After Mythos, zero trust will no longer be enough against AI-powered attacks

AI News


In April, Anthropic made its powerful new Claude Mythos artificial intelligence model available to select organizations as a preview of its powerful capabilities to help identify unknown cybersecurity vulnerabilities. Within hours, an unauthorized group reportedly gained access to it, and what was intended as a tool to test a company’s security suddenly had the potential to become one of the most effective hacking models available to bad actors.

The security landscape has fundamentally changed. It is false hope to believe that threat actors will eventually lose access to Mythos or something similar. Anthropic itself estimates that other AI labs could develop their own models that rival Mythos’ capabilities in as little as 18 months. The likelihood of widespread availability only increases.

Organizations now operate in a completely different world when it comes to cybersecurity. Today’s enterprises must rethink their current strategies and modernize their systems against these new and powerful AI-enabled threats, especially for the U.S. defense and intelligence communities. What is needed is a new approach to commonly adopted cybersecurity norms, and it starts with recognizing one truth: Zero trust alone is not enough.

Impact on U.S. national defense and intelligence

One of the most alarming consequences of Mythos falling into the wrong hands is that it levels the playing field. This essentially puts new cyber weapons in the hands of adversaries who would otherwise be at a disadvantage.

What makes Mythos so powerful is its ability to discover zero-day vulnerabilities incredibly quickly and leverage those vulnerabilities to launch autonomously scalable attacks. Virtually any group or nation-state can now have this capability against U.S. defense and intelligence networks.

Many defense and intelligence IT teams have an advantage over their civilian sector counterparts given the architecture they have already built, but those who are still modernizing their systems are particularly vulnerable. A recent Everfox survey of defense IT leaders found that 78% identify outdated infrastructure as the leading cause of cyber vulnerabilities. They must have a special reason to accelerate modernization now.

The United States must now look for ways to regain the advantage, as AI models such as Mythos provide America’s adversaries with cheaper and faster ways to exploit potential cyber vulnerabilities.

Traditional cybersecurity models are becoming obsolete

The instinct for many IT teams is to enhance their existing security blueprints by providing better threat intelligence, faster threat detection, improved automated responses, and more identity controls. All of these are important, but it may be unrealistic to expect them to serve as the foundation for effective cybersecurity today.

As exploitation timelines shorten, threat intelligence becomes less effective. The time it takes for a publicly disclosed cybersecurity vulnerability to be exploited in the wild has decreased significantly from more than a year in 2020 to just 10 hours today. As more AI-enabled hacking tools enter the landscape, we expect the gap to continue to close fairly quickly.

Threat detection safeguards are similarly becoming less effective, as cyber vulnerabilities can now be exploited by AI models operating at machine speed. Threat detection and response can buy time and every second can count, but in today’s world of AI-driven attacks, it is less reliable as an effective safeguard.

Identity controls may also become less effective than the primary method of protecting sensitive networks. Don’t get me wrong. Zero Trust access policies are important. The adoption of zero trust identity controls should continue to advance. But with many major privacy breaches over the past three years, from Storm-0558 to Scattered Spider, starting at the front door and working their way to high-end targets, it’s clear that in some cases, access control cannot be relied upon as the sole basis for cybersecurity.

The lesson here is to stop designing systems that focus on keeping attackers away from everything, and start designing them to protect the important things that attackers can never access.

A security architecture that stands out

What does such a design look like? It should be built on three principles:

Consider the outer layer to be a consumable item. Assume that your company’s laptops, productivity environments, and standard endpoints are likely to be compromised. They need to be hardened to slow attackers and generate useful telemetry, while saving precious time and budget to secure the network perimeter and protect the crown jewel.

Leave it to the boundaries between the layers. All data transfer from the external layer to the internal layer must pass through an enforcement point that allows movement based on the content of the data, not the sender. This cross-domain transfer inspects the content of the data, applies policies to verify whether the data is allowed to be entered, and logs it if it is allowed. Confining the environment and making it easier to control, monitor, and defend.

Protect your crown jewels with the same fail-proof security as the outer layer. If the outer layer were to fall due to a compromised identity, it would not provide the same path of entry into the Crown Jewels. Harden this layer with hardware isolation and enforcement of data policies that require requests that a compromised external layer cannot generate. This compromises valuable information only if an attacker breaks the second, architecturally distinct enforcement layer, and their attempts are detected at the monitored perimeter.

Many defense and intelligence organizations have been building out exactly this way for decades by separating high-side sensitive networks from low-side untrusted networks, providing secure cross-domain data transfer with content inspection, and establishing enclaves with clear enforcement boundaries. Mythos now has increased urgency for all national security agencies to modernize their networks in this way. Because the question is no longer whether an attacker can gain the ability to compromise critical systems. What the architecture will look like when that happens.

Petko Stoyanov is Everfox’s Chief Technology Officer.

Copyright © 2026 Federal News Network. Unauthorized reproduction is prohibited. This website is not directed to users within the European Economic Area.





Source link