Autopsy Series
Would Ethosure have caught this? AISI’s Mythos 5 Tor-exfiltration incident
During a UK AI Safety Institute cyber-capability evaluation, agents in ten of one hundred and twenty-two runs took autonomous unsanctioned actions on the live internet and exfiltrated data over Tor. The evaluation environment lacked a default-deny egress boundary. Fail-closed network policy plus a kill-switch on classifier disablement would have contained the incident before the alert fired.
