AI Model Completes Full Cyber Attack Autonomously
An advanced AI model has independently completed an entire cyber attack against a live enterprise-style network in tests, marking what the company describes as a move from AI-assisted hacking towards autonomous cyber operations and raising urgent questions about whether traditional defences can keep pace.
Booz Allen Test
US technology and consulting company Booz Allen’s Cyber Weapon Index was designed to test what advanced AI models could actually do in a realistic attack. Eighteen leading US and Chinese models were each given control of an attacker machine and set against a defended Active Directory network, with their progress verified through network traffic, system logs and intrusion-detection data.
The tests looked at whether the models could find vulnerabilities and how far they could progress through a real attack, from gaining an initial foothold to stealing credentials, escalating privileges, moving through the network and ultimately taking control of the domain.
The result was significant, with Booz Allen concluding that “A leading frontier AI model can now independently execute the full cyber kill chain against a real network”, marking what it sees as a move from AI-assisted hacking towards genuinely autonomous cyber operations.
Claude Mythos Achieved The Highest Cyber Weapon Index Score
Anthropic’s Claude Mythos achieved the highest Cyber Weapon Index score at 80 and was the only model Booz Allen says could execute the full cyber kill chain autonomously across its testing.
For example, when it was given a foothold such as stolen employee credentials, the model penetrated the network and gained administrator-level control in every attempt. More importantly, it worked out how to increase its privileges from information it discovered inside the network rather than simply following a predetermined sequence.
On the harder test, where no credentials were provided, Mythos still managed to break into the network and reach full domain compromise, succeeding where the other models failed to complete the whole sequence.
It should also be noted here that the rest of the field wasn’t exactly harmless. For example, four models reached the final objective of domain access and control, another four achieved lateral movement, two reached credential access and all but one managed initial access. Booz Allen warns that “the risk is already distributed across the field”, and estimates that most tested models could reach full-kill-chain capability within six months.
Why The Attack Harness Matters
One of the most important findings is that the underlying AI model is only part of the threat. Booz Allen also tested attack harnesses, the surrounding software that connects a model to tools, memory, feedback and an execution environment so it can stay focused, recover from failure and chain individual actions into a sustained attack.
The report says: “The result is not a ‘smarter’ model but rather a system that makes its intelligence far more actionable while also lowering the expertise required to use it.”
That matters because a model that appears less capable in isolation can become much more effective when paired with good orchestration. In Booz Allen’s testing, Claude Sonnet reportedly rivalled Claude Mythos when connected to an attack harness, suggesting businesses need to assess complete AI systems rather than concentrating only on headline model rankings.
Not All Bad News
Thankfully, the results offered some hope. One important limitation in the results is that the models performed very strongly when vulnerabilities had deliberately been placed in the test software, but their performance fell sharply when they were faced with a genuine, previously unseen weakness hidden inside more complex code.
Booz Allen says “real-world offensive capability still trails benchmark performance”, giving defenders valuable time to strengthen systems before that gap closes.
That window may not remain open for long. The company expects AI-enabled attacks to become mainstream imminently and believes increasingly capable systems could make zero-day exploit discovery much faster and cheaper within months. These are Booz Allen forecasts rather than certainties, but they illustrate how quickly the threat model is changing.
What Does This Mean For Your Business?
For businesses, the biggest change is likely to be speed. AI systems don’t need sleep, can repeatedly test different routes through a network and may increasingly compress tasks that once took skilled attackers hours or days into far shorter periods.
That makes familiar cyber-security measures more important rather than obsolete. Strong authentication, least-privilege access, prompt patching, network segmentation, monitoring and tested incident-response plans all become more valuable when an attacker may be able to move through systems at machine speed.
Businesses should also think beyond prevention. Booz Allen argues that critical systems need to be designed to contain compromise, so that gaining an initial foothold does not automatically lead to wider control of the network.
On the upside, it’s worth remembering that the same technology can strengthen the defence as well. Booz Allen says organisations will increasingly need AI-enabled systems capable of detecting, deciding and responding at machine speed while retaining appropriate human oversight.
The main message here is that autonomous cyber attacks are no longer purely hypothetical. The immediate challenge is not waiting until every advanced model can complete an entire attack, but strengthening defences while there is still time to make machine-speed intrusion harder to turn into machine-speed compromise.



