OpenAI, Anthropic and 100-plus firms warn AI attacks are about to scale

OpenAI, Anthropic and 100-plus firms warn AI attacks are about to scale

OpenAI, Anthropic and 100-plus firms warn AI attacks are about to scale OpenAI Group PBC today published an open letter signed by more than 100 technology companies, banks, insurers and security vendors warning that artificial intelligence-enabled cyberattacks will become far more widespread within months and that defenders have a narrow period left to get ready. “We have a limited window to strengthen cyber defenses,” the letter opens. Hospitals, water treatment plants and the infrastructure that carries internet traffic are named as the assets most at risk. The roster is unusually broad for a document of this kind. Anthropic PBC, Google LLC, Microsoft Corp., Amazon Web Services Inc., Oracle Corp., Cisco Systems Inc. and IBM Corp. all signed, as did CrowdStrike Holdings Inc., Palo Alto Networks Inc., Cloudflare Inc., Okta Inc. and Fortinet Inc. Capital One Financial Corp., Mastercard Inc., Visa Inc. and Citigroup Inc. appear on the list beside the Center for Internet Security. Organizers said more names will be added. The letter argues that status quo security will not hold, pointing at longstanding bugs, excessive permissions, misconfigurations and weak authentication that attackers exploit today without any help from AI. Cyber-capable models, the signatories say, can hand specialist skills to teams that cannot afford to hire them. Nobody can absorb the problem alone, which is where the call for a collective response comes in. The asks are divided across four groups. Organizations are told to make cyber defense an immediate leadership priority, clear out high-risk weaknesses and raise their standards for AI-generated code. Security and technology vendors should test their products against what current models can do, get defensive tooling into the hands of critical infrastructure operators and share threat intelligence and playbooks. Governments are asked to coordinate locally, nationally and internationally, and to pay for protecting essential services. The list for frontier AI developers runs longest, covering model access, funding for defenders, accountability for their own systems and support during live incidents. Federal agencies gave the warning some grounding earlier this month. In an advisory issued Aug. 18, the U.S. National Security Agency, the Cybersecurity and Infrastructure Security Agency and Federal Bureau of Investigation said threat actors are using AI-generated exploitation scripts, disguised as legitimate monitoring tools, for reconnaissance and capability development against Siemens S7 programmable logic controllers. Water and wastewater utilities and critical manufacturing are among the sectors named. Attackers picked up 88% of newly public proof-of-concept exploits inside 48 hours over the first six months of the year, CrowdStrike found in its annual threat hunting report. AI does not have to invent new exploit techniques to cause serious problems, Diana Kelley, chief information security officer at agentic AI security company Noma Security Inc., told SiliconANGLE via email. Agents that surface vulnerabilities humans missed, automate reconnaissance and chain known attack paths at machine speed make old weaknesses considerably more dangerous. Kelley reads the letter as an admission that AI is changing the economics of attack faster than most organizations are paying down security debt. She added that a company’s own agent deployments now form part of its attack surface. What the letter does not carry is commitments. No deadlines, spending pledges or measurable targets accompany it, Axios noted. John Gallagher, vice president at operational technology and internet of things security company Viakoo Inc., told SiliconANGLE via email that the technical premise holds up and the optimism around it does not. “Where the open letter misses reality is in the idea that defenders hold an advantage because they can find and fix vulnerabilities that have accumulated for years,” Gallagher said. “In OT and critical infrastructure, the current pace of remediation is glacial.” Maintenance windows have to be negotiated, devices and applications coordinated, and a plant asset that fails to come back online can cost a fortune. Gallagher was sharper about the timing. A frontier developer shipping more capable models while warning that disaster is months away invites a cynical read, he said, “kind of like an arsonist selling fire extinguishers.” Most of the vendors on the list already sell AI security products. OpenAI’s own Daybreak program is among them, and and Palo Alto Networks said this month it would put those models to work inside customer environments. Image: SiliconANGLE/GPT Image 2 A message from John Furrier, co-founder of SiliconANGLE: Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities. 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI. Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.

Original Source

Read the full article at Siliconangle →

KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.