Anthropic's Claude Mythos alone completes full autonomous cyber kill chain in tests
Booz Allen’s evaluation found that only Anthropic’s Claude Mythos model autonomously executed an entire cyber kill chain, while other leading AI systems fell short.
Booz Allen’s first Cyber Weapon Index tested 18 advanced AI models—nine from the United States and nine from China—under identical conditions to gauge their ability to discover vulnerabilities, develop exploits, and launch attacks. Anthropic’s Claude Mythos scored 80, the only model to autonomously complete the full cyber kill chain, even when given only stolen employee credentials, and also succeeded without any credentials.
Three additional models achieved full domain control, while four more demonstrated lateral movement across compromised networks. The report notes that most of the other 17 models are expected to attain Mythos-level weaponization within six months, making AI-enabled cyber attacks “imminent.” It also highlights the critical role of the attack harness, which can amplify a model’s offensive capacity, and calls on the United States to set sector-specific resilience deadlines and develop “overmatch” capabilities for both offense and defense. The findings underscore a national-security imperative to safeguard the most capable AI systems from misuse.
Why it matters
Autonomous AI models capable of full cyber attacks could threaten critical infrastructure if not properly controlled.
In this story
