Goblin News
Goblin NewsAI news, distilled.
← Back to feed
9

AI Offensive Cyber Capabilities Doubling Every 5-10 Months, New Research Finds

SecurityTop News1 source·Apr 6

Summary

  • • Frontier AI models' offensive cybersecurity capabilities are doubling every 5.7 months for post-2024 releases — the fastest acceleration rate ever measured.
  • • Leading frontier models GPT-5.3 Codex and Opus 4.6 now achieve 50% success on expert-level attack tasks requiring 3+ hours of human expert work.
  • • Real-world AI-orchestrated cyberattacks are documented: cybersecurity is now ranked by the 2026 International AI Safety Report as the domain with the strongest evidence of AI-caused real-world harm.
  • • Open-weight model GLM-5 lags the closed frontier by only 5.7 months, raising concerns about rapid capability diffusion to any actor worldwide.
Adjust signal

Details

Stat

AI offensive cyber capability doubling time: 9.8 months overall, 5.7 months for post-2024 frontier models

Applies METR's time-horizon methodology across 7 open-source benchmarks plus a 291-task expert human timing study with 10 professional offensive security practitioners. The acceleration from 9.8 to 5.7 months reflects a steepening trend in recent model generations.

Stat

GPT-5.3 Codex and Opus 4.6 achieve 50% success on tasks requiring 3.1h and 3.2h of human expert work

These P50 task-horizon figures represent the difficulty level at which frontier models succeed on a coin-flip basis. Three-plus hours of expert offensive security work covers a meaningful range of real-world attack sub-tasks, well beyond simple CTF challenges.

Research

Scaling GPT-5.3 Codex to 10M context tokens raises its P50 task horizon from 3.1h to 10.5h — benchmarks are lower bounds

Standard evaluations used a fixed 2M-token budget. Increasing context allocation alone — without architectural changes — more than triples the autonomous attack task length the model can handle. All reported benchmark figures are therefore lower bounds on current capability.

Security Alert

Anthropic disclosed first documented large-scale AI-orchestrated cyber espionage campaign in late 2025

A threat actor used Claude to decompose complex attack chains into discrete sub-tasks and automate 80-90% of operations. This is the first publicly confirmed case of AI used as an orchestration layer for a full-scale espionage campaign rather than a point tool.

Security Alert

Opus 4.6 discovered 500+ high-severity zero-days in heavily-fuzzed open-source libraries in early 2026

These were libraries already subjected to millions of CPU-hours of automated fuzzing. The model found them without specialized scaffolding, demonstrating frontier AI can surface vulnerabilities that traditional automated security tooling has missed at scale.

Security Alert

AI security startup AISLE found all 12 CVEs in the January 2026 OpenSSL disclosure, including bugs dating to 1998

OpenSSL is among the most scrutinized open-source codebases in existence. Discovering bugs that survived decades of expert review signals AI-assisted vulnerability research now operating beyond the historical frontier of human security auditing.

Market Impact

Open-weight GLM-5 lags the closed-source frontier by only 5.7 months on the capability curve

A sub-six-month lag means offensive capabilities developed at the frontier will appear in openly downloadable models within one product cycle, expanding the pool of potential threat actors far beyond well-resourced organizations with API access.

Policy

The 2026 International AI Safety Report ranks cybersecurity as the domain with the strongest evidence of real-world AI harm

Cybersecurity has moved from a theoretical risk category to the leading domain of documented real-world AI harm, ahead of biosecurity, misinformation, and other previously prominent concerns — a significant shift for policy and investment priorities.

Stat = quantitative finding, Research = methodology/analysis result, Security Alert = documented or demonstrated threat, Market Impact = ecosystem effect, Policy = regulatory/governmental framing

What This Means

AI offensive cybersecurity capabilities are no longer a future risk — they are an accelerating present one, with documented real-world espionage campaigns, mass zero-day discovery in hardened codebases, and a capability doubling time measured in months rather than years. The rapid diffusion of these capabilities into open-weight models means the threat is not confined to well-resourced state actors or organizations with frontier API access. For AI practitioners and security teams, this research demands a fundamental reassessment of defensive security timelines: the window between a capability appearing at the frontier and becoming broadly accessible is now measured in months.

Sentiment

Mostly alarmed at rapid AI offense scaling outpacing defenses

@emollickEthan Mollick · Professor @WhartonView post
Impressed

Here’s an independent domain extension of METR’s famous time-horizon analysis, applying it to offensive cybersecurity with real human expert timing data. Similar to METR: 5.7 months doubling time. Frontier models now succeed 50% of the time at tasks that take human experts 10.5h.

@kyjryKyle Ryan · Head of R&D @Pensar, Adjunct Professor of Computer Science @Fordham UniversityView post
Alarmed

Lynchus extends METR's time-horizon methodology to offensive cyber with real expert timing data. The key takeaway for me: offensive cyber capability is now advancing faster than our ability to measure it. That's a risk assessment blind spot for the entire field.

@clwdbotVaclav Milizé · Co-founder @mangoai, AI devView post
Alarmed

AI just got better at hacking than most of your security team... offensive cyber capability doubling every 5.7 months... the part that should scare you: this isn't theoretical... at 5.7-month doubling, every vulnerability window that was safe for 6 months is now safe for 3.

@sorimmelspacherSven O. Rimmelspacher · EntrepreneurView post
Concerned

Lynchus reports AI offensive cyber capability now doubling about every 5.7 months. That compression turns time and token budget into a brute force advantage over human pace. Defense must scale with compute, not hope.

Split

Offense scaling exponentially (~80/20 concerned vs impressed by progress); defense adaptation lagging.

Sources

Similar Events