Home SliderAI, Mythos and the New Era of Global Cybersecurity Risk

AI, Mythos and the New Era of Global Cybersecurity Risk

by internationalbanker

By Alexander Jones, International Banker

 

On June 22, the Five Eyes issued a joint statement warning that the evolving artificial intelligence (AI) landscape “is rapidly transforming cyber risk, and we must act swiftly to remain ahead”. The call to action from the intelligence alliance comprising the United States, the United Kingdom, Canada, Australia and New Zealand marks a significant inflection point, not only in how governments understand cyber risk, but also in how powerfully advanced AI is compressing cyberattack timelines.

“The rapid pace of frontier AI development means cyber risk assumptions can become outdated in months, not years. We must act before and be prepared to adapt and withstand evolving threats,” the Five Eyes’ representative cybersecurity executives wrote in the statement. “Cyber resilience is not an IT issue—it is central to operational continuity and market trust. Leaders who act now will reduce exposure, strengthen resilience, and build confidence with customers, partners, and investors. Those who delay will face growing and avoidable risk.”

This assessment reflects a growing alignment between intelligence agencies, central banks and financial regulators that AI is accelerating both the identification of vulnerabilities in digital systems and the speed at which those vulnerabilities can be transformed into operational attacks. It thus suggests that the underlying mechanics of cyber risk are shifting faster than institutional defence structures can adapt.

Frontier AI systems such as Anthropic’s Claude Mythos model have become a focal point in this transition. According to Anthropic, Mythos represents “a new class of intelligence built for ambitious projects focusing on cybersecurity, autonomous coding, and long-running agents”. Although access remains restricted and detailed technical specifications are limited, multiple industry reports and controlled evaluations describe such models as capable of identifying large volumes of software vulnerabilities across operating systems, browsers and enterprise applications.

One of the most striking findings from Anthropic’s internal testing emerged during controlled evaluations, in which Mythos uncovered 271 security flaws within Mozilla’s Firefox browser and successfully generated working exploits for 181 of them.

One of the most striking findings from Anthropic’s internal testing emerged during controlled evaluations, in which Mythos uncovered 271 security flaws within Mozilla’s Firefox browser and successfully generated working exploits for 181 of them. More broadly, assessments conducted by Anthropic’s own security researchers indicated that Mythos identified thousands of previously unknown vulnerabilities across major operating systems, web browsers and widely used software applications.

Because these so-called “zero-day vulnerabilities” have not yet been disclosed or patched, they present particularly valuable opportunities for attackers seeking to compromise critical systems. Reports also suggest that officials involved in evaluating the model, including specialists from the US National Security Agency (NSA), were particularly struck by the speed and efficiency with which Mythos located software weaknesses that had previously remained undiscovered.

Given the high degree of interconnectedness of digital infrastructure across finance, energy, telecommunications and cloud services, moreover, a weakness in one widely used system can translate into broader exposure across multiple institutions and jurisdictions. This interdependence creates conditions for correlated cyber events, in which multiple entities experience disruption from a shared underlying cause.

Modern AI systems are increasingly capable of scanning large and complex codebases, identifying latent weaknesses and surfacing security flaws that may have remained undetected for extended periods. Vulnerabilities that once required targeted human effort to uncover can now be continuously identified across multiple systems in parallel, thereby compressing the traditional cybersecurity-response lifecycle.

The time between discovery, patching and exploitation is shrinking, reducing the buffer that institutions have historically relied on to manage risk exposure. The core cyber-risk focus is thus shifting towards detecting how quickly and broadly failures can proliferate through networks and systems following the initial exploitation.

Another key feature of Mythos-class systems is their ability to connect multiple low- and medium-severity vulnerabilities into coherent chains for exploitation. While traditional cybersecurity practice typically involves assessing the risk of individual vulnerabilities, AI systems operate across combinations of weaknesses, treating them as interconnected components within a broader system architecture. In turn, this enables the construction of attack paths that may not be apparent when vulnerabilities are evaluated in isolation.

The implications of this latest wave of AI systems extend beyond Mythos or any other single comparative model. The broader AI ecosystem is evolving in ways that suggest these capabilities will diffuse across multiple platforms over time, partly due to the rapid transfer of techniques between models and organisations. Innovations in one frontier system are often replicated or adapted in competing systems, narrowing capability gaps over relatively short time periods and consequently reducing the likelihood that these advanced capabilities will be confined to just a few actors.

Due in no small part to its reliance on complex, interconnected digital infrastructure and its sensitivity to operational disruptions, the financial-services sector sits at the heart of this evolving risk landscape. With legacy systems still deeply embedded within core banking architectures, many financial institutions continue to combine modern cloud-based infrastructure with older technology designed for stability rather than continuous security iteration.

These systems often require extensive testing and regulatory approval before updates can be deployed, which, in turn, creates considerable delays between identifying potential vulnerabilities and remedying them. And as AI systems accelerate the rate at which vulnerabilities are discovered, such delays become more consequential.

Organisations are increasingly required to manage a growing backlog of security issues, prioritising remediation based on risk exposure while balancing operational continuity. This shifts cybersecurity from a periodic maintenance function into a continuous allocation problem under time pressure.

The high degree of interconnection across the financial infrastructure also means that banks, payment systems, clearing mechanisms and trading platforms invariably depend on shared vendors and standardised software environments. A single class of vulnerability can thus impact multiple institutions concurrently, such that cyber events increasingly represent seismic, systemic shocks rather than isolated incidents.

“Models such as Mythos illustrate the nature of the challenge because they amplify existing cyberattack techniques by operating at machine speed,” the International Monetary Fund (IMF) explained in a May 7 report. “Attackers have the advantage over defenders because discovering and exploiting vulnerabilities can occur faster than patching and remediation. In a financial system built on common software and shared service providers, this can create simultaneous vulnerabilities across many institutions.”

Operational constraints compound the industry’s challenges in this context. As vulnerability discovery accelerates, financial institutions may need to boost the frequency of system updates and security interventions, which, in turn, could trigger more frequent periods of system downtime, greater operational friction and heightened complexity in maintaining service stability.

Uneven access also plays a significant role in determining the sector’s resilience—or lack thereof. Advanced AI-driven cybersecurity tools require significant computational resources and technical expertise. Larger financial institutions are better positioned to deploy such systems at scale, while smaller institutions may face limitations in adoption. As such, inequality in defensive capabilities is more exposed across the financial ecosystem, with potentially significant implications for systemic resilience.

The increasing speed and interconnectedness of cyber risks have thus prompted financial authorities to frame cybersecurity in terms of threats to financial stability. The concern is not limited to individual breaches but also extends to the potential for correlated disruptions across multiple institutions and critical-infrastructure sectors.

In such scenarios, cyber incidents may propagate through payment systems, liquidity networks and operational dependencies, creating secondary effects that resemble traditional financial stress events. These could include disruptions to settlement systems, delays in transaction processing and reduced confidence in financial infrastructure.

“This is a wake-up call because cyber risk is moving to machine speed, while much of bank defence still operates at human speed,” Nitin Seth, ​co-founder and chief executive officer of Incedo, a data, digital and AI services firm, told Reuters. “It also breaks a long-standing assumption in banking security—that vulnerabilities can remain hidden for extended periods before they are discovered and weaponised.”

The convergence of intelligence assessments, frontier AI capabilities and systemic financial dependencies, therefore, points to a structural transition in the nature of cybersecurity. Vulnerability discovery is becoming continuous rather than episodic. Exploitation is increasingly driven by automated systems capable of operating across multiple stages of an attack simultaneously. And defence mechanisms must operate under similar time constraints, often within frameworks not designed for continuous, high-frequency adaptation.

For financial institutions and critical infrastructure providers, this creates an environment defined by persistent exposure and continuous remediation. Security outcomes are increasingly determined by the speed at which organisations can adapt to newly surfaced vulnerabilities and by their ability to manage correlated risks across interconnected systems.

The Five Eyes warning thus reflects recognition of this shift at an institutional level. The response now underway is to move towards a cyber environment characterised by machine-speed dynamics, in which stability depends less on eliminating risk and more on maintaining continuous operational resilience in an evolving, highly automated threat landscape.

 

Related Articles