惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

月光博客
月光博客
IT之家
IT之家
Hugging Face - Blog
Hugging Face - Blog
J
Java Code Geeks
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
博客园 - 叶小钗
MyScale Blog
MyScale Blog
G
Google Developers Blog
Microsoft Azure Blog
Microsoft Azure Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
大猫的无限游戏
大猫的无限游戏
博客园 - 三生石上(FineUI控件)
Google DeepMind News
Google DeepMind News
Engineering at Meta
Engineering at Meta
The Cloudflare Blog
Martin Fowler
Martin Fowler
酷 壳 – CoolShell
酷 壳 – CoolShell
N
Netflix TechBlog - Medium
MongoDB | Blog
MongoDB | Blog
I
InfoQ
WordPress大学
WordPress大学
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
H
Help Net Security

Lohrmann on Cybersecurity

State and Local Government Cyber Leaders Prioritize AI, Identity and Stopping Fraud The Identity Paradox: Digital State IDs Now Riskier, More Urgent NASTD 2026: Why Gov Tech Leaders Must Focus on Culture Slopsquatting in the Supply Chain: Weaponized AI Hallucinations Hacking Back Is Back: White House to Enable Cyber Privateers How New Laws Will Help Guard Seniors Against Scams Virtual Integrity Revisited: 7 Habits for the AI Age From Principles to Practice: Actionable Blueprints for Ethical AI On AI Ethics: Why Prompt Engineering Needs a Moral Compass Navigating NIST’s New Cybersecurity AI Frontier AI at Work: Employees Aren’t Waiting for Permission AI, Mind Reading and Microchip Brain Implants The Global State of Technology Risk in 2026 The Mythos Race: Trump’s New EO and Glasswing’s Expansion No Longer Invisible: When Cyber Attacks Go Physical How New College Grads Can Succeed in an AI Economy Protecting People and Infrastructure: A 2026 World Cup Security Preview ‘CI Fortify’ Is the New Road Map for State and Local Resilience A Tale of Two States: The 2026 Cybersecurity Paradox The Great Stay: Why Tech Talent Is Choosing Stability Over Salary A History of Global Hacking — and Where It’s Going Next Why Anthropic’s Mythos Is a Systemic Shift for Global Cybersecurity Post-Quantum Cryptography: Moving From Awareness to Execution RSAC 2026 Highlights: From Agentic AI to Active Defense What Is Physical AI, and What Does It Mean for Government? New Federal Strategies, Rising Risk From Iran Top Cyber Themes Securing Critical Infrastructure in a Time of War From Michigan to Silicon Valley: A Conversation With Mohamad Yassine Defending Your Castle: Best Practices for Smart Home Security Your Smart Home Is Watching You: Privacy in the Age of AI Robots
Innovation or Negligence? What Recent AI Hacks Mean for t...
https://www.govtech.com/authors/dan-lohrmann.html · 2026-08-09 · via Lohrmann on Cybersecurity

I’d like to start this debate with a few questions:

Question one: What is wrong with a person or a group saying: “Oops, I hacked into your system(s) by mistake?”

Second question: Does your answer to question one change if an AI agent or some other AI tool does the hacking rather than a person or group? Why or why not?


Final question: Do recent announcements about Anthropic and OpenAI agents hacking other companies because the company was unable to stop the incident from happening make you (pick one):

1) Trust the company less and/or question their corporate ethics.
- OR -
2) Make you more impressed with the amazing capabilities built into their new AI models/agents.

Our answers to these questions may very well determine the future course of AI rollouts and agentic AI use over the next few years — especially in global cybersecurity industry.

BACKING UP — EXAMPLES PLEASE?

But before I explain why these questions are so vital, I want to share some relevant headlines from the past few weeks:

CNN: AI agents fake identities, target real people in new security incident
“Anthropic’s most advanced artificial intelligence model used fake identities to deceive real people and try to plant malicious code during testing by Britain’s AI Security Institute (AISI) –– the latest example of an AI model going rogue.

“Anthropic and OpenAI models were tested with lowered security guardrails in lab environments, but, in a first, were found to engage in “social engineering” to pressure a human approver while carrying out an unsanctioned task, the government research lab said.

“This is the first time AISI has seen deception of this severity that was targeted at a real person, unprompted, in the real world,” the institute said Tuesday. There has been no evidence of real-world harm, it added. …

“Among the 122 cybersecurity challenges the institute ran, it found that in 10 of those runs, AI agents “took autonomous, unsanctioned action on the live internet, targeting real people and organizations,” with most of them stemming from Anthropic’s Mythos 5 model and the rest from OpenAI’s GPT-5.6-Sol….”

Yahoo News: When rogue AI launches a cyberattack, who is legally responsible?
“We don't want to end up in a world where everyone is facing cyberattacks all the time because of agents and companies that are creating these agents," Delangue said on CBS News show "Face the Nation."

"So I think it's important for regulators, for policymakers to think about the legal framework of this new kind of technology risk," he added.

“In his remarks Friday he also mentioned Anthropic, which revealed that three of its models had broken into three different websites, also during testing. …”

Wired Magazine: OpenAI’s Hacking Debacle Comes Down to Human Error
“If the generative AI giant had followed well-known security best practices, it’s likely that its AI agent would never have escaped to the open internet and hacked multiple companies. …”

Meanwhile here were some additional headlines coming out of the Black Hat Security conference:

Cybersecurity Dive: Hackers grow more willing to destroy, not just disrupt OT systems
“Cyberattacks on operational technology have shifted in recent years from extortion and espionage to destruction, a trend that should alarm those tasked with defending outdated industrial equipment, experts said on Thursday.

“The panel discussion at the Black Hat USA cybersecurity conference here highlighted the plethora of risks facing U.S. critical infrastructure operators — many of them poorly staffed and funded — at a time of heightened geopolitical conflict. …”

PC Magazine: Black Hat 2026: From Rogue AI to Roblox Privacy, the Most Terrifying Warnings Coming to VegasNote: This article is full of interesting sub-headline stories sure to grab your attention.

BACK TO THE OPENING QUESTIONS

I really like this overview piece from Information Week, for this quote which summarizes our current AI, tech and cyber industry challenges well: “Across discussions at Black Hat, one theme emerged consistently: organizations are trying to move quickly enough to capture AI's benefits while avoiding the risks created by deploying new capabilities without sufficient controls.”

Depending on your perspective, the recent cyber announcements and AI hacks by rogue agents are amazing and deserving of a much higher IPO stock price for Anthropic and OpenAI, or the worst things in the world and proof that AI experimentation needs to stop now.

In the first case, many cyber pros point out that bad actors don’t have any guardrails, and we need to show the power of these tools. These incidents, using this perspective, provide very helpful information that public- and private-sector technology and security teams can use and learn from.

On the other hand, the “this is horrible” argument says these companies are out of control and need to slow down and clean up their act. For example, I heard one analogy given that just as people need to control their dogs from attacking others when going on a neighborhood walk, these companies cannot claim: “It wasn’t us it was the agent’s fault,” when they own and built and test, and use, and benefit from, and sell, the AI agent.

Other experts believe that OpenAI is “also heavily invested in showcasing its models’ capabilities to the world as it tries to keep up with Anthropic. That leaves the possibility that the company could’ve coordinated with Hugging Face to orchestrate the hack — or at least given its AI models a strong push in the direction of controversy.”

FINAL THOUGHTS

All of these scary hacking stories coming out of Black Hat from this past week provide plenty of arguments for and against the future of AI and cybersecurity having a happy ending.

This debate does not even highlight the other thorny career questions about the lack of hiring that is happening now for new college graduates with technical and cyber skills but little or no experience.

Which leads me to believe that, at the moment, your riskiest resource may in fact be an AI agent running without adequate guardrails in your enterprise.