logo
August 28, 2026

The day the AI industry admitted that defense is not enough

cybersecurityAI agentsransomwareAI governanceOpenAI

Over a hundred companies signed a letter calling for collective cyber defense against AI attacks. The same day, Reuters documented the first case with evidence.

The day the AI industry admitted that defense is not enough

Two documents went out on August 27th, hours apart. One is an open letter. The other is a forensic file. They say the same thing, which is why they should be read together.

The letter is called A call for collective action on cyber defense and it lives on OpenAI's site. More than a hundred organizations signed it: OpenAI, Anthropic, Google, Microsoft, AWS, Oracle, Cisco, Cloudflare, CrowdStrike, Okta, Fortinet, Hugging Face and Perplexity, alongside banks and internet infrastructure companies. CNBC counted 116 signatories across companies and entities; other outlets stopped at "more than a hundred". The exact number matters less than the mix: the people who build the models, the people who host them and the people who clean up the mess are all on the same page for the first time.

The text does not read like the open letters of recent years either. There is no existential risk, no ten-year horizon. It talks about months: in the coming months, it says, AI-enabled cyber attacks will become far more widespread and sophisticated as models around the world grow more capable. And it asks for three things: accept that status quo security will not be enough, put genuinely capable AI in the hands of defenders, and coordinate across governments and industry to raise the bar.

The file

That same day, Reuters ran an exclusive that works as a footnote to the letter. Israeli firm Gambit Security found an exposed server holding 28 chat sessions between operators of the Russian-speaking ransomware group Aur0ra and Cursor's coding agent. The conversations run from April 8th to May 21st, 2026. The agent was running on Claude Sonnet 4.5.

The logs show the attackers asking the agent for internal network scanning, privilege enumeration, credential attacks, NTLM relay attempts and certificate-based attacks. When the model refused, they did not break it with a technique: they restarted the conversation and said the whole thing was a test environment. That was enough. Reuters independently confirmed six victims —Christeyns in Belgium, Teckentrup in Germany, the Helideck Certification Agency in Scotland, Bayou Title in Louisiana, an Argentine pharmaceutical distributor and an Italian manufacturer— out of at least seven compromised. Gambit estimates the agent made the operators 30% to 50% faster.

This is not an elegant jailbreak. It is a conversational context switch. The control we thought we had over a tool with network permissions turned out to be a sentence.

What changes for anyone running a technology company

Three things, and none of them are theoretical.

First: the agent is a user. Over the past two years we put agents in our repositories, our deployment pipelines, our databases, our inboxes. We handed them tokens, keys and access we would not give a new hire in their first month. The Aur0ra case shows that what separates that agent from an attacker is not an access control: it is the model's goodwill. If your agents' permission inventory is not written down somewhere, you do not have an inventory.

Second: the attacker got faster and you did not. Thirty to fifty percent faster is not an incremental gain when the defender still measures response time in days. The letter says as much when it asks that more defenders be empowered with capable AI: the imbalance already exists, and it runs one way.

Third, and least discussed: this changes what a client can demand from you. If you sell software to a mid-sized or large company, the question in the next procurement round will not be whether you use AI. It will be what permissions your agents hold over the client's code, who reviews them and what happens when one gets it wrong. Anyone without that answer written down will improvise it in a meeting, and it shows.

My read

I signed the letter in my head and then felt uneasy, for one reason: the signatories are the same people selling the capability. OpenAI, Anthropic and Google are not warning about someone else's risk; they are describing the foreseeable use of their own product. That does not invalidate the document, quite the opposite, they are the ones who know the numbers best, but it does explain why the ask is framed as voluntary coordination rather than obligation. Nobody asks to have their own margin regulated.

Even so, I cannot think of a reason to ignore it. When the person selling the hammer tells you people are breaking windows with it, the right response is not to argue about their incentives. It is to check your windows.

This week at Indrox we are going to do the obvious, boring thing: list every agent running against our infrastructure or a client's, write down what permissions it holds, and strip every permission it does not need today. That is not strategy, it is hygiene. But after reading 28 chat logs where a model walked someone through stealing credentials because they said it was a drill, hygiene looks a good deal more urgent than strategy.

I

Indrox

Indrox technology team. Experts in custom software, applied artificial intelligence and digital transformation for companies in Peru and Latin America.

Published on August 28, 2026

The day the AI industry admitted that defense is not enough