
The introduction of Mythos and GPT-5.5 has revolutionized artificial intelligence capabilities in detecting cyber vulnerabilities, marking a watershed moment in cybersecurity. According to Business Standard, Anthropic and participants in Project Glasswing found more than 10,000 new high- and critical-severity cyber vulnerabilities during the first month of use. Ninety-five percent of these vulnerability disclosures had no public advisory at the time, meaning they were not listed on vulnerability databases and thus not widely known. A report by Epoch AI showed that critical cyber vulnerabilities reported by 21 leading technology companies went from less than 10 to 400 following the release of Mythos. The median time for vulnerability exploitation has fallen from one year in 2021 to a projected one minute in 2027, with the length and complexity of tasks these leading models can complete autonomously doubling every 3-4 months.
Cyber threat activity targeting India's finance and healthcare sectors has reached alarming levels in the first half of 2026. According to data shared by the government in Parliament, cyber threat activity remained elevated with detections already crossing 60% of the levels recorded during the whole of last year. CERT-In detected and mitigated almost 3.5 lakh instances of malicious scanning, probing and vulnerable services in the finance sector between January and June 2026, compared with 5.7 lakh instances during the whole of 2025. The healthcare sector recorded another 18,855 instances in the first six months, equivalent to nearly 55% of the 34,480 detected and mitigated during all of 2025. Together, finance and healthcare accounted for just under 3.7 lakh instances in the first half of 2026.
The banking sector's rapid AI adoption is creating new vulnerabilities as Moody's warns that big banks are becoming dependent on a small group of Silicon Valley firms. According to Moody's latest report, the financial sector's race to integrate AI into operations is leaving institutions vulnerable to widespread outages and price gouging by profit-hungry tech bosses. The rating agency notes that more than 75% of City companies now use AI, with insurers and international banks among the biggest adopters, primarily for automating administrative tasks and core operations including insurance claims processing and creditworthiness assessments. Lloyds Banking Group's CEO Charlie Nunn recently announced a £13bn AI strategy involving £2bn in cost cuts, which will affect staff and require continued reskilling efforts.
Despite technological challenges, fraud cases involving bank staff have shown a declining trend from 2,624 cases in FY21 to 1,935 in FY25 and 400 in the first half of FY26. As reported by Business Standard, staff fraud represents only 8% of total cases but likely much higher in value. The decline suggests that existing controls including maker-checker systems, job rotation, and whistleblower schemes are working effectively. However, the industry acknowledges that more robust prevention measures are needed given the significant value of these frauds and the additional risks posed by AI integration.
Industry experts recommend shifting from annual audits to a 'data + behaviour + controls' framework that triggers in real time. As reported by Business Standard, focus areas should include employee access to accounts of relatives without mapped business reasons, after-hours logins (9 PM–6 AM), repeated transaction limit overrides, and round-tripping activities. The framework should mandate biometric login with non-negotiable single biometric identity and prevent the same ID from playing both maker and checker roles for the same transaction. Additionally, no ID should remain active for more than 15 minutes if not used, minimising password-sharing risks. Moody's warns that a set of dominant AI model and infrastructure providers could exert control over AI service pricing, creating additional challenges for fraud prevention budgets. The proposed framework includes four-eye principle governance requiring at least two distinct authorised people to review critical actions before execution.
India faces an urgent need to upgrade its cybersecurity infrastructure, particularly in state-level providers and small and medium enterprises. According to Business Standard, in India, we may need to implement a cash-for-clunkers programme to encourage our state-level infrastructure providers to upgrade to the latest software. Many service providers including state electricity boards, municipalities, and water utilities run outdated versions that are very vulnerable. The report suggests we may also need to put in place a central-level cyber defence agency, with the authority to help critical infrastructure sectors or key enterprises during a cyberattack. The analysis emphasizes that attacks from state actors cannot be handled at an individual enterprise level and requires coordinated national response. The introduction of AI models with Mythos-level capability has made speed of response critical, as enterprises are notoriously slow in implementing patches while attackers can reverse engineer patches and weaponize them in minutes.