2 days ago
They Told You!
On August 27th, more than a hundred companies who spend every other day of the year trying to eat each other's lunch signed the same letter. OpenAI alongside Anthropic and Google. Microsoft alongside AWS. And then the names that made me stop and reread the list — Visa, Mastercard, Capital One, General Motors, Shopify. The count was 116 within days, north of 130 shortly after, and 156 as of September 3rd. It's still climbing, which is not how press releases behave.
The warning: "We have a limited window to strengthen cyber defenses."
I went in ready to be skeptical, because we've all seen the cycle where very serious people warn us about AI right before shipping the next model. I came out convinced — but not for the reason the coverage suggested. Read principle one of that letter carefully and you'll notice something. It enumerates longstanding bugs, excessive permissions, misconfigurations, unpatched software, weak authentication, and technical debt in legacy systems. Not one item on that list is about artificial intelligence. The most advanced AI companies on the planet got together to warn you about your unpatched software.
And the attack they're warning about "in the coming months"? It already happened, twice. Anthropic's own threat intelligence team disrupted a Chinese state-sponsored operation where the AI toolchain executed 80 to 90 percent of the tactical work without human intervention across roughly thirty targets. Then CISA confirmed hackers targeted more than a hundred internet-exposed U.S. water systems in July — modifying PLCs to disable shutdown processes and alarms, which is a polite way of saying they removed the smoke detectors. How did they get in? Unitronics default credentials, a CVE with 2021 in the name, and federal remediation guidance that had to tell operators to check whether the default password "1111" was still in use.
No comments yet. Be the first to say something!