Gone in 77 seconds: AI now hacking faster than humans | Information Age | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


The HAWK algorithm has succumbed to Claude Mythos. Photo: ChatGPT

Chastened security researchers are regrouping after an AI platform broke a post-quantum computing (PQC) algorithm previously considered unbreakable – marking the latest step in an onslaught of AI-powered campaigns that now comprise the majority of cyberattacks.

The HAWK algorithm, a post-quantum computing (PQC) encryption tool designed to protect digital signatures from being cracked by looming cryptographically relevant quantum computers (CRQCs), has been in development for several years and had never been broken.

Its seeming robustness helped it progress through years of human and computer review and validation, and in May it became one of just nine candidate algorithms to reach the third round of the National Institute of Standards and Technology (NIST) decade-long battle royale to set standards for quantum-proof security.

Until, that is, researchers at AI firm Anthropic showed HAWK to its Claude Mythos Preview AI cybersecurity tool – which took just 60 hours to discover a mathematical flaw that cut HAWK’s strength in half, leading its development team to withdraw it from the NIST process.

Mythos also figured out how to crack a weakened version of the ubiquitous Advanced Encryption Standard (AES) – which is widely used to secure online browsing, shopping and other types of data and transactions – over 200 times faster than previously possible.

While neither hack affected real-world security, Anthropic notes the results “show the potential for frontier AI models to help discover flaws in important cryptographic algorithms, both before and after real-world deployment.”

“This is cryptography research working as intended,” they added, “stress-testing algorithms to build trust and ultimately make systems more secure” – and with each hack costing just $140,000 (US$100,000) worth of AI tokens, they are well within the reach of researchers and governments.

Test your systems before cybercriminals do

They’re also within the reach of determined cybercriminals who, security researchers are now warning, have embraced AI at speed – and are already using it to conduct all manner of penetration testing and cyberattacks on unsuspecting organisations around the world.

AI is now “embedded across modern adversary operations,” CrowdStrike noted in its 2026 Threat Hunting Report, calling it “a tool, target, and force multiplier for adversaries” – with one hacking campaign sending nearly 200,000 AI requests in two minutes.

During the first half of this year, 88 per cent of the cyberattack proofs of concept that CrowdStrike observed had been discovered as vulnerabilities less than 48 hours before their release.

CrowdStrike watched China-linked nation state groups Vault Panda and Genesis Panda using AI to find and exploit critical vulnerabilities in victims’ networks within 24 hours, while the Snarky Spider group progressed from account takeover to data theft in under five minutes.

“AI is changing how attacks are planned, executed and scaled while expanding the attack surface organisations must defend,” CrowdStrike head of counter-adversary operations Adam Meyers said, advising organisations to “secure AI as aggressively as they adopt it.”

Study after study is confirming just how aggressively AI is amplifying cybercrime, with IBM recently noting one in four of 602 studied malicious breaches was AI-enabled – a 56 per cent increase over last year – and that those breaches cost an average $8.5 million (US$6 million).

Some hackers are tapping AI’s accessibility to target particularly vulnerable parts of the global economy, with European law enforcement agency Interpol this month warning that 55 per cent of cybercrime reported in Africa involves AI – with little legal recourse likely.

And with AI giants unabashedly escalating an arms race built around ever more powerful cybersecurity models – and the humblebragging that accompanies each successful breach conducted by AI models and their autonomous agents – things are only getting worse.

Gone in 77 seconds

Continuous advancements in AI attacks are shortening the time to compromise at a dizzying pace: last year, for example, security firm Horizon3 said its autonomous AI-based pentesting platform had solved Orange Cyberdefense’s complex GOAD test in 14 minutes.

More concerning: Horizon3, which recently completed a $354 million (US$250 million) funding round to scale up its technology, has said its AI autonomously compromised a real-world bank in 77 seconds, amidst warnings that AI is now hacking faster than humans can.

The US government knows this is a problem, and recently called major AI labs together to share plans of a new AI cybersecurity framework that it’s keeping secret for now.

Yet the same government is tacitly encouraging further refinement of AI attacks, announcing that it will not safety test open-weight AI models – systems, like Moonshot’s newly released Kimi K3 AI, whose underlying logic is available to anybody to scrutinise and improve.

This will free security innovators to apply more heat, with AI Labs already pursuing ever more complex capabilities in many fields: OpenAI, for one, recently shared AI testing that had produced results for ten longstanding mathematics challenges.

AI agents are even proving adept at finding undiscovered weaknesses in existing systems that had escaped humans for years – with Palo Alto Networks’ automated NOVA system examining 3,915 open-source software projects and identifying 14,090 previously unknown vulnerabilities.

The threat landscape is evolving so quickly that Five Eyes national security partners recently issued a call to action, warning that frontier AI models are “fundamentally transforming both offensive and defensive cyber capabilities.”

“AI is not a future consideration – it is already here.”





Click Here For The Original Source.

——————————————————–

..........

.

.

National Cyber Security

FREE
VIEW