
In April, unauthorized Mythos access taught us what we already know where AI is concerned: anything we can use, attackers can use better. At least for now.
On the day Mythos was released for limited testing, unauthorized users hacked it and presumably started playing with the model. This gave them access to a powerful AI cybersecurity tool (released under Anthropic’s Project Glasswing) designed for use in closed environments to help defenders spot vulnerabilities at scale, prioritize and remediate critical flaws, and essentially keep up with or ahead of attackers.
As it was compromised through a porous third-party environment, adversaries have access to the same technology that was supposed to be used against them. Though no cases of it being malicious use have been detected in the following days, it would not be unlikely to see instances of this same technology being used against defenders.
We’ve known threat actors have been successfully weaponizing AI since GenAI came out. It’s not surprising that regulated, compliance-bound, hierarchal organizations have been struggling to come up to speed since then.
But all those excuses, while valid, are not acceptable anymore. Attackers are experts at adopting and scaling AI for their own use.
Organizations need to adapt and adopt with the same proficiency, despite the operational roadblocks that currently stand in the way.
Why AI Takes So Well to Cybercrime
The reason AI is now “perfecting” old attacks is because attackers can use AI-enabled attacks to move faster through cybercriminal enterprises with few barriers to face.
Threat actors are free to use AI however they choose, and we see them mainly using it to speed up old processes – from writing phishing emails to creating new ransomware models and identifying targets.
Now a single, force-multiplied threat actor could launch a bot-based, AI-driven attack that successfully penetrates thousands of organizations in a nearly indefensible amount of time.
Before AI models were publicly released, the time it took for attackers to enter systems and obtain their objectives ranged from 10 days to a few weeks. We’ve seen the ransomware cycle from initial entry to data exfiltration or encryption brought down to a few days to a few hours, when it used to take a few weeks initially.
On top of that, old RaaS hierarchies are thinning out. The typical model of various attacker syndicates doing this, or that part of the process in the style of an assembly line, is giving way to agentic agents that can do those tasks for them.
This cuts out the middlemen and puts more profits directly into operators’ pockets.
Anthropic, Open AI, Gemini Are Only Half the Problem
While the misuse of US-based AI models is a cause for concern, competing overseas models like DeepSeek are out there, and out of our regulatory control.
After two decades in cybersecurity, I’ve noticed an exceptional ability to create good malware fast in different parts of the world. Some models are almost certainly being used for nefarious purposes, and perhaps with more success.
Have they already been weaponized? Are hidden agentic exploits already in our systems unnoticed? It can be impossible to tell, but this is all the more reason for organizations to level up their AI defensive capabilities and do it this year.
This isn’t a “next several years” problem, and CISOs that make it so might not be CISOs for long.
With AI Out There, What’s the Hold Up for Defenders?
This is the million-dollar question, but it’s not that hard to unravel. AI adoption is dependent on three things: technology, people, and processes.
The AI technology is already out there. The AI tools on the market today have legitimately successful use cases, from customer service to sales and marketing, and cybersecurity.
The problem is that most organizations don’t have the maturity of infrastructure or governance to handle the changes.
Look at Mythos. Nothing was wrong with the model; it was an access management hole in the third-party ecosystem that resulted in a same-day breach.
AI tools are powerful and powerfully sought after. AI is an incredible force-multiplier for good or ill. If organizations lack the proper guardrails, compliance policies, and automated security controls to take something like Mythos or Open AI on, it might be better to wait until they do.
This is hard: there is a tremendous top-down push to adopt AI, as quickly as possible and for as much as possible. In high-stakes industries like financial services, AI-powered fraud is rampant. Senior security leadership are forced to adopt and deploy quickly to combat these brands of threats at scale.
It’s a difficult balance, but again: all the more reason for teams to start maturing their processes, GRC, and add AI security controls now.
While this sounds nebulous and intimidating, AI really doesn’t change security demands all that much. It just demands a doubling down on the basics.
What Works When Creating an AI-Ready Security Stack
Remember, Mythos didn’t fall to an AI-powered attack of its own making; it caved to a simple access issue in the supply chain. NotPetya, the ransomware shot heard around the world, was the result of another compromised third party whose updates were pushed worldwide.
When defending AI systems (and non-AI systems) against AI attacks, remember what adversaries are using artificial intelligence for.
They’re generally not cranking out APTs around the clock, and they haven’t cracked quantum cryptography (yet). They’re doing the simple things fast: looking for basic vulnerabilities, spotting zero days, finding toxic combinations where a few open doors in the right places could lead to big access wins.
They are finding and exploiting simple credentials at scale, creating phishing campaigns faster and better, and using LOTL techniques to exfiltrate data: essentially the same things attackers have always been doing, but at machine speed.
This is great news, and the reason why AI defense is fundamentally simple. Table stakes use cases for secure AI innovation are:
- Visibility into all legitimate and shadow AI usage. Shadow IT has now become shadow AI.
- Data classification to know what kind of data you have.
- Granular AIM policies based on the principle of least privilege so you can control who can access what.
Organizations need a clear map of all the data being touched by AI tools, the lifecycle of that data, and who is accessing it (customers, partners, internal use only) along the way.
Lastly, red teaming is no longer optional. Before you deploy an AI tool within your environment, do a mandatory red teaming exercise. Your objective should be: can I exfiltrate data out of this model?
Because as soon as that model goes live, that’s exactly what AI-powered attackers are going to do.
