AI security gap is closing fast: Defenders should move now

AI models have grown significantly more capable at cybersecurity work over the past year, reshaping both the threat landscape and the defensive toolbox. Currently, defenders hold an edge because they can deploy stronger models for defensive purposes than the open-weight models available for offensive research. That advantage is temporary — the gap will close soon.

Two realities are not yet widely understood in the community, one good and one bad.

  • Bad news: Near-frontier open-weight models capable of offensive security research exist today. Kimi K3 is an Opus 4.X-class model with no relevant cybersecurity safeguards.
  • Good news: Teams don't need to wait for "Mythos access" or OpenAI's cyber program to start defensive work. Frontier models — with the notable exception of Fable 5 — will perform defensive cybersecurity tasks right now.

The uncertainty around Mythos 5's release has created a kind of paralysis among defenders, many of whom are underusing the powerful tools available today. This post shares how Vercel is thinking about AI-enabled defensive cybersecurity and why teams should be moving with more urgency.

The OpenAI/Hugging Face security incident

A YouTube video from OpenAI researchers about the widely reported Hugging Face security incident is a must-watch for anyone focused on cybersecurity. It clarifies that two separate security incidents occurred, both exploiting vulnerabilities that will be found in most computer systems.