Logo
FrontierNews.ai

Claude Mythos Just Broke Into a Real Corporate Network. Here's What That Means.

Anthropic's Claude Mythos became the only AI model to fully compromise a real corporate network in a new security benchmark, achieving a score of 80 and gaining complete administrator control on every attempt. The finding, published by defense consulting firm Booz Allen on Wednesday, tested 18 of the world's most advanced AI models from American and Chinese developers against a live intrusion scenario with no human guidance. Yet the headline-grabbing result masks a more unsettling discovery: the model itself may matter far less than the software that controls it.

What Did Booz Allen Actually Test?

Booz Allen's Cyber Weapon Index measured how far each AI model could advance through a real intrusion without any steering or tool menus. The firm gave each model an attacker machine and issued commands one at a time, deliberately stripping away the engineering that normally surrounds production AI systems. The goal was to measure what a model could do alone, in its rawest form.

The scoring combined two separate challenges. First, researchers measured whether each model could find vulnerabilities in compiled software with no source code available. Second, they tracked how far the model could advance through an intrusion against a defended Active Directory network, starting from first access all the way to full domain administrator control. Booz Allen scored what network logs actually proved happened, not what the models claimed, using traffic records, security logs, and intrusion-detection sensors.

Claude Mythos dominated the results. Given a stolen employee credential, it took administrator control on every single attempt. It also worked out its own route to higher privileges rather than following a script. On the harder test, with no credentials at all, it broke in from outside and took the domain anyway. Every other model failed that challenge.

How Did Other Models Perform?

The rankings revealed a significant gap between the top performer and the rest of the field. Behind Claude Mythos came Grok-4.5 on a score of 49 and GPT-5.6 Sol on 46. Meta's Muse Spark 1.1 and Moonshot's Kimi K3 tied on 38, with Z.ai's GLM-5.2 on 37 and Claude Opus 4.8 on 36. Alibaba's Qwen3-Coder finished last on 4. Three models besides Mythos took full domain control, and four more moved laterally inside the network, with all but one getting in unaided.

But here's where the story gets complicated. Claude Sonnet 5 placed 15th of 18 with a score of just 13 when tested alone. However, when Booz Allen paired it with an attack harness, the software that connects a model to hacking tools and keeps it on task, it rivalled Mythos. That is a gap of 67 points closed by plumbing.

Why the Software Around the Model Matters More Than You'd Think

A harness lets a model stay focused, adapt, recover from failure, and chain single actions into a sustained operation. Booz Allen's conclusion is blunt: the model is no longer the unit of risk. The system is. This finding suggests that the engineering surrounding an AI model may be more important than the model's raw capabilities when it comes to real-world threats.

The firm also concedes what it has not measured. It has not tested Chinese or open-weight models paired with optimised harnesses. Its results, however, strongly suggest that fully capable combinations already exist. This gap in testing is significant because it means the true landscape of AI-enabled cyber threats may be even broader than the index reveals.

A second finding received almost no attention when the report was published. One model declined a task on the grounds that it had no credentials. Its cyber-tuned sibling, handed the identical task, complied and carried it out. Booz Allen draws a general rule from that: guardrails are not a fixed property of a model, and their effectiveness shifts with context and configuration. A refusal in one setting tells you nothing about another.

What Are the Real-World Implications?

  • Vulnerability Detection Varies Widely: Against a deliberately planted flaw, all models scored near the ceiling. But against a genuine unseen flaw buried in a large production library, every one of nine frontier models scored zero. Only Anthropic's frontier models spotted that flaw, and only Mythos understood it well enough to exploit it.
  • Defenders Still Have Time: Booz Allen frames the gap between benchmark performance and real-world offensive capability as breathing room. Real-world attacks still trail what these models can do in controlled tests, which buys defenders time to prepare.
  • Rapid Capability Growth Expected: The firm expects most of the 18 models tested to reach Mythos's level within six months, calling mainstream AI-enabled attacks imminent.

Booz Allen published the index alongside Vellox Labs Guile, a product built to disrupt autonomous attacks. The same release says coordinated counter-AI playbooks cut attacker success by more than 95% in the firm's own testing, though nobody has verified that figure independently.

What Policy Changes Are Being Proposed?

The report separates its policy recommendations from its sales pitch. Booz Allen wants enforceable, sector-specific deadlines forcing critical infrastructure operators to prove they can contain an intrusion. The firm also calls for a national programme testing foreign and open-weight models under realistic conditions. Additionally, it wants governed access for vetted defenders to the capabilities they are meant to defend against.

The report cites July's Hugging Face breach as the moment a model completed the kill chain in the real world rather than a laboratory. One major model is notably missing from the index itself. OpenAI's Astra was not tested, and OpenAI said on Tuesday that it had reached the company's critical cybersecurity threshold. The index arrives measuring a field that has already moved.

How Should Organizations Prepare for AI-Enabled Attacks?

  • Test Your Defenses: Organizations should conduct their own intrusion tests using frontier AI models to understand their actual vulnerabilities, not just theoretical ones.
  • Implement Coordinated Playbooks: Booz Allen's testing suggests that coordinated counter-AI playbooks can significantly reduce attacker success rates, making them a priority for security teams.
  • Focus on System-Level Security: Since the software surrounding a model matters as much as the model itself, invest in robust tooling and orchestration that can detect and disrupt autonomous attacks.
  • Monitor Model Configuration Changes: Guardrails shift with context and configuration, so security teams should monitor how AI models are being tuned and deployed within their organizations.

The Cyber Weapon Index reveals that AI-enabled cybersecurity threats are no longer theoretical. Claude Mythos's ability to break into a real network unaided demonstrates that frontier models have reached a level of autonomous capability that demands immediate attention from defenders. Yet the more important lesson may be that the model alone is not the threat. The system built around it is. As organizations prepare for an era of AI-enabled attacks, they should focus less on which model is being used and more on how it is being orchestrated, controlled, and deployed.

" }