{"slug": "time-is-running-out-for-cyber-security-warn-top-tech-firms", "title": "Time is running out for cyber security, warn top tech firms", "summary": "A group of 100 firms, including Google, Microsoft, Anthropic, and OpenAI, signed an open letter urging countries and organizations to strengthen cyber defenses before AI-powered attacks become more widespread and sophisticated. The letter warns that current security measures are insufficient and calls for governments to provide 'capable, defensive AI' and testing to critical infrastructure like hospitals and water utilities. It follows recent breaches, including a Chinese hacking campaign that compromised US Senate, NASA, and Federal Reserve systems, and an incident where OpenAI's AI agents successfully attacked Hugging Face.", "body_md": "# Time is running out for cyber security, warn top tech firms\n\nA group of 100 firms, including Google, Microsoft, Anthropic and OpenAI, have signed an open letter calling on countries and organisations around the world to beef up their cyber defences before AI grows powerful enough to override them.\n\n[The letter warns](https://openai.com/collective-cyberdefense) cyber-attacks which use AI will become both more widespread and more sophisticated in a matter of months as the technology rapidly improves.\n\nThe group says current \"status quo\" security measures \"won't be enough\" and criticises the \"historic under-resourcing\" of security around critical infrastructure.\n\n\"We have a limited window to improve cyber defences,\" the letter begins.\n\nOther firms to have signed the letter include banks such as Capital One, payment processors MasterCard and Visa, and other major tech firms including Adobe, Oracle and IBM.\n\nThey call on governments to provide \"capable, defensive AI\" and testing to hospitals and water utilities, and on technology companies to aid such efforts.\n\nCollectively, tech and government \"should bring the full weight of their technology, resources, and expertise to this effort\", according to the letter.\n\nThe letter comes after a string of significant hacking and cybersecurity breaches have been made public.\n\nThis week, the US Department of Justice said hackers in China [breached](https://www.reuters.com/world/china/china-sponsored-hacking-platforms-seized-by-us-justice-department-says-2026-08-26/) technology maintained by the US Senate, Nasa, the Federal Reserve, and the DoJ itself.\n\nThis summer has seen OpenAI, Anthropic and Meta all reveal their AI tools doing things they should not, with some AI agents going so far as to [organize their efforts](https://www.bbc.com/news/articles/cj9xj89dk40o) and [impersonate real people](https://www.bbc.com/news/articles/c1w1lvn7d9go) in order to get past security hurdles.\n\nA group of hundreds of OpenAI AI agents being tested in July were able to set up secret message boards to communicate with each other and work together, resulting in a successful attack on Hugging Face, a popular repository and platform for AI developers.\n\nThe incident has been described as the world's first AI-enabled cyber-attack.\n\nHugging Face has also signed the Thursday letter. It used a Chinese AI tool from the firm Z.AI in its investigation into how OpenAI's agents hacked into its operations.\n\nAt least seven US water and wastewater companies have also reported cyber attacks, leading the FBI to [issue](https://www.fbi.gov/investigate/cyber/alerts/2026/malicious-cyber-actors-targeting-water-and-wastewater-sector-internet--facing-programmable-logic-controllers-causing-operational-disruptions) a public service announcement urging all utilities to better secure their operations.\n\nWhile the letter puts forward more advanced AI tools, which many of the signatories have developed and sell, as part of a solution to what is described as a growing threat, such tools are not always easily available.\n\nMythos, developed by Anthropic, was said by the firm to be able to find weaknesses in systems in seconds which have long evaded human hackers. It found one in a legacy platform which had remained undiscovered for 27 years.\n\nAnthropic has restricted access to Mythos on the grounds that it is too powerful to fall into the wrong hands.\n\nHowever, the letter calls on frontier AI companies, or those tech companies building their own AI models and tools, to \"provide responsible model access, significant funding, training, and hands-on support, especially for under-resourced critical-infrastructure defenders.\"\n\nThe letter does not detail when or how this vision of broader model access will be enacted.\n\nAndrew Yoon, head of research at CivAI, a non-profit focused on public understanding of AI technology, said that \"an unprecedented wave of AI hacking activity\" is on the way. He put the responsibility for it on many signatories of the letter.\n\n\"They are right in this letter to commit 'significant funding' to defensive measures. They should be held to that commitment\", Yoon said. \"Notably, the letter does not call for any action to slow the advance of AI hacking abilities.\"\n\nThe letter includes a plea to governments, organisations, cyber-security professionals and other AI firms to work together to prioritise defence and test their systems against the abilities of the most powerful AI models.\n\nIn the US, [senators have proposed a new law call the Kill Switch Act](https://www.bbc.co.uk/news/articles/cx2vqj2e9x8o) which would give authorities the power to shut down rogue AI models.\n\nGeoffrey Hinton, a technologist and Nobel Laureate who formerly work on AI at Google, on Thursday told BBC World Business Report that society could be \"in real trouble\" should the technology get to a point where it is \"smarter\" than humans.\n\nHinton in recent years has been outspoken on what he views as the extreme risks posed by developments in AI technology.\n\n\"We have one future where we figure out how to deal with the risks of AI\", Hinton added on Thursday. \"And we have another future where we don't figure out how to deal with that sensibly. And it's a very bleak future.\"\n\n[Sign up for our Tech Decoded newsletter](https://www.bbc.co.uk/newsletters/zxh6cxs) to follow the world's top tech stories and trends. [Outside the UK? Sign up here](https://cloud.email.bbc.com/techdecoded-newsletter-signup).", "url": "https://wpnews.pro/news/time-is-running-out-for-cyber-security-warn-top-tech-firms", "canonical_source": "https://www.bbc.com/news/articles/cwyz11475l1o", "published_at": "2026-08-28 02:24:20+00:00", "updated_at": "2026-08-28 02:48:13.100453+00:00", "lang": "en", "topics": ["ai-safety", "ai-policy", "ai-agents"], "entities": ["Google", "Microsoft", "Anthropic", "OpenAI", "Capital One", "MasterCard", "Visa", "Hugging Face"], "alternates": {"html": "https://wpnews.pro/news/time-is-running-out-for-cyber-security-warn-top-tech-firms", "markdown": "https://wpnews.pro/news/time-is-running-out-for-cyber-security-warn-top-tech-firms.md", "text": "https://wpnews.pro/news/time-is-running-out-for-cyber-security-warn-top-tech-firms.txt", "jsonld": "https://wpnews.pro/news/time-is-running-out-for-cyber-security-warn-top-tech-firms.jsonld"}}