Seksan Mongkhonkhamsao | Moment | Getty Images
“We now estimate a narrow three-to-five-month window for organizations to outpace the adversary before AI-driven exploits start to become the new norm,” he wrote in a blog post on Wednesday. “This impending vulnerability deluge demands urgency.”
The rise of increasingly sophisticated AI models such as Anthropic’s Mythos has raised the stakes, putting pressure on cybersecurity teams to step up their defenses as they brace for a wave of cyberattacks capable of exploiting previously unknown software vulnerabilities. The concerns led to White House meetings with bank leaders and technology giants.
Google this week said it stopped an attempt to use AI for a “mass exploitation event,” but hackers are already using available AI tools to exploit software vulnerabilities.
Last month, Anthropic limited the rollout of the Mythos to a select group of companies to test and fix vulnerabilities before hackers abuse them. The group included Palo Alto Networks, CrowdStrike, Amazon, Apple and JPMorgan.
OpenAI announced its GPT-5.5-Cyber model last week and followed that with the rollout of its Daybreak cyber initiative.
“The big question just a few weeks ago was: ‘Are we overstating the model capabilities?’ With more testing, I can confidently say we weren’t,” Klarich wrote. “In fact, these models are likely even better at finding vulnerabilities than we initially realized.”