Brief IA

OpenAI's GPT-5.5 Competes with Claude Mythos in Cyberattacks

🤖 Models & LLM·Tom Levy·

OpenAI's GPT-5.5 Competes with Claude Mythos in Cyberattacks

OpenAI's GPT-5.5 Competes with Claude Mythos in Cyberattacks
Key Takeaways
1The British Institute for AI Security has tested GPT-5.5, which matches Claude Mythos in simulations of complex cyberattack scenarios.
2GPT-5.5 outperformed Claude Mythos in expert-level security tasks, achieving a success rate of 71.4%.
3Tests in simulated environments show that GPT-5.5 resolves network attacks in 2 attempts out of 10, compared to 3 for Claude Mythos.
💡Why it mattersThese advancements highlight the growing capabilities of AI in the field of cybersecurity, posing significant security challenges.
Le brief IA que lisent les pros

Le brief IA que les pros lisent chaque soir

Les 7 actus IA du jour, décryptées en 5 min. Gratuit.

Inclus dès l'inscription : notre sélection des meilleurs guides & comparatifs IA.

Choisis ton rythme

Gratuit · Pas de spam · Désabonnement en 1 clic

📄
Full Analysis

GPT-5.5 and Claude Mythos: A Tight Competition in Cybersecurity

The British Institute for AI Security (AISI) recently tested OpenAI's GPT-5.5 model, revealing that it achieves a level of cyber attack capability comparable to Anthropic's Claude Mythos Preview. This finding is significant as GPT-5.5 is only the second model, after Mythos, to have completely solved a complex multi-step enterprise attack simulation. However, it is important to note that this success was achieved on a network without active defenses in place.

The AISI emphasizes that these capabilities are increasingly emerging as a byproduct of overall AI improvements in areas such as autonomy and programming, rather than being explicitly trained for this purpose. This trend is observed in AI-powered cyber attack capabilities.

Evaluation of GPT-5.5's Capabilities

The AISI subjected GPT-5.5 to a series of cyber attack tests. The model successfully completed a multi-step enterprise attack simulation, becoming the second model after Claude Mythos Preview to achieve this feat. In isolated expert-level security tasks, GPT-5.5 even outperformed Anthropic's model.

For the AISI, the capabilities first observed in Claude Mythos in April are not an isolated case but a byproduct of broader gains in autonomy, reasoning, and coding. GPT-5.5's performance on expert tasks is particularly remarkable.

GPT-5.5's Performance on Expert Tasks

The AISI evaluates AI models with a set of 95 capture-the-flag tasks spread across four difficulty levels. The advanced tasks, developed in collaboration with cybersecurity companies like Crystal Peak Security and Irregular, cover reverse engineering, exploit development for various memory vulnerabilities, cryptographic attacks, and decryption of obfuscated malware.

At the "Expert" difficulty level, GPT-5.5 achieves an average success rate of 71.4%, according to the AISI. Claude Mythos Preview stands at 68.6%. The gap falls within the statistical margin of error, but GPT-5.5 could be the highest-performing model tested so far. For comparison, GPT-5.4 achieved 52.4%, and Claude Opus 4.7 reached 48.6%. All current top models have fully solved the basic tasks since at least February 2026.

Network Attack Simulation

Isolated tasks test individual skills, but real attacks require chaining multiple steps. To capture this, the AISI uses cyber ranges: simulated network environments with multiple hosts, services, and vulnerabilities.

The simulation "The Last Ones" (TLO) covers 32 steps across four sub-networks and about 20 hosts. The AI agent starts without any identification and must find vulnerabilities, steal credentials, move laterally through the network, and ultimately reach a protected database. The AISI estimates that a human expert would take about 20 hours to accomplish this.

GPT-5.5 fully solved TLO in 2 out of 10 attempts. Claude Mythos Preview achieved the same level in 3 out of 10 attempts. Performance continues to improve with inference computing power, and even the best models have not yet reached a plateau. The more tokens the model spends "thinking," the more likely it is to succeed in a hack.

That said, the tests had no active defenders, no security monitoring, and no consequences for actions that would trigger alarms in the real world. The ability of GPT-5.5 or Mythos to withstand well-defended systems remains an open question. However, for poorly protected networks, the capability is clearly present.

Limitations and Challenges

A second simulation called "Cooling Tower," which models an attack on an industrial control system, was beyond the capabilities of GPT-5.5. No model has yet solved this 7-step scenario. According to the AISI, GPT-5.5, like Mythos, struggled with upstream computing steps rather than the control system itself.

Bypassing Security Measures

Beyond raw capability, the AISI also tested GPT-5.5's security measures for public use. Researchers discovered a universal bypass that worked on every reported malicious cyber request by OpenAI, including multi-step agent scenarios. It took only six hours to develop.

OpenAI subsequently deployed several security system updates, but the AISI was unable to verify the effectiveness of the final configuration due to a configuration issue in the deployed version. This once again proves that bypasses remain a serious security weakness in LLMs, even the most capable ones.

A key difference from Mythos: GPT-5.5 is already available in ChatGPT and via the API, while Anthropic still limits Claude Mythos to a small group. The AISI's results suggest that Anthropic may have skipped this additional precaution layer. Or perhaps critics are right, and the slow deployment has less to do with security ethics than with Anthropic's computational constraints.

Brief IA — L'actualité IA en français

L'essentiel de l'actualité de l'intelligence artificielle, décrypté et expliqué chaque jour.