23 September 2026

The U.S. Is Highly Vulnerable to Cyber Threats From China. Here’s What It Should Do

Council on Foreign Relations | Adam Segal

The United States Department of Justice and FBI seized platforms operated by Chinese state-sponsored hackers targeting NASA and the Federal Reserve, highlighting severe vulnerabilities in American critical infrastructure. This operation follows previous federal campaigns in 2024 and 2025 that dismantled botnets controlling thousands of Internet of Things devices and removed malware from over 4,000 domestic computers.

Chronic underinvestment in infrastructure modernization and poorly secured software have left vital water, gas, and telecommunications networks exposed to digital siege. The digital asymmetry is widening. Emerging large language models like Anthropic’s Claude Mythos and OpenAI’s GPT 5.5 accelerate offensive capabilities, threatening to erase Washington's defensive advantages. To counter this, a joint study by the China Strategy Initiative and the CFR Digital and Cyberspace Policy Program released a new report outlining eighteen recommendations to rebuild federal capacity, enhance resilience, and impose costs on Beijing.

Comment

The integration of advanced artificial intelligence models like Anthropic’s Claude Mythos and OpenAI’s GPT 5.5 fundamentally alters the speed of cyber operations. These systems lower the technical barrier for generating sophisticated exploit code. Consequently, offensive actors can identify and exploit zero-day vulnerabilities at a scale that outpaces manual human analysis. This shift compresses the decision cycle for network defenders.

The downstream effect of this automated capability is a critical reliance on AI-driven defensive synthesis. Traditional signature-based detection mechanisms, such as those used by the Cybersecurity and Infrastructure Security Agency, cannot counter rapid, LLM-generated polymorphic malware. Ultimately, the security of municipal water systems across the twelve targeted states is contingent on integrating autonomous defensive agents capable of neutralizing these automated payloads before they reach operational technology networks.

Strategic Question for Discussion
If offensive cyber campaigns leverage Anthropic’s Claude Mythos to automate zero-day discovery, how can the Cybersecurity and Infrastructure Security Agency validate autonomous defensive patches without introducing secondary software vulnerabilities into critical infrastructure?
The pattern of rapid software exploitation suggests that manual validation of defensive patches will become obsolete under the pressure of automated zero-day discovery. My assessment is that the Cybersecurity and Infrastructure Security Agency is likely to transition toward isolated, sandboxed environments where AI agents continuously test and deploy patches autonomously. This shift risks introducing minor operational disruptions, but it represents the primary mechanism to match the operational tempo of LLM-generated exploits.
Share your assessment in the comments below.