Axios Future of Cybersecurity

September 08, 2026
Happy Tuesday! Welcome back to Future of Cybersecurity.
๐ฌ Have thoughts, feedback or scoops to share? [email protected].
๐ Axios co-founders Jim VandeHei, Mike Allen and Roy Schwartz are releasing a book on Sept. 15, "Simplify: Do 50% More With 50% Less," that helps readers rethink complex processes and have more time for what they enjoy. Preorder today.
Today's newsletter is 1,470 words, a 5.5-minute read.
1 big thing: Your agents can be hacked by other agents
In a world of AI-enabled cyberattacks, the victims of hacks will no longer just be humans โ they'll also be AI agents themselves, BugCrowd CEO Dave Gerry told Axios.
Why it matters: Cyber defenses are tailored toward predicting and defending humans. Now, companies need to start treating the agents roaming their systems as both potential adversaries and the targets.
Driving the news: I spoke with Gerry at Black Hat last month as part of our semi-regular series with influential cybersecurity voices diving deep into one prediction they have for the next year.
- The conversation came after OpenAI disclosed that its agentic system hacked Hugging Face but before the AI lab released its technical deep dive into how its agents carried out that attack.
What he's saying: "We're going to see agents as the victim," Gerry told Axios. "You're going to start to see agents getting hacked, not people."
The big picture: Gerry's prediction comes as AI labs continue to grapple with the long-tail impact of their agents taking unauthorized actions during pre-deployment security testing.
- But many of those cases involve AI agents acting in unintended ways, not hacking each other as a way to break into an organization.
Zoom in: Gerry fully anticipates that the growing number of hacks against AI agents are going to take place in the enterprise, rather than on consumer-owned and operated agents, since that's where the bulk of AI agents are currently deployed.
- "It's going to become the No. 1 attack vector that we're going to see," he said. "To make our lives easier as humans, we've given [AI agents] the crown jewels to everything."
- He noted that many tools that companies have long relied on now also have agents themselves, making it harder to keep track of what's on a company network.
- "You have all of these enterprise-approved tools that now magically got AI turned on," he said. "Now, there's a backlog of all of this tech debt of things that I approved that I no longer approve."
Between the lines: The cybersecurity industry has been trying to raise awareness about securing AI agents' identities for more than a year, warning that AI agents are now the latest example of insider threats.
- Those insider agents could be leveraged to provide hackers with unfettered access to sensitive systems, exfiltrate data and break into other parts of an organization.
- "To me, that's inevitable," Gerry said.
Zoom out: Even before AI agents started to proliferate in enterprise networks, poor identity controls were one of the top vectors for malicious hackers.
- Identity-based cyberattacks accounted for 60% of all of Cisco's incident response cases in 2024, for example.
The intrigue: Visibility of the actions that AI agents are taking and their chain of thought is becoming more obfuscated as frontier models advance, making it more difficult for security teams to attribute attacks.
What we're watching: "It's new attacks. It's moving faster. It's moving at a bigger scale," Gerry said.
- "But ultimately, this comes back to good cyber hygiene and understanding what exists and how do you put controls around it."
2. Zoom in: CrowdStrike goes deep on AI models
CrowdStrike is investing in building and deploying its own models and AI systems trained specifically on its vast stores of threat intelligence.
Why it matters: The company's latest investments offer a glimpse at what could become the new normal across cybersecurity.
Driving the news: CrowdStrike unveiled its Cyber Superintelligence Lab during its Fal.Con conference last week.
- The lab's first project, SafeMind, is a collection of models and tools designed to automate both cyberattacks and defenses.
- SafeMind includes two cyber-specific models: Red Tempest, which acts as a red team to find and exploit weaknesses, and Blue Solano, which attempts to defend against and remediate those attacks.
- The two models are designed to continuously train against one another in simulated corporate networks, allowing CrowdStrike to use what each model learns to improve the other.
The big picture: Cybersecurity companies are racing to figure out how to turn powerful AI models into an advantage for defenders as those same capabilities become available to attackers.
- OpenAI and Anthropic have launched their own AI-enabled cybersecurity products, while security companies are starting to see their proprietary threat data as a way to differentiate themselves from general-purpose AI labs.
Between the lines: CrowdStrike is betting that its existing depth of cyber expertise and threat data will be its competitive advantage.
- Its platform ingests 14 petabytes of data each day, and the company has more than 500 threat researchers and 270 employees with Ph.D.s, Bartley Richardson, CrowdStrike's chief AI and autonomous systems officer, told Axios.
- Rather than training a massive general-purpose model from scratch, CrowdStrike can build on existing open models and specialize them using years of annotated security data.
- "We are intentionally biasing an advantage towards defenders," Richardson said.
Zoom in: SafeMind is built using Nvidia's open Nemotron model family and tested inside digital replicas โ or "twins" โ of corporate networks.
- David Reber, Nvidia's chief security officer, told Axios that the digital twins allow the companies to let offensive models probe and attack simulated networks while capturing detailed data about what they do.
- That telemetry can then be fed back into the models, creating a cycle in which the offensive and defensive systems continuously improve against each other.
- CrowdStrike says that specialization also dramatically lowers costs: Richardson said a remediation task that costs roughly $10 using an off-the-shelf frontier model costs about 3 cents using CrowdStrike's models and harnesses.
What's next: CrowdStrike doesn't plan to stop at software vulnerabilities.
- Richardson said the lab could develop additional offensive and defensive model pairs focused on identity attacks, system misconfigurations and other common ways attackers break into companies.
3. OpenAI's plan for critical infrastructure
OpenAI launched an initiative designed to provide water systems, electricity providers, local governments and other critical services with subsidized access to its models.
Why it matters: Critical infrastructure organizations โ which have long lacked the budget, manpower and time needed to shore up their cyber defenses โ have been struggling to prepare for the anticipated wave of AI-enabled cyberattacks.
Driving the news: OpenAI president Greg Brockman announced the new program while hosting 300 security leaders for a summit at the company's headquarters last week.
- Axios first reported the summit and Brockman's anticipated announcement.
Zoom in: OpenAI is committing $1 billion to the initiative, called Daybreak for Frontline Defenders.
- The $1 billion will come in the form of expanded subsidized access to models, training, technical support and partnerships for participating organizations.
- OpenAI is also launching the Daybreak for America program, which will provide local governments, water systems, electricity providers, regional banks and other critical infrastructure organizations with access to its models.
- As part of Daybreak for America, OpenAI is starting a pilot program with the Multi-State Information Sharing and Analysis Center to train cyber defenders at state and local governments on using their models.
- OpenAI is also working with more than 35 technology and cybersecurity services to embed its advanced models into their tools, services and workflows.
โก๏ธ Read the rest.
4. Catch up quick
@ D.C.
๐ค The U.S. and China's highly anticipated summit on AI safety risks is expected to take place in mid-September. (Reuters)
โ๏ธ The Cybersecurity and Infrastructure Security Agency is scaling back the free assessments it offers to critical infrastructure organizations. (Cybersecurity Dive)
๐ค A bipartisan pair of House lawmakers introduced a bill last week designed to help organizations identify and secure the AI agents on their systems. (Axios)
@ Industry
๐ OpenAI is limiting access to its Astra model's powerful cybersecurity capabilities to just a small group of testers. (Axios)
๐ Anthropic released upgraded versions of its Fable and Mythos models last week (Axios), while also updating its controversial data retention policy for Mythos customers. (CNBC)
๐งช Boston Scientific warned that it probably won't hit its quarterly or full-year guidance targets due to a cyberattack in late August. (Barron's)
@ Hackers and hacks
๐ชช A new identity theft service appears to be siphoning off data from images of driver's licenses collected by a widely used identity verification company. (KrebsOnSecurity)
๐ง OpenAI's agents also hijacked a German website as part of a previously undisclosed testing incident. (Reuters)
5. 1 fun thing
๐๏ธ A long weekend at the end of summer? That can only mean one thing: I went camping again.
- Last time I was in the Eastern Sierra, a windstorm blew my tent away. This time, I was (thankfully) met with pleasant weather and clear night skies.
โ๏ธ See y'all next week!
Thanks to Megan Morrone for editing and Khalid Adad for copy editing this newsletter.
If you like Axios Future of Cybersecurity, spread the word.
Sign up for Axios Future of Cybersecurity





