The Mythos Era and the Rise of Autonomous AI Attacks

The Mythos Era and the Rise of Autonomous AI Attacks
# CS4Cyber

What happens when AI-powered attacks begin moving faster than human-led security operations?

June 19, 2026
Mike Wilkes
Mike Wilkes
Shareth Ben
Shareth Ben
Omid Razavi
Omid Razavi
The Mythos Era and the Rise of Autonomous AI Attacks
What happens when AI-powered attacks begin moving faster than human-led security operations?
That question framed our recent CS4Cyber session with  Mike Wilkes , CISO at  Aikido Security  and a former CISO at Major League Soccer, Marvel, ASCAP, and architect of major infrastructure projects for ING Bank, Sony, and Macy’s.
Mike joined  Shareth Ben  and me for a discussion on the Mythos Era, a new phase of cybersecurity shaped by autonomous AI systems capable of finding, combining, and exploiting vulnerabilities at machine speed.
The session brought together cybersecurity, customer success, support, services, and post-sales leaders. The discussion was technical, but its implications reach well beyond the security organization.

A Step Change in Capability

Mike described Mythos-class models as a meaningful increase in code analysis and reasoning capability.
These systems can review large volumes of code, identify vulnerabilities that have remained undiscovered for years, and determine how weaknesses might be combined into an exploitable path.
The truth is somewhere between ‘the sky is falling’ and ‘this is nothing.’ Mythos represents a real step change in capability.
The immediate effect is a sharp increase in the number of vulnerabilities found and the speed at which they may be exploited.
Mike noted that the typical exploitation window for some zero-day vulnerabilities has fallen from days or weeks to hours.
The exploitation window for a zero-day used to be measured in days or weeks. Now it can be measured in hours.
Most organizations cannot test and patch production systems within that timeframe.
Who can patch production in three hours? Almost no one.
This creates an uncomfortable gap between machine-speed attacks and human-speed response. That gap may widen before defensive practices catch up.
Mike also cautioned against treating Mythos readiness as a simple certification or end state.
There are no Mythos-ready organizations yet. Even Anthropic is not ready to have Mythos-class tools pointed at it by threat actors.

Automated Testing Changes the Economics

One of the clearest examples came from Mike’s experience with autonomous penetration testing.
A traditional penetration test of an API with hundreds of endpoints might cost between $7,000 and $15,000 and take several weeks to complete.
An autonomous test of a similar environment cost approximately $4 and took around 80 minutes. It identified several critical vulnerabilities and validated which findings were genuinely exploitable.
The difference in cost and speed is significant.
Testing that once required a specialist engagement can now be performed continuously. Organizations can test far more applications, more often, and earlier in the development process.
Mike also shared examples involving hundreds of applications, where autonomous systems produced actionable findings within hours and enabled some teams to verify fixes within the same day.
The larger challenge soon becomes operational.
Once thousands of vulnerabilities are identified, organizations must determine which ones are reachable, exploitable, and connected to critical systems. They must also know who owns the affected code and who has the authority to act.
Finding vulnerabilities is no longer the hardest part. The harder questions are which ones are reachable, which are exploitable, and who owns the fix.
Finding vulnerabilities becomes easier. Prioritizing and fixing them becomes the harder work.

Vulnerability Scores Are Losing Their Value

Security teams have traditionally relied on CVSS scores and similar measures to decide which vulnerabilities to address first.
Mike questioned whether that model remains sufficient.
AI systems can combine several lower-severity weaknesses into a serious attack path. A medium-rated vulnerability may become critical when paired with another weakness or exposed through a reachable service.
Security scoring is becoming less useful because AI can chain two medium-severity vulnerabilities into one critical attack path.
This changes the unit of analysis.
The question becomes whether a vulnerability can be reached, exploited, and connected to something that matters.
Mike pointed to EPSS as one useful approach because it estimates the probability that a vulnerability will be exploited. Even that must be considered alongside the organization’s own architecture, exposure, and business context.
A high score in an isolated internal system may carry less immediate risk than a moderate weakness exposed through an internet-facing service.
Security teams need a clearer picture of actual risk rather than relying on a single score.

The Defender Still Has an Advantage

The discussion was not entirely pessimistic.
Defenders know their own code, architecture, release schedules, and operating environment. Attackers often begin from the outside with limited visibility.
Defenders still have an advantage. We know our code, architecture, release schedules, and operating environment. Attackers usually begin from the outside.
That creates an advantage when organizations test their own software before release, maintain accurate asset inventories, and build security checks into development workflows.
AI can help defenders review source code, assess dependencies, test applications, and validate fixes before changes reach production.
Mike’s view was that organizations may eventually reach a point where exploitable code is identified and corrected before release.
The goal should be to stop shipping exploitable code.
The near term will be difficult. Attackers can adopt autonomous tools quickly, while enterprise security teams must work through governance, testing, ownership, and change-management constraints.
Still, the same technology increasing offensive capability can strengthen defense.
Mike also made the point that organizations do not need access to the most advanced frontier model to improve their security posture.
You do not need a frontier model to do good security. Well-orchestrated open models can already deliver meaningful results.

The Basics Matter More Than Ever

A recurring point throughout the session was the importance of basic security discipline.
Organizations still struggle with asset inventories, identity controls, API security, patching, DNS configuration, software dependencies, and production visibility.
Autonomous attacks do not make these controls irrelevant. They make weaknesses in these areas easier to find and exploit.
Mythos is a shock to the system. It is forcing organizations to return to the basics and finally do vulnerability management well.
Mike encouraged leaders to focus on several practical questions:
  • Do we know where AI is being used?
  • Do we know which applications and services are exposed?
  • Can we identify every software component and dependency?
  • Do we know who owns each system and each fix?
  • Can we test and deploy changes quickly without introducing new risk?
These questions are familiar. The required speed and consistency are changing.

From Periodic Reviews to Continuous Security

Many security processes still operate on fixed schedules.
Penetration tests may occur annually. Patches may follow monthly cycles. Governance reviews may take weeks. Production changes may require long approval paths.
Autonomous attacks will not follow those calendars.
Security testing, vulnerability assessment, and remediation will need to become continuous parts of software development and operations.
This will place greater importance on infrastructure as code, representative test environments, automated regression testing, and the ability to replace systems quickly rather than manually repairing each one.
It will also require greater confidence in automated defensive actions.
Human judgment remains essential, especially where customer impact, business continuity, and accountability are involved. Human approval cannot remain the constraint on every routine decision when threats are evolving within minutes.

Implications Beyond Security

The Mythos Era also has consequences for customer-facing organizations.
Customer success, support, and services teams may be involved in incidents that develop faster and affect more customers at once. They will need clearer protocols, better access to trusted information, and closer alignment with security and engineering.
Customers will expect timely explanations and evidence that risks are being addressed.
This makes cyber resilience part of the customer relationship.
Security leaders and post-sales leaders need a shared understanding of exposure, communication, customer impact, and recovery. That work should begin before an incident occurs.

The Work Ahead

The Mythos Era does not require organizations to abandon everything they know about cybersecurity.
It requires them to perform the fundamentals with greater speed, visibility, and discipline.
Accurate asset data matters. Ownership matters. Reachability matters. Testing must happen earlier and more frequently. Remediation must become faster and increasingly automated.
The organizations that make progress will be those that connect security architecture with software delivery, operating accountability, and customer trust.
Thank you to Mike Wilkes for sharing his experience and practical perspective, to Shareth Ben for guiding the discussion, and to everyone who contributed questions and comments.
We created CS4Cyber to bring cybersecurity and post-sales leaders together around the issues affecting customer trust, resilience, and long-term value.
Join the  CS4Cyber  at SuccessLab community to continue the discussion, connect with fellow leaders, and access recordings and transcripts of our sessions.
Comments (0)
Popular
avatar
ďťż
Dive in

Related

Video
The Mythos Era and the Rise of Autonomous AI Attacks
By Mike Wilkes • Jun 18th, 2026 • Views 38
Blog
The Rise of Intelligent Loyalty
Dec 30th, 2024 • Views 2
Video
The Mythos Era and the Rise of Autonomous AI Attacks
By Mike Wilkes • Jun 18th, 2026 • Views 38
Blog
The Rise of Intelligent Loyalty
Dec 30th, 2024 • Views 2
Terms of Service
Your Privacy Choices