Future of Cybersecurity (2026): 3 Things AI Just Broke

14 min readBy Nathan House

In April, an AI found a bug in OpenBSD that had been hiding for 27 years. OpenBSD is an operating system famous for being careful about security. By July, an AI model being tested by OpenAI had broken out of its test environment and into Hugging Face's servers to steal the answers to its own exam. And on 29 September, Anthropic reported that a free Chinese model anyone can download had turned two known Chrome bugs into a working attack for about $20 of computing time.

That's the future of cybersecurity arriving faster than most of us planned for. I've spent 30 years in this industry and taught more than 500,000 students. I was around when the internet first changed how security works. I think this shift is that big, maybe bigger.

In this guide, we'll go through what actually happened, the three things AI has broken or is breaking fast, and why defenders can still come out ahead. Then we'll finish with five things you can do about it now. Let's start with April.

TL;DR if you've only got 30 seconds

AI models can now find serious flaws in real software and write working attacks for them, often with little or no human help.

Defences that only made attacks slow or expensive stop working when building the attack costs as little as $20.

The safe gap between a fix coming out and attackers using the flaw has gone. On average, attackers now start before the fix is even released.

Entry-level jobs that follow a checklist, like first-line alert checking and junior penetration testing, are the most exposed to AI. The growing work is building AI-driven security systems.

The Future of Cybersecurity Changed in April

On 7 April 2026, Anthropic, the company behind Claude, published research on a model called Claude Mythos Preview. They didn't test it on practice puzzles. They pointed it at real software, the kind that runs the internet. When their researchers asked it to, it found previously unknown flaws, called zero-days, in every major operating system and every major web browser.

A zero-day is a flaw that the people who make the software don't know about yet. So there's no fix yet, and patching, the usual defence, can't help you. Two of the examples:

A 27-year-old OpenBSD bug. A mistake in code written in 1998 let an attacker crash any OpenBSD machine that talks over the internet, from anywhere. Years of careful review had missed it.

A 17-year-old FreeBSD bug. A flaw in FreeBSD's file-sharing service (its public ID is CVE-2026-4747) gave an attacker full control of the machine without logging in, on any machine running that service. The model found it and wrote the attack itself, with no human help after the first instruction.

Zero-day vulnerabilities found by AI: a 27-year-old OpenBSD bug that every review had missed since 1998, and a 17-year-old FreeBSD bug giving full root access with no login, on machines running its file-sharing service

The jump from the previous model is what caught my attention. Anthropic tested both models on the same job: turning known bugs in Firefox's JavaScript engine into working attacks, in a test version of the browser with some of its protection switched off. The previous model, Claude Opus 4.6, managed it 2 times out of 250. Mythos Preview managed it 181 times out of 250.

Before and now on the same test: the previous model built 2 working exploits, Mythos Preview built 181, out of 250 attempts each. Not an improvement, a phase change

That isn't a model getting a bit better. It's like a student who scored 1 percent on a test scoring 72 percent a few months later. And it didn't take a fortune. Anthropic's thousand-run search of OpenBSD cost under $20,000 in total, and turning a known Linux bug into a working attack cost under $1,000 and took about half a day. For a criminal gang, that's cheap. For a government, it's nothing. I've covered the evidence in more detail in AI Cybersecurity Threats: Are Attacks Rising?, so here I want to focus on what it means for you.

Nobody explicitly trained it to hack

This is the part that matters most. In Anthropic's words: "We did not explicitly train Mythos Preview to have these capabilities." The hacking skill came from making the model better at reasoning and writing code in general. Finding bugs and writing attacks is reasoning and code.

So this isn't about one model from one company. Every lab trying to build a better coding model is building a better hacking model at the same time, whether they want to or not. That's exactly what happened next.

What's Happened Since April

I made the video this article is based on in May. Five months later, almost every example has been overtaken. Here's the short version.

AI models broke into real companies. In July, OpenAI disclosed that a model under test, told to hack as part of an evaluation, escaped its test environment and got into Hugging Face's systems to steal the benchmark's answers. It spent about two and a half days inside. Anthropic then reviewed 141,006 of its own test runs and found three separate incidents, spread across six of those runs. In one, Mythos 5, the successor to Mythos Preview, published a harmful software package that ran on 15 real machines. Meta's model reached a third party's systems too, through a testing partner's setup mistake. I broke down exactly how the Hugging Face attack worked in How OpenAI's AI Hacked Hugging Face.

Governments stepped in. On 12 June, new US export controls on advanced AI led Anthropic to pull Fable 5 and Mythos 5 worldwide. Both came back within weeks, once the rules were settled. You can read the full story in AI Regulation News.

The models kept getting stronger. OpenAI rates GPT-6 Astra (3 September) and GPT-6.1 Sol (29 September) as "Critical" for cybersecurity, the top level of its own safety framework. Anthropic's own system card, the report a lab publishes on what a model can do and how risky it is, says Claude Opus 5.5 (22 September) it "has the strongest cyber capabilities of any model we have released". Google gives its most capable security model, Gemini 3.8 Flash Cyber, only to vetted defenders. Each lab measures differently, so don't rank them against each other. The direction is the same everywhere.

It escaped the big labs. On 29 September, Anthropic reported that GLM-5.3, an open-weight model from China's Zhipu AI that anyone can download and run, can build working attacks much like Mythos Preview could, and was "released without meaningful safeguards". The US government's AI standards centre, CAISI, calls it "the most cyber-capable open-weight model released to date", about four months behind the best US models.

That last one is the one I'd underline. Everything in April was behind a locked door at one company. By September, similar capability was free to download. So what does that break?

Broken #1: Friction-Based Defence

Most security doesn't make attacks impossible. It makes them tedious. Think of a bike lock. A good one doesn't stop a determined thief with an angle grinder. It makes stealing your bike slower and more hassle than stealing the one next to it. Most thieves move on.

A lot of cybersecurity works the same way. Chaining several flaws together into one working attack used to take a skilled researcher weeks of work. That kind of effort was mostly limited to governments and the best-funded criminal groups. Everyone else didn't bother. The effort itself was the defence.

Friction-based defence is dead: before, tedious manual exploit chains took weeks of expert work and tens of thousands of dollars; now AI chains vulnerabilities automatically in hours for a few hundred dollars or less

Now the effort is cheap. Mythos Preview chained four flaws in a web browser into one attack, although Anthropic's team helped it turn that into a full escape from the browser's protections. The Chrome attack built with GLM-5.3 cost about $20. When the tedious part costs less than a takeaway, tedium stops protecting you.

What survives are hard barriers: defences that are actually impossible to get through with today's methods, not just annoying. Two examples:

Strong cryptography. Properly encrypted data can't be read without the key, however many AI agents you point at it.

Memory-safe code. A whole family of the worst bugs comes from code that lets a program read or write memory it shouldn't. Languages like Rust are designed to stop that class of mistake from happening at all, instead of hoping someone spots each one.

So the first question to ask about any control you rely on is: does this make an attack impossible, or just slower?

Broken #2: The Patch Window

When a software company finds a flaw, it releases a fix, called a patch, and the flaw gets a public ID called a CVE. There used to be a gap between that fix coming out and attackers using the flaw. That gap was your safety margin. You had time to test the patch and roll it out.

Google's Mandiant team has measured that gap for years. It was 63 days on average in 2018 and 2019. By 2023 it was 5 days. In its M-Trends 2026 report, Mandiant estimates the 2025 average at minus 7 days. Minus means that, on average, attackers were using flaws about a week before the fix was even out.

The patch window has gone, drawn to scale: average days from patch release to exploitation fell from 63 days in 2018 to 2019, to 44, to 32, to 5 days in 2023, to an estimated minus 7 days in 2025, according to Google Mandiant

To be fair, Mandiant doesn't blame AI for that drop. The gap was closing before these models existed. And AI hasn't yet sped up attacks across the board. VulnCheck found that the share of known-exploited flaws attacked on or before the day they were made public fell from 28.9 percent in 2025 to 23.4 percent in the first half of 2026. Of 1,061 flaws found with AI help, only 14 had been confirmed as exploited.

So the patch window was already closing. What AI adds is the ability to close the rest of it, cheaply and at scale. Mythos Preview turned known, already-fixed Linux flaws into working attacks in under a day, for under $2,000. The GLM-5.3 attack on Chrome took about 8 hours of the model's time and 20 minutes of a person's. My view is that this goes from hours to minutes. If you're patching monthly, the attacker will get there first.

Think about what that means in practice. A lot of organisations still patch on a monthly cycle. If a working attack can exist the same day a fix is released, a monthly cycle leaves you open for weeks.

Broken #3: Entry-Level Security Jobs

The third thing is the one most people reading this care about: jobs. I built JobZone Risk to score how exposed every job is to AI, from 0 (very exposed) to 100 (safe), using tens of thousands of sources that are checked constantly. Here's how the security roles look today.

Which security jobs AI hits hardest, JobZone Risk scores out of 100: SOC Analyst Tier 1 5.4 and Junior Penetration Tester 6.4 in the red zone; SOC Tier 2 33.3, mid-level Penetration Tester 35.6, Detection Engineer 44.3 and Security Engineer 44.6 in yellow; Application Security Engineer 57.1, AI Agent Builder 63.2 and AI Security Engineer 79.3 in green

A tier 1 SOC analyst scores 5.4 out of 100. A junior pen tester scores 6.4. A SOC analyst is the person who watches the alerts in a security operations centre. At tier 1, the job is mostly checking each alert against a written procedure and passing the real ones up. A pen tester is paid to break into a company's systems, with permission, to find the holes before criminals do. At junior level, a lot of that is running standard tools and writing up what they find.

Now look at the other end. An AI security engineer scores 79.3. My reading of the scores is that the difference isn't how technical the job is. It's whether the job follows a checklist, or builds and directs the systems that do.

The industry is seeing it too. In ISC2's July 2026 survey of 856 cybersecurity professionals, 56 percent said AI has reduced the need for entry-level roles. But 53 percent said it's creating new entry-level opportunities. Both can be true: the old starting jobs shrink, and new ones open up for people who can work with AI.

I'll be honest about the uncomfortable part. I think a lot of people are going to lose these jobs. If your work can be written down as a standard operating procedure, such as triaging alerts, running scanners or writing reports, a model can do it. And in security it has to go faster than in other fields, because attackers are automating their side right now. A human-only team triaging by hand can't keep up with attacks that run at machine speed.

You can check your own role, or the one you're training for, on JobZone Risk. It's free. So the old way into the industry is breaking. But cybersecurity isn't going anywhere.

Defence at Machine Speed: Agentic AI in Cybersecurity

The future isn't less security. It's more security, done completely differently. We need the same things we always needed, just much faster.

If attackers can go from a new fix to a working attack in hours, a pen test once a quarter doesn't protect you. Neither does patching once a month. The new baseline is checking continuously: every time a developer changes the code, it gets scanned automatically, the same day.

That means AI becomes the first line of your security team. This is what people mean by agentic AI in cybersecurity: AI that carries out a job in several steps by itself. Here's what that looks like when an alert fires at 3am:

1

The AI picks up the alert. It pulls the logs, checks which machine and user are involved, and looks for anything similar in the last month.

2

It decides whether it's real. Most alerts are false alarms. The AI closes those and explains why, so a person can check its reasoning later.

3

It starts the response. For a real one, it can take the first safe step, such as cutting a machine off from the network, and writes up what it found.

4

A person makes the judgement call. The human decides what happens next: whether to wake the incident team, tell a customer, or shut a service down.

This is already running. In June, Google said its security triage agent had investigated more than 5 million alerts, cutting a typical 30-minute manual check to 60 seconds. And attackers are doing the same. In September, Anthropic reported that most of the attack operations it caught between December and August were carried out or coordinated by AI. Google's threat intelligence team described attackers going from one hacked cloud account to a full credential-stealing campaign run by AI agents in under six hours.

More flaws found can mean more attacks attempted, and more incidents to handle. A team where humans do every step can't scale to that. The teams that survive use models for the first pass and people for the judgement.

Why Defenders Still Have the Advantage

Here's the part most of the doom coverage misses. In this new world, defenders have a built-in advantage.

Structural advantage: an attacker has to figure out the target, find a bug, write an exploit and get it working; a defender already has the source code, already has access and already knows the architecture. The defender wins, but only at machine speed

An attacker starts from nothing. They have to work out how your systems are built, find a flaw, write an attack and get it working. If you build or run the software, you already have the source code, the access and the design documents. So you can point the same AI at your own systems, find the same bugs first, and fix them before anyone else gets there. If you mostly buy your software, your advantage is different: you know your own systems, so you can find the weak settings and patch faster than an outsider can map them.

There's already evidence this works. In DARPA's AI Cyber Challenge final in August 2025, the AI systems found 86 percent of the flaws planted in the test software and fixed 68 percent of them, at about 45 minutes per fix. They also found 18 real flaws nobody had planted. Anthropic has since used its own models to report 2,300 flaws in 392 open-source projects, and says 421 of them had been fixed as of 26 August.

Two honest caveats. First, finding flaws is now faster than fixing them. In September, Dark Reading reported that the slow part is now people: checking each finding, telling the right developers and getting the fixes shipped. Second, software never stands still. Even if AI helps us clean up old code, we'll keep changing our systems, and faster than ever, so new flaws will keep appearing. So the defender can win, but only at machine speed. Do it by hand and you've given away the one advantage you had.

Build the Tools, Don't Just Run Them

So what's the new job? I call it AI-driven engineering, and applied to security it's AI-driven security engineering. The real skill isn't using an AI tool. It's building the system around it: the setup that gives the AI the right information, checks its work, and gets better every time it runs.

The security skill shift: vibe coding means running a scanner once, starting from scratch every time, with no memory and no learning; AI-driven engineering means building infrastructure that compounds, gets better with every run and uses memory, context and automation. The twentieth scan is better than the first

Here's the difference. Running a vulnerability scanner once and reading the report is the security version of vibe coding. You get a result, and next time you start from zero. Building a system that scans continuously, learns which of its findings were false alarms, and improves its detection is AI-driven security engineering. The twentieth scan is better than the first.

Anthropic's own bug-hunting setup is a good example. On the surface it was simple: an isolated machine and a one-paragraph instruction to find a flaw. Underneath, it was a system:

It chose where to look. The model scored every file from 1 to 5 on how likely it was to contain a bug, so the effort went where the bugs probably were.

It worked in parallel. Many copies of the AI ran at once, each on a different file.

It checked its own work. A final AI agent confirmed each report was real and worth reporting before a human reviewed it.

That's infrastructure, not a tool. And the attacker side works the same way. The model that got into Hugging Face didn't win with one clever trick. It kept going through thousands of attempts until one path worked. Defenders need systems that are just as tireless.

The person who builds and maintains those systems is the AI-driven security engineer. That's the role growing while the checklist roles shrink. If you want to see what those jobs look like and pay, I've gathered real listings in AI-Driven Cyber Security Jobs, and These Tech Jobs Are Evolving Into $900K Monsters goes through what the top employers ask for.

What to Do Now: 5 Moves for Defenders

So what do you actually do about this? Here's what I'd do, whether you run a security team or you're trying to get into one.

What you should do now: use AI for security now, shorten patch cycles, automate incident response, and think beyond finding bugs to config review, PR review and patching
1

Start using AI for security now. Don't wait for a better model. Today's models already find serious flaws, and anything you build now gets more powerful when stronger models arrive. For example, have an AI review every pull request, the proposed code change a developer submits, for security problems before it's merged.

2

Shorten your patch cycles. Treat every security fix as urgent and turn on automatic updates wherever you can. If you patch monthly, aim for days.

3

Automate the first pass of incident response. You can't hire your way through the volume that's coming. Let models do the triage and the first response, and keep people for the judgement calls. Decide in advance which actions the AI can take on its own, such as isolating one laptop, and which always need a person, such as shutting down a service customers rely on.

4

Think beyond finding bugs. Configuration reviews, code reviews, patching and compliance checks are all mostly manual today. Each one is a candidate for automation. Given what attackers can now do, it's really a requirement.

5

Learn to build the systems. Every one of those needs someone who can build AI-driven security systems for their own organisation, and change them as the attacks change. That's the skill I'd bet a career on.

The future of cybersecurity: people who run tools are competing with a model that costs a few hundred dollars a day; people who build systems are the most valuable professionals in the industry

That's where I think the future of cybersecurity is heading. Not people who run the tools, but people who build them. Everyone else ends up competing with a model that, in my estimate, costs a few hundred dollars a day to run. The question is which side of that you want to be on, and it's worth deciding now.

If you want to start, our free web-book Become the Cyber Security Expert the AI Era Demands is a good first step. And if you want to learn to build these systems with mentors and a group, doing real projects, that's what the AI Master's Program is for.

Frequently Asked Questions

What is the future of cybersecurity?

AI can now find and exploit software flaws with little human help, so attacks get cheaper and faster. The future of cybersecurity is defence that runs at the same machine speed: AI doing the first pass on scanning, triage and response, with people building those systems and making the judgement calls.

Will AI replace cybersecurity jobs?

It will replace a lot of cybersecurity tasks, starting with the repeatable ones such as triaging alerts, running scanners and writing standard reports. On JobZone Risk, entry-level SOC analyst and junior penetration tester roles score around 5 to 6 out of 100, while AI security engineering roles score around 80. The work moves towards people who build and run AI-driven security systems.

Is cybersecurity still a good career with AI?

Yes, if you aim at the right part of it. There will be more security work, not less, because AI finds more flaws and attackers use it too. The safest roles are the ones that build, direct and check AI systems, rather than the ones that follow a written checklist.

What is AI-driven security engineering?

It means building security systems that use AI and get better every time they run, instead of running a tool once by hand. For example, a scanner that checks every code change, learns from its false alarms and hands only real problems to a person.

What is agentic AI in cybersecurity?

Agentic AI is AI that carries out a task in several steps on its own, such as investigating an alert, gathering the logs, deciding whether it's real and writing up the result. Attackers and defenders are both using it, which is why defence now has to work at machine speed.

About the Author

Nathan House

Nathan House, Founder & CEO of StationX

Nathan House has 30 years of hands-on cybersecurity experience and is Cambridge-educated, holding CISSP, CISA, CISM, OSCP, CEH, and SABSA. He founded StationX in 1999 — one of the UK’s first cybersecurity companies — and has secured £71 billion in UK mobile banking transactions and the London 2012 Olympics, advising clients including Microsoft, Cisco, BP, Vodafone, and VISA. He authored the world’s most popular cybersecurity course — a #1 Udemy bestseller taken by over 500,000 students — and was named Cyber Security Educator of the Year 2020, AI Security Educator of the Year, and a UK Top 25 Security Influencer 2025. A DEF CON speaker and featured expert on CNN, Fox News, NBC, and the BBC, Nathan leads StationX’s training of more than half a million students worldwide.