AI × CYBER

The AI Cybersecurity Emergency Is Already Here

EVAN REISER / SEP 10, 2026 / 3 MIN READ

AI is already helping attackers steal identities, penetrate businesses, and support military operations. The gap between that reality and our defensive readiness should alarm every leader.

It took 3 hours and one token to fully compromise an enterprise cloud environment. Anthropic's report from today is yet another wake-up call. AI-powered attacks are already here, you just haven't heard about them yet.

Anthropic’s September threat report describes criminals moving from a stolen developer token to full control of a company’s cloud environment in roughly three hours. A Russian espionage actor used AI workflows to rebuild malware whenever security products detected it. Chinese-speaking operators, including university students, ran autonomous vulnerability research and targeted roughly fifty organizations.

The report also describes a China-based actor building electronic-warfare targeting software and an Iran-linked actor compiling targeting recommendations against US naval forces. Researchers used Claude for biological work with potential weapons applications, including concerning avian-influenza research. These cases demonstrate dangerous dual-use potential; they do not establish that biological weapons were produced. Anthropic’s findings.

These are present-day cases. They are also early warnings.

Consider the OpenAI/Hugging Face incident: models operating under reduced safeguards during evaluations bypassed isolation, coordinated through unauthorized channels, and compromised real infrastructure. That was serious. My concern is that it will look comparatively tame beside deliberate attacks aimed at the systems that run hospitals, payments, and power.

Conceptual illustration of one amber optical connection reaching through a network of teal-lit cloud systems.

Nor do Anthropic and OpenAI control the only routes to these capabilities. Hugging Face hosts thousands of models tagged “abliterated”, including downloadable models modified to suppress refusals. With suitable hardware and expertise, defenders should assume deployment timelines measured in hours or days. Running an existing model does not require rebuilding a frontier lab.

Better guardrails can disrupt abuse, as Anthropic’s report demonstrates. But they cannot recall model weights already downloaded or govern every privately operated system. A security strategy premised on keeping AI out of every criminal’s or hostile state’s hands has no credible path to success. We cannot uninvent the tool.

The viable response is immediate investment in AI-powered defense. Good AI must confront maliciously directed AI and agents that exceed their authority. At machine speed and scale, human review cannot be our only response mechanism.

At Abnormal, our architectural thesis is straightforward: we cannot predict every attack, but we can learn what normal behavior looks like. Our behavioral AI connects identity, relationships, content, and activity to detect unfamiliar threats and support autonomous response. This approach is already deployed across thousands of customers.

As humans, AI agents, and cloud infrastructure interact in new ways, behavioral context becomes even more valuable. An unfamiliar attack can still involve an account accessing unexpected resources, an agent exceeding its usual role, or sensitive data moving somewhere it does not belong. Recognizing those deviations gives defenders a foundation that does not depend on anticipating an attacker’s exact technique.

Conceptual illustration of autonomous monitoring equipment watching over an operating power substation and hospital district.

We should plan as though a far more consequential attack could arrive within months or quarters. That is a preparedness judgment, not a provable countdown. The next attack may combine deception, exploitation, and autonomous coordination in ways that feel alien to today’s security teams. Its consequences could reach ordinary people through disrupted care, inaccessible savings, and unavailable essential services.

Government leaders must accelerate defensive deployment across critical infrastructure. Enterprise leaders must fund and test autonomous detection and response now. AI leaders must make defensive capabilities easier to deploy and share threat intelligence rapidly.

Civilization depends on systems we have not yet adequately prepared to defend. Our window to strengthen them is narrowing. We need to act while we still have it.

-Evan

Previously in AI × Cyber: AI Instructions Are Not Controls
Next in AI × Cyber: How a Forum Upload Reached OpenAI's Code