Monday , August 24 2026
GPT 5.5

GPT-5.5 matches Claude Mythos in cyber attack tests: Report

Key Points:

The UK’s AI Security Institute (AISI) tested OpenAI’s GPT-5.5 and found it can perform cyberattacks like Anthropic’s Claude Mythos Preview.

After BDJobs, Directorate of Secondary and Higher Education 390k data surfaced online

A group of hackers named “Madarax” claims they have stolen and are offering to sell the personal information of about...
Read More
After BDJobs, Directorate of Secondary and Higher Education 390k data surfaced online

Researchers show new technique to bypass AI safety guardrails in Grok and Gemini

A new hacking technique has been demonstrated to steal data from Elon Musk's Grok AI. It uses a simple trick...
Read More
Researchers show new technique to bypass AI safety guardrails in Grok and Gemini

About thousands of leaked AWS keys Held Full Admin Rights

More than 9,300 AWS access keys that were made public from August 2022 to August 2026 are still active, says...
Read More
About thousands of leaked AWS keys Held Full Admin Rights

US Bank investigates LockBit’s Data Breach Claims

US Bank is looking into LockBit's claims about a breach and stolen data. The ransomware group says they will share...
Read More
US Bank investigates LockBit’s Data Breach Claims

Five new malware families actively targeting Asian Gov.t infra

Central Asian government agencies have been attacked in a cyber spy operation that used a small but different range of...
Read More
Five new malware families actively targeting Asian Gov.t infra

T-Mobile Cuts Cables to Remove Chiness Salt Typhoon Hackers from Network

T-Mobile’s cybersecurity team reportedly physically cut a network cable connecting compromised infrastructure to the outside world. According to Bloomberg, the move...
Read More
T-Mobile Cuts Cables to Remove Chiness Salt Typhoon Hackers from Network

Splunk, Zyxel Patch Multiple Flaws Enabling RCE and Root Command Execution

Splunk has issued security fixes for 17 weaknesses in different apps and add-ons, such as Splunk MCP Server, Splunk AI...
Read More
Splunk, Zyxel Patch Multiple Flaws Enabling RCE and Root Command Execution

“Zombie Card” attack revels expired Visa card may be used for contactless payments

Security experts have shown that expired credit cards can still be used. A study from the University of Massachusetts Amherst,...
Read More
“Zombie Card” attack revels expired Visa card may be used for contactless payments

Critical Zimbra RCE Flaw Actively Exploited in the Wild

CERT Polska has alerted that bad actors are actively exploiting a security flaw in Zimbra Collaboration Suite to execute code...
Read More
Critical Zimbra RCE Flaw Actively Exploited in the Wild

Operation CameraSwarm
A single hacker compromise 1400+ Dahua camera worldwide 

Operation CameraSwarm compromised 14,500+ Dahua IP cameras mostly in Ukraine and Russia. The operation lasted for at least 35 days...
Read More
Operation CameraSwarm  A single hacker compromise 1400+ Dahua camera worldwide 

GPT-5.5 is the second model, after Mythos, to fully complete a complicated enterprise attack test. This was done on a network without any active defenses.

AISI sees this as part of a larger trend: skills for cyberattacks are growing from general AI advances in areas like independence and coding, not from specific training.

…………………………………………………………………………………………………………………………….

OpenAI’s GPT-5.5 matches Anthropic’s Claude Mythos Preview in cyber tests by the UK AI Security Institute. The agency believes this shows a bigger trend in AI attack skills.

The UK AI Security Institute tested OpenAI’s GPT-5.5 with many cyberattack challenges. The key point: GPT-5.5 is the second model after Claude Mythos Preview to finish a complex test of a business attack. For some expert security tasks, GPT-5.5 did better than Anthropic’s model.

AISI sees that the abilities noticed in Claude Mythos in April are not just a one-time thing. They come from larger improvements in independence, thinking, and coding.

GPT-5.5 edges out Claude Mythos on isolated expert tasks

AISI tests AI models using 95 capture-the-flag tasks at four difficulty levels. The harder tasks were created with help from cybersecurity companies Crystal Peak Security and Irregular. They include reverse engineering, creating exploits for different memory problems, cryptographic attacks, and unpacking hidden malware.
At the hardest “Expert” level, GPT-5.5 has an average success rate of 71.4 percent, according to AISI. Claude Mythos Preview has 68.6 percent. The difference is small, but GPT-5.5 might be the best model tested so far. For comparison, GPT-5.4 scored 52.4 percent and Claude Opus 4.7 got 48.6 percent. Every top model has completely solved the basic tasks since at least February 2026.

After Mythos, GPT-5.5 also cracks a full network attack simulation

Isolated tasks check single skills, but real attacks need many steps linked together. To show this, AISI uses cyber ranges: fake network settings with many hosts, services, and weaknesses.

The simulation “The Last Ones” (TLO) has 32 steps in four subnets and around 20 hosts. The AI agent begins without any credentials. It must find weaknesses, steal credentials, move through the network, and finally reach a secured database. AISI thinks it would take a human expert about 20 hours.

GPT-5.5 solved TLO in 2 out of 10 tries. Claude Mythos Preview managed it in 3 out of 10. AISI says performance improves with more computing power, and top models are still getting better. The more tokens the model uses to “think,” the better its chances are for a successful hack.

The tests had no defenders, no security checks, and no punishments for actions that would trigger alarms in real life. It is unclear if GPT-5.5 or Mythos can compete with strong systems. However, they clearly have power against weak networks.

A second test called “Cooling Tower” shows an attack on an industrial control system. GPT-5.5 could not solve it. No model has completed this 7-step challenge yet. AISI says that GPT-5.5, like Mythos, made mistakes in the upstream IT steps instead of the control system itself.

A universal jailbreak bypassed every safeguard

AISI checked how safe GPT-5.5 is for people. The researchers found a way to bypass safety that worked on all harmful cyber requests OpenAI marked, even complex ones. It took only six hours to create.

OpenAI made many updates to the safety system, but AISI couldn’t check how well the final setup worked because of a problem with the version used. This shows again that jailbreaks are still a big security problem in LLMs, even the best ones.

One main difference from Mythos is that GPT-5.5 can be used in ChatGPT and via the API, but Anthropic keeps Claude Mythos for a small group only. The AISI results show that Anthropic might have been too careful. Or maybe the critics are right, and the slow release is more about Anthropic’s computing limits than safety concerns.

Check Also

LiteLLM

LiteLLM supply chain attack reveals 153GB of stolen credentials online

153GB record surface online stolen during the LiteLLM supply chain attack linked to thousands of …