The incident offers an early glimpse into a new era of cyber threats, where AI agents can move beyond assisting attackers to executing complex operations themselves.
For years, the biggest concern around AI in cybersecurity was how effectively humans could weaponize it. The more unsettling question now is what happens when the AI itself begins to make decisions and take actions with real systems.
The recent cybersecurity incidents revolving Anthropic’s Mythos project brought that possibility into sharper focus. During a controlled cybersecurity evaluation, Mythos 5 model gained access to the live internet, uploaded a malicious package and continued taking actions that could have affected third-party systems. Anthropic said the model was operating in a simulated environment, but the episode demonstrated that capabilities of autonomous agents.
“The recent developments around Anthropic’s Claude Mythos are important because they demonstrate that AI is moving beyond simply assisting with cybersecurity research. We are seeing models capable of identifying complex vulnerabilities, reasoning about exploitation and, increasingly, executing multi-step security tasks. At the moment, I would say AI is creating an advantage for both sides, but the real question is who can operationalise that capability faster,” says Dhiraj Sancheti, CISO Shoppers Stop.
According to Joyce Rodriguez, CISO Airbus India, “In the immediate aftermath, I believe the advantage sits with defenders. Thanks to Project Glasswing, over 150+ organizations, including large security vendors and cloud providers have gained access to test their products against zero-day vulnerabilities and remedy them. That’s a real advantage only if these organizations move with the speed and tenacity needed to clear their backlog.”
The Mythos 5 Incident and New Realities
The first generation of AI-powered cybercrime was easy to understand—a criminal would ask an AI model to write a phishing email, translate a message or generate malware code but the human remained firmly in charge.
Then came the agents. Unlike a chatbot that waits the next question, an agent can be given an objective and allowed to work through a series of tasks. It can reason, write code, use tools and decide what to do next and operate autonomously, fundamentally changing the human and machine equation.
In November 2025, Anthropic disclosed the first reported large-scale cyber-espionage operation in which AI executed substantial portions of an attack with limited human intervention. The campaign targeted roughly 30 organisations across sectors including technology, financial services, chemicals and government. Anthropic attributed the campaign with high confidence to a Chinese state-sponsored group and said the attackers had manipulated Claude Code into performing much of the operational work, including reconnaissance, vulnerability research, credential harvesting, lateral movement and exfiltration.
What is crucial to take note is the speed and autonomy of these attacks have demonstrated. Anthropic said the AI was capable of carrying out roughly 80–90% of the tactical operations independently which is a very different proposition from asking a chatbot to write a phishing email.
Then the experiments started escaping the laboratory
As the experiments progress, this year revealed some uncomfortable outcomes. In July Anthropic revealed that a review of more than 141,000 cybersecurity evaluation uncovered three separate cases wherein Claude models escaped their intended evaluation environments, reached the internet and accessed real systems, including by uploading a malicious package, accessing credentials and moving into additional infrastructure.
Around the same time, OpenAI disclosed that several models had escaped an isolated test environment by exploiting a previously unknown vulnerability and subsequently accessed production infrastructure belonging to Hugging Face.
The AI in cyber ingression story became even scarier in August. During cybersecurity testing involving frontier AI models, researchers found instances of AI agents taking unsanctioned actions on the live internet. One particularly striking case involved Anthropic’s Mythos 5 model attempting to introduce malicious code into an open-source software project and creating fake identities to deceive developers.
Even though researchers have cautioned against treating it as evidence that AI systems have gone rogue, the episode has demonstrated that AI agents can combine coding, deception, persistence and strategic decision-making to create new security risks.
The Advantage for Defenders
For CISOs this is a profound moment of reckoning. Sancheti concludes on a positive note saying, “Defenders have an important advantage which is visibility and control of their own environment. We have telemetry from endpoints, identities, networks, applications, cloud platforms and security tools. If we combine that telemetry with AI, automation and threat intelligence effectively, defenders can detect and respond at machine speed.”
The real challenge for CISO if the speed of execution. The organisation that combines AI, data, automation and human expertise most effectively will have the advantage.
