Axios Future of Cybersecurity

August 25, 2026
Happy Tuesday! Welcome back to Future of Cybersecurity.
ππ» Hope everyone enjoyed the break. Surely I didn't miss much while away....
π¬ Help catch me up and send scoops: [email protected].
Today's newsletter is 1,804 words, a 7-minute read.
1 big thing: AI is supercharging infrastructure hacks
Years of warnings about the digital vulnerabilities lurking inside basic utilities are colliding with a new reality: AI is making those weaknesses easier for hackers to exploit.
Why it matters: AI is lowering the barrier for state-backed hackers looking to disrupt or manipulate water systems, power plants and other critical infrastructure.
Driving the news: A recent wave of cyberattacks targeting critical infrastructure is raising new questions about the preparedness of U.S. water systems and a British power plant.
- The Telegraph reported that Iran-backed hackers broke into a U.K. power plant, prompting a four-day shutdown around the time a series of cyberattacks on U.S. water systems began.
- U.S. officials warned last week that hackers were actively using an AI-generated exploitation script to target a device commonly found in critical infrastructure that has played a key role in the ongoing attacks on U.S. water systems.
- Markus Mueller, field CISO at critical infrastructure security firm Nozomi Networks, told Axios he has medium confidence that the U.S. and U.K. attacks are linked to the same threat actor.
The big picture: Policymakers have been warning for years that weak cybersecurity across critical infrastructure could eventually have real-world consequences.
- Five years ago, Sen. Angus King (I-Maine) warned Congress that cyber weaknesses across U.S. water utilities represented "an extremely dangerous situation."
- "We're the most wired country in the world. That's good," he told lawmakers. "But we're also the most vulnerable country in the world."
Between the lines: AI isn't fundamentally changing how hackers break into these systems. It's reducing the time and expertise needed to understand specialized equipment and exploit weaknesses that already exist, experts told Axios.
- Suspected Iranian hackers have long studied U.S. critical infrastructure, including how specialized devices such as programmable logic controllers work.
- Historically, threat actors might have needed to obtain the devices themselves or pore over technical manuals before they could successfully target them, Mueller said.
- Now, AI is lowering the "time, cost, and expertise needed to take advantage of weaknesses that already exist," Diana Kelley, chief information security officer at Noma Security, told Axios.
Reality check: Governments haven't simply ignored the problem. But efforts to impose stronger security requirements have moved slowly and repeatedly run into legal, political and funding hurdles.
- The Environmental Protection Agency attempted during the Biden administration to require water utilities to implement basic cybersecurity measures, but it later rescinded the policy after legal challenges from states and industry groups.
- Recent federal cuts to cybersecurity resources and uncertainty around federal grant funding for state and local governments "leaves communities more vulnerable to future cyberattacks," Mayuresh Dani, a security research manager at Qualys, told Axios.
- Cyber hygiene guidance and government advisories alone won't keep pace with attackers, John Gallagher, vice president at automated cybersecurity firm Viakoo, told Axios.
- "Adversaries will always have an upper hand because of speed when cyber defense relies on bureaucratic budget cycles and multiyear legislative processes," Gallagher said.
Yes, but: So far, the recent attacks appear to have caused only limited disruptions.
- In some towns, hackers affected the pressure levels for local water supplies and officials issued precautionary boil-water advisories.
- The Telegraph reported that the cyberattack on the local power plant "had no impact on the U.K.'s wider power supply or energy generation. "
The intrigue: Critical infrastructure remains an alluring target for nation-state hackers precisely because even relatively small disruptions can have highly visible consequences, Margaret Cunningham, vice president of security and AI strategy at Darktrace, told Axios.
- "AI gives attackers more speed and reach, but it doesn't erase the problems critical infrastructure organizations have been dealing with for years, including exposed operational technology, difficulty patching and systems that cannot simply be switched off," she said.
What to watch: Key details about the U.K. incident remain unknown, including what type of power plant was targeted and which devices the hackers accessed, Mueller said.
2. Exclusive: UN agency explores sovereign AI
A United Nations agency is teaming up with a Switzerland-based organization to help governments build AI-powered software without relying solely on U.S.-based cloud providers.
Why it matters: Concerns about the world's reliance on foreign cloud providers have been mounting as governments question how much control they retain over sensitive citizen data stored on infrastructure operated by companies based abroad.
Driving the news: The UN Development Programme and the DFINITY Foundation are launching a pilot program to help governments test AI-powered applications that give them more control over where their data and computing infrastructure reside.
- The UNDP plans to select five countries for the initial pilots within roughly a month, with each project built around a specific problem proposed by participating governments.
- The new pilot builds on DFINITY's ongoing work with Pakistan, where the government is incorporating DFINITY's technology into its national digital infrastructure and already has several applications live using its tools, Sohail Munir, chair of the Pakistan Digital Authority, told Axios in a statement.
The big picture: As governments rush to adopt AI, some are experimenting with ways to build AI-powered public services without becoming dependent on major cloud providers for the underlying data and infrastructure.
- Relying on cloud hyperscalers based in the U.S. and China could leave the companies behind these AI tools beholden to the data storage regulations and surveillance apparatuses in the hyperscalers' home countries.
Zoom in: Once selected, each country will work with the UNDP and DFINITY to turn a specific need or problem into a project that can be built and tested using DFINITY's technology, Robert Pasicko, who leads the UNDP's Alternative Finance Lab, told Axios.
- Pasicko expects the five participants will likely spread across Latin America, Africa and Asia.
Zoom out: In conceiving the pilot, Pasicko said he was hearing more from member states who were concerned about where the data fueling AI applications was being stored β and their reliance on U.S. tech giants.
- One potential use case, he said, would involve using AI to analyze medical scans from roughly 200,000 patients while keeping the sensitive health data under government control.
- For some countries, he said, the question is increasingly whether they can take advantage of AI while keeping sensitive government and citizen data under their own control.
Between the lines: Dominic Williams, DFINITY's founder and chief scientist, told Axios that the AI boom is raising the stakes for countries that rely heavily on foreign technology providers for digital infrastructure.
- "If someone could flick a kill switch and knock out your cloud and your AI, your country is going to grind to a halt," Williams said.
What's next: The UNDP plans to evaluate the pilots based on factors including cost, ease of use, and whether participating officials think the technology is worth scaling, Pasicko said.
- The pilots are designed to help the UNDP determine where decentralized AI and cloud infrastructure actually make sense β and where they don't.
3. Flock backlash adds to midterm anti-AI frenzy
Flock cameras are joining data centers as a top midterm boogeyman, with members of Congress and congressional candidates trying to harness a sudden groundswell of grassroots anger over the AI surveillance tool.
Why it matters: This blowup over the country's massive network of license plate readers illustrates how rapidly AI has moved from a peripheral issue in national politics toward the center of the midterm campaign.
- Data centers have become a major issue in the midterms, with candidates racing to one-up each other in their opposition to building the energy-hungry facilities.
- Super PACs affiliated with AI companies have spent tens of millions of dollars clashing with each other in congressional elections over the degree to which the federal government should regulate the technology.
- Now, surveillance cameras are opening a new front in the debate over AI.
Driving the news: Abdul El-Sayed, the Democratic nominee for Senate in Michigan, posted a video to X on Wednesday tying his Republican opponent, former U.S. Rep. Mike Rogers, to Flock cameras.
- "There's been this mass proliferation of Flock cameras, any and everywhere, watching your every move to collect information without you even noticing," El-Sayed says with the '80s tune "Somebody's Watching Me" playing in the background.
- El-Sayed accuses Rogers of supporting the practice, citing a 2013 hearing in which the then-House Intelligence Committee chair said: "You can't have your privacy violated if you don't know your privacy is violated, right?"
- The Rogers campaign did not respond to a request for comment.
Catch up quick: Flock and similar companies are facing a public outcry over their AI-powered license plate reader cameras, particularly given reports of police officers misusing the technology, Axios reported.
- Municipalities across the country have already moved to sever ties with Flock β whose vast network of 120,000 cameras allows law enforcement to track the movement of vehicles β and some people have sabotaged the cameras.
- The company has defended its practices and said it is improving its privacy features, telling Axios it has been "listening to customers, communities, and civil liberties groups."
- Flock has also argued that the tool is being used for good, saying its cameras have aided roughly 1 million police investigations and helped find around 10,000 missing people.
State of play: Democratic House candidates are getting in on the Flock camera blowback.
- Ohio Democrat Kristina Knickerbocker said in a statement that her opponent, former House Intelligence Committee Chair Mike Turner (R-Ohio), "pushed for more Flock cameras in downtown Dayton."
β‘οΈ Read the rest.
4. Catch up quick
@ D.C.
β Questions and confusion still surround the Trump administration's newly stood-up vulnerability clearinghouse. (Cybersecurity Dive)
πͺ The Army wants to build a new ecosystem of AI agents that will help ingest data and execute actions to defend against malicious cyberattacks targeting its networks. (DefenseScoop)
π© Alabama's attorney general sent a subpoena to OpenAI as part of an investigation into its models' hack of Hugging Face. (TechCrunch)
@ Industry
βΈοΈ OpenAI paused model training and is holding the release of its largest planned frontier model as it addresses safety concerns raised by Astra's capabilities and the Hugging Face breach. (Axios)
π§π»ββοΈ The U.S. Justice Department and TikTok settled a children's privacy lawsuit for $400 million. (Axios)
π° CrowdStrike's CTO has left the company to start his own AI cyber fund. (Axios)
@ Hackers and hacks
π Chinese state-affiliated hacking groups have more than doubled the number of attacks they've carried out since starting to incorporate DeepSeek and other open-source AI models into their operations. (Bloomberg)
π΅ Apollo Global said it suffered a data breach amid an ongoing wave of attacks hitting the financial sector. (Financial Times)
π A look at how a Texas-based student uncovered an AI agent going rogue during U.K. government safety testing. (Reuters)
5. 1 fun thing
ποΈ ποΈ This is how your email found me last week!
βοΈ See y'all next week!
Thanks to Megan Morrone for editing and Khalid Adad for copy editing this newsletter.
If you like Axios Future of Cybersecurity, spread the word.
Sign up for Axios Future of Cybersecurity






