as they appeared. They layered additional security controls. They postponed major changes in favor of stability. That approach depended on time. Time to detect issues. Time to respond. Time to fix.

AI removes that buffer.

When vulnerabilities can be discovered and exploited in near real time, the way of working of “patch and wait” breaks down. As noted by Forrester, “Like the COBOL crisis brought on us by Year 2000 projects, vulnerabilities found in aging OSes and systems will require the knowledge of folks who built those systems decades ago. Claude Code (and other models) are good at writing greenfield software, but may not be as effective at patching ancient code without breaking things.” 

Systems that cannot adapt quickly are no longer just inefficient, they are increasingly indefensible, and hence a security and business risk. 

Old systems just can’t keep up with the new AI pace. 

A new way forward

Modernization is not just about cloud migration or cost efficiency. It is about (re)building core enterprise systems that can respond at the same speed at which risks emerge.

That requires systems that are AI-native, continuously adaptable, and that stay “Forever Young”, without technical and functional debt. 

But it also requires that AI must become part of the solution.

The same capabilities that make models like Mythos powerful in the hands of attackers can be used to transform how organizations modernize, build, maintain, evolve and secure their core systems.

From legacy liability to leading edge

We need a new way of building and evolving the systems. A new approach that combines speed and agility, while reducing risks. This is where Rappit’s AI-led platform and agentic modernization blueprint comes in. Instead of simply “lifting and shifting” outdated applications into the cloud, Rappit redefines modernization as an intelligent, AI-led process. Its agentic approach uses AI to analyze legacy systems, automatically transforming inputs into scalable, cloud-native foundations. This dramatically reduces the time, cost, and risk traditionally associated with modernization.

The blueprint is not about migration, it’s about reimaging it for the future. By leveraging AI agents to guide and accelerate decision-making, Rappit enables enterprises to continuously modernize and adjust to changes in the business and market. Legacy complexity is broken down, technical debt is removed, and systems are rebuilt in a way that supports ongoing change. The result is a future-ready system built for today’s reality: modern, secure, ready to add advanced AI capabilities as they evolve and inherently adaptable.

A turning point for business leadership

In conclusion: legacy systems cannot support modern security standards and are significant and often underappreciated attack targets. They are attractive precisely because they are hard to defend. Bain & Company points out that the coming wave of AI-powered attacks on legacy systems is a business risk of the highest order, not a technology problem to be delegated downward. 

IBM’s 2025 data breach report puts the average data breach due to e.g. insecure systems at a record €10.22 million. When you set a €3M modernization project next to a single incident with the old system, it provides a different perspective. Consider the case of British Airways that failed to secure a known vulnerability and paid the price: a £20 million GDPR fine, widespread reputational damage, and long-term customer trust impact after hackers compromised payment data. 

Many incidents never reach the public, with companies preferring to pay huge ransomware demands to regain access to their core systems and keep the incident out of the headlines. Because downtime, which can reach millions per hour in some sectors, is even more costly than the ransom itself.

The cost of doing nothing is rising faster than the cost of change.

Businesses that don’t recognize the sense of urgency and wait for an incident to justify the modernization project of their outdated enterprise applications will learn this the hard way. 

The time to act is now.