Cybersecurity experts are warning that companies have only six months to prepare for the increasing threat of automated cyberattacks. Frontier AI models, which can autonomously execute end-to-end compromises, have already demonstrated their capabilities in several benchmark tests. With multiple organizations confirming that these models can successfully breach production-grade enterprise networks, the time for complacency is over.
Booz Allen, a consulting firm, has become the latest organization to publicly acknowledge the threat posed by frontier AI models. In their evaluation, Anthropic’s Mythos 5 model scored an impressive 80 on the Cyber Weapon Index (CWI), a metric developed to benchmark a model’s capabilities in finding and exploiting vulnerabilities. While this may seem like a strong showing, experts warn that the true danger lies not in the current state of frontier models, but in their future development.
The CWI is a complex measure that takes into account several factors, including a model’s ability to find and exploit vulnerabilities, execute attacks, and evade detection. In the case of Mythos 5, its high score indicates that it can successfully breach enterprise networks with ease. However, the real concern lies in the fact that these models are becoming increasingly sophisticated, and their capabilities will only continue to improve.
The implications of this threat are stark. As Brad Medairy, president of Booz Allen’s National Cyber practice, notes, “the balance of power shifts to the offense” when facing human attackers. With automated attacks capable of delivering effects at speed and scale that traditional defenses cannot keep pace with, companies will need to adapt quickly to stay ahead.
One of the most significant challenges in addressing this threat is the fact that human-speed cybersecurity operations will no longer be enough. A four-hour response time, once considered reasonable, will soon become inadequate. As Medairy notes, “an adversary that’s an agent operating at scale can outpace the defenses.” This means that companies must invest in AI-speed defenses and secure their attack surfaces to prevent breaches.
The development of open-weight models, which make autonomous attacks less costly, will only accelerate this trend. These models, which are becoming increasingly sophisticated, will soon make it cheaper for attackers to launch automated cyberattacks. As Nico Waisman, chief information security officer at XBOW, notes, “open-weight models have gotten materially better at cyber, and that’s what moves the ROI calculation.” This means that companies must prioritize investing in AI-powered defenses and improving their cybersecurity posture to prevent breaches.
In conclusion, the threat of automated cyberattacks is real and growing. Companies have only six months to prepare for this new reality, and it will require significant investments in AI-speed defenses and attack surface security. The stakes are high, but the consequences of not acting swiftly will be catastrophic.
Source: Dark Reading — 2026-09-04