AIâs âmiddle classâ has gotten dramatically better at hacking
AIâs âmiddle classâ has gotten dramatically better at hacking
As the White House and federal agencies grapple with frontier AI models and their hacking capabilities, researchers are warning that the industryâs âmiddle classâ of smaller models may end up posing a greater threat over the long term.
Research from XBOW this week shows that a growing class of both proprietary and open-source models are becoming strategically important in the offensive security ecosystem. Models like Z.aiâs open-weight GLM-5.2, xAIâs Grok 4.5, Anthropicâs Opus 4.7, Metaâs Muse Spark 1.1, still perform very strongly at many hacking and exploitation tasks that worry policymakers.
âItâs not even that the open-source variants orâŚnot quite frontline competitors are catching up [to frontier models] as such,â said Albert Ziegler, head of AI at XBOW. Itâs that they are crossing a certain threshold, which means that suddenly they are providing net value at a cheaper price.â
That wasnât necessarily the case as recently as six months ago, when testing on mid-tier class models showed they struggled to complete âmoderately complexâ agentic tasks. Todayâs middle class largely can. Their relative cheapness means users can spend many times more resourcesârunning them repeatedlyâto solve the same challenges.
âBecause these models are cheaper, itâs okay to give them more time, and they come from behind and leapfrog the big frontier model,â said Ziegler. âNow, that didnât work half a year ago becauseâŚif you wanted to run some open-source model on a complex task in an agentic wayâŚon a long horizon, then it would just get lost.â
GPT 5.5, now considered a near-frontier model, delivered one of the best performances on exploitation benchmarks that XBOW has recorded to date.
The jump between OpenAIâs GPT 5 and 5.5 ârepresented one of the clearest 2026 leaps in autonomous web application testing,â according to the report. It saw marked improvements over previous middle-class models in exploiting both âwhite boxâ and âblack boxâ scenarios, or with and without access to the underlying victim source code. It also missed fewer vulnerabilities, with a âmiss rate,â or failure to spot a vulnerability, of 10%, while GPT 5âs rate was four times larger, 40%.
The emergence of GPT 5.5 changed âthe practical baseline for what frontier models can do in offensive workflows,â the XBOW report said.
But the performance leap goes deeper than that. GPT 5.5 performed higher in tests without source code access, while GPT 5 heavily leaned on source code.
âThat last result is significant: working without the code, as an attacker would, GPT-5.5 beat a prior version that could read it,â the XBOW report said. âWhat translated into findings was the ability to reach and prove a vulnerability against the running system, not to infer it from a pattern in the source.â
XBOWâs testing found that source code access was not as important to these modelsâ success as other factors, like live interaction with the actual website or software being exploited.
Frontier models like Mythos and GPT 5.6 are indeed more capable on individual cybersecurity tasks, but they can also come with exponentially higher token costs.
New research this week from Anthropic tested two models â Mythos Preview, which is used in Project Glasswing, and Opus 4.8 â to learn how quickly multi-agent swarms could find vulnerabilities in 15 open-source software projects when they coordinate and share information.
While a team of agents working individually and assigned to core directories found 21 vulnerabilities, the coordinating agent swarm found 266. But both tests had to burn through millions of tokens â 6.5 million and 27 million â to get there. Beyond the difficulties with getting access to frontier models, few individuals or organizations have the budget to underwrite that kind of research.
The way these systems coordinate can differ significantly from how humans work together.
Another experiment tested agentsâ ability to coordinate on the development of a fantasy-themed video game. Earlier models, models like Opus 4.6, failed to properly coordinate and produced âbadâ results, while later models like Mythos and Opus 4.8 were able to achieve better results but did so by hardly coordinating at all on tasks.
âThe lack of coordination shown by agents in the fantasy gameâŚin which they siloed themselves and largely failed to merge their workâroughly mirrors some ways in which humans can fail to coordinate,â the Anthropic blog stated.
Further, agents are more homogeneous than humans and âoften act the same in situations where different people might take a much more diverse range of actions.â
XBOW also tested Mythos Preview, finding that it showed âexceptionalâ source-code reasoning and reverse engineering abilities, particularly with source code access. Like other models, losing live-site access had a big impact on its performance, and while Mythos is excellent at finding vulnerabilities, itâs less effective at exploiting them.
]Ziegler said the recent incidents at companies like OpenAI, Anthropic, Meta and others where frontier models escaped sandboxes and hacked into project-adjacent parts of the internet should rightfully alarm lawmakers, and demonstrate the upper-tier capabilities of large language models.
Like most industries, cybersecurity favors cheap, high-performing tools over expensive ones. The widely adopted tools that have the most impact tend to be affordable and effective, not luxury products.
And while these models still require human management to be wielded responsibly by law-abiding organizations, that cost tradeoff can look more attractive to malicious hackers, who tend not to care about collateral damage caused by their agents.
âPurely from an attackerâs perspective, I think we already are [there],â Ziegler said.
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content â general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached â you'll always get the same 5 for this article.