Three wake-up calls in four months. The industry is testing the attacker. It also needs to rethink the defender.

Faced with autonomous attackers, the cybersecurity industry has largely converged on the same response: more testing.

In April 2026, Anthropic disclosed that Mythos, restricted from public release, had autonomously discovered and exploited thousands of zero-day vulnerabilities across major operating systems and browsers, including a seventeen-year-old FreeBSD flaw that gave an unauthenticated attacker full root access. The UK’s AI Security Institute ran its own evaluation and confirmed the model could take over a simulated corporate network end to end, without a human directing any step after the initial prompt, in three of ten attempts. Anthropic restricted access to a small number of trusted organizations instead, precisely because the offensive capability had outrun what most defenders could handle.

Two months later, Anthropic’s own red team gave the second signal, and it was arguably the more important one. Researchers studied 832 accounts banned from Claude for malicious cyber activity, mapping nearly 14,000 observed techniques against the MITRE ATT&CK framework. The finding that mattered wasn’t technique count or technical sophistication, both of which turned out to be weak predictors of how dangerous an actor actually was. What predicted danger was whether AI had been wired into live operational execution rather than used for research and planning.

The clearest case was a state-linked actor Anthropic tracked as GTG-1002, who scored as high-risk not because the model was unusually capable, but because of what had been built around it: an AI coding tool wired into a broader offensive platform connected to open-source penetration testing tools, allowing reconnaissance to flow directly into exploitation, exploitation into credential theft, and credential theft into lateral movement as one continuous operation instead of a series of tasks a human had to hand off one at a time. The model wasn’t what made the actor dangerous. The coordination architecture around it was.

Then, in July, it stopped being something you had to go looking for in a lab report or a red team study. Hugging Face disclosed that its production infrastructure had been breached by an autonomous AI agent that took more than 17,000 actions over a single weekend, reaching internal datasets and service credentials. Days later, OpenAI confirmed the agent belonged to its own models running during what was meant to be an internal security test, not a hostile actor at all. Hugging Face said it needed AI assistance to reconstruct the intrusion because it moved across too many systems too quickly for a human team to trace by hand.

That is three signals in four months. A demonstration that the capability exists. A study showing real attackers are already organizing around it, not just using it. And a live incident, at a company that builds this technology, where nobody was even trying to cause harm.

No wonder the industry has rallied around testing. Continuously simulating what an attacker like that would do to your environment, before it happens for real, is a completely reasonable response to everything above, and it is the right first move. It answers a question worth answering: where are we exposed. What it does not answer is what happens after something gets through anyway, and the honest read of the three events above is that something will.

Testing and Fixing Are Moving Together, and That Deserves Credit

The old critique of offensive testing was that it produced a report nobody acted on. That critique is losing its force.

DARPA’s AI Cyber Challenge is a useful marker here. At the 2024 semifinals, the best autonomous systems identified 37 percent of planted vulnerabilities in real open-source projects and patched 25 percent of them. One year later, at the 2025 finals, those numbers jumped to 86 percent identification and 68 percent patching. That is not incremental progress. That is a category learning to close the loop in the space of a single product cycle.

Not all of that closing looks the same, though. A flaw in home-grown code has a clear owner: an autonomous pentest catches it, an agentic tool generates the fix, and it moves through the same code review and CI pipeline any other change would, all without the SOC. Misconfigured cloud permissions, exposed APIs, and access that’s broader than it needs to be don’t have that kind of clear owner. They land on the SOC, and closing them is a race against the same autonomous attacker this piece keeps coming back to, one that can find an overly permissive role or an exposed endpoint the moment it exists, not months later.

This matters, because it would be easy to build a case for “the SOC needs to transform” on a strawman where prevention is stagnant and response is the only lever left. That is not accurate. Prevention is improving quickly, and it deserves the investment it is getting.

But faster, better prevention does not reduce how often you’ll need a good response. The attack surface is growing faster than any testing program can cover it, and the gap between a vulnerability becoming known and it being exploited keeps shrinking. If anything, that means you need a strong response more often, not less. What better prevention actually changes is which failures get through. The ones that reach production are, almost by definition, the ones automated testing didn’t catch, which makes them the harder cases, not the easier ones.

What Changes When the Attacker Is Autonomous

A human attacker researches a target, forms a hypothesis, and executes one step at a time. Every step costs time.

An autonomous attacker, the kind behind all three disclosures above, does not work that way. It can run reconnaissance, exploit development, and lateral movement in parallel rather than in sequence. It does not get tired, wait for a colleague to review its work, or need a meeting to decide what to do next. That is exactly the pattern Anthropic’s researchers found inside GTG-1002’s operation: reconnaissance flowing into exploitation, exploitation into credential access, and credential access into lateral movement, as one continuous chain rather than a queue of tasks waiting on a person to move each one forward.

The change isn’t a new class of vulnerability. It is that offensive operations no longer need a person running each step before the next one can start.

Defenders, meanwhile, are still largely organized around exactly the coordination overhead the attacker no longer has.

The SOC’s Real Bottleneck Was Never Detection

Security teams have more telemetry, more detection content, and more tooling than at any point in the industry’s history. That was never the constraint.

The constraint is what happens between the alert firing and the response being executed. A single investigation routinely needs the identity team to confirm whether an access pattern is legitimate, IT or endpoint operations to pull device context, cloud or platform engineering to confirm what the workload actually does, and the application or business owner to say whether taking it offline is even an option. Recent industry surveys put the average mid-market SOC at thousands of alerts a day, a volume no human team can investigate one alert, and one round of cross-team calls, at a time.

Every one of those handoffs is a place where a human is waiting on another human in a different department, with a different manager and a different set of priorities. That model made sense when attackers also moved at human speed, because both sides were bound by the same coordination cost. It does not make sense against an attacker that runs every stage of an intrusion at once.

The SOC Is Already Being Priced Like the Next Big Bet

If continuous testing is attracting investment because organizations need to understand the attacker faster, the same logic should already be driving investment into the response side.

It is. Money is moving into this category fast, and much of it is landing in the same place: an assistant bolted onto a human-led workflow. Better search, faster investigations, sharper summaries.

But that’s not where this is headed. The smaller, faster-growing slice of that investment isn’t buying analysts a better assistant. It’s building systems that don’t just recommend the next move, they make it, with a human governing the outcome instead of approving every step. That’s the part of the market still finding its footing, and it’s the part that actually closes the gap instead of narrowing it.

The attacker’s advantage was never that any individual step was slow. It was that defenders needed multiple humans, systems, and teams to align before acting. A faster assistant inside that same structure narrows the gap. It does not close it.

Closing it requires rebuilding coordination around a layer that sits across identity, endpoint, cloud, and the SOC itself, correlating what each of those systems knows and acting on it directly. That does not mean ripping out the existing stack. Point tools will keep improving, and organizations will keep needing best-of-breed capabilities as new attack surfaces emerge. The transformation is in the layer that connects those systems and decides what to do with what they collectively know, not in replacing any one of them.

Why Isn’t the Industry Moving Faster?

If the model is available and the results are real, why isn’t the industry moving faster?

It is not purely a purchasing decision, and framing it that way lets leadership off the hook too easily. It takes a leader willing to fund a structural change while still fighting today’s fires, not just a budget line. That is a harder ask than buying a platform.

Most enterprises are already past the point of experimenting with agents. One recent survey of over 900 security practitioners found 81 percent of technical teams had moved past planning into active testing or production, yet only 14 percent had full security approval to do so. Almost 90 percent had already had a confirmed or suspected AI agent security incident in the past year. Teams are moving without leadership having made the transformation decision at all, which is its own kind of risk.

Where leadership has engaged, the barrier they name most is governance, not capability. Roughly two-thirds of organizations cite security and risk concerns as their top barrier to scaling agentic AI, ahead of regulation or technical limitations, according to recent McKinsey research. More than a third of executives report having no formal plan for supervising AI agents at all, and a similar share admit they could not immediately shut down a rogue agent if they needed to.

None of this means the caution is misplaced. Governing a system that can take action inside your environment is a genuinely harder problem than governing a system that only makes suggestions.

But caution without a transformation plan is not caution.

It is delay with a good excuse.

This Is Not a Tooling Problem

The organizations that struggle with this will not be the ones that lack access to the technology.

The technology is already here. Security teams are using AI to investigate alerts, enrich context, and automate pieces of response. Autonomous testing is demonstrating that AI systems can continuously evaluate environments and identify attack paths faster than traditional processes allowed. The question of whether AI can do meaningful security work is settled.

The harder question is whether an organization is willing to change how the work gets done, not just who or what does it.

Adding AI into an existing SOC is the easy version of this. It can summarize an alert, enrich an investigation, or recommend a response, and those improvements are real. They make individual analysts faster. What they do not do is change the operating model underneath them, because the SOC was built around human coordination for good reasons: it creates accountability, manages risk, and keeps decisions tied to business context.

That structure is not the problem.

The problem is that it assumed the other side would keep moving at human speed too.

An autonomous attacker does not wait for a different team to provide context, and it does not pause while ownership gets clarified. That is the coordination overhead defenders still depend on and attackers no longer have.

Closing that gap means answering two questions no single tool can answer for you. What can the system act on independently? What still requires sign-off?

Both questions already have practical answers emerging.

What a system can act on independently is increasingly an identity question. Agents need scoped, time-bound permissions instead of standing access. They need to have exactly the access required for a task, with the ability to understand what they can touch and when that access expires.

What still requires sign-off comes down to which actions are safe to reverse. A governed system can isolate a compromised endpoint or cut off a stolen login on its own, because if it is wrong, access can be restored. It should not take a production system offline or lock out an executive on its own, because the business impact may not be reversible.

The line is not about how serious the alert looks.

It is about whether undoing the action is easy or not.

Autonomous red teaming earned its budget by answering a question leaders already knew how to ask: where are we exposed. The response side earns its budget by answering the harder one: when something gets through, can we act as fast as what got through us.

That is a redesign, not an upgrade, and it is the only version of this that actually closes the gap rather than narrowing it.

Where This Leaves the Trade-Off

None of the three disclosures that opened this piece were hypothetical. Together they show offensive AI capability crossing a line most defensive programs were not built to handle: demonstrated under controlled conditions, confirmed inside a real attacker’s operation, and proven by accident inside a production environment, all within a single quarter.

Every organization now faces a smaller version of that same trade-off. Building the operating model described here means putting your name on an agentic system that can take action inside your environment, and that is a real decision, not a formality.

But the field underneath it is moving fast. Governance, coordination, and identity models for agents are being built out in real time, by practitioners figuring it out as they go, not left waiting for someone else to solve it first.

Not building it means staying in a model bounded by how quickly five different teams can get on a call.

That risk doesn’t ask anyone to sign off on it.

It just sits there, invisible, until the night it isn’t.