For twenty years, the bottleneck in software security was discovery. Finding a serious bug in a mature codebase took a skilled researcher days or weeks, which meant most bugs simply sat there, undiscovered, until someone with the right incentive went looking.
2026 broke that assumption. Frontier AI models can now read a codebase, reason about it, and surface exploitable flaws at a pace no human team can match. Anthropic said it plainly in its May update on Project Glasswing: progress on software security used to be limited by how quickly vulnerabilities could be found, and "now it's limited by how quickly we can verify, disclose, and patch the large numbers of vulnerabilities found by AI."
That sentence is the whole story of this article. If finding is cheap and fixing is expensive, the companies that win are the ones with enough skilled hands to close the gap.
Sources: Anthropic, "Project Glasswing: An initial update" (May 22, 2026); OpenAI's Astra announcement as reported by R&D World (September 1, 2026). Some independent researchers have questioned how much of the headline numbers reflect the model alone versus the surrounding tooling — but nobody disputes the direction.
What actually happened in 2026
April: Mythos and Project Glasswing. Anthropic announced Claude Mythos Preview on April 7 and, citing its ability to find software vulnerabilities, declined to release it publicly. Instead it gave roughly 50 organizations that build or maintain critical software — including Microsoft, Apple, Google, AWS, Cisco, Nvidia and the Linux Foundation — access to scan and fix their own code first.
May: the backlog becomes visible. After one month, most partners had each found hundreds of high- or critical-severity bugs. Cloudflare alone reported around 2,000 bugs across its critical-path systems. Across more than 1,000 open-source projects, Mythos flagged 6,202 likely high- or critical-severity issues; of a sample independently reviewed by outside security firms, about 90% turned out to be real. Vendors started shipping unusually large patch batches — Palo Alto Networks pushed a release with over five times its normal number of fixes, and Microsoft warned that its patch volumes would "continue trending larger for some time."
June–September: Mythos-class capability goes mainstream. Anthropic released Claude Fable 5 — the same underlying model as Mythos 5, with safeguards that route sensitive cybersecurity requests elsewhere — to general customers, followed by Fable 5.1 and Mythos 5.1 on September 1. The same day, OpenAI said its upcoming Astra model is the first it rates at its "Critical" cybersecurity threshold: with the right tools, it can find previously unknown flaws and chain them into working exploits without step-by-step human guidance.
Why this is a hiring problem, not a tooling problem
It's tempting to read the headlines and conclude that AI will now do security for you. In practice, every AI-found vulnerability creates a chain of human work that the model doesn't finish on its own.
What the model does well
- Reads large codebases and flags suspicious patterns at scale
- Proposes a root cause and, often, a candidate patch
- Writes a proof-of-concept to show a bug is exploitable
- Re-scans after a fix to check the obvious variants
What still needs a skilled engineer
- Deciding which of 400 findings actually matter in your environment
- Writing a fix that doesn't break the product or the customer contract
- Testing, staging and rolling out the patch without an outage
- Upgrading the dozens of open-source dependencies patched upstream
- Watching for exploitation in the window before everyone has patched
And the clock is shorter than it used to be. The same capabilities that help defenders find bugs help attackers too. When a model like Astra can turn a freshly disclosed vulnerability into a working exploit in hours, the gap between "patch available" and "patch deployed" stops being an IT hygiene metric and becomes the main thing that determines whether you get breached.
The math has changed. If your scanners now produce ten times more valid findings and your security team is the same size it was in 2025, your backlog is growing every week — and your exposure window is growing with it.
It isn't just your code
Even companies that never touch a frontier model are affected. Every major operating system, browser, crypto library and open-source framework your product depends on is being scanned and patched at an unprecedented rate. That's good news — but each upstream fix lands on your team as a dependency upgrade, a container rebuild, a regression test and a deployment. The surge in upstream patching turns directly into downstream engineering work.
The roles the AI era is creating demand for
The work above maps onto a specific set of roles. Some already existed and are now in much higher demand; a couple are genuinely new.
Turns a flood of AI-generated findings into a ranked, deduplicated backlog. Needs enough engineering depth to read the code, confirm exploitability and judge real-world impact — the filter between "the model flagged it" and "we're fixing it this sprint."
A strong software engineer who writes and reviews the actual fixes — reviewing AI-proposed patches critically, rather than merging them blindly, and making sure they hold up under real traffic and edge cases.
Keeps hundreds of dependencies current as upstream patch volume spikes — SBOMs, automated upgrade pipelines, policy-as-code and fast, safe rollouts. The role that turns "patch available" into "patch deployed" in days, not quarters.
Writes detections for newly disclosed vulnerabilities so you can spot exploitation attempts during the window before every system is patched. Shorter exploit timelines make this window more dangerous and this role more valuable.
Secures the AI systems your own company is shipping — prompt injection, agent permissions, data leakage, model supply chain. A new specialty that combines application security with hands-on experience building LLM products.
Hardens the infrastructure layer where many AI-found flaws actually become exploitable — IAM, network segmentation, misconfigurations. Limiting what an attacker can reach with one bug is the cheapest form of defense in depth.
Why Latin America is the natural place to scale this work
US companies can't hire their way out of the remediation backlog domestically — the US security talent gap was a well-known problem before AI made it bigger. LATAM fits this specific kind of work better than most offshore options, for five reasons.
1. Remediation is real-time work. Triage meetings, patch reviews, staged rollouts and incident calls all happen during the US business day. Engineers in Buenos Aires, São Paulo, Bogotá or Mexico City work in the same hours as your team — an emergency patch on a Tuesday afternoon doesn't wait for someone on the other side of the planet to wake up.
2. The region's security culture is engineering-first. LATAM's largest fintechs, banks and e-commerce platforms run at massive scale and are heavily targeted, so their security teams grew up writing code, not just running tools. That's exactly the profile AI-era remediation needs: people who can read a finding, open the codebase and write the fix.
3. The benches complement each other. As we mapped in our guide to hard-to-fill cybersecurity roles, Argentina is strong in application and cloud security, Brazil has deep detection-and-response experience from its banking SOCs, Mexico has a solid DevSecOps bench, and Colombia is growing fast in GRC and identity. A remediation function needs all of those, and a cross-border LATAM search can staff it.
4. Cost lets you match the new volume. If your valid findings went up tenfold, a 10% increase in security headcount won't close the gap. Senior LATAM talent typically costs well below equivalent US hires (see our 2026 rate benchmarks), which is the difference between a remediation team of two and a team of five.
5. These engineers already work alongside AI. The best LATAM security engineers we screen use AI-assisted code review and scanning daily. They treat model output as a strong first draft that needs verification — the right instinct when an AI-proposed patch could break production or miss a variant of the bug.
A note on model access and compliance
One honest caveat. The most capable cyber models are tightly controlled. Mythos 5.1 is currently limited to selected US organizations, and in June the US government briefly restricted access to Mythos 5 and Fable 5 for non-US nationals before lifting the restriction. Access policies are still evolving.
In practice this shapes how you set up the team rather than whether you can use LATAM talent. The companies we work with keep restricted scanning tooling inside their own US-controlled environment, under a US security lead, and route the findings to a broader remediation team that works with generally available tools. Check the current terms of any model you use, and involve legal when export controls might apply — but the bulk of the backlog is ordinary engineering work that a distributed team can do.
How to structure an AI-era security team
The pattern we see working is a small US core that owns discovery, risk decisions and disclosure, plus a LATAM pod that owns throughput:
- A US-based security lead owns scanning, prioritization and vendor disclosure
- A LATAM triage engineer turns raw findings into a ranked backlog
- Two or three LATAM remediation engineers write and review fixes
- A DevSecOps engineer automates dependency upgrades and rollouts
- A detection engineer covers the exposure window on critical bugs
- Track time-to-patch, not number of findings, as the headline metric
Frequently asked questions
What did Claude Mythos find?
Through Project Glasswing, launched April 7, 2026, roughly 50 partner organizations used Claude Mythos Preview to find more than 10,000 high- or critical-severity vulnerabilities in their first month. Mozilla fixed 271 vulnerabilities in Firefox 150, and across 1,000+ open-source projects Mythos flagged 6,202 likely high- or critical-severity issues, about 90% of which held up under independent review in a sampled subset.
What are Claude Fable 5.1 and OpenAI's Astra?
Claude Fable 5.1 is Anthropic's generally available Mythos-class model, released September 1, 2026; it shares weights with Mythos 5.1 but routes sensitive cybersecurity requests to a less capable model. Astra is OpenAI's upcoming model, the first it rates at its "Critical" cybersecurity threshold, meaning it can find unknown flaws and build working exploits with minimal human guidance.
Why does AI vulnerability discovery increase the need for security engineers?
Each AI finding still has to be triaged, fixed, tested, deployed and monitored by people. When discovery volume rises tenfold and attackers can weaponize disclosed bugs faster, companies need more engineers to close the gap between "patch available" and "patch deployed."
Why hire cybersecurity talent from Latin America?
LATAM engineers work in US business hours, which matters for real-time patching and incident response; the region's fintech and banking sectors produced engineering-first security talent; and senior rates are typically well below US equivalents, making it feasible to scale remediation teams.
Can LATAM engineers use Mythos-class models?
Access to the most capable cyber models is restricted — Mythos 5.1 is currently limited to selected US organizations. Most companies keep restricted tooling inside a US-controlled environment and route findings to a distributed remediation team using generally available tools. Always check current model terms and export rules.
Final thoughts
Mythos, Fable 5.1 and Astra don't make security teams obsolete. They make the slowest part of security — fixing things — the part that matters most. Every company is about to learn about more of its own vulnerabilities than it has ever known before, and attackers will be learning about them at the same time.
The companies that come out ahead will be the ones that treat this as a capacity problem and staff for it now, with engineers who can work in their time zone, read their code, and ship fixes quickly. That's what LATAM's security talent pool is well placed to do.
At IT Mates, we help US companies build exactly these teams — AppSec and triage engineers, remediation engineers, DevSecOps, detection engineers and AI security specialists — sourced across Argentina, Brazil, Colombia, Mexico and Chile, and screened for hands-on engineering depth rather than certification counts.
Sources
- Anthropic — Project Glasswing: An initial update (May 22, 2026)
- Anthropic — Project Glasswing
- R&D World — Fable 5.1 and OpenAI's Astra cyber threshold (September 1, 2026)
Want the full market picture? Our LATAM Tech Talent Intelligence Report covers seniority, English proficiency, and market maturity across 8 countries — a useful starting point before scoping a security remediation team.
Is your vulnerability backlog growing faster than your team?
Get a vetted security shortlist in 72 hours.
Tell us the role — AppSec and triage, remediation, DevSecOps, detection engineering or AI security — along with seniority and rate range. We'll map the talent pool across LATAM, screen for genuine hands-on depth, and deliver a curated shortlist within 72 hours.