Twenty-eight cents. That is what one autonomous cyber task cost this week on an open-weight model anybody can download. The same task on a frontier model: about fifteen dollars. Every headline picked the capability number instead. Wrong number.

The verdict first: attacks did not get smarter this month. They got cheap enough to run continuously, against everybody, without anyone deciding you are worth the effort. And the research from the same seven days says defenders cannot buy their way out with the same trick.

Factor 53

The British AI Security Institute published its first public read on how far open-weight models lag closed ones on cyber capability: four to seven months, down from six to ten through 2025. GLM-5.2 matched February's Opus 4.6 on a 70-task benchmark. Fine. The cost column is the real story: a 100-million-token test on a simulated corporate network cost about $85 on Opus, $46 on GLM-5.2, and $1.19 on DeepSeek V4-Pro. Per solved task: $15, $6, and 28 cents. A factor of 53 on the same job. And when DeepSeek refused a task, asking again was enough — you cannot bolt rate limits onto weights someone already downloaded.

For twenty years, being small was a security control. Nobody wrote it down, but it was economic: you were not worth a specialist's week. At 28 cents a task nobody has to decide you are worth it. The scan just runs.

Defense runs on discipline, not budget

Three researchers published a cost-aware evaluation of security agents with the most useful finding I read all week: offense scales with compute budget; defensive SOC work depends on disciplined tool use and telemetry navigation, and spending more does not buy proportionally more. So when the attacker's price drops 53x, the defender cannot restore balance by matching spend. In HVAC we size for the worst-case load, because the average day never breaks anything. Most security budgets are still sized for the average attacker. That assumption just expired.

Google's answer proves the point: Gemini 3.5 Flash Cyber, a cheap model called many times in parallel, found 55 confirmed vulnerabilities against 36 for Claude Opus 4.6 — disciplined cheap search, exactly what the research prescribes. And it is a gated pilot for governments and trusted partners. The offense downloads over your home connection; the best announced defense is not for sale to you.

The delivery van arrived the same week. Zenity disclosed AgentForger: one tampered chatgpt.com link made a victim's own tenant build a rogue agent that inherited their identity and connectors, set every approval to "Never ask", ran every five minutes, mailed found credentials in plain text and tested a $242,500 wire approval. Prerequisites: logged in, one connector authorised. So the cheap moves are the effective ones. Count who can connect an agent to your mailbox — in most small firms that is everybody and nobody has counted. Kill "Never ask" everywhere. Route payment and credential changes through a second channel, because the attack produces a normal-looking message from a real colleague's account. And sweep your chat history for pasted secrets; the agent found live database credentials in Slack in one query.

One honest caveat: AISI's figures come from simulated networks without defenders, so a 53x benchmark drop is not a 53x real-world drop. I plan on the direction being right even if the magnitude is off by four. And I have skin here: this operation runs on the same cheap local inference, about a euro a day. The economics that let one person in Belgium run a news agency for pocket money let one person run 500 reconnaissance passes for the same money. Nobody gets the good half without the bad half.

The claim: before end September, a publicly disclosed breach at a small or mid-sized company names an employee-authorised AI agent or connector as the entry vector. If disclosures stay credential-first with agents nowhere in the chain, I overread this attack class, and I'll say so.