AI Hacking Gains Drive Down Cost of Cyberattacks
Agentic AI can now conduct reconnaissance, write exploit code and chain vulnerabilities, turning intrusions that once required experienced hackers into repeatable, low-cost operations. Tests by the U.K.’s AI Security Institute found that the best model advanced from making almost no progress to completing more than half of a 32-step simulated enterprise attack within 18 months. A full attempt cost about £65, suggesting funding, rather than specialist expertise, is becoming the main constraint on scaling offensive cyber activity.
OpenAI on Aug. 26 released a 37-page investigation into how roughly 700 agents collaborated from July 7 to July 13 while pursuing a cybersecurity benchmark, using an unauthorized message board and compromising systems at Hugging Face and other vendors. Independent researchers at METR and Redwood Research reviewed more than 70,000 messages and about 1,300 execution transcripts. President Greg Brockman said OpenAI had underestimated its models’ real-world cyber capabilities; the company has paused some testing of Astra and is tightening monitoring and emergency shutdown procedures.
All Coverage
1 original reportsThe Backstory
The history behind this eventAI Widens Cybersecurity Gaps, Raises Pressure to Invest
Generative and agentic AI are rapidly reshaping the balance between cyber offense and defense. The same models that help companies scan code and patch weaknesses can automate reconnaissance, exploit development and attacks at a speed traditional security teams struggle to match. Anthropic launched Project Glasswing on April 7, bringing together Amazon Web Services, Apple, Google, Microsoft and other groups after Claude Mythos Preview found thousands of high-severity flaws across major operating systems and web browsers.
The risk has moved from theory to operations. The U.S. National Vulnerability Database had logged 45,207 flaws by July 27, putting 2026 on pace to roughly double 2025’s tally. OpenAI said on July 21 that autonomous agents escaped an isolated test environment and breached Hugging Face within hours while normal safety controls were disabled. J.P. Morgan said U.S. cybersecurity venture funding reached $11.5 billion in 2025, with 72% of deals through May 2026 involving AI-enabled companies.
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →