Last month, I found myself contemplating pulling funds from my savings account to invest in gold—a notion that reflects the anxiety surrounding today’s digital landscape. Despite fortified security measures like firewalls and two-factor authentication, the safety of internet transactions appears increasingly compromised. A slew of cybercriminals is targeting organizations globally, including hospitals, energy infrastructure, government entities, and financial institutions.
The sophistication of cyberattacks has accelerated, partly due to the capabilities of AI technologies. With the advent of advanced coding tools, attackers now employ AI to create malware that evades traditional defenses. According to cybersecurity firm Palo Alto Networks, there was a staggering fourfold rise in daily cyberattacks from 2024 to 2025 across their client base. Hackers are now capable of executing breaches in minutes and automating cyber-espionage, posing significant threats to organizational security. Alex Stamos, former chief security officer at Yahoo and Facebook, highlighted the surge in offensive cyber activity, emphasizing that businesses face constant hacking attempts.
If agencies like the NSA are concerned about the escalation in cyber threats, it's clear that my savings might not be as secure as I’d like to think. A myriad of vulnerabilities in my bank’s systems could be a direct target, or an AI-generated phishing email could trick an employee into granting hackers access to sensitive data. Even if my bank has robust cybersecurity measures, breaches at other companies I interact with could expose my financial details. The potential for exploitation seems endless, and the readiness to address these threats is woefully inadequate.
The term "software engineering" has long been viewed as inadequate compared to the standards of disciplines like mechanical or civil engineering. Software often runs with numerous vulnerabilities for years—much of what underlies the internet has been built without stringent checks. Stamos noted that software has been constructed in an insecure, haphazard manner for decades. While some critical software, such as that for the International Space Station, is rigorously tested, most applications are deployed with minimal oversight. Bugs, once identified, are typically patched post-deployment.
Historically, this laxity has been manageable due to the difficulty of discovering vulnerabilities and the scarcity of highly skilled hackers. But the landscape has shifted dramatically. Cybersecurity expert Giovanni Vigna from UC Santa Barbara pointed out that patching vulnerabilities is exceedingly quick; attackers reduced the time it takes to exploit publicly known weaknesses from over 700 days in 2020 to just 44 days in 2025—far quicker than the average remediation time in cybersecurity.
Governments and corporations are acutely aware of the threat posed by AI-driven cyberwarfare. The alarm was sounded earlier this spring with the release of two sophisticated AI models—Claude Mythos Preview from Anthropic and GPT-5.5-Cyber from OpenAI. Experts assert that these models rival the skill level of elite human hackers, leading their creators to restrict public access. Instead, only select partners and government agencies were granted access to these advanced tools to bolster cybersecurity.
To counter the impending wave of AI-enhanced attacks, organizations can leverage AI itself to detect vulnerabilities ahead of malicious actors. Anthropic has utilized Claude Mythos Preview to uncover thousands of undiscovered bugs in open-source software, significantly aiding Mozilla in securing bugs in the Firefox browser. Continuous AI monitoring for intrusions could prove to be a game changer compared to traditional cybersecurity audits. Increased frequency of software updates across various platforms is a clear indicator that companies are utilizing AI for vulnerability scanning.
However, these adaptive measures may be arriving too late. A plethora of free AI hacking tools is becoming available, allowing less experienced criminals to exploit vulnerabilities easily. While companies are implementing safeguards, they can only do so much, and incidents like the recent Canvas hack underscore the escalating problem. Shortly thereafter, ShinyHunters, a notorious hacking group known for employing AI, reportedly breached Oracle’s HR system, potentially accessing data from over 100 organizations. The Trump administration's decision to limit access to the powerful Mythos model further complicates defensive measures.
The urge to withdraw personal savings and invest in gold isn't entirely unfounded, considering the looming threats. Experts warn that substantial changes must occur urgently, as open-source AI models are on the cusp of matching the capabilities of leading models like Mythos and GPT-5.5. Raffi Krikorian, Mozilla's chief technology officer, emphasized the need for sweeping upgrades across our digital infrastructure, reminiscent of the Y2K readiness efforts. Unlike the extensive preparations taken back then, we face a much shorter timeline to secure our systems, leading cybersecurity professionals to express skepticism about organizations' ability to patch their vulnerabilities promptly.
While advancements in hacking techniques are on the rise, they simultaneously expose weaknesses in digital frameworks. Coding tools can generate flawed code, and with many organizations not conducting robust security checks, the potential for crises increases. Recently, there were incidents where cybercriminals successfully accessed numerous Instagram accounts by merely asking Meta’s AI agent for access, emphasizing the gaps in current security measures.
As we move forward, increased outages and cyberattacks seem inevitable. Vulnerable sectors and organizations, particularly those with older systems and limited resources, could be disproportionately affected. Hospitals, for instance, face ongoing challenges with data breaches, and the stakes are high when patient safety is at risk. John Riggi from the American Hospital Association noted that the issue is less about willingness and more about available resources to enhance cybersecurity measures, particularly in light of AI's expanding threat landscape.
Looking ahead, worst-case scenarios may involve widespread outages and security breaches affecting critical services. With estimates suggesting significant ramifications for millions, every cybersecurity expert I consulted echoed the sentiment of an unpredictable and difficult future. Anthropic’s projections indicate that a single major cyber event could impact at least 100 million individuals, highlighting the urgency of collective action.
While there are steps individuals can take to protect themselves, such as using password managers, keeping software updated, and being alert to phishing schemes, more substantial precautions may be necessary in this evolving landscape. Simplifying your digital life through the use of less complex devices or platforms can also enhance security.
In any case, the prospect of riding out potential AI-driven cyber chaos looms large. Whether a scarcity of vulnerabilities will help stabilize the situation remains uncertain; as new capabilities emerge, the cycle of exploitation may recommence, leading us into another wave of systemic challenges.


