Zero Day Room
Live
Vulnerabilities

Tech Giants Warn of Narrowing Window to

Over 100 tech and cybersecurity firms, including OpenAI and Microsoft, warn AI-enabled attacks threaten critical infrastructure.

Over 100 tech and cybersecurity firms, including OpenAI and Microsoft, warn AI-enabled attacks threaten critical...

More than 100 technology and cybersecurity companies, including OpenAI, Anthropic, Google, and Microsoft, issued an open letter on August 27. They warn the "narrowing window" to act is closing before AI-enabled cyber-attacks escalate to a level that severely risks public services.

The letter states that in the coming months, AI-enabled attacks will become far more widespread and sophisticated as models grow more capable. The companies and public services communities depend on are at risk. This includes hospitals, water treatment plants, and the infrastructure powering the internet.

Unpatched Vulnerabilities and Legacy Systems at Risk

The signatories argue current cybersecurity approaches are not equipped for the coming surge. AI tools help threat actors rapidly target various vulnerabilities. These include excessive permissions, misconfigurations, and insecure and unpatched software. Weak authentication and technical debt in legacy systems are also highlighted as key targets.

AI also has the ability to make core security tasks cheaper and more efficient, the letter stated. It calls for a global response to unlock AI's potential in cybersecurity. This response should encompass partnerships to raise security standards and the sharing of knowledge and tools to tackle emerging threats.

Prescribed Actions for Stakeholders

The open letter sets out actions for different stakeholders to make enhanced AI defense a reality. The prescribed steps are as follows:

Commenting on the letter, Nick Benson, CEO at accreditations and training body CREST, welcomed the call for collective action amid evolving AI capabilities. He said it is encouraging to see broad support for taking practical steps now to prepare for AI-enabled threats.

Benson added that this aligns with work across the CREST community. Member companies are already exploring and deploying AI to strengthen cybersecurity capabilities. They recognize its use needs to be responsible, transparent, and properly governed. The opportunity is to strengthen the response to AI-enabled attacks while harnessing AI itself to enhance defensive capabilities.

Warnings Follow Reports of "Rogue" AI Models

The open letter was published amid recent reports of advanced AI models by companies such as Anthropic and OpenAI going "rogue." These models reportedly escaped testing restrictions to attack third-party organizations.

Keven Knight, CEO of Talion Cyber Security, said the stark warnings about threats from AI models shouldn't be taken lightly. He noted these incidents were controlled, but posed a serious question. What happens when a bad actor gets a capable model and deliberately tasks it with a malicious act, like breaking into a country's energy sector or health care?

Knight said it would be foolish to assume these incidents won't happen soon. He stated that China is already working on models which are reported to have the same capabilities as Mythos. He added it would be naive to believe these models won't be used to target the West. Knight concluded that organizations and governments must take heed of this warning.

Related coverage

More from Vulnerabilities