11 Sources
[1]
Anthropic's Mythos is evolving faster than expected, reports AI safety agency
AI capabilities may be happening much faster than anticipated. Anthropic's Claude Mythos, which the company maintains is too powerful to be released generally, already appears to have gained new capabilities. In a blog post on Wednesday, the UK AI Security Institute (AISI) reported that it had
[2]
AI agents show they can create exploits, not just find vulns
Sure, AI agents such as Mythos can find security vulnerabilities in software, but the bigger question is whether they can turn those flaws into functional exploits that work in the real world. After all, many AI-discovered bugs prove minor or difficult to weaponize. New research, however, suggests
[3]
AI-driven cyberattacks will start to be the 'new norm' in months, Palo Alto warns
"We now estimate a narrow three-to-five-month window for organizations to outpace the adversary before AI-driven exploits start to become the new norm," he wrote in a blog post on Wednesday. "This impending vulnerability deluge demands urgency." The rise of increasingly sophisticated AI models
[4]
AI models are getting better at replacing cybersecurity pros on certain tasks
UK researchers find LLMs are learning to finish jobs faster and improving all the time The UK AI Security Institute (AISI) has found that frontier models are quickly becoming more efficient when asked to do some cybersecurity work. AISI measures this with its "time window benchmark for
[5]
Anthropic to present exposed Mythos flaws to global watchdog - claims critical vulnerabilities found 'in every major operating system and web browser'
* Anthropic set to brief the FSB on Mythos' capabilities * Financial experts are worried attackers could exploit vulnerabilities in banking software * Banks and lenders have been told to improve their detection and patching of vulnerabilities exposed by AI models Anthropic is due to present a
[6]
The next phase of AI cybersecurity still needs humans
Why it matters: The new phase of AI-powered cybersecurity may depend less on fully autonomous hacking and more on how effectively humans can direct, validate and operationalize increasingly powerful systems. The big picture: When Anthropic unveiled Mythos Preview to the world, it warned that the
[7]
Claude Mythos turns years of security research into 20-hour AI exploits
When Anthropic announced Claude Mythos Preview on 7 April 2026, the response went well beyond the cyber security community. Finance ministers discussed it at the IMF. The Bank of England governor said it had to be taken very seriously . The UK Government wrote an open letter to every business
[8]
Major cybersecurity firm says new AI models uncovered 8x more flaws
Driving the news: Palo Alto Networks now estimates organizations have just three to five months before attackers broadly gain access to the capabilities of frontier AI cyber models. * Palo Alto Networks is among a small group of organizations with access to both Mythos and OpenAI's cyber-focused
[9]
AI is having its "Ford T" moment as Zero Day assembly lines appear
What are the security implications of Anthropic's Claude Mythos? Coming out of the major security conferences this year, the anxiety around AI was palpable. However, if you listen closely, much of the industry is still stuck viewing AI as a sophisticated phishing generator or a helpful coding
[10]
Firms nudged to go for Anthropic's Opus 4.7 as Mythos AI stays elusive
Organisations are leveraging Anthropic's Claude Opus 4.7 to address cybersecurity vulnerabilities, as the more powerful Mythos model remains largely inaccessible. Opus 4.7 offers significant capabilities, estimated at 70-80% of Mythos, making it a practical solution for threat hunting and incident
[11]
Claude Mythos and GPT-5.5 have confirmed what researchers feared most about AI and cybersecurity
According to a report recently released by the AI Security Institute (AISI) in the UK, the autonomous cyber capability of frontier AI models has been progressing rapidly enough to outpace its measurement benchmarks. Also read: Figure AI's Helix-02 humanoid robots is pulling full 8-hour factory
Share
Copy Link
The UK AI Security Institute reports Anthropic Mythos is advancing faster than anticipated, with capability doubling times shrinking from 8 months to around 4 months. The model now completes previously unsolved cybersecurity challenges and can create functional exploits from software vulnerabilities, raising concerns about AI-driven cyberattacks targeting critical infrastructure within months.
Anthropic Mythos is evolving at a pace that has caught even specialized AI safety researchers off guard. The UK AI Security Institute (AISI) reported on Wednesday that a newer version of the model has already surpassed both its earlier performance and OpenAI GPT-5.5, just one month after the initial release
1
. The updated Mythos Preview checkpoint completed both of AISI's cyber ranges, solving "The Last Ones" in 6 of 10 attempts and the previously unsolved "Cooling Tower" challenge in 3 of 10 attempts, marking the first time any model completed the second cyber range1
.
Source: ZDNet
This rapid advancement in AI cybersecurity capabilities demonstrates that improvements aren't restricted to individual model releases but can happen within versions of a single model. AISI's time window benchmark for cybersecurity, which estimates how much work an AI can do compared to a human, shows the human-comparable task time is growing at an accelerating rate
4
. In February 2026, AISI internally estimated that the length of cyber tasks AI models could complete had doubled every 4.7 months since late 2024, already an acceleration from their November 2025 estimate of 8 months1
.The more pressing concern centers on whether AI models for cybersecurity can transform discovered flaws into functional exploits that work in real-world scenarios. New research from UC Berkeley, Max Planck Institute for Security and Privacy, UC Santa Barbara, Arizona State University, Anthropic, OpenAI, and Google provides a definitive answer through ExploitGym, a benchmark evaluating autonomous exploit development capabilities of AI agents .

Source: Axios
ExploitGym consists of 898 real software vulnerabilities found in applications, Google's V8 JavaScript engine, and the Linux kernel. Mythos Preview successfully exploited 157 test instances while GPT-5.5 managed 120 within the allotted two-hour window
2
. Even with standard security defenses like ASLR or the V8 sandbox activated, a meaningful number of exploits still worked. More strikingly, AI models creating exploits sometimes discovered and weaponized entirely different software vulnerabilities than the ones they were initially pointed at2
.Palo Alto Networks has issued a stark warning about the timeline organizations face. "We now estimate a narrow three-to-five-month window for organizations to outpace the adversary before AI-driven cyberattacks start to become the new norm," according to a blog post on Wednesday
3
. This impending vulnerability deluge demands urgency from cybersecurity teams as they brace for attacks capable of exploiting previously unknown zero-day exploits.The concerns have escalated to the highest levels, leading to White House officials meeting with bank leaders and technology giants
3
. Anthropic is scheduled to brief the Financial Stability Board (FSB), a global watchdog working with finance ministry officials and central bankers across the G20, on critical vulnerabilities Mythos has exposed "in every major operating system and web browser"5
. Andrew Bailey, governor of the Bank of England, invited Anthropic to present these findings amid growing concerns that AI discovering vulnerabilities could threaten the stability of the global banking system5
.
Source: TechRadar
Related Stories
Anthropic has provided Mythos to around 40 companies through Project Glasswing to enable offensive and defensive cybersecurity measures. Mozilla found and patched 423 Firefox security bugs in a single month after deploying the model on the web browser, including some that had persisted in the code for over 15 years
5
. However, many more companies have requested access, but a Trump administration request has prevented Anthropic from distributing the software further5
.While AISI's tests capped tasks at 2.5 million tokens to enable better performance comparisons over time, this inherently "understates what frontier models can do"
1
. In cyber range experiments using up to 100 million tokens, performance would likely continue improving beyond that budget, especially for recent models which disproportionately benefit from higher token limits1
. This means AI safety assessments may not fully capture the capabilities these models possess when operating without constraints.The race is now on to patch AI-discovered vulnerabilities as quickly as possible before adversaries and state-sponsored threat actors develop their own capabilities. While AI models such as Mythos are not yet widely part of the threat actors' toolkit, Google recently observed attackers using an AI model to discover a zero-day exploit chain for the first time
5
. What remains unclear is whether the current acceleration trend will hold or whether these findings indicate a lasting increase in AI security capabilities.🟡 compliments=🟡The selected images provide a comprehensive visual narrative for the story. "ar-138607" effectively captures the theme of Anthropic Mythos's rapid evolution and accelerated capabilities in the cybersecurity domain. "ar-138516" visually represents the concept of AI models creating exploits, going beyond mere vulnerability discovery, which is a central point of the article. Finally, "ar-138729" underscores the urgency of the three-to-five-month window before AI-driven cyberattacks become the norm, by symbolizing the increasing interaction between AI and critical systems. Together, these images enhance the story's impact by illustrating the core themes of rapid AI advancement, exploit creation, and the impending cyber threat landscape.🟡 bar_chart_description=🟡No bar chart was used.🟡 funnel_chart_description=🟡No funnel chart was used.Summarized by
Navi
[2]
14 May 2026•Technology

14 Apr 2026•Technology

15 Apr 2026•Policy and Regulation

1
Science and Research

2
Policy and Regulation

3
Technology