Back to News
SecurityAI Understanding briefing

Palo Alto Networks warns of real‑time cyberattacks enabled by Mythos‑level AI models

Tom Scully, Palo Alto Networks’ Asia‑Pacific director, told ChosunBiz that open‑weight AI models matching Anthropic’s Mythos could appear within months, giving hackers the ability to launch attacks in near‑zero time.

4 min readRead the original reporting
Source-provided image accompanying Palo Alto Networks warns of real‑time cyberattacks enabled by Mythos‑level AI models
Attributed reportingSource recorded
Publisher
biz.chosun.com
Source link
biz.chosun.comhttps://biz.chosun.com/en/en-it/2026/09/26/LS6ZW5DSEFEY5DW3O6F4NQHXDA/?outputType=amp
Source type
Reporting by a news outlet — not a first-party document.

What we could not confirm independently: This claim is attributed to the named outlet. We did not verify it against a first-party document. (biz.chosun.com)

ContextUnderstand this in 60 seconds

Start here

Key terms

Weight
A learned numeric value that scales signals passing through a neural network.
Test yourselfAI Ethics Quiz

What happened

Tom Scully, director for government and critical infrastructure at Palo Alto Networks, warned that open‑ AI models with performance comparable to Anthropic’s Mythos may become publicly available in the next three to five months. In an interview with ChosunBiz after his keynote at SMARTCLOUD SHOW 2026 in Seoul, Scully said such models would let attackers execute “real‑time” cyber‑attacks, compressing the detection‑to‑exfiltration timeline to seconds. He cited Palo Alto’s own penetration testing of Mythos, which uncovered 75 vulnerabilities – up from five previously known – and reduced a two‑year assessment to three weeks. Scully urged corporations to adopt AI‑driven security platforms, such as Palo Alto’s Cortex, to cut mean‑time‑to‑detect (MTTD) and mean‑time‑to‑respond (MTTR) from minutes to seconds. He also highlighted the need for safeguards around autonomous security agents and referenced upcoming U.S. CMMC certification requirements that Korean firms must meet.

During his keynote at SMARTCLOUD SHOW 2026, Scully warned that the "golden window" for organizations to build AI‑based defenses is only three to five months before open‑ models with Mythos‑level capabilities appear. He emphasized that Mythos, unveiled by Anthropic in April 2026, already demonstrates expert‑level vulnerability detection.

Palo Alto Networks participated in Anthropic’s Project Glasswing consortium, gaining early access to Mythos for penetration testing. The testing revealed a jump from five to 75 identified vulnerabilities and compressed a two‑year assessment timeline to three weeks, illustrating the model’s potency.

Scully described the current security stack as fragmented, with corporations averaging 83 separate tools. He promoted Palo Alto’s Cortex platform, which consolidates data from up to 90 billion daily security events into actionable alerts, reducing MTTD to seven minutes and MTTR to one minute.

He also cautioned that autonomous AI agents, if left unchecked, could act beyond intended boundaries, urging the implementation of monitoring and safeguard mechanisms.

Source details: biz.chosun.com ↗

Why it matters

If open‑ models matching Mythos become widely accessible, the speed and sophistication of cyber‑attacks could increase dramatically, threatening corporations, critical infrastructure, and national security. The ability to automate vulnerability discovery and exploit generation in minutes – or even seconds – would shrink the defensive window that security teams currently rely on. Palo Alto’s own testing shows that cutting‑edge AI can uncover dozens of new flaws in weeks, suggesting that malicious actors could achieve similar results at scale. This shift could force a rapid overhaul of security operations, push firms toward integrated AI‑centric platforms, and accelerate regulatory scrutiny, especially in sectors bound by standards like the U.S. Department of Defense’s CMMC.

The emergence of powerful, openly available AI models could democratize advanced hacking techniques, eroding the traditional advantage that well‑funded defenders have over attackers.

Speeding up the attack lifecycle from hours to minutes would pressure organizations to rethink incident response processes, potentially requiring real‑time automation and tighter integration of AI across security tools.

Regulatory implications are significant: standards like CMMC may be updated to address AI‑enabled threats, and governments could consider export controls on high‑performance models, echoing recent policy debates in the U.S. and Europe.

The financial impact could be substantial, as faster breaches increase data loss, ransom demands, and remediation costs, while also exposing supply‑chain vulnerabilities in critical sectors such as defense and aerospace.

Interactive Mechanism

Interactive Mechanism: How It Actually Works

Explore the underlying technology behind this development interactively.

Agent Lifecycle Stage:
1
User Intent & Planning: "Audit customer refund request #4092 and settle payment."
2
Tool Calling: Emits structured JSON call crm_get_transaction(id='4092').
3
Guardrail & Verification:🛡️ Paused: High-value action requires human operator sign-off.
4
Final Settlement: Refund recorded, email receipt dispatched, and audit log stored.
Core takeaway: An AI agent is not just a language model—it is a closed loop of planning, tool invocation, and environment feedback. Production systems require self-healing retries and strict human approval guardrails.
Interactive Concept Check+10 Points
AI Ethics Quiz

Impossibility results in algorithmic fairness (e.g. Kleinberg et al., Chouldechova) show what?

What to watch next

Key developments to monitor include the release of any open‑ models claiming Mythos‑level performance, adoption rates of AI‑centric security platforms (e.g., Cortex), and policy responses such as tighter export controls or new certification mandates. Watch for announcements from Anthropic, other large model developers, and open‑source communities about model releases, as well as any coordinated industry efforts to share threat intelligence on AI‑driven attacks.

Release timelines and licensing terms of any open‑ models claiming Mythos‑level performance.

Adoption metrics for AI‑driven security platforms, especially those offering unified management of dozens of tools.

Policy developments around AI model export controls, CMMC updates, and other national cybersecurity frameworks.

Industry collaborations or consortia focused on sharing AI‑generated threat intelligence and best‑practice defenses.

Related guides & quizzes

AI EthicsAI AgentsAI Models ExplainedFuture of AITest what you know — try a free AI quizLook up an AI term in our glossaryFollow the AI regulation tracker
Found this useful?