Thought Leaders
Agentic Attacks: Lessons from Chickens, Cats, and Giant Wombats

AI as the Apex predator in Dev world
Evolutionary Pressure: A Quick Primer
Before we get into the meat of this, there are a couple of concepts worth establishing. The first is evolutionary pressure.
Evolution is not a choice. Animals don’t choose to evolve one way or another — their environment forces them to, or their environment eliminates them. So when we talk about the way an animal evolved, or why it exists as it does today, we’re not talking about a series of conscious decisions. We’re talking about random mutations and environmental pressures that pushed a species in one direction or another.
Right now, software companies are entering a similar evolutionary moment. AI systems capable of autonomously identifying vulnerabilities, generating exploits, and accelerating cyberattacks are changing the pressure developers and security teams operate under.
AI is now creating that same kind of environmental pressure for software companies. Models capable of autonomous vulnerability discovery, exploit generation, and large-scale attack automation are changing the security landscape far faster than most organizations are prepared for.
The specific evolutionary pressure I want to talk about is the apex predator on Earth right now: humans. And the way three very different animals responded to that pressure.
Who Did It Worse: The Giant Wombat or the Chicken?
The Giant Wombat
The giant wombat — I’m blanking on the exact name, but it lived in Australia — weighed about 6,000 pounds. Before humans arrived, Australia was a verdant, green, almost paradisical place. Would that we had never touched it. These enormous wombats lived largely unbothered. Some predators occasionally took one down, but given their sheer size, the abundance of food, and their ability to reproduce, they held their own against everything the continent had to throw at them.
Then humans showed up.
A couple of things happened immediately. First, humans saw this massive source of protein that could feed a group for weeks — longer, if they could preserve the meat. Second, they started clearing the forests the wombat depended on, either by cutting trees for firewood or by burning entire swaths of land to drive animals out into the open where they could be killed. Humans are extraordinarily good at this kind of coordinated, efficient destruction.
In a very short period of time — geologically speaking, practically overnight — humans deforested large portions of the continent and hunted every last giant wombat out of existence.
It’s worth noting that not every Australian animal went extinct. The kangaroo, small wombats, koalas, and others survived — because they were small enough, fast enough, or adaptable enough to stay out of reach. By the time Europeans arrived, the continent had been shaped into something harsh and unforgiving. A smaller human population, rugged and adapted to extreme conditions. Animals that were either very small, very deadly, or both. As they say: everything in Australia is trying to kill you.
That’s version one.
The Chicken
Now, in its own way, the chicken is arguably the most successful land animal on Earth. Roughly 70% of the total bird biomass on the planet is domesticated chicken. There are even pockets where chickens have gone feral — on islands where they have no natural predators, like the Cayman Islands — and they’ve thrived.
Chickens evolved into something humans find extraordinarily useful: they reproduce quickly, they grow fast, they produce eggs. Humans feed them, protect them, and actively encourage them to multiply. By almost any metric of biological success — population size, geographic spread, resource access — the chicken is winning.
Except, of course, for the part where we eat them.
So the chicken succeeded by becoming the perfect food. That’s not nothing. But there’s a ceiling on that kind of success.
The Cat: The Right Answer
There is one animal that, I’d argue, got this almost exactly right.
The cat.
Cats aren’t apex predators. They don’t dominate humans or prey on them. But instead of being crushed by the human expansion or subjugating themselves to human appetites, they did something different: they co-evolved alongside us. They made themselves useful by hunting rats and small birds that were drawn to human settlements and, somewhere along the way, they made themselves wanted. They became companions.
The result? Cats reproduce quickly. They have abundant food sources, either as pets or as opportunistic hunters around human habitation. They face few serious predators. They are everywhere humans are.
And again, this wasn’t a choice they made. It wasn’t a strategy. It was just how evolutionary pressure played out. But the outcome is remarkable: instead of fighting the apex predator, or feeding the apex predator, they befriended the apex predator.
What This Has to Do with AI
So why does any of this matter?
The arrival of models like Anthropic’s Mythos and Project Glass Wing is, I’d argue, the equivalent of the day humans landed in Australia. Except the timeline is compressed dramatically. What took generations to play out on that continent is going to happen in years — maybe less.
There’s a lot of writing right now about how security teams should respond to the threat of AI-enabled hacking. I think that framing is a mistake. This isn’t primarily a security problem. It’s an engineering problem.
Here’s what’s changing: prior to this new wave of AI, both defenders and attackers operated in a world of relatively limited stakes. Attacks happened. Breaches happened. But the pace and sophistication were bounded by human capacity. That has fundamentally changed. Now there are AI models specifically designed to find and exploit vulnerabilities autonomously, at scale, without fatigue.
Most developer teams are the giant wombat in this story. They’ve lived in an environment where yes, there were threats, but nothing quite like this. They built systems that were reasonably secure against the pressures they actually faced. They hadn’t encountered anything like what’s coming.
That’s about to change.
The Three Options — and Why Only One Works
When this new threat arrives, organizations will effectively have three choices:
- Be the wombat. Don’t adapt. Get wiped out. This will happen to a lot of companies. Some will never come back.
- Be the chicken. Become reactive, scrambling to patch each new vulnerability as it appears. This is the “pull out the spear and treat the wound” approach. It’s better than nothing, but when there are 45 spears coming at you from every direction, that one skill won’t save you. You’re still food; you’re just slower to reach the table.
- Be the cat. Fundamentally change your relationship with the threat. Use AI to defend against AI. Embed security into engineering from the ground up. Design systems assuming breach — not hoping to prevent it.
The goal isn’t to hire more security analysts to patrol the perimeter. That’s trying to protect the elephants on the savannah. It doesn’t scale against this kind of threat. The goal is to redesign the savannah.
What “Becoming the Cat” Actually Looks Like
This is not surface-level work. It’s not running an AI security scanner on your codebase once a quarter. It requires a rethinking of how development gets done.
Practically, that means things like:
- Simpler codebases that are easier to reason about and audit
- Pulling from libraries with known, vetted security postures
- Building infrastructure on the assumption that breach is a when, not an if — and making lateral movement as difficult as possible once a bad actor is inside
- Befriend the predator by leveraging it just like the attacker. AI models can amplify engineering teams and security teams to evolve their defenses and get ahead of the curve.
Companies founded tomorrow have a clean slate. They can build this way from day one. Companies that already exist, with customers, with sensitive data, with live systems, don’t have that luxury. They have to start transitioning now.
The Call to Action
Anthropic has said this themselves: there will be a reckoning. There will be economic and societal disruption from AI-enabled attacks. Some companies will not survive. They will be compromised by people using these tools, and they will never fully recover. That is going to happen.
So here’s the message: start meow.
Engineering and security need to sit in the same room. Go through the threat landscape together. Build a shared roadmap. One where the primary work is done by engineering and design teams, validated by security, not the other way around. Security can’t lead this. Security can check the work. But the fundamental change has to come from the people building the systems.
The companies that start this process today won’t all make it. But they’ll have set the conditions for survival. And in the environment that’s coming, that’s the best any of us can do.
Be the cat.












