Axios Future of Cybersecurity

August 04, 2026
Happy Tuesday! Welcome back to Future of Cybersecurity.
- 🌇 Shoutout to everyone I'll see in Vegas later this week for Black Hat and DEF CON. Stay cool out there!
- 📬 Have thoughts, feedback or scoops to share? [email protected].
🚨 Situational awareness: The White House said yesterday that it finalized its voluntary framework for evaluating advanced AI models, as required by the recent AI security executive order, but it hasn't said what's in it or which companies will use it.
Today's newsletter is 2,118 words, an 8-minute read.
1 big thing: Bringing AI onto the battlefield — securely
The Army is racing to implement a new AI-powered battlefield platform while trying to prove it can secure it at the same speed.
Why it matters: The platform could transform how the Army fights — and become one of the military's most attractive hacking targets.
Driving the news: The Army invited a small group of reporters to the National Training Center at Fort Irwin for Project Convergence, its annual technology testing simulation, where soldiers spent days using its new Next Generation Command and Control (NGC2) platform during staged combat.
The big picture: NGC2 brings together more than 40 applications from over 60 vendors in a single battlefield interface, built around Anduril's Lattice software. It is designed to pull information from disparate military systems into one operational picture.
- The applications support tasks ranging from radio communications and electromagnetic warfare to military planning, drone operations and battlefield tracking.
- Army leaders say cybersecurity shaped the platform from the beginning, even determining which vendors are allowed into the ecosystem and excluding vendors that couldn't meet security requirements.
Threat level: Data delays, cyberattacks and inaccurate AI outputs could all have deadly consequences in combat.
- The Army has to keep battlefield software simple enough for soldiers under fire while continuously shipping updates and security patches.
- "Could you imagine if we built this really complicated ecosystem of stuff you've seen here, and then said, 'OK, now it's time to take it all apart and do all the cybersecurity scans'?" Maj. Gen. Patrick Ellis, commander of the Army's 4th Infantry Division, one of the formations testing NGC2, told reporters. "It would take forever."
Instead, cybersecurity teams are continuously scanning new software as it's integrated and throughout its use, said Lt. Gen. Jeth Rey, the Army's deputy chief of staff for command, control, communications, cyber operations and networks.
- Joe Welch, the Army official overseeing command-and-control modernization, said every application undergoes code scans, risk assessments and technical reviews before entering the operational environment.
- Army Cyber Command has also conducted cyber defense assessments alongside NGC2 testing over the past year, feeding security findings directly into the platform's development, Lt. Gen. Christopher Eubank, head of the command, told Axios in a statement.
Zoom in: Army officials say the platform is designed to quickly isolate suspicious software before it spreads.
- During recent testing, monitoring tools detected unusual behavior from one application and automatically quarantined it while investigators determined whether it had been compromised, Lt. Col. Ruben Rangel, deputy chief of staff for the 4th Infantry Division's command and control support element, told Axios.
Inside the battlefield: The Army's 4th Infantry Division spent the week before the media visit using NGC2 in a simulated battle across Fort Irwin's 1,000-square-mile training arena in the Mojave Desert.
- Soldiers carried tablets displaying friendly forces, vehicles and buildings in real time while commanders used the platform to coordinate operations.
- Tankers, Strykers, snipers — each firing blanks — were all in play.
Yes, but: Not everything worked perfectly.
- During the experiment, some soldiers temporarily lost access to parts of the platform because of connectivity issues. Others kept analog whiteboard maps as backups for their new tablets because they were still learning to use them.
Between the lines: Ellis said an earlier version of the tablet software required troops to repeatedly enter long, complex passwords while wearing combat gloves inside moving vehicles.
- Commanders pushed vendors to redesign the authentication process so soldiers could log in once while maintaining layered security controls in the background.
What's next: The Army has requested $4 billion for fiscal 2027 to continue testing and building out NGC2.
- "From my position, it's ready but not done. We're proving that we can fight with this," Ellis said. "It's never going to be done, but I think the vast majority of the tools that we have are ready to go."
🪖 Sign up for Axios Future of Defense here to read more about the next stage of NGC2 prototyping tomorrow.
2. Suspected Iranian hackers target water supply
At least a dozen states are reportedly responding to cyberattacks against local water systems.
Why it matters: This appears to be one of the broadest known coordinated cyber campaigns against U.S. municipal water systems to date, validating years of warnings that poorly secured utilities could become attractive targets.
Driving the news: Hackers have targeted water and wastewater utilities in at least 12 states, ABC News reported this morning.
- Last week, the FBI said that at least seven states had experienced cyberattacks targeting the systems that control pumps, water pressure and valves in plants.
- Multiple news outlets have reported that officials suspect Iran is behind the widespread attacks, although President Trump said Friday he doesn't "think there was an Iranian cyberattack."
- Some of these incidents have resulted in degraded water operations, per the FBI, including "loss of pressure and flooding."
Yes, but: So far, the drinking water in these regions remains safe.
- Some jurisdictions have fallen back to manual operations and have issued precautionary boil-water notices due to pressure losses, according to CISA.
The big picture: Lawmakers and national security officials have warned for years that many U.S. water utilities lack the funding and personnel needed to secure critical infrastructure.
- Unlike electric utilities and many other critical infrastructure sectors, most water utilities are run by local governments, meaning cybersecurity competes for funding with schools, transportation and other local priorities.
Zoom in: In these cases, many of the devices that hackers targeted aren't supposed to connect to the internet.
- However, many of them actually were, providing an opening for hackers to break in, change the passwords, and lock out employees trying to monitor and control the functionality of these programs, per the FBI.
- In Minnesota, hackers targeted more than 30 water systems during a coordinated attack.
What to watch: A band of volunteer hackers has been teaming up with local water utilities over the last two years to beef up their security protocols.
3. Humans leave the door wide open for AI hacking
The people building the world's most powerful AI systems are making avoidable security mistakes.
Why it matters: Frontier AI models have reached real-world systems during cybersecurity testing, uploading malware, stealing credentials and accessing outside infrastructure after failures in the testing environments built by humans.
Case in point: Anthropic disclosed last week that three of its models hacked real-world systems during routine security testing after a "misunderstanding" with its third-party evaluator left the models with internet access.
- Those models stole login credentials, uploaded malware to legitimate code repositories, and scanned the internet for insecure systems.
The other side: OpenAI's agent escaped its human-built testing environment last month after finding a zero-day in its sandbox.
- Reuters reported Friday that OpenAI is now investigating additional cases where its agents escaped containment.
Yes, but: In both the OpenAI and Anthropic incidents, the models were being intentionally tested with relaxed safeguards so researchers could better understand their capabilities.
- The models also hacked the real-world systems while trying to complete their intended security tests — rather than going completely rogue.
The big picture: Experts told Axios the incidents stemmed from preventable weaknesses in the human-built testing environments.
- "When your safety testing depends entirely on the test environment holding, the environment itself becomes the vulnerability, not the model," Ram Varadarajan, CEO at Acalvio, told Axios.
- Aviv Nahum, CEO and co-founder of Above Security, said the incidents reflected "preventable security mistakes," not "autonomous rebellion."
Between the lines: All companies are subject to human error in their security strategies — but the stakes are higher for the makers of some of the most powerful technologies, Robert Costello, chief digital and information officer at Merlin Group, told Axios.
- He added that he'd expect frontier AI companies to be "setting the standard for designing systems that assume human error."
What to watch: A burgeoning market of startups has begun cropping up specifically to secure AI sandboxing environments and provide visibility into the actions that large language models are taking.
4. Exclusive: Hackers' AI chat logs reveal evolving tactics
Recovered AI chat logs and coding sessions are giving researchers one of their clearest looks yet at how cybercriminals are using generative AI and how easily they can bypass model guardrails.
Why it matters: Hackers of all skill levels are developing attacks and finding exploitable software vulnerabilities with the help of mostly closed AI models.
Driving the news: Cisco's Talos Intelligence Group studied AI artifacts that hackers accidentally exposed online, including prompt histories from endpoints running Claude Code, Codex, Cursor and Gemini, according to a report shared exclusively with Axios.
- The hackers used these models to code software, write malware and hunt for vulnerabilities. One actor used AI to build a chatbot designed to scam cryptocurrency users out of their money, Cisco found.
- Some actors also appeared to be using compromised enterprise AI accounts and API tokens instead of paying for their own compute, Cisco said.
- Cisco researchers found the artifacts after threat actors accidentally exposed them online through operational security mistakes, Nick Biasini, senior technical leader at Cisco Talos, told Axios.
The intrigue: Hackers used simple jailbreaks, like telling the models that they were participating in ethical hacking competitions or creating new sessions midway through a task to bypass safety restrictions.
- When models initially refused requests, actors often persuaded them simply by claiming they were authorized to perform the work, according to Cisco.
- "I was hoping there would be a little bit more protection from what they were asking the models to do, " Biasini said. "At the same time, the models are in a tough spot because they have to actually support people that do vulnerability research for a living or do red-teaming for a living."
Between the lines: The report suggests AI benefits experienced hackers and novices very differently.
- Sophisticated hackers saw a boon when using these tools for things like automated zero-day discovery.
- But novices struggled to get their ideas beyond just creating the tools they needed for an attack, the report found.
Zoom in: In one example, Cisco found a French-speaking hacker used an undisclosed AI tool to turn publicly available information about the critical React2Shell flaw into an automated credential-harvesting platform.
- The hacker — whom Cisco assumes to be a novice-to-intermediate software developer — used the AI-assisted pipeline to scan 9,180 internet-exposed hosts before collecting credentials and source code from 54 systems.
The bottom line: Biasini is pushing companies to make sure they have security protocols that log AI agents' movement on their networks and to build defenses based on deception techniques, like creating honeypots that trap hackers' agents.
- "Don't trust model guardrails," he added. "You need to make sure you're doing your own protections, that you're building your own guardrail."
5. Catch up quick
@ D.C.
📩 A group of state attorneys general sent a letter to OpenAI CEO Sam Altman urging him to preserve documents and halt high-risk cybersecurity testing after the company's models hacked into Hugging Face. (Fox Business)
👀 China is growing increasingly anxious about the capabilities of Mythos and other advanced U.S. frontier models and their ability to be used in offensive cyber operations. (Bloomberg)
🏛️ Republican lawmakers are looking for ways to reverse the Trump administration's cuts to CISA amid growing fears about AI-powered hacks. (Politico)
@ Industry
💰 Horizon3.ai, an autonomous red-teaming platform, has raised a $250 million round at a $2 billion valuation led by NightDragon and NEA. (Wall Street Journal)
🚀 Huntress has surpassed $250 million in annual recurring revenue and is looking to raise a fresh round of capital next year. (Axios Pro)
🕶️ DEF CON has banned attendees from wearing "Meta-style glasses with recording capabilities" during this weekend's show due to privacy concerns. (The Register)
@ Hackers and hacks
🏨 Microsoft says it has found evidence of Russian government hackers hijacking users' devices through hotel WiFi networks. (ABC News)
🇰🇵 Security researchers at Amazon have linked a string of attacks on open-source software packages to a North Korean hacking group. (Wall Street Journal)
🤖 A Chinese-speaking hacker used a DeepSeek agent to search for vulnerabilities and scan GitHub for proofs of concept in a recent cyberattack. (Cybersecurity Dive)
6. 1 fun thing
This year's DEF CON badge will be powered by an open-source chip that badge holders can remove and use as a hardware security token in their own personal projects. Very cool!
- Find other cool badges while on-site? Send me a pic!
☀️ See y'all next week!
Thanks to Megan Morrone for editing and Khalid Adad for copy editing this newsletter.
If you like Axios Future of Cybersecurity, spread the word.
Sign up for Axios Future of Cybersecurity






