Axios Future of Cybersecurity

September 22, 2026
Happy Tuesday! Welcome back to Future of Cybersecurity.
๐ฌ Have thoughts, feedback or scoops to share? [email protected].
Today's newsletter is 1,788 words, a 6.5-minute read.
1 big thing: Microsoft disrupts AI-powered cybercrime service
Microsoft has taken down digital infrastructure tied to a powerful cybercrime platform that relied on AI tools throughout its operations, the company said this morning.
Why it matters: While the AI industry panics about extinction risks that are years away, financially motivated hackers are already using existing AI tools to turn stolen corporate network access into opportunities for fraud.
Driving the news: Microsoft's Digital Crimes Unit obtained authorization from the U.S. District Court for the Eastern District of Virginia to take down infrastructure tied to an AI-enabled cybercrime platform called EvilTokens.
- Working with its industry and law enforcement partners, Microsoft seized 50 websites used to operate the service and disabled more than 150 additional domains tied to its infrastructure.
- British police told Axios in a statement that they arrested two men, aged 32 and 38, earlier this month in connection with EvilTokens.
- The platform helped paying hackers break into email inboxes, then used an AI chatbot to analyze victims' messages, map internal roles, identify trusted relationships, and seek out conversations about payments.
- The AI condensed work into hours that could otherwise have taken the hackers several days, helping them determine who controlled the money, whom they trusted and whom to impersonate.
Catch up fast: EvilTokens launched in February when researchers began observing the phishing service successfully compromising Microsoft accounts through a tactic known as device-code phishing.
- Researchers at Microsoft and other cybersecurity firms then tracked EvilTokens as it gained traction among cybercriminals.
- A Microsoft spokesperson told Axios that the company started publicly warning customers about EvilTokens' tactics in April and began building its case as it gained deeper visibility into the operation.
- "Once the scale and sophistication of the threat became clear, we moved quickly," the spokesperson added. "In fact, this was a relatively accelerated operation from initiation to execution."
Threat level: Microsoft now estimates that EvilTokens compromised more than 12,000 email inboxes across 10,000 organizations, including those in construction, financial services, real estate, higher education and healthcare.
- Microsoft saw the highest concentrations of victim activity in the U.S., Canada, the UK, Australia, India and France.
- Coinbase, one of the companies that helped Microsoft with the investigation, traced about $1.1 million in revenue to the platform.
How it works: EvilTokens used a subscription model for its platform, charging hackers a $1,500 initiation fee and $500 a month for access.
- Users were given a range of personalized phishing lures to pick from, including those posing as construction bid proposals, business partnership agreements, employee compensation and benefits notices, and password expiration warnings.
- Once a target clicked a malicious link, EvilTokens tricked them into entering a code on Microsoft's legitimate sign-in page that unknowingly granted the hacker access to their account.
- After gaining access, hackers could use EvilTokens' AI tools to sift through the victim's inbox for financial conversations, identify high-value employees and determine whom to impersonate.
- Hackers could then use the compromised account to send additional phishing emails to the victim's internal and external contacts โ and used information from the inbox to make their fraud attempts more convincing.
The big picture: EvilTokens is the latest example of how AI models are helping malicious hackers scale and speed up attacks they've long carried out โ while lowering the barrier for less-sophisticated hackers to get in the game.
- Microsoft also found evidence that "large portions" of EvilTokens were "vibe coded," or built using AI tools themselves โ underscoring how AI was used on both sides of the cybercrime operation, it said today.
- "The same technology was lowering barriers at both ends of the operation: helping criminals build malicious tools more quickly and helping their customers turn compromised accounts into actionable opportunities for fraud," Steven Masada, associate general counsel and general manager in Microsoft's Digital Crimes Unit, wrote in a blog post.
What to watch: Law enforcement is conducting its own investigation into EvilTokens, Microsoft said.
2. Exclusive: AI agents to fight AI agents
Palo Alto Networks wants to fight AI with AI by setting a mix of frontier models and open-weight models loose on customers' networks around the clock to find vulnerabilities before hackers do.
Why it matters: It's the latest example of major cybersecurity vendors tapping AI agents to defend at the same speed and scale that AI is giving attackers.
Driving the news: Palo Alto Networks is rolling out a new subscription service today that allows customers to use a mix of gated frontier models โ including Anthropic's Mythos 5 and OpenAI's GPT-5.6-Cyber โ and open-weight models to find security flaws on their systems and recommend fixes, the company shared first with Axios.
- The service continuously tests web apps, APIs, cloud infrastructure, source code repositories and network assets as a customer's environment changes, and attempts to string individual flaws together into viable attack paths.
- Customers can also pair the service with Palo Alto's virtual patching tools to mitigate vulnerabilities before an official patch is available.
The big picture: Security vendors are racing to keep pace as increasingly capable AI models give both attackers and defenders new tools.
- "The capability and technology continues to evolve much faster than you can create security for it," Palo Alto Networks CEO Nikesh Arora told Axios.
By the numbers: In Palo Alto Networks' own testing, the company found that no single AI model caught more than 40% of the vulnerabilities on a company's complex environment.
- At the same time, the vulnerabilities that Mythos 5 and GPT-5.6-Cyber found only overlapped less than 10% of the time.
Between the lines: Tapping multiple AI models in defense, alongside human expertise, is the future for the cyber industry, especially given that each model is trained on different data, Arora said.
What to watch: As AI expands into legal work, desktop tools and other enterprise applications, Arora said, Palo Alto Networks will look at where enterprise AI adoption ends up concentrating to determine what it needs to secure next.
- "If you believe that half of what's going to happen or be possible with AI hasn't been invented yet, then half of that security is missing, too," Arora said.
3. OpenAI's pitch after U.S., China talks
OpenAI released international AI safety standards yesterday as world leaders, namely the U.S. and China, weigh how to mitigate risk.
Why it matters: The U.S. approach to coordinating on AI risk with China will be heavily informed by industry recommendations.
Driving the news: OpenAI is proposing solutions that CEO Sam Altman will cover in his address at the United Nations Security Council in New York tomorrow.
- U.S. Treasury Secretary Scott Bessent and Chinese Vice Premier He Lifeng over the weekend discussed a U.S.-China AI dialogue in which one country would notify the other when AI incidents reach a national security risk threshold.
What they're saying: OpenAI recommends leveraging AI safety institutes around the world to facilitate standard-setting through the Center for AI Standards and Innovation, which is part of the U.S. Commerce Department.
- The company also recommends shared global measurements for classifying incidents and how to track, report and respond to alignment issues.
- The goal is to have international standards for incidents that happen before deployment in test settings and those that occur in the real world, an OpenAI official told Axios.
What we're watching: Expect AI labs to continue chiming in as all eyes are on President Trump and Chinese President Xi Jinping's meetings and a state dinner featuring industry heavy hitters later this week.
4. Gemini piles onto AI hacking incidents
Google's Gemini AI model broke into three companies' systems using basic hacking techniques during model testing earlier this year.
Why it matters: Google was one of the only AI labs that hadn't yet publicly disclosed a security breach involving its agents during routine pre-deployment testing.
Driving the news: On Friday, Google confirmed the three incidents, which happened in May.
- The incidents happened as part of a test run that third-party evaluator Irregular was operating โ similar to other security breaches involving OpenAI, Anthropic and Meta's AI models.
What they're saying: "Safe development of powerful AI models is critical and we invest deeply in this area," Heather Adkins, vice president of security engineering at Google, said in a statement.
- Adkins added that her team contacted the affected entities and "worked with our training partner on the changes they've now made to their testing processes."
- An Irregular spokesperson confirmed to Axios that the Gemini incident involved the same security issues that led to similar incidents involving other AI labs' models.
- The spokesperson also said in a statement that all "relevant labs were notified in late July" and that "all known issues on our end were remedied and resolved weeks ago."
Zoom in: The hacks happened while Gemini was completing a "capture the flag" hacking exercise, where the model was asked to retrieve information from software operated by a fictional company inside a testing environment, per the Wall Street Journal.
- However, the fictional company had the same name as a real one.
- In one case, the model guessed passwords for a protected system until it gained access. In the other two cases, the model found credentials in a public repository that then allowed it to access other protected systems.
Yes, but: Google's model stopped its actions as soon as it realized it had accessed real companies.
5. Catch up quick
@ D.C.
๐ค As President Trump eyes a new AI czar, he may turn to insiders โ including national cyber director Sean Cairncross โ due to potential investing conflicts. (Axios)
๐ฐ The Trump administration is weighing a plan to establish an incubator for investing in cyber research and startups. (Bloomberg)
@ Industry
๐งช OpenAI shared a new internal procedure for reporting instances of misaligned AI while also unveiling details about six additional incidents of its models going rogue during pre-deployment testing. (Axios)
๐ฅ Anthropic will embed Accenture employees within the company to help test the safety of its AI models. (CNBC)
๐ง Multiple staff members at the U.K. AI Security Institute are on leave from work due to low morale and burnout after months of testing new AI models under tight deadlines. (Financial Times)
@ Hackers and hacks
๐ Hackers used Anthropic's Claude to break into an OpenAI employee's ChatGPT account and suggest changes to the company's private cache of software. (Wall Street Journal)
๐ข Cybersecurity teams with the U.S. Coast Guard and the FBI boarded two U.S.-bound oil tankers last month to investigate a reported cyberattack on at least one of the ship's networks. (TechCrunch)
๐ฑ Researchers used a modified version of a GLM AI model to break into a TikTok user's camera. (Washington Post)
6. 1 fun thing
โ๏ธ The latest dispatch from dystopia? AI agents now have a hotline to call to snitch on one another.
โ๏ธ See y'all next week!
Thanks to Kate Marino for editing and Khalid Adad for copy editing this newsletter.
If you like Axios Future of Cybersecurity, spread the word.
Sign up for Axios Future of Cybersecurity

Decode the cyber challenges reshaping business, government and geopolitics. With Sam Sabin.





