After Mythos, zero trust alone won’t be enough against AI-powered attacks

In April, Anthropic made its powerful new Claude Mythos artificial intelligence model available to a select number of organizations as a preview of its remarkable capabilities to help identify unknown cybersecurity vulnerabilities. Within hours, an unauthorized group reportedly accessed it, and what was intended as a tool to test enterprise security suddenly had the potential to become one of the most effective hacking models available to bad actors.

The security landscape has fundamentally shifted. It is a false hope to believe that threat actors will not eventually be able to obtain Mythos or something similar to it. Anthropic itself estimates other AI labs could develop their own models that match the capabilities of Mythos in as few as 18 months. The likelihood of widespread availability is only increasing.

Organizations are now operating in a very different world when it comes to cybersecurity.  Enterprises today need to revisit their current playbooks and modernize their systems against these new powerful AI-enabled threats, especially America’s defense and intelligence communities. What is required is a new approach to generally adopted cybersecurity norms, and it starts with acknowledging one truth: Zero trust alone simply isn’t enough.

Impact on U.S. defense and intelligence

One of the most alarming possible consequences of Mythos falling into the hands of bad actors is that it levels the playing field. It essentially puts a new cyber weapon in the hands of an adversary who otherwise would have been at a disadvantage.

What makes Mythos so powerful is its ability to discover zero-day vulnerabilities incredibly quickly and use those vulnerabilities to perform an autonomous scalable attack. Now, practically any group or nation-state could have this capability against U.S. defense and intelligence networks.

While many defense and intelligence IT teams have a leg up on their private sector counterparts given the architectures they have already built, those that are still modernizing their systems are particularly vulnerable. A recent Everfox survey of defense IT leaders found that 78% acknowledged outdated infrastructure as a primary source of cyber vulnerability. They should have particular reason to accelerate modernization now.

Because AI models such as Mythos provide America’s adversaries a cheaper, faster way to exploit possible cyber vulnerabilities, the U.S. must now look for ways to regain the advantage.

Traditional cybersecurity models are now becoming obsolete

The instinct of many IT teams is to reinforce their existing security blueprint by providing better threat intelligence, faster threat detection, improved automated response and more identity controls. While every one of them is important, it may be unrealistic to expect them to serve as the foundation of effective cybersecurity today.

Threat intelligence becomes less effective as exploitation timelines shorten. The amount of time it takes for a publicly released cybersecurity vulnerability to actually be exploited has sharply declined from more than one year in 2020 to just 10 hours today. As more AI-enabled hacking tools enter the environment, that gap can be expected to continue closing considerably fast.

Because cyber vulnerabilities now have the potential to be exploited by AI models operating at machine speeds, threat detection safeguards are likewise losing effectiveness. Threat detection and response can buy some time, and every second can matter, but in today’s world of AI-driven attacks, they are less reliable as effective safeguards.

Identity controls may no longer be as effective as a primary method of securing sensitive networks, either. Make no mistake, zero trust access policies are important. The progress made adopting zero trust identity controls should continue. But because many significant identity breaches of the past three years, from Storm-0558 to Scattered Spider, began at an entry point and progressed to a crown-jewel target, it is clear that in some cases access control alone can’t be relied upon as a cornerstone of cybersecurity.

The lesson here is to stop designing systems focused on keeping attackers out of everything, and start architecting them to protect the critical things they should never be allowed to reach.

The security architecture that holds the line

What does such a design look like? It should be built around three principles:

Consider the outer tiers expendable. Just assume that enterprise laptops, productivity environments, and standard endpoints are likely to be compromised. They should certainly be fortified to slow attackers and produce informative telemetry, but save valuable time and budget for securing network boundaries and protecting the crown jewels.

Let the boundaries between the tiers do the work. Every transfer of data from an outer tier to an inner tier should cross an enforcement point that authorizes its movement based on what the data is, not who claims to be sending it. This cross-domain transfer inspects the data’s content, enforces policies that validate if it is permissible to enter, and logs when it does so. It constrains the environment and makes it easier to control, monitor and defend.

Protect crown jewels with security that cannot fail the same way as the outer tier. If the outer tier falls because identity was compromised, that cannot provide the same entry path to the crown jewels. Reinforce this layer with hardware-enforced separation and data policy enforcement that requires a claim the compromised outer tier cannot produce. This helps crown jewels only be compromised if an attacker defeats a second, architecturally different enforcement layer, and any attempt to do so will be detected at the monitored boundary.

Many defense and intelligence organizations have architected exactly this way for decades by separating high-side classified networks from low-side untrusted ones, providing secure cross domain data transfer with content inspection, and establishing enclaves with distinct enforcement boundaries. Mythos now gives all national security agencies increased urgency to modernize their networks this way. Because the question is no longer whether an attacker could gain the capability to compromise a critical system; it is what your architecture will look like when they do.

Petko Stoyanov is chief technology officer for Everfox.

Copyright
© 2026 Federal News Network. All rights reserved. This website is not intended for users located within the European Economic Area.

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *