The Race to Stop AI From Turning Vulnerabilities Into Breaches
In June, the Five Eyes cyber cybersecurity agencies warned that frontier AI is reshaping cyber offense and defense faster than organizations can adapt. Their message was clear: “The timeline is not years, it is months.”
Since then, the warnings have hardened into deadlines.
The European Central Bank told eurozone banks to submit plans for AI-enabled cyber threats by October 31, 2026. And Canada’s financial regulator warned banks and insurers that advanced AI models could shrink the time they have to identify, fix, and respond to vulnerabilities.
The regulators are catching up to what the data already shows. AI has collapsed the time between a flaw’s disclosure and its exploitation — from about 10 months in 2021 to three hours in 2026. No patch cycle keeps pace with that. The question for security leaders is shifting from which flaws to fix first to how far an attacker can move after the first foothold.
Why AI-speed risk feels so hard to control
Cyber defenders are being asked to control threats moving faster than their own systems.
The risks are familiar: exposed systems, legacy debt, slow patch cycles, weak identity controls, and delayed incident response. What has changed is the pace — and the pressure.
Frontier AI can help defenders find and assess vulnerabilities faster. But attackers get the same advantage: faster discovery, faster exploits, and faster ways to connect weaknesses into attack paths.
Psychologists Susan Folkman and Richard Lazarus called this stress appraisal: anxiety spikes when a threat feels severe and control feels uncertain. That’s what frontier AI creates for security leaders: machine-speed vulnerability discovery colliding with human-speed patching, testing, and response.
The Zero Day Clock is ticking faster
The Zero Day Clock tracks the time between a vulnerability’s public disclosure and confirmed exploitation. Its data tells a stark story: attackers keep getting faster, while patching still takes time.
Not every vulnerability is exploited. But widely used software, exposed systems, and critical infrastructure can become targets quickly.
The risk grows when attackers can analyze flaws, build exploits, and test attack paths faster than defenders can validate and deploy a fix.
That is the problem frontier AI makes harder.

The median time from disclosure to exploitation has fallen from about 10 months in 2021 to three hours in 2026.
From isolated tasks to attack chains
The U.K. AI Security Institute has found that advanced models are improving at longer, multi-step cyber tasks. In a controlled 32-step corporate-network simulation, Mythos Preview was the first model to complete the full chain, succeeding in 3 of 10 attempts and averaging 22 steps. Claude Opus 4.6 followed, averaging 16 steps.

AISI’s newer GPT-5.5 evaluation also found that the capability jump was not limited to Mythos. The institute said frontier AI cyber performance is part of a broader trend across recent models.
This does not prove AI can autonomously breach every well-defended enterprise.
It shows that more of the attack chain — from reconnaissance to exploitation and lateral movement — is becoming easier to automate.
The AI vulnerabilities race goes global
Those evaluations cover only the models researchers can test. Michael Adjei, Illumio global solutions architecture director, worries about the ones they can’t.
“My concern is what is being developed in secret,” Adjei said. “There’s Mythos and other frontier AI that we know about. But systems being developed in secret could be even more powerful.”
His concern is no longer theoretical.
On June 24, Chinese security firm 360 Security Technology (formerly Qihoo 360) unveiled two AI security tools under its Yitian Tulong family of AI models. Founder Zhou Hongyi called one of them, Tulongfeng, China’s version of Mythos. It hunts for software flaws. The second tool, Yitianzhen, automates cyber defense and incident response.
360 said Tulongfeng found 3,432 software flaws, including 105 confirmed by Chinese authorities, though the claim could not be independently verified.
Whether the model has matched Mythos matters less than what the announcement signals: the AI race to find and use software flaws has already begun.
The tools are new. The access problem isn't.
CISA, NSA, FBI, and other partners have warned that PRC-backed groups have breached U.S. critical infrastructure and stayed inside those networks. That access that could be used for far more than espianage.
Now AI is entering that picture.
In November 2025, Anthropic said it had disrupted what it called the first largely AI-orchestrated cyber espionage campaign. Anthropic tied the campaign, with high confidence, to a Chinese state-sponsored group.
The company said the attackers used Claude to automate parts of the work. That included finding targets, finding flaws, exploiting them, and taking data.
Antropic said the campaign targeted about 30 organizations, including financial firms and government agencies.
CrowdStrike has also warned that China-linked hackers pose the top espionage threat to technology companies, especially firms tied to AI, chips, software, and other key sectors.
Together, these reports change the security conversation.
Organizations cannot plan around one AI model, one vendor, or one country. They need to prepare for a future where attackers can find flaws, build exploits, and run cyber operations faster.
“Frontier AI does not change vulnerability management or vulnerability risk,” Adjei said. “It amplifies existing problems at machine speed.”
How to limit the reach after the foothold
Frontier AI is making the race harder to win. Defenders are trying to find, assess, and stop vulnerabilities while attackers use the same speed to turn flaws into attack paths.
With so many variables moving at machine speed, no team can control every outcome.
That shifts the question from what’s vulnerable to what attackers can reach next.
One foothold should not become free movement across the environment.
That is where segmentation changes the outcome.
“Organizations also need controls that reduce exposure, limit lateral movement, and rapidly quarantine compromised systems before attackers reach their objectives,” Adjei said.
Learn why visibility and segmentation are essential to breach containment. Schedule a breach containment demo.

.webp)
.webp)


.webp)