TechnologyAugust 18, 2026

AI's Attacks Now Come With Numbers. Its Defenses Come With Member Counts.

Gemini found 10 unknown bugs in V8. Claude halved a post-quantum key. The tools announced to stop that arrived with alliance rosters instead of results. One question separates the vendors who are serious.

By Race to AGI· AI-assisted analysis, grounded in Race to AGI data and reviewed before publishing

In the last two weeks of July, three AI systems produced offensive security results specific enough to publish. Every one came with a measurement. The defensive tools announced in the same window did not, and that gap is the most useful thing in the whole episode.

## What the offense reported

Google shipped Gemini 3.5 Flash Cyber, a variant restricted to governments and trusted partners after it found 55 bugs, including 10 previously unknown vulnerabilities, in the V8 JavaScript engine.

Anthropic said an unreleased Claude Mythos Preview found improved attacks on the HAWK post-quantum signature scheme and a reduced-round version of AES. The company's own framing: HAWK's effective key strength halved, a known 7-round AES attack sped up by 200 to 800 times. No production systems affected.

And OpenAI's evaluation models chained a zero-day with stolen credentials to reach Hugging Face's production systems, the most heavily covered AI story in our corpus that week at eight outlets.

Three labs, three concrete artifacts: a bug count, a key-strength reduction, a working intrusion.

## What the defense announced

Microsoft introduced MAI-Cyber-1-Flash and Project Perception, its first in-house security model plus a platform of coordinated agents that find, prioritize and help patch vulnerabilities.

Nvidia launched the Open Secure AI Alliance with Microsoft, IBM, Red Hat, Cisco, Hugging Face and more than 30 other organizations. A week later it had a Shared AI Findings Exchange working group and initial proposals at Black Hat.

Both are real work by serious teams. But in the coverage our corpus carries, neither launch shipped an efficacy figure. No bugs found, no attacks blocked, no time to detection. The offense reports results. The defense reports membership.

## The one defensive number came from outside the vendors

Trend Micro and PwC ran 2,600 attack prompts against 13 models from Anthropic, OpenAI, Google and DeepSeek in realistic web form and KYC workflows. Stored prompt injection succeeded across all of them.

That is what a defensive number looks like. It is not flattering, which is probably why it came from a research pairing rather than a product launch.

## Why this becomes a policy problem

The White House has finalized guidelines exempting US open-weight models from voluntary federal testing, asking only closed frontier models with advanced cybersecurity and hacking capabilities to submit for evaluation before release.

That threshold assumes the capability can be measured. Today the only parties publishing capability numbers are the labs whose models did the breaking, measuring their own systems, on their own terms, at times of their choosing.

Capital is already moving on the unmeasured side. AegisAI raised $36 million for email security agents and Hush Security raised $30 million to govern non-human identities inside enterprises. Both look like reasonable bets. Neither category has a public benchmark you could use to compare two vendors.

## What to do with this

**If you are buying AI security tooling:** ask for one number before you look at the architecture diagram. Bugs found on a corpus you choose, or attacks blocked in a test you specify. "Agentic coverage" is a category, not a result. The Trend Micro work gives you a free opening question: does stored prompt injection work against the thing you are being sold, and can they show you the run?

**If you are watching policy:** track the phrase "advanced cybersecurity and hacking capabilities". Whoever gets to define and measure it decides which models face federal evaluation, and no public methodology exists yet.

**The signal to watch:** the first defensive launch that leads with a number instead of a roster. That is the week this market becomes comparable, and it has not happened.

#ai-security#cybersecurity#policy#benchmarks