Back to feed

Booz Allen report finds Claude Mythos completes autonomous cyber kill chain

2 min
Booz Allen report finds Claude Mythos completes autonomous cyber kill chain

This digest was compiled by AI from multiple sources — links to the originals are below.

Booz Allen Hamilton's Cyber Weapon Index found Anthropic's Claude Mythos autonomously completed a full cyber kill chain in tests. The report evaluated 18 AI models from the U.S. and China, with several others reaching domain access or lateral movement. Booz Allen warns mainstream AI attacks are imminent, with most models expected to reach similar weaponization within six months.

Key Facts

  • Booz Allen Hamilton's Cyber Weapon Index evaluated 18 AI models, nine from the U.S. and nine from China.
  • Anthropic's Claude Mythos was the only model to autonomously complete the entire cyber kill chain, including identifying vulnerabilities, gaining network access, and achieving administrator-level control.
  • xAI's Grok-4.5 and OpenAI's GPT-5.6 Sol reached full domain access or lateral movement within networks.
  • Booz Allen expects most tested models to reach similar weaponization levels within six months.
  • The report urges the U.S. to set deadlines for critical infrastructure to demonstrate resilience against AI-enabled attacks.

Cyber Weapon Index Findings

Booz Allen Hamilton's Cyber Weapon Index evaluated 18 AI models, nine from the U.S. and nine from China. Anthropic's Claude Mythos was the only model to autonomously complete the entire cyber kill chain, demonstrating the ability to identify vulnerabilities, gain network access, and achieve administrator-level control. Several other models, including xAI's Grok-4.5 and OpenAI's GPT-5.6 Sol, showed significant progress in autonomous attack capabilities, reaching full domain access or lateral movement within networks.

Attack Harness Amplification

The report emphasizes that the 'attack harness' software, which connects AI models to hacking tools, dramatically amplifies their offensive potential. Booz Allen warns that mainstream AI attacks from financially motivated criminals and state-sponsored actors are imminent. Most tested models are expected to reach similar weaponization levels within six months.

Policy Recommendations

The firm urges the U.S. to set deadlines for critical infrastructure to demonstrate resilience against AI-enabled attacks. Booz Allen also calls for the development of superior offensive and defensive AI capabilities.

2 sources

Time · lag behind first