CERT Polska rebuilt the MikroTrick attack chain from MikroTik's unlabeled September 3 patch and had a working exploit for CVE-2026-86060 in about an hour. The fix quietly disables a rogue "ops" account, evidence the chain was already exploited in the wild.
Reality
- Evidence68
- Adoption62
- Hype gap+8
- Incentives45
- Confidence60
Chen Yixin, who runs the Ministry of State Security, cited the two frontier models in the Cyberspace Administration's journal as evidence of a disruptive upgrade in offensive cyber capability, without alleging either was used against China.
Reality
- Evidence62
- Adoption38
- Hype gap+24
- Incentives72
- Confidence58
Politico reported that ENISA and CERT-EU ran an advanced OpenAI model over an EU project's code and got four fixed flaws out of it. Poland's CERT, doing the same kind of work, said it tested every hypothesis on real systems.
Reality
- Evidence58
- Adoption62
- Hype gap+16
- Incentives71
- Confidence52
Chen Yixin's signed article calls Claude Mythos and GPT-5.5-Cyber a serious risk to China's critical information infrastructure. It cites no incident, and only one of the two is sold to customers at all.
Reality
- Evidence58
- Adoption35
- Hype gap+45
- Incentives72
- Confidence55
CrowdStrike will run OpenAI's cyber-tuned model inside its own harness while policing OpenAI's Codex agents at runtime, which leaves one vendor configuring what agents can reach and auditing what they did.
Reality
- Evidence46
- Adoption24
- Hype gap+33
- Incentives84
- Confidence51
Tenable says context can cut remediation to 1.6% of findings. If that holds, the scarce resource next year is asset truth, not patching speed.
Reality
- Evidence26
- Adoption14
- Hype gap+58
- Incentives86
- Confidence62