AI-Powered Medical Device Cyberattacks Are Coming … Faster Than Expected

From the May 2026 SoftwareCPR newsletter – an edited excerpt about cyberattacks:

Last month, we explained that cybersecurity monitoring is not optional extra work. It is a basic duty across the full life of a medical device. AI can help with monitoring effectively and efficiently.

That duty is becoming even more important as AI becomes also a threat. AI-driven cyberattacks have already begun. So far, victims have been few and often well known. Attack methods have also mostly matched the early stages of AI use.

That is changing. Anthropic’s recently announced Mythos model appears to be an enormous step forward in cyberattack capability. Early testing found that Mythos performed unexpectedly better at complex, multi-step attack simulations. Those gains were once thought to be further in the future. This indicates that highly capable AI-based attacks are no longer just a theory. Anthropic has limited access to Mythos for now, but that may not last forever. OpenAI has just announced a highly capable cyber model of their own. Other AI makers may release similar models.

These models change medical device cybersecurity in two major ways as they can:

  1. Speed up how fast attackers find, link, and use weaknesses.
  2. Raise the skill level of attacks much faster than expected.

That increases risk during both product development and real-world use. The answer is preparation before you become a target.

During development, manufacturers should strengthen secure-by-design practices for future releases. A Secure Product Development Framework is not only about meeting FDA and EU guidance. It is also a practical way to build cybersecurity into the development process. That includes strong threat modeling and architecture reviews “up front” in development. That way, protections can be designed in. Security processes will include third-party software oversight, automated vulnerability scanning, and adversarial testing.

Once products are in the field, speed will matter most. Manufacturers will likely need better telemetry from the products themselves to detect issues. Designs – especially software – should be patch-ready. Fast incident analysis and patch development/deployment will also be critical.

Do not wait before AI-driven threats threaten your products. Compare your development process against secure-by-design expectations and needs. Update your cybersecurity industry and postmarket monitoring plans ASAP.

Want to receive our newsletter and get information like this? Subscribe here: https://www.softwarecpr.com/join-mailing-list/ 

About the author

Mike Russell helps organizations succeed without compromising speed, quality, or regulatory compliance. His 40+ years of leadership and advisory experience ranges from startups to Fortune 20 companies and national governments. He expertise includes product and software development, cybersecurity, AI, and leadership. Mike served on the AAMI group that created TIR45, Guidance on the use of Agile practices in the development of medical device software. He is also an AAMI expert faculty member for software validation (product and non-product) and agile. For SoftwareCPR, he co-created and delivers training on compliant agile and medical device cybersecurity. As an executive, Mike led organizations of up to 1,100 people with over $100 million budgets.

Upcoming Public Courses

No public courses are planned at this time.

If you would like to discuss a private, onsite course, please fill out the form below.

Or just email training@softwarecpr.com for more info.

Corporate Office

15148 Springview St.
Tampa, FL 33624
USA
+1-781-721-2921
Partners located in the US (CA, FL, MA, MN, TX) and Canada.