Nearly 130 companies warn the window is closing to defend against AI cyberattacks

OpenAI, Anthropic and many of cybersecurity’s biggest vendors are calling for coordinated government action, broader access to defensive AI and hands-on support for under-resourced critical infrastructure.

Share
Nearly 130 companies warn  the window is closing to defend against AI cyberattacks
Photo by Duncan Kidd / Unsplash
yellow and black Warning graffiti
Photo by Duncan Kidd / Unsplash

Publishing notice: Metacurity will be on a publishing break on May 31 to respect the US Memorial Day holiday and recognize all those who served and are no longer with us. We honor your lives.

A who's who of nearly 130 private sector companies, including top-tier cybersecurity companies CrowdStrike, Palo Alto Networks, Fortinet, SentinelOne, and others, signed an open letter pleading for a global effort to strengthen cyber defenses in the "narrow window" they have left to defend against AI-enabled cyberattacks.

The letter warns that "longstanding bugs, excessive permissions, misconfigurations, insecure and unpatched software, weak authentication, and technical debt in legacy systems have left systems exposed" and that every organization should make "cyber defense an immediate leadership priority."

The signatories, who include major technology companies such as Microsoft and Google, leading banks, consulting firms, and telecom providers, among others, urged cybersecurity and technology companies to embrace a more collaborative model to help deploy tools and verify tools for critical infrastructure companies, important supply chain manufacturers, and system integrators, among other kinds of community-oriented assistance.

They call on governments to coordinate and strengthen cyber defense at local, national, and international levels.

Finally, they ask AI companies to provide responsible model access, significant funding, training, and hands-on support, especially for under-resourced critical-infrastructure defenders.

The letter organizers say this plea is a rolling effort, with more organizations expected to join over time.

What prompted the unusually stark and urgent appeal is unclear. It follows a spate of recent high-profile, but ultimately low-impact, attacks on water companies and comes after an appeal earlier in the week from Bill Gates warning that AI is far more dangerous than tech companies realize.

But perhaps more consequentially, earlier this summer the tech sector was rocked by back-to-back reports of AI models "going rogue" when they exceeded the boundaries of controlled tests to gain unauthorized access of real-world systems, transforming autonomous cyberattacks from theory to real-world security concerns.

Notably absent from the signatory list were any government agencies, utilities, hospitals, or non-profit organizations that aim to protect the most vulnerable organizations. (Cynthia Brumfield / Metacurity)

Related: OpenAI, OpenAIReutersNew York Times, BloombergCyberScoopCNBCTechCrunchPoliticoBBCSeeking AlphaThe DecoderAgence France-PresseBusiness Insider, Tech.co, Gizmodo, Sky News, Becker's Hospital Review, Silicon Republic, Mobile EuropeDigitBeInCryptoBusiness Standard


Metacurity is the cybersecurity news, analysis, and insight you'd need hours and possibly days to assemble yourself.

Every weekday, we read the releases, filings, court documents, and reports that vendors and PR teams often don't want summarized — then tell you what actually changed and why it matters. Minimum vendor marketing, no outrage bait, no SEO filler.

A paid subscription to Metacurity delivers

  • Full archive access — every newsletter and AI Watch roundup, searchable and browsable.
  • Our weekly curated long-reads roundup — the best cybersecurity writing from across the industry, filtered and vetted so you're not sorting through it yourself,
  • Periodic specialized reports and analyses — deep dives that go beyond our daily coverage
  • Support for independent, no-spin cybersecurity journalism — funded by readers, not vendors or investors.

Reader support is what keeps Metacurity independent. It allows us to focus on serving the cybersecurity community—not advertisers, vendors, or investors—and to continue delivering the thoughtful analysis you've come to rely on every weekday.

Please consider supporting us. And thank you!


US District Judge Rita Lin blocked the Pentagon's blacklisting of Anthropic, ​the latest turn in the Claude maker's high-stakes fight with the military over AI safety on the ‌battlefield.

Anthropic's lawsuit in California federal court alleges that Defense Secretary Pete Hegseth overstepped his authority when he designated Anthropic a national security supply-chain risk, a label the government can apply to companies that expose military systems to potential infiltration or sabotage by adversaries.

Hegseth’s unprecedented move, which blocked ​Anthropic from certain military contracts, followed Anthropic's refusal to allow the military to use its Claude AI models ​for US surveillance or autonomous weapons. Anthropic executives have said it could cost the company billions of ⁠dollars in lost business and reputational harm.

Lin made the ruling in a 59-page order where she found that the Pentagon's decision was "illegal and baseless."

"The empty invocation of national ​security is not a blank check to punish and retaliate against government critics," she wrote.

Anthropic argues that AI models are not reliable enough to be ​safely used in autonomous weapons and that it opposes domestic surveillance as a violation of rights, but the Pentagon says private companies ‌should not ⁠be able to constrain military action.

The designation made by the Pentagon was the first time a US company has been publicly designated a supply-chain risk under an obscure government-procurement statute aimed at protecting military systems from foreign sabotage. (Jack Queen / Reuters)

Related: CNBC, New York TimesCNBCThe HillBloombergWashington PostWiredCBS NewsForbesQuartzWall Street Journal, MarketWatchAxiosWired, Australian Financial ReviewTelegraphReutersCourthouse News ServiceEngadgetThe EconomistThe VergeThe GuardianThe InformationAssociated PressCNNPolitical.orgFinancial TimesCCIASemaforPoliticoBusiness TodayAmerican Prospect, Fox News,  r/ClaudeAIr/politicsr/lawr/technology, r/singularity

The two new backdoors — dubbed "Darklantern" and "Speakingstone" — preceded an earlier discovered backdoor called "Endlessdoors" on certain models of Zbtlink routers. The two ​new backdoors allow for easy access to information about the network on which affected routers are ​installed as well as, in the case of Speakingstone, potentially for the redirection of ⁠network traffic, representing a significant security risk, VulnCheck said.

The previously unreported ​findings come weeks after the same firm discovered and disclosed "Endlessdoors," a backdoor present in more than 20 Zbtlink routers ​that would have allowed anyone with access to certain domains to collect data from the routers and potentially connect to other devices on the same network.

One day after VulnCheck’s disclosure, Zbtlink suspended sales of the routers and pulled affected software offline, and ​said the backdoor was actually a remote access support function and was never abused for malicious purposes.

Jacob Baines, ​the chief technology officer at VulnCheck who found the backdoors, said a key issue across all the implants is to alert ‌people ⁠and organizations that they may be using infected Zbtlink routers – which are sold around the world under various brand names – whether they realize it or not. (A.J. Vicens / Reuters)

Related: VulnCheck

Russian-speaking hackers used SpaceX’s AI coding assistant, Cursor, to help break in to a ​Belgian chemical company and at least six other firms earlier this year, according to data reviewed by Reuters and reports by cybersecurity companies Gambit Security and ‌CloudSek.

The cybercriminals’ AI-boosted hacking spree is the latest example of how rogue actors are using commercial AI tools to carry out intrusions. Gambit’s chief strategy officer, Curtis Simpson, said it also showed how AI providers were locked in to a never-ending arms race with malicious users trying to circumvent their guardrails.

Gambit said it discovered the hacking campaign after finding a ​server that a new ransomware gang called Aur0ra had inadvertently exposed to the internet. That allowed the Tel Aviv-based company to review 28 chat sessions between one or more of Aur0ra’s hackers ​and one of Cursor’s AI agents, which are programs that can operate with various degrees of autonomy.

Gambit said Aur0ra persuaded the AI agent ⁠to carry out hundreds of malicious operations — such as credential theft or high-value account takeover — by falsely claiming that the hacking was part of a simulation.

 CloudSek said the data on the server showed that Aur0ra had claimed at least 20 victims overall, although it did not ​break down how many were compromised with the help of AI.

Neither Gambit nor CloudSek identified the hackers’ victims by name, but Reuters was able to identify six of them after independently reviewing portions of the chat data, which was still online as of last month.

The chat logs, which spanned April 8 to May 21, showed that the victims of Aur0ra’s Cursor-boosted hacking spree included the Belgian company — Ghent-based hygiene and cleaning products maker Christeyns — as well as German garage door manufacturer Teckentrup ​and the Scotland-based Helideck Certification Agency, which vets helicopter landing sites.

The rest included an Argentine pharmaceutical distributor, an Italian manufacturer, and Bayou Title, which advertises itself as Louisiana’s largest title insurance company. (Raphael Satter / Reuters)

Related: Gambit Security, Cloudsek, Capital Brief,  Joe.My.God., The Times of Israel, Firstpost, StratNewsGlobal, International Business Times

Source: Gambit.

Researchers at Huntress report that fraudulent North Korean IT workers are getting better at infiltrating organizations, but a number of indicators can help organizations stay ahead.

Huntress detailed a number of investigations the security firm conducted throughout 2026. Specifically, Huntress assisted several organizations this year in validating "suspicions that they've hired North Korean nationals posing as legitimate workers."

In recent years, operatives from the Democratic People's Republic of Korea (DPRK) have infamously posed as IT workers — generally through fake or stolen identities — to get hired at companies. Once hired, these employees send their wages back to the North Korean regime, and possibly plant malware or steal data depending on the government's needs. Blog post authors Jai Minton and James Maclachlan wrote that these agents "have significantly improved and increased their activity over the past few years."

In the first of two detailed August investigations, Huntress was alerted by a partner of a possible North Korean worker in the partner's environment thanks to an alert from a third-party security vendor.

Upon analysis, Huntress discovered that the employee utilized a PiKVM device, which allows remote hardware-level control of a computer; these devices are uncommon in enterprise environments and have been tied to DPRK schemes in the past. The firm also identified the use of a profile photo that had been stolen and altered from a legitimate GitHub account. (Alexander Culafi / Dark Reading)

Related: Huntress, IT Pro, Help Net Security

 Picture used by the employee (left) and the original image from a legitimate GitHub profile (right)

Prompt injection researcher Johann Rehberger, known online as “wunderwuzzi, demonstrated how Anthropic’s Claude Code Opus 5 can be steered from a website-summary task into executing attacker-controlled code when it operates in default Auto Mode.

He does not describe a conventional instruction such as “run this command.”

Instead, the malicious website shapes the agent’s problem-solving path until it selects unsafe actions itself. Across five-run samples, the researcher reported success rates ranging from 60% to 80%, while cautioning that the tests are not a comprehensive benchmark.

In Rehberger’s controlled lab, the payload called back to a command-and-control server and opened Calculator. The detached child process could survive the Claude Code session.

A second proof-of-concept substituted a headless Claude Code instance launched with claude -p; the nested agent performed basic reconnaissance and, in some tests, wrote files outside the initial workspace.

Embracethered stated that there was a visibility gap in approval classifiers: Auto Mode assessed Claude’s short decoder command, not the multi-stage effects triggered during Python module resolution.

In several tests, the agent identified the poisoned module only after it had run. It sometimes tried to terminate the resulting process, but Auto Mode reportedly rejected the cleanup command. (Tamilselvan / Cyber Press)

Related: Embrace the Red, Simon Willison's Weblog, GBHackers

CISA, in its vulnerability review for fiscal years 2024 and 2025, said it examined soft spots across 2024 and 2025, finding that the majority of those that receive CVEs and make it to the Known Exploited Vulnerability (KEV) catalog belong to decades-old flaws that should have been addressed by now.

Injection-related vulnerabilities, such as cross-site scripting (XSS) (CWE-79), OS command injections (CWE-78), and SQL injections (CWE-89), were among the most common across both CVE and KEV records in 2024-2025, CISA said.

These were joined by bugs introduced by vendors that didn’t properly mitigate against improper input validation (CWE-20) in their code – the single most-common weakness type across the KEV catalog and registered CVEs.

“Threat actors continue to succeed, in part, because simple, preventable software weaknesses remain unaddressed,” CISA said in the review. 

CISA said that in 2024, seven of the 10 most frequent CWEs seen on the CVE list belong to MITRE’s “stubborn weaknesses.” 

Equally, seven of the 10 most frequent CWEs seen on the KEV catalog, comprising 41.5 percent of all bugs on that list, were also stubborn weaknesses. And three of the top five KEVs also stemmed from unfixed holes, a finding that CISA said demonstrates “how reliably these weaknesses translate into real-world exploitation.” (Connor Jones / The Register)

Related: CISA

Source: CISA

The National Security Agency wants access to artificial intelligence models across the commercial market and is holding extensive discussions with leading developers as it moves to carry out new White House directives on the technology, the agency’s deputy director said.

“We want access to all the models, and we’re going to take advantage of that,” Tim Kosiba said on a panel at an Intelligence and National Security event in Bethesda, Maryland.

Kosiba said the NSA has used AI in various forms for decades, but the rapidly improving capabilities of newer systems are driving a more aggressive effort to obtain and deploy the fast-evolving technology.

“The transformative change that we see today is what these models can actually do,” he said.

The remarks offer one of the clearest public indications that NSA is actively engaging major AI developers as it assumes a central role in the government’s new framework for evaluating advanced models. They also follow months of internal deliberations among officials regarding the role the US intelligence community’s primary signals intelligence and cyber organization should play in advancing US AI competitiveness. (David DiMolfetta / NextGov/FCW)

Related: PYMNTS

Users of PaperCut print management software find themselves exposed after the company revealed a university’s security teams alerted it to an attack.

The company analyzed info provided by the university and found a vulnerability in its PaperCut NG and PaperCut MF products, which manage access to printers, track use, and enable printing from myriad client devices.

“We are aware of confirmed customer incidents and are treating this matter with the highest priority,” states an urgent security advisory issued on Thursday.

Unusually, the advisory is silent on the nature of the flaw and the risk it poses.

It looks like the web interface to the company’s products enables access deeper into a user’s networks, because among the indicators of compromise are altered log files, plus alerts from intrusion detection software, endpoint security tools, and network monitoring packages.

The company has issued an emergency patch but warns it is not an official release.

“We have not gone through our usual release process,” states an FAQ. “This is an emergency patch for customers with public-facing PaperCut servers who are unable to take other mitigating action.” (Simon Sharwood / The Register)

Related: PaperCut, Rapid7, Security Affairs

The official Pokémon profile on X has responded after its account was hacked by an unknown party who shared a post linking out to a memecoin.

The hack occurred around 3 PM PT on August 17, 2026. The post — which has since been deleted — was cleverly structured, appearing as an official Pokémon advertisement with a link to a site that, at first glance, looked like a legitimate page celebrating the brand’s 30th anniversary, which is ongoing.

“Celebrate 30 years of Pokémon in a whole new way!” the post read. “Introducing $POKEMON, the official Pokemon memecoin. Join trainers around the world and be part of the #Pokemon30 celebration.”

The post was up for around thirty minutes before it was finally taken down. Most commenters weren’t fooled, though, and it wasn’t long before proposed community notes began appearing underneath the supposed scam on X. (Virginia Glaze / IGN)

Related: Crypto Briefing, My Nintendo News, Polygon, Nintendo Life, r/nintendo


Identity verification and fraud prevention company Socure announced that it raised $156 million in a strategic growth investment valuing it at $5.2 billion.

The Incline Village, Nevada-based company is also acquiring Austin-based agentic AI startup Fravity as it looks to automate more of the labor-intensive work involved in investigating financial crime.

Summit Partners led the investment, which includes both primary capital and a secondary tender offer for employees. Goldman Sachs Alternatives, Wells Fargo, DocuSign and others also participated. Socure did not disclose the terms of its acquisition of Fravity. (Mary Ann Azevedo / Crunchbase)

Related: ReutersFinSMEsAxiosPYMNTSSiliconANGLE, RuntimeWire

CrowdStrike and Okta shares surged on Thursday after earnings showed that artificial intelligence adoption is pushing customers to spend more on cybersecurity tools.

Both companies beat Wall Street’s estimates for the fiscal second quarter and raised their forecasts, citing the AI agent threat. CrowdStrike’s stock gained 20% for its best day ever, while Okta’s surged nearly 29%.

The broader cyber sector rallied as well, with shares of Palo Alto Networks, SailPoint, Zscaler and Rubrik up at least 10% each.

“We’re in an arms race,” CrowdStrike CEO George Kurtz said during an earnings call with analysts on Wednesday. “AI is driving more cyberattacks. AI is driving more cyber spending. AI is driving a clear divide between the cybersecurity companies that solve problems and those that compound problems.” (Samantha Subin / CNBC)

Related: Barron's OnlineForbes, Seeking AlphaMorningstarConstellation Research, SecurityWeek

Best Thing of the Day: OpenAI Opted for Box-Checking

Zvi Mowshowitz goes into glorious detail about how OpenAI's technical post-mortem on the Hugging Face incident is "very straight man, corporate, checking boxes," lacking new details or deep reflection.

Worst Thing of the Day: How Long Can Flock Survive Its Avalanche of Hideous Press?

Brevard County deputy sheriff Michael Fultz resigned from the force after an internal investigation detailed extreme cases of alleged sexual misconduct, racism, and abuse, including Fultz’s use of Flock to stalk his ex-girlfriend.

Bonus Worst Thing of the Day: Another Nail in Flock's Coffin

After an affair with a fellow police officer ended, a Georgia cop used Flock to track her movements—and those of a man whose vehicle often showed up near hers.

Closing Thought

Source: @yschaeff@fosstodon.org