As cited
Copy frozen at (site build).
ai security
AI’s ‘middle class’ has gotten dramatically better at hacking
Researchers at XBOW report that mid-tier AI models have crossed a capability threshold in offensive security tasks, making them attractive for hacking despite costing less than frontier models. Models like GPT 5.5 now perform nearly as well as frontier competitors on vulnerability discovery and exploitation, with GPT 5.5 achieving a 10% miss rate compared to GPT 5's 40% on black-box scenarios. The lower cost of mid-tier models allows attackers to run them repeatedly with extended reasoning, offsetting their individual task performance gaps and creating a more accessible offensive security toolkit.
Why it matters: Security teams and defenders must monitor the proliferation of cheaper mid-tier models in the threat landscape, as attackers will prefer affordable, high-performing tools over expensive frontier models for conducting reconnaissance and exploitation campaigns at scale.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
ai security
AI’s ‘middle class’ has gotten dramatically better at hacking
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
ai security
AI’s ‘middle class’ has gotten dramatically better at hacking
XBOW research shows that mid-tier artificial intelligence (AI) models including open-source variants are now efficient enough at hacking and exploitation tasks to pose a long-term strategic threat, despite being cheaper and slower than frontier models. These models can compensate for lower per-task performance through repeated iterations and extended reasoning horizons; GPT 5.5 demonstrated notably improved vulnerability discovery and exploitation capabilities without source code access. Anthropic's agent swarm research revealed that coordinated multi-agent systems can discover vulnerabilities at scale, though frontier models require prohibitively high token costs that limit adoption to well-resourced organizations.
Why it matters: Security practitioners and policymakers should prioritize mid-tier AI capabilities as an emerging offensive threat, since attackers can afford repeated, high-volume exploitation attempts using cheaper models where defenders cannot, and coordinated agent swarms amplify vulnerability discovery at scale.
- Source published
- First seen by Cybersecurity Tracker