Why now
AI gave attackers machine speed. Match it with proof your defences hold — every day, not once a year.
AI has collapsed the time between a weakness existing and a breach happening. The tools you’ve bought were built for a slower world — and in Australia, your obligations just moved. Here’s what changed, and what to do about it.
The future of cyber warfare will run at machine speed – algorithm vs. algorithm – with humans by exception.
Snehal AntaniCEO and co-founder, Horizon3.aimore “manoeuvre decisions per minute” an algorithm-driven attack can make than the team defending against it.
By the time a defender has sifted the logs, triaged the alerts and won approval to act, the attack has already adapted and moved on.
Within five years that gap could reach 100,000× — fast enough to leave human-paced defence behind.
Horizon3.ai — Our security visionAI handed attackers scale and speed.
In April 2026, Anthropic’s Project Glasswing revealed that an AI model had found thousands of zero-day vulnerabilities across every major operating system and browser — flaws that had survived decades of expert review. The lesson isn’t a new kind of vulnerability. It’s that the effort to find, weaponise and chain weaknesses has collapsed towards zero. What used to take a skilled team weeks now compresses into minutes.
Weaponised faster
Raw findings become working exploits in near real time.
Barrier removed
Chaining weaknesses together no longer needs rare expertise.
Path compressed
Initial access to a high-value asset, in one short hop.
The people building the AI are saying it plainly.
Not vendor noise — the labs building these models and the national cyber authorities watching them, in their own words.
During our testing, we found that Mythos Preview is capable of identifying and then exploiting zero-day vulnerabilities in every major operating system and every major web browser when directed by a user to do so.
the bottleneck in cybersecurity is now verifying, disclosing, and patching the large numbers of vulnerabilities that Mythos-class models can surface.
AI will make it easier, faster and cheaper to discover and exploit weaknesses that previously required more time, skill or resource for attackers to identify.
So what? Left unchecked, this only gets worse.
None of this is a one-off. The economics now favour the attacker, and the curve runs one way. Here’s the trajectory if defending stays an annual, human-paced exercise.
Automated attacks keep getting through.
Automated attacks will keep getting through organisations that have deployed every recommended tool — because this was never a tools problem. It’s an effectiveness problem: siloed products aren’t built to work as one, and attackers move through the seams between them.
The gap widens.
Adversaries will shift to autonomous attack platforms faster than defenders can improve — and prove — their controls actually hold. The distance between tools deployed and attacks stopped keeps growing.
Defence becomes humans by exception.
Within a decade, defence will run algorithm against algorithm. No human team can keep pace with attacks that adapt in seconds — and as automation lowers the barrier to entry, the volume of those attacks only climbs.
The trajectory is set. What you control is whether you can prove — today, and every day after — that your defences hold, and keep proving it as the curve steepens.
Two things got worse at once: more weaknesses, less time.
Speed isn’t the whole story. AI is also surfacing genuinely new weaknesses — Project Glasswing found flaws that had hidden in widely used software for decades, invisible to millions of automated tests and years of expert review.
So defenders are caught in a pincer: the pool of exploitable weaknesses keeps growing, while the time to weaponise any one of them collapses. More to fix, and less time to fix it. “Patch everything” was already a losing race — now the backlog grows faster than any team can clear it.
Your obligations are tightening — and the clock isn’t yours to set.
This isn’t a fixed bar you clear once. It’s a ratchet, tightening on timelines you don’t control — audit cycles, contract renewals, regulator deadlines. And primes are pushing the same requirements down the supply chain.
DISP
Moving from four to eight mandatory controls.
SOCI & CIRMP
Demonstrated cyber resilience for critical infrastructure.
APRA CPS 230 / 234
Tested, board-attested operational resilience.
Essential Eight ML2
Evidence for every control — and a defensible path to maturity.
For Australian defence and critical-infrastructure suppliers, security uplift you can prove is now tied to revenue — the contract you’re bidding for assumes it. Attestation by checklist won’t survive contact with an auditor, let alone an attacker, and the time to find the gaps is before the assessment, not after it.
And if you’re still working towards Essential Eight Maturity Level 2, continuous testing shows exactly which controls have evidence gaps — a defensible path to maturity you can start now, not just a longer to-do list.
The attacker’s AI has new moves. So does your testing.
For every step an AI-armed attacker takes, NodeZero takes the same one first — against your real environment, safely, with evidence you can hand to an auditor.
| An AI-armed attacker | NodeZero, first |
|---|---|
| Finds weaknesses across your environment faster than your team can patch them | Finds the same weaknesses first — safely, inside your production environment |
| Turns raw findings into working exploits in near real time | Proves which findings are genuinely exploitable, with evidence at every step |
| Chains weaknesses into a path to the assets that matter | Walks the same attack paths end-to-end, and shows you exactly where they lead |
| Iterates until something gets through | Re-tests continuously — not once a year — and verifies every fix actually holds |
Meet machine-speed attack with machine-speed proof.
You can’t out-human an AI-armed attacker, and you can’t wait a year between tests. NodeZero runs real attacks inside your environment — continuously, safely — and proves exactly what an attacker could reach today. Not a simulation. Not a scanner’s guess. Proof. And because it’s real proof, it’s also the evidence your DISP, Essential Eight and SOCI obligations now demand.
It runs on inference, never training — your environment’s data is used to find risk, not to train a model, and stays inside the boundary you approve.
Every action is deterministic, production-safe and reproducible — the creative AI does the thinking, never the exploiting. The AI approach →
Don’t assume you’re secure. Prove it.
See NodeZero run against a live environment with the Drochaid team.
