Axios Future of Cybersecurity

July 28, 2026
Happy Tuesday! Welcome back to Future of Cybersecurity.
📬 Have thoughts, feedback or scoops to share? [email protected].
Today's newsletter is 1,712 words, a 6.5-minute read.
1 big thing: Hugging Face hack is a wake-up call
OpenAI models' accidental hack of Hugging Face is the warning shot defenders have been afraid was coming.
Why it matters: If defenders and policymakers don't take the warning seriously, public utilities, financial firms, hospitals and communications systems could face greater risk as more capable AI systems become available.
Driving the news: OpenAI CEO Sam Altman is in D.C. this week to push for the speedy rollout of his company's latest model, which just hacked into Hugging Face.
- People familiar with the breach investigation told Reuters that OpenAI didn't notice its AI agent had gone on a dayslong hacking spree until after the FBI was notified.
- Sources also told Bloomberg that OpenAI's models conducted the attack in a matter of hours, while a human hacker would have needed weeks.
The big picture: For years, cyber and national security experts have warned that AI models would one day be able to carry out the kind of multistep, sophisticated cyberattack that OpenAI's models just performed.
- "Our defenses are not prepared to keep up," Andrew Rubin, CEO and founder of Illumio, told Axios. "Organizations no longer have time to detect, investigate, and respond before the damage is done."
- Chris Krebs, CISA director during the first Trump administration, told Axios that security leaders need to go to their boards now to warn them about what's to come.
- "You don't have to fix everything at once, but you should be able to answer two questions: Can you spot an AI operating inside your network? And can you shut it down fast?" Krebs added.
Yes, but: OpenAI's models hacked Hugging Face while in a testing environment where researchers purposefully turned off safety guardrails.
- Greg Brockman, co-founder and president of OpenAI, told Fortune that the company has been staffing up to tackle cyber defense issues and he hopes the Hugging Face incident can "bring together the industry because everyone's interests are very aligned."
Threat level: It's now only a matter of months before easy-to-jailbreak open-source models — especially those from Chinese companies — are capable of replicating what OpenAI's models did, experts warned.
- Stripping guardrails from an open-source AI model is "trivial for anyone who wants both," Rob T. Lee, chief AI officer at the SANS Institute, told Axios. Those models were already formidable at hacking and cybersecurity tasks a year ago, he added.
- Don't be surprised if these capabilities are soon in the hands of ransomware crews, intelligence agencies and a "lone operator renting compute by the hour," said Alexander Leslie, senior adviser at Recorded Future.
- "If you're waiting for the first criminal copycat, you're wasting time and burning through a shrinking head start," Leslie added.
Reality check: Defenders already have tools to mitigate many of these tactics, though AI could make attacks faster and more scalable.
- Limiting the access of internal AI agents and maintaining activity logs of what an agent does on a system can help organizations limit harm and spot suspicious activity, Andrew Jones, chief product officer and co-founder of Adaptive Security, told Axios.
Between the lines: The difference now is that adversaries will soon be able to scale and carry out their attacks faster than ever.
- Hackers will likely spend the next few months using AI agents to lower the costs and time spent on their existing operations, rather than trying out new hacking techniques, said Frank Teruel, chief operating officer at Arkose Labs.
- "It's an impending sea change," he added. "Frontier labs can put classifiers in front of these capabilities, but open-weight models a few months behind cannot, and the copies already downloaded never will."
What to watch: OpenAI has said it's working on a technical report detailing how the Hugging Face attack happened that should be available in the "coming weeks."
2. Microsoft, Google join race for small models
Cybersecurity and AI companies are increasingly betting specialized AI models, rather than general-purpose frontier systems, will become defenders' tools of choice for many security tasks.
Why it matters: High token costs and limited access to frontier cyber models have made it harder for many defenders to use AI at scale.
Driving the news: Over the last week, Microsoft and Google joined Cisco in unveiling specialized cybersecurity AI models designed for specific defensive tasks.
- Microsoft unveiled MAI-Cyber-1-Flash, its first cybersecurity model trained in-house, alongside a new suite of AI security agents.
- Google DeepMind introduced Gemini 3.5 Flash Cyber, a model offered through Google's CodeMender program built to identify and patch software vulnerabilities.
The big picture: John "Four" Flynn, vice president of security and privacy at Google DeepMind, told Axios he anticipates cyber defenders will need more than just one large language model to fend off cyber threats in the future.
- Instead, Flynn — who was previously CISO at Amazon and Uber — predicts defenders will also need a series of small AI models that specialize in specific cyber tasks and are cheaper to run.
- "We're hitting a need that people are really struggling with," Flynn said. "They either don't have access to the programs that are out there or it's just the token cost is insane."
Between the lines: Microsoft is making a similar bet, arguing cyber-specific models can deliver strong performance while reducing inference costs.
- "We're not going to let the attackers have all the productivity increases," David Weston, corporate vice president of AI security at Microsoft, told Axios.
Yes, but: Defenders remain cautious about turning security work over to autonomous AI agents.
- Weston said Microsoft expects organizations to gradually build trust in the technology before allowing agents to operate with greater independence, adding that the company still has to "earn the right" to make those systems more autonomous.
What to watch: Flynn said DeepMind has seen "surprising interest" in the model from organizations that either lack access to frontier cyber models or can't afford to run them at scale.
3. The people testing AI for danger can't keep up
The pace of AI development combined with soaring compute costs is squeezing the AI researchers responsible for evaluating frontier models — just as those models' capabilities are becoming harder to measure.
Why it matters: When safety testing can't keep pace, models capable of hacking companies or aiding in the development of bioweapons could reach the public before anyone knows what they can do.
- Last week's breach of Hugging Face, carried out autonomously by OpenAI's models in the middle of safety testing, shows that some of the highest-risk behaviors can emerge during pre-release testing itself.
Several challenges are tying up AI safety and security researchers just as U.S. frontier AI companies race to get new models to market:
- Some testers tell Axios that they're getting far less time to study models' capabilities before release — in some cases just days instead of weeks.
- Building benchmarks that can accurately probe models' security skills is becoming cost-prohibitive as bigger tests chew through ever more compute.
- Researchers often get access to a single, rate-limited API endpoint shared with other testers, so they quickly hit usage caps and can't run large or thorough evaluations in the time they have before deployment.
Reality check: The models themselves are also getting in the way of their own evaluations as they start to cheat more and learn when they're being evaluated, former METR researcher Lawrence Chan told Axios.
➡️ Read the rest.
4. Catch up quick
@ D.C.
🛑 A bipartisan House bill would call for top AI firms to create a "kill switch" that shuts down or slows models the government deems too dangerous. (Politico)
🩹 The head of the government's go-to cloud security program said companies that can't quickly patch systems shouldn't be selling to the government. (Nextgov)
@ Industry
🧠 Anthropic released Claude Opus 5, a model that performs nearly as well as the company's most powerful consumer-facing model, Fable 5, at a fraction of the cost. (Axios)
🤝 Nvidia launched the Open Secure AI Alliance yesterday as it continues to build support for the open-weight AI model ecosystem. (Axios)
🌐 Anthropic CEO Dario Amodei said he's "never advocated" for a ban on open-weight AI models. (Axios)
@ Hackers and hacks
💰 Hugging Face's CEO says he asked OpenAI for $100 million in compute to bolster his company's cyber defenses after the recent hack. (Business Insider)
🐞 The total number of security flaws discovered and recorded in the National Vulnerabilities Database is on pace to double this year. (Bloomberg)
⏰ AnMed, a nonprofit health system serving South Carolina and Georgia, has reportedly been given 72 hours to respond to a ransom demand after a cyberattack affected patient services this week. (Healthcare IT News)
5. 1 fun thing
I was the target of a job scam — and it was so detailed, even I was surprised.
Why it matters: Gone are the days of easy-to-spot phishing emails that offer hourly work at random companies. What I received is the type of hyper-personalized scam email that AI unlocks.
📩 Some spooky good things that stood out:
- The scammer impersonated an actual recruiter for the company where they claimed to be working on behalf of Palo Alto Networks and included her photo. (I found the person on LinkedIn and sent her a note, and she confirmed it was an impersonation.)
- The job was clearly tailored to my skillset: The scammer said they were recruiting for a director of cyber intelligence and editorial strategy at Palo Alto Networks, and they included a lot of details about my work history and skills that would make me a standout candidate.
- The scammer also clearly used Gmail's confidential mode, which made it impossible for me to forward the email to anyone else, including Palo Alto Networks or the person they were impersonating.
Reality check: There were some natural tells that anyone can look out for, including:
- The email came from a personal Gmail account, not an official company address.
- The role they described wasn't listed anywhere.
- The recruiter they impersonated is actually an internal recruiter, meaning she recruits for roles at her company — not on behalf of other companies, according to her LinkedIn.
The bottom line: Be vigilant. Always check to see what address the email was sent from and try to find the sender on an alternative platform to find out if it's actually them.
👀 See y'all... later this week!
Thanks to Megan Morrone for editing and Khalid Adad for copy editing this newsletter.
If you like Axios Future of Cybersecurity, spread the word.
Sign up for Axios Future of Cybersecurity





