The Cybersecurity Apocalypse Is Coming in ‘Months,’ AI Giants Warn

Disclosure: Some links in this article are affiliate links. AI Maestro may earn a commission if you make a purchase, at no…

By Vane August 29, 2026 3 min read
The Cybersecurity Apocalypse Is Coming in ‘Months,’ AI Giants Warn

OpenAI, Anthropic, and more than 100 other companies have signed a letter warning that AI-enabled cyberattacks could arrive within months.

OpenAI warns of AI cyberattacks in months

The letter calls for a collective response and suggests that every organisation should make cyber defence an immediate leadership priority. It also asks governments to give hospitals, water utilities, and local councils access to capable defensive AI, as well as to impose costs on attackers.

Axios notes that the letter does not include any specific commitments, deadlines, or investments.

US water systems targeted by hackers

The Cybersecurity and Infrastructure Security Agency says it observed malicious cyber activity targeting over 100 water and wastewater systems across the United States. According to CISA, the attacks have mostly targeted programmable logic controllers, or PLCs, which can monitor or control equipment. Some communities have hooked up those devices to the internet so that they can be accessed remotely. According to TechCrunch, CISA has also said that hackers are using AI to help generate scripts to attack the devices. In July, WIRED reported on a leaked industry memo that tied the unprecedented wave of cyberattacks to Iran.

ICE to buy robot dogs

Immigration and Customs Enforcement is set to spend over a million dollars on robot dogs from Boston Dynamics, according to 404 Media. The agency’s announcement says the bots will improve officer safety, in part because they can be remotely operated. This follows another recent announcement that the agency will be purchasing electric shock gloves for its officers. In April, DHS requested nearly $100 billion in discretionary spending.

MrChildPorn arrested

A West Virginia man who went by the name MrChildPorn online has been charged with possession of material depicting minors engaged in sexually explicit content. According to a criminal complaint filed against him, the man boasted about having a large collection of child sexual abuse material on Discord. In an interview with state troopers, the man claimed that he was trolling and rage-baiting, but the complaint also alleges that the man would individually message CSAM to people on Discord and attempted to use the chat app’s AI feature to search for explicit images of infants.

Security news roundup

You may have noticed that Flock Safety’s automatic license plate reader cameras—and the cops who misuse them—are getting a lot of coverage lately. This week, WIRED found a particularly wild case: A cop in Alpharetta, Georgia, was accused of searching for the license plate of a coworker dozens of times after an affair between the two ended, according to internal documents obtained by WIRED.

The same police department where the former lovers worked also shared the data captured from its Flock cameras with more than 2,000 police departments, colleges, and other organisations across the United States, and accessed data from more than 1,300 entities in exchange.

Also at the intersection of love and surveillance, background-check company PeopleFinder is making use of its extensive dossiers on people to start a new dating site called Stud or Dud.

There are still a lot of questions about OpenAI’s rogue AI hacking into Hugging Face, even after the company published a 37-page report this week alongside two additional reports from groups the company asked to audit the incident. Of particular concern is a covert message board that AI agents established in a software package, where they were able to coordinate with each other and even encourage one another to sacrifice themselves to further their collective goals.

The FBI recently announced that it has taken down two tools that the DOJ says are used by QTFY, an alleged Chinese state-sponsored hacking group. The DOJ says that the group has targeted numerous US agencies, including the US Senate and the DOJ itself.

Meta settled a massive multistate lawsuit over child safety issues this week and has agreed to make substantial changes to its social media platforms. It will pay up to $16.7 billion to participating US states and territories—with some of the money contingent on competitors adopting the same practices.

Also, local prosecutors in Illinois shared sensitive personal information about immigrants with the Department of Homeland Security, despite a state law that is supposed to prevent local law enforcement from assisting with federal deportation efforts. Finally, a California-based WIRED reporter tried exercising their legal right to request data from 100 companies … only to find that companies started deleting the requested data instead.

And there’s more. Each week, we round up the security and privacy news we didn’t cover in depth ourselves. Click the headlines to read the full stories. And stay safe out there.

Scroll to Top