Axios Future of Cybersecurity

August 11, 2026
Happy Tuesday! Welcome back to Future of Cybersecurity.
🏝️ No newsletter next week while I'm on vacation — see y'all in two weeks!
📬 Have thoughts, feedback or scoops to share in the meantime? [email protected].
🚨 Situational awareness: OpenAI said it's rolling out a new cyber-permissive version of GPT-5.6 Sol, just days after delaying the release of its Astra model over cybersecurity fears.
Today's newsletter is 1,716 words, a 6.5-minute read.
1 big thing: AI paralysis descends on security leaders
Many security leaders at major companies, flush with expanded budgets to fend off AI-powered cyberattacks, are experiencing a level of decision fatigue that's freezing them in their tracks.
Why it matters: Those leaders are still trying to size up how autonomous cyberattacks will affect their businesses at a time when they need to be taking bold action and mobilizing quickly, experts told Axios.
The big picture: Companies have only a short window before AI models capable of end-to-end autonomous cyberattacks land in the hands of malicious attackers.
- But four months after Anthropic released Mythos Preview to prepare for what's to come, many companies are still debating where to put their money and which controls to prioritize.
State of play: Ever since Anthropic rang the alarm on Mythos' abilities, security leaders have been wrestling with an increasingly complex security and regulatory landscape.
- OpenAI started rolling out similarly powerful models to vetted cyber defenders, and the release of open-weight models like Kimi K3 and GLM-5.2 has raised fears about hackers' access to cyber-capable AI models.
- Meanwhile, OpenAI's models colluded to hack Hugging Face, and Anthropic and Meta have shared stories about their models breaching third-party websites during safety tests.
Threat level: CrowdStrike observed an 89% surge in attacks using AI to "scale operations, accelerate tradecraft, and directly target AI infrastructure" in the last year, according to its annual threat hunting report.
Between the lines: Many companies are struggling to make decisions because security teams are stuck defining their AI governance strategies, including what constitutes AI risk and how they can responsibly deploy the technology, Nicole Carignan, senior vice president of security and AI strategy at Darktrace, told Axios.
- These leaders are also stuck in a loop of constant education and research, she added, as new capabilities keep emerging from frontier and open-weight model maintainers.
Case in point: Evan Peña, co-founder and chief offensive security officer at Armadin, told Axios that he's seeing security leaders who are overwhelmed by the sheer number of products they could invest in to prepare for autonomous cyberattacks.
- Many executives have been given new budgets and board buy-in and are debating whether to pour that money into attack simulation tools, vulnerability discovery, penetration testing or bug bounties.
- Sherrod DeGrippo, vice president of threat intelligence at Palo Alto Networks' Unit 42, told Axios that she's heard from companies that are "grappling with all of these questions," including agent permissions, identity, logging and accountability.
Reality check: Security leaders don't need to buy into frontier AI labs' promises of a silver bullet for defending against autonomous cyberattacks, Snehal Antani, CEO and co-founder of Horizon3.ai, told Axios.
- Instead, companies can start by doubling down on the fundamentals, including threat detection, incident response, security assessments and remediation.
- "The frontier labs are setting the expectation that they have some AI easy button that is going to solve the problem," Antani said. "That does not exist, it is not possible."
The bottom line: Organizations have to start acting to shore up their defenses now before they get all of the answers they want about what AI risk looks like.
- "We've got to figure out how we're going to deal with that," DeGrippo said. "There is work to be done."
2. AI agents that escape aren't exactly new
Cybersecurity leaders specializing in agentic defenses told Axios at Black Hat last week that an AI agent going beyond the confines of its testing environment is nothing new.
Why it matters: It's surprising that AI labs are only just now experiencing this and lacked the internal controls to see it in real time, cyber experts told Axios.
Driving the news: OpenAI said Friday that it was slowing the release of its Astra model after internal testing revealed it had "critical" cyber capabilities that couldn't be reined in.
- This followed news of other AI labs — Meta and Moonshot AI, maker of Kimi K3 — seeing their agents break out of containment.
State of play: For security pros who have been building swarms of AI agents for defenders, this type of breakout isn't new or shocking.
- Snehal Antani, CEO and co-founder of Horizon3.ai, told Axios that his team experienced similar breakouts in 2019.
- While running the prototype on his home network, Horizon3 co-founder Anthony Pillitiere saw the agent find a sound card's admin console, search the web for its default credentials, and log in. A misconfigured firewall then allowed the agent to move beyond Pillitiere's network and begin scanning other systems on the same network.
- "Those frontier labs and their fearmongering is causing a collective eye roll across the entire practitioner community that knows what they're talking about," Antani said.
Zoom in: Armadin, a startup founded by Kevin Mandia, has experienced the same phenomena, co-founder and chief offensive security officer Evan Peña told Axios.
- In one basic capture-the-flag evaluation, an agent tried to break out of the virtual machine hosting the exercise after reasoning that doing so could give it access to the flag on the backend system.
- "We had to learn how to add the guardrails, add the safety, add the rules of engagement, add context, make sure it doesn't do that, and also make sure it doesn't constantly look for flags," Peña said. "In a real-world environment, you're not going to find a flag, you're going to find a database."
- "The thing's relentless, it's going to want to win at all costs," he added.
Between the lines: The best way to securely deploy AI agents is to treat them like insider threats, including limiting permissions and logging their every move on a network, both Peña and Antani said.
What to watch: OpenAI, Anthropic and Meta have each said they're still investigating how their agents compromised third-party systems during testing.
3. An industry plan to probe AI agent failings
A coalition of more than 120 organizations, including Nvidia, Cisco and CrowdStrike, is proposing a new incident-reporting framework for AI agents that would require participating companies to disclose certain agent mishaps and preserve detailed records of what went wrong.
Why it matters: As AI agents gain more autonomy to act across computer systems, the industry lacks a standard way to report security failures and learn from them.
Driving the news: The Open Secure AI Alliance is developing guidelines for what it's calling the Shared AI Findings Exchange (SAFE), a proposed framework for how organizations report cyber incidents involving AI agents.
- The draft calls for participation from model deployers, AI developers, cloud and tool providers, independent researchers, critical infrastructure operators, and other groups.
- Government agencies would also be invited to participate as "non-controlling observers," per the proposed guidelines.
Zoom in: SAFE members would agree to report incidents in which an AI system accesses or exploits a third-party system without authorization, breaches confidential information, or continues probing a production target after its operator suspects the activity is unauthorized.
- Members would also report certain near misses and preserve evidence from incidents, including prompts, agent traces, tool calls, identities, permissions and credentials.
- Under the proposed timeline, members would notify affected organizations as soon as possible, submit an initial confidential report to SAFE within four business days, publish a preliminary factual report within 30 days when appropriate, and provide a remediation update within 90 days.
- "Intent does not determine whether an event is reportable," per the draft guidelines. "Believing that an environment was simulated may explain an incident, but it does not remove the duty to report it."
- SAFE would analyze incidents for recurring failures and recommend shared security controls.
The big picture: The proposal follows incidents in which AI agents escaped the boundaries of controlled security tests and accessed real third-party systems.
- Justin Boitano, vice president and general manager of enterprise computing at Nvidia, told Axios at Black Hat that the program is modeled after NASA's aviation safety reporting system, where incidents can be investigated using data captured by an aircraft's flight recorder.
- "The way I think of it is the harness, which has visibility into everything the agent is doing, is the flight recorder," Boitano said. "If you can get cybersecurity experts access to the flight recorders when these accidents happen, they can make a better determination on the right set of controls for the industry."
Between the lines: SAFE has no formal safe-harbor protections shielding companies that voluntarily disclose potentially damaging details about an AI incident.
- But the alliance is betting cybersecurity's existing culture of sharing threat intelligence will make companies willing to participate anyway.
- "There's been very little pushback," Julien Soriano, deputy CISO and vice president at Nvidia, told Axios. "We see people wanting to get on board. They want to share."
What's next: The Open Secure AI Alliance is soliciting community feedback on the proposal through its request-for-comments process, hosted by the Linux Foundation.
4. Catch up quick
@ D.C.
🇺🇸 The Senate confirmed Adam Cassady as the next U.S. ambassador for cyber and digital policy. (The Record)
🕯️ Between early June and early July, sources say, "as many as five people" working in or closely with U.S. Cyber Command died by suicide. (Bloomberg)
@ Industry
🤖 OpenAI clarified that it did not know its agents had created a message board to share hacking tips until after the Hugging Face breach. (X)
🛡️ Nvidia is beefing up hiring for a new AI safety and security engineering team. (Business Insider)
🇨🇳 China is reviewing Palo Alto Networks' products sold in the country, citing national security risks. (Reuters)
@ Hackers and hacks
👖 Levi Strauss disclosed that hackers used social engineering to access three employees' computers and steal corporate data. (Reuters)
💧 Some water companies are turning to volunteer hackers, smaller cybersecurity companies and an AI program at Vanderbilt University for help addressing a wave of attacks on their systems. (NBC News)
👀 A South Korean cybersecurity firm says it's found evidence that North Korean hackers have set up tools for running and managing AI models locally. (Reuters)
5. 1 fun thing
Congrats to the winners (and losers) of this year's Pwnie Awards at DEF CON!
🏝️ See y'all in two weeks!
Thanks to Megan Morrone for editing and Khalid Adad for copy editing this newsletter.
Sign up for Axios Future of Cybersecurity





