Companies have just six months to prepare for a new era of automated cyberattacks, as frontier AI models continue to demonstrate their ability to autonomously compromise networks and systems with ease. The latest benchmarking efforts from Booz Allen and other cybersecurity experts confirm that these advanced machine learning models can execute end-to-end attacks at speeds and scales previously unimaginable.
At the heart of this concern is Anthropic’s Mythos 5, a frontier model that has been shown to be capable of acting as a fully autonomous hacker. In a recent evaluation, Booz Allen released the Cyber Weapon Index (CWI), which measures a model’s ability to find and exploit vulnerabilities, as well as its capacity for execution and attack. Mythos scored an impressive 80 on this index, outpacing other contenders including SpaceXAI’s Grok-4.5.
However, it’s not just the current capabilities of frontier models that should be worrying companies – it’s where we’re headed in six months’ time. Brad Medairy, president of Booz Allen’s National Cyber practice, warns that the balance of power is shifting towards attackers, who will soon have the advantage when facing traditional defenses. “When facing human attackers, defenders had the upper hand,” he says. “But with autonomous attacks at scale and speed, the tables are turning – defenders won’t be able to keep pace.”
This shift in power dynamics has already been demonstrated by recent attacks on Taiwanese government servers by a Chinese-speaking cyber-threat group. The attack, which took place over just four days, showed how autonomous hacking operations can compress reconnaissance and attack-execution steps, giving attackers an unparalleled advantage.
The lesson for companies is clear: human-speed cybersecurity operations will no longer be enough to keep pace with the evolving threat landscape. “A four-hour response time today may seem reasonable – even exceptional – but that won’t be fast enough in the future,” says Medairy. With autonomous attacks increasingly becoming the norm, organizations must adopt AI-speed defenses and prioritize securing their attack surfaces.
But it’s not just frontier models that will accelerate attackers’ capabilities – it’s open-weight models that make autonomous attacks more cost-effective. These models have improved significantly in recent months, making it cheaper for attackers to automate their operations. “You no longer need frontier access to do this,” says Nico Waisman, CISO at XBOW. “That’s the point where automation becomes the cheaper option – not just the impressive one.”
In conclusion, companies have a narrow window of opportunity to prepare for the coming storm of automated cyberattacks. By understanding the capabilities and limitations of frontier models, as well as the emerging threat from open-weight models, organizations can take steps to secure their attack surfaces and adapt to the evolving threat landscape. The clock is ticking – six months may seem like plenty of time, but in cybersecurity, that’s an eternity.
Source: Dark Reading — 2026-09-04