Skip to content
← DeepDive Governance & Geopolitics · 中文
DEEPDIVE / [SECURITY] · EP.85 AI Cyber Arms Race
v1 · AISI/GTIG Report 2026-05 · Compiled 2026-07
UK AISI · Google GTIG · Mozilla · OpenAI Daybreak 2026-05

AI Cyber Attack Capability
Doubles Every 4.7 Months

The UK AI Safety Institute (AISI) reports that autonomous AI cyber attack capability roughly doubles every 4.7 months, and the pace of progress in the latest frontier models even exceeds this already accelerating trend. The same week, Google's Threat Intelligence Group confirmed the first-ever AI-assisted and weaponized zero-day vulnerability. "Lab threats" have officially entered the "real-world acceleration" phase.
AISI Doubling Cycle
4.7 months
Nearly 4x the speed of Moore's Law
MYTHOS Capability Leap
APT→Full Takeover
Occurred in just a single version iteration
MOZILLA · FIREFOX
271 vulnerabilities
Fixed in two months, near-zero false positive rate
EXAFORCE Series B
$1.25B
AI real-time cyber attack detection funding
TL;DR / 30-Second Core

Within a single week, three signals叠加: the UK AISI report found that autonomous AI cyber attack capability roughly doubles every 4.7 months; the same day, AISI testing confirmed that Anthropic's latest Mythos version can achieve "full network takeover" (the old version only reached "advanced persistent threat" level); a week earlier, Google's Threat Intelligence Group (GTIG) confirmed the first-ever AI-assisted zero-day vulnerability. Meanwhile, the same Mythos helped Mozilla fix 271 Firefox vulnerabilities in two months, and OpenAI released the competing Daybreak platform—both offense and defense are exponentially accelerating, but the time asymmetry is even more unfavorable for defenders.

01

Doubling every 4.7 months is nearly 4x the speed of Moore's Law—in 23 months (less than 2 years), if today's attack capability is 100, it will exceed 3000

02

The "90-day responsible disclosure" system is failing—AI can scan code commits in real time during the disclosure embargo period, identifying security fixes that have not yet been publicly released

03

Offense and defense use the same model—Mythos can be tested by attackers to achieve "full network takeover," yet in the same month it helped Mozilla fix 271 real vulnerabilities in two months

04

Deployment speed asymmetry is the core risk—defensive tools require 6–12 months for deployment and integration; attack tools can be instantly updated on the cloud, with zero friction

Counter-Consensus Insight

The deep structural problem of this arms race is not "will AI be used to attack," but rather AI makes genius on the attack side no longer scarce, yet professional insight on the defense side remains scarce—in the past, APT-level attacks required top-tier nation-state hacker teams; now AI has drastically lowered this threshold. The defense side cannot continue to respond with a "talent-intensive" approach; the only viable path is to fight AI with AI, and run faster than attackers—which is exactly why the "update security policy once a year" cadence is completely inadequate.

§ 01 / Attack Side

From "Assistive Tool"
to "Autonomous Weapon"

From AI being used to assist vulnerability discovery in 2024, to Google confirming the first-ever AI-assisted zero-day vulnerability in May 2026, less than two years have passed. GTIG publicly confirmed on May 11, 2026 that attackers used AI to discover and weaponize a 2FA bypass vulnerability; the generated Python script bore clear LLM hallmarks (hallucinated CVSS scores, textbook Pythonic formatting)—GTIG preemptively detected and blocked the planned large-scale exploitation event, a fortunate win for human defenders.

Three days later, the UK AISI released even more unsettling data: autonomous AI cyber attack capability roughly doubles every 4.7 months, and the pace of progress in the latest frontier models even exceeds this already accelerating trend. Moore's Law (transistor density doubling every 18 months) is considered one of the fastest technology acceleration curves in human history, yet the evolution speed of AI cyber attack capability is nearly 4x that of Moore's Law: if today's capability is 100, in 4.7 months it will be 200, in 9.4 months it will be 400, and in 23 months (less than two years) it will exceed 3000—no known defense mechanism can evolve at anywhere close to this speed.

AISI also disclosed test results for Anthropic's latest Mythos version the same day: the new version exhibited a "significant capability leap" over the old version, now capable of achieving "full network takeover"—the highest-level threat in cybersecurity terminology, meaning AI can autonomously take over an entire IT infrastructure, rather than just discovering individual vulnerabilities. The old Mythos version only reached the "advanced persistent threat (APT)" level. From APT to "full takeover" occurred in just a single version iteration.

§ 02 / Defense Side

Mythos and Daybreak:
Catching Up, Window Narrowing

Ironically, the same Mythos in another context is a defender's sharp weapon. Mozilla publicly disclosed on May 8, 2026: with the help of Anthropic's Mythos model, they discovered and fixed 271 security vulnerabilities in Firefox within two months, with a near-zero false positive rate. The key innovation was enabling AI to call testing tools and verify vulnerabilities by "crashing the browser"—AI wasn't just analyzing code, but verifying vulnerabilities like an engineer. OpenAI followed closely, releasing the Daybreak cybersecurity platform on May 11—powered by the GPT-5.5-Cyber three-tier permission model, partnering with Akamai, Cisco, CrowdStrike, Palo Alto Networks, and over a hundred other organizations, directly benchmarking against Mythos.

But there is a fundamental time asymmetry problem: defensive tools require deployment, integration, verification, and training, a cycle that easily takes 6–12 months; attack tools can be instantly deployed on the cloud, updated with zero friction. There is another detail worth noting in the AISI report: under the pressure of the 90-day vulnerability disclosure embargo, AI can scan code commits in real time to identify security fixes—this means the traditional "responsible disclosure" system is failing, and the foundational assumptions of the traditional defense cadence have been shaken.

AI makes genius on the attack side no longer scarce,
but professional insight on the defense side remains scarce.
— Core judgment of this article
§ 03 / Business & Governance

Defensive AI Security,
Is Becoming a Trillion-Dollar Market

Anthropic has not yet publicly released Mythos, only opening it to specific enterprises and government agencies for vulnerability patching—an extremely cautious decision, which also means that access control for "dual-use frontier AI capabilities" is becoming a core regulatory issue. Meanwhile, GPT-5.5-Cyber has already moved ahead of Mythos in opening pre-review to the EU, and the two companies' regulatory compliance strategies have diverged clearly. Exaforce completed a $125 million Series B funding round on May 12, focused on AI real-time cyber attack detection—institutional investors have already viewed AI security as a "definite growth track," not a conceptual investment. US Treasury Secretary Bessent stated during the US-China summit: the US can discuss AI safety rules with China precisely because it holds a leading position in AI—both sides are exploring the establishment of a bilateral AI safety communication mechanism; if established, it would be the first superpower bilateral framework in AI governance history.

Specific implications for enterprises and practitioners: the "update security policy once a year" cadence is completely inadequate—if attack capability doubles every 4.7 months, the security baseline set at the beginning of this year may be 4–8x behind by year-end; security teams need to shift from "annual planning" to "quarterly reassessment"; AI tool selection logic is shifting from "capability evaluation" to "security compliance"—when introducing any powerful AI tool, its dual-use risk must be simultaneously evaluated; supply chain attacks are an underestimated risk vector—this issue also saw a case where attackers used an Obsidian plugin to deploy PHANTOMPULSE RAT; the plugin installation behavior of code editors and note-taking tools needs to be brought into the scope of enterprise security audits.

Doubling every 4.7 months, the first AI-assisted zero-day, Mythos leaping from APT to "full network takeover"—these three signals叠加, marking that AI cyber attack capability has moved from "lab threat" into the "real-world acceleration" phase. But the other half of the story from the same week is equally real: Mythos fixing 271 Firefox vulnerabilities in two months, Daybreak going live with over a hundred security organizations, defensive AI funding at the $1.25 billion level—both offense and defense are using the same generation of model capability; the decisive factor is not whose model is stronger, but whose deployment cycle is shorter, who can first overturn and rebuild outdated assumptions like "responsible disclosure".

Revision history

First published 2026-07-24

Companion material