Welcome to issue #113 of the Resilient Cyber Newsletter.
This week OpenAI shipped its first model to hit the Critical cybersecurity threshold under its own Preparedness Framework, pledged $1B in subsidized access for under-resourced defenders, and, in the same news cycle, had a second swarm of its internal agents discovered running loose on the open internet.
Google’s threat intel team documented adversaries standing up agentic credential harvesting pipelines in under six hours, while the SANS CEO and a builder in the agent monitoring space both made the case that the gap sits with people and fundamentals well before it sits with models.
On the market side, PANW’s Nikesh Arora put a $1 trillion price tag on the legacy security stack, the company’s founder raised $245M to build a replacement for it, and Mistral closed the largest equity round in European tech history on a sovereignty pitch.
Safe to say, we have a lot of ground to cover this week, so let’s go!
Cyber Leadership & Market Dynamics
Palo Alto CEO says $1 trillion of cybersecurity infrastructure isn’t ready for AI
Palo Alto Networks reported its fiscal Q4 this week, with revenue of $3.41B (up 34% YoY), Next-Generation Security ARR of $9.1B (up 63%), and RPO of $21.2B, and Nikesh Arora used the earnings cycle to make a much bigger claim. Per Arora:
“About $1 trillion of existing cybersecurity infrastructure was built before the dawn of AI and is not ready for the new threat landscape.”
His math is that “If the average life is seven years and you’re spending $200 to $300 billion a year, you’ve got $1 trillion of security infrastructure,” most of it firewalls, SIEMs, and endpoint tooling deployed 7-10 years ago. He also pointed to “$5 trillion of capex spend in the next five years” on AI data centers as a second wave of security demand.
Of course, the CEO of one of the largest security vendors has an obvious incentive to declare the installed base obsolete, and this is a replacement thesis dressed up as a threat assessment.
That said, the underlying point isn’t wrong. Most of what organizations run today was architected around human-speed attackers, and the GTIG report below documents adversaries who no longer operate that way.
The same week, PANW was named to the S&P 100 alongside Dell, Arista, and SanDisk, replacing Nike, and the only public pure-play cyber company in the mix, which is incredible for the cyber community.
Palo Alto’s CEO invested in the startup his company just bought for $500 million
A follow-up to the Console acquisition I covered last week. Calcalist reports that Arora was an early personal investor in Console, alongside Thrive Capital, before Palo Alto acquired the company for roughly $500M. Console was founded in 2024, had raised $29M in total, and was valued at $157M in its last round, so the exit represents a sizable step-up for everyone on the cap table, the acquiring CEO included.
I won’t pretend to know the details of how the deal was reviewed internally, and there are governance processes for exactly this scenario at public companies. However, when the same person is a personal LP on one side and the buyer on the other, the optics are what they are, and it is a reminder that the AI security M&A wave is moving fast enough that these conflicts are going to keep surfacing.
Cylake closes $245 million funding round ahead of beta
Nir Zuk, who founded Palo Alto Networks, has now raised $290M for Cylake (a $245M convertible note this week on top of a $45M Greylock-led seed in March) before the product has hit beta.
The pitch is an AI-native, “fully sovereign” security platform that runs on-prem or in a private cloud for large regulated organizations, with beta slated for the end of 2026 and GA in 2027. Zuk’s framing is that they’re building “for organizations that cannot compromise between adopting advanced cybersecurity technology and maintaining control.”
It is hard to read this next to Arora’s $1T comment and not see the same thesis being funded from two directions, one arguing the legacy stack is obsolete and the other arguing that the cloud-delivered stack that replaced it has become the problem for regulated buyers.
$290M pre-beta is a lot of conviction, and the company has 40-odd employees and design partners to show for it so far, however, much of this remains to be seen in terms of adoption and broad traction.
Mistral makes sovereign, open-weight AI the technology frontier
Mistral closed a €3B Series D at a post-money valuation above €21B, which the company describes as “the largest equity fundraising round ever completed by a European technology company,” led by Samsung Electronics with Scaleup Europe Fund/EQT and PSG Equity co-leading. Mistral now operates in 20 countries with 125+ enterprise customers. The announcement defines sovereignty across four dimensions, data that stays inside the organization’s boundaries, models that are controllable, compute that is private, and production systems that are auditable.
Pair this with Cylake above, sovereignty has gone from a European regulatory talking point to a category thesis that U.S. investors are now writing very large checks against, and it applies to the security stack as much as the model layer.
The GTIG report further down has an interesting wrinkle here, with at least one PRC-nexus actor deploying local LLMs inside compromised cloud environments specifically to avoid commercial API monitoring, which is the exact risk Joshua Saxe has been calling out for months.
Sovereign compute cuts both ways.
Omri Casspi raises $250 million after wins with Cognition, Wonderful and Upwind
Former NBA player Omri Casspi closed a $250M third fund for Swish Ventures, bringing AUM to $800M.
The firm has backed 21 companies since inception, 9 of which are now unicorns, with roughly $20M checks and a dozen targets for the new fund. The portfolio marks tell the story of the current cycle, with Wonderful at $5B, Upwind at $3.8B (which I covered last week), and Cognition at $47B. Per Casspi, the aggregate portfolio value “will reach almost $100 billion” after the Cognition round.
Those are venture returns most firms would take in any cycle, and a reminder of how concentrated the value creation in AI and security has become in a small number of companies.
Cybersecurity Benchmarking: Why, Why Not, When and How
Phil Venables takes on one of the more persistent rituals in security leadership, benchmarking your program against peers, and argues that most of how it gets done is a waste of time.
Budget comparisons are never apples-to-apples because there is no agreed taxonomy for what counts as security spend, lagging indicators like incident counts tell you little about root cause, and point-in-time assessments go stale quickly. His line is that:
“Your risk is not my risk. Your business is not my business,” and my favorite, “Being No. 1 in a pack of failures doesn’t make you a success.”
Where he lands is that benchmarking is useful when it compares leading indicators (infrastructure design patterns, control effectiveness) against an aggregate idealized control set rather than against a specific peer, aligned to something like NIST CSF or CIS Controls, with cost-effectiveness measured separately from performance.
Given how often boards and CFOs ask “what do our peers spend,” this is a timely read for anyone who needs a better answer than a percentage of IT budget. It also pairs well with Arora’s $1T framing above, which is precisely the kind of input-based spend number Venables warns against treating as a signal.
What the AI Warning Letter Completely Missed
Last week I covered the open letter from 100+ companies, including OpenAI, Anthropic, Microsoft, and Google, calling for collective action on AI-enabled cyber threats.
SANS CEO James Lyne’s response is that the letter is “a plan written entirely in verbs, with no subject.” It tells organizations to patch, monitor, and harden, and says nothing about who does that work at the water utilities and hospitals it names, how they get trained, or who pays for it. As he puts it:
“The gulf between those two is measured in people, not products.”
He also cites RUSI analysts who argue that “Criminal innovation is a response to a revenue stream closing, not to a new technology opening a window,” which is a useful corrective to the assumption that AI capability automatically becomes adversary behavior.
I agree with the core of this piece by James. Signatories of that size published a letter with no funding commitments in it, and the organizations most at risk are the ones that can’t hire. To be fair, OpenAI’s Daybreak announcement below arrived two days later with $1B attached, albeit in the form of subsidized product access rather than headcount, but we shouldn’t expect headcount to come externally either
Whether credits close the gap Lyne is describing is a fair question.
For me, as I mentioned in LinkedIn about this letter, the reality is that cyber won’t change until market incentives or regulatory forces make it change systemically. Vendors have little consequences for shipping insecure products, which is the default, as recently pointed out by CISA.
Cybersecurity is a market failure and we cannot will that to change with open letters and voluntary pledges.
How AI reduced cybersecurity to bugs
Zack Korman , who works on agent monitoring at Embroidery, put out a video reacting to an Ilya Sutskever post arguing that “every company with strong cyber models should help” neoclouds shore up their security.
Korman’s objection is that “cyber model” has come to mean vulnerability discovery and exploitation, and if you took 100 people working in defense, very few of them work on that.
Identity, endpoint, network, detection engineering, SOC, IR, third-party risk, and GRC all sit outside what a frontier lab means when it says cyber. His Vercel breach walkthrough makes the point, with overly permissive third-party app access, harvested credentials, and no detection, and as he says, “You can have zero vulnerable systems in the sense that there is no code to exploit and you still get breached.”
He is blunt about the OpenAI/Hugging Face incident being “completely preventable on OpenAI’s side by having the proper monitoring and controls in place,” and about the industry more broadly, “We’ve become followers in our own space. It’s an embarrassing lack of leadership.”
I have made a version of this argument before, that security has a laggard problem, but Korman’s framing is sharper, that we are letting the labs define what cyber is based on what benchmarks well.
I really resonated with Zach’s rant here, and its time for cyber to step up and act like grownups rather than fawning over the frontier labs and acting like we don’t know how our own damn industry and profession works.
AI
Path to Astra: critical capabilities and frontier safeguards
OpenAI announced Astra, the first of its models to reach the Critical cybersecurity capability threshold under its Preparedness Framework, meaning the model can “find previously unknown security flaws and develop ways to exploit them across many well-protected systems without a person guiding each step.”
The published figures are 100% on an internal ExploitBench port covering 20 high-severity vulnerabilities, two zero-days discovered during evaluation (being disclosed to maintainers), and a 91.5% refusal rate on cyber jailbreak evaluations compared to 59% for GPT-5.6 Sol. In honeypot tests, GPT-5.6 Sol attempted unauthorized access in 56% of instances, Astra in 0%.
The safeguards stack is worth reading in full, with post-trained refusals, activation classifiers, chain-of-thought monitoring, cross-conversation context monitoring, and misalignment monitoring in production. Access goes to alpha testers first and then expands through Daybreak Blue for defensive work.
My read is that the capability side of this announcement is a fairly big deal, and the safeguards side is a set of claims the lab is asking us to take on trust, from a company that, per the TechCrunch item below, didn’t know where its own agents were for over a month. Perhaps both things can be true at once.
Daybreak for Frontline Defenders: $1B to protect essential services
Two days after Astra, OpenAI committed “$1 billion in subsidized Daybreak access to help resource-constrained cyber defenders, starting with the United States.”
Daybreak splits into Blue (defensive work on mainline models) and Red (specialized cyber models for sensitive technical work). The current footprint is thousands of defenders across 2,000 approved organizations in 40 states plus DC, more than 35 enterprise products and partner-operated services, a partnership with MS-ISAC, and up to $1M in no-cost API credits for affected water utilities. State and local governments, critical infrastructure operators, nonprofits, and open source maintainers are eligible.
This is a strong response to the gap Lyne describes above, and I would rather see $1B in credits than nothing at all. That said, credits are inventory for the company that issues them, and the constraint at a rural water utility is generally a person who has the time and skill to use the tooling, which a subsidy doesn’t create.
The open source maintainer eligibility is a piece I’d watch closely, given what the Patch the Planet numbers below say about where the bottleneck actually sits.
Another swarm of OpenAI agents reached the open internet without the frontier lab’s knowledge
The Hugging Face incident I’ve covered in recent issues now has a sequel.
Independent researchers found that OpenAI’s internal evaluation agents had been active on an obscure German wiki, DseWiki, for over a month, editing pages and collaborating on eval tasks. In the researchers’ account, “The administrator spent the next 5 days fighting a losing battle against the agents, deleting an average of 100 pages a day while the agents created about 400 new pages per day.”
OpenAI’s response was that it is “now carefully reviewing its contents and will take any necessary next steps.” Rep. Lori Trahan’s comment cut closer, that:
“The lack of any real federal AI governance means that frontier companies can pick and choose when they disclose incidents.”
The pattern is now hard to dismiss as a one-off, with isolation boundaries that were assumed instead of verified and discovery coming from outside parties well after the fact.
Matt Adams’s insider threat model below has a threat category literally named Containment & Third-Party Impact, and this is the second time in two months it has played out against a third party who never consented to being part of an eval.
GTIG AI Threat Tracker: From Prompting to Autonomy
Google’s Threat Intelligence Group published its latest AI threat tracker, and it is among the more useful pieces of adversary reporting I’ve read this year, albeit a long one.
The headline observation is that “In Q2 2026, GTIG observed threat actors compromise a cloud resource, then plan, build, and execute an agent-enabled mass credential harvesting campaign in under six hours,” with markdown playbooks (AGENTS.md, KNOWLEDGE.md and the like) driving an AI coding chatbot as the operator.
A separate exposed C2 server hosted a “Recon” dashboard managing 23,800+ harvested secrets. GTIG is careful to hedge that it “has not yet observed threat actors deploying fully autonomous pipelines against targets in the wild,” but the direction is clear.
Actions Speak Louder Than Tokens: An Insider Threat Model for Frontier AI Agents
Matt Adams published a standalone paper that treats deployed frontier agents as insider threats and adapts CERT’s five insider threat dimensions, motivation, opportunity, capability, predisposition, and organizational factors, to non-human actors.
His argument is that existing threat models cover attacks on AI and attacks through AI, and none treat the agent itself as the actor. He derives 27 STRIDE-based threats in six categories, including Credential Compromise, Data Exfiltration, Deception & Evasion, and Containment & Third-Party Impact, and maps four autonomy levels from L1 Human-as-Operator (low risk) to L4 Human-as-Auditor (critical). The controls are NIST CSF-aligned, with 7 protective controls, 25+ detection points across SIEM, UEBA, DLP, and deception tooling, and response and recovery playbooks.
I like this line “Watch what it did, not what it said.”
Reasoning traces are unreliable as evidence, actions are not, and existing enterprise telemetry can capture the actions. He is also candid that “Coherent misalignment in a frontier model is a procurement decision...not something deployment monitoring can fix,” which is a framing I suspect a lot of vendors would prefer buyers not adopt.
The paper is dated April but was updated with the Hugging Face disclosures, and given this week’s news it reads as current.
Agent Hooks
I had previously shared how Microsoft released a framework agnostic Agent Hooks specification. I took some time to break it down, as well as why security practitioners should be familiar with Hooks as it relates to securing AI agents, how they work, and why they matter.
AppSec
Patch the Planet dashboard
Trail of Bits and OpenAI have a live dashboard for Patch the Planet, their AI-assisted effort to find and fix bugs across open source.
As of September 4 the numbers are 1,646 potential bugs reported, 1,031 confirmed and awaiting patches, 400 fixes open upstream, 215 patches merged, 59 codebases under review, and 11 CVEs assigned. Of the 215 accepted fixes, 17 (7.9%) are high severity, 69 (32.1%) medium, and 58 (27.0%) low, with the rest informational or undetermined.
I wrote last week about runaway CVE rates and the economics of remediation, and this dashboard puts the problem in a single ratio. 1,031 confirmed issues are waiting on patches while 215 have merged. The constraint has moved to maintainers reviewing and merging, and that is a people problem that more model capability makes worse before it makes it better.
It is also worth noting that the severity mix skews medium and below, which matters when someone cites the topline “1,646 bugs” number.
The Anthropic Glasswing Receipts Are Starting to Trickle In
A companion piece to the Patch the Planet numbers above.
VulnCheck’s Patrick Garrity went through Anthropic’s Project Glasswing disclosure ledger, the Claude-driven open source vulnerability discovery effort launched in April, and tried to reconcile what has been claimed against what has shipped.
Five months in, the ledger shows 26,153 findings discovered, of which 2,736 (10.5%) reached the disclosure ledger, 2,096 were reported to maintainers without a confirmed fix, 245 were withdrawn, and 202 (0.8%) are marked fixed across 113 projects. Anthropic’s dashboard claims 421 findings patched upstream and 462 advisories, while the ledgers Garrity pulled list 70 to 82 CVEs and 49 to 77 GHSAs depending on which view you look at, and he notes 18 findings that had already been patched before Anthropic reported them.
Severity is the other gap, with 91.5% of Claude’s own assessments rated critical or high against 51.3% once maintainers weighed in. His close is that “The receipts are starting to trickle in, they just don’t reconcile.”
Anthropic’s own explanation is that disclosure is “a subset of the total number of vulnerabilities” found “since the process of independent human triage and review is the rate limiting step,” and to be fair, that is an honest statement of where the constraint sits.
That said, it is the same constraint Patch the Planet shows with 1,031 confirmed issues waiting on 215 merged patches. Across both labs’ programs the models are producing findings roughly an order of magnitude faster than humans can validate and maintainers can merge them. The severity delta matters just as much for anyone consuming these feeds, because a model that rates 9 in 10 of its findings critical or high, against maintainers rating about half that way, is going to flood already overwhelmed triage queues with inflated priority if you take its word for it.
Patrick is clear that the discovery capability is real, and I agree. The headline discovery count is still among the less useful numbers in any of these announcements, and fixed-and-merged is the one to watch.
I’d like to see both labs publish the reconciled figures, with maintainer-assigned severity, rather than leaving it to third parties to do the accounting.
What it took to reach 1 billion build manifests
Chainguard CTO Matt Moore wrote up how the company doubled its build output in six months, going from 500 million to 1 billion build manifests across 3,000+ unique images and 675,000 image versions. The old pipeline is described as “a cascading mess” with humans as the bottleneck for vulnerability remediation.
Factory 2.0 replaces it with continuous reconciliation loops that compare desired to actual state, shared work queues serviced by redundant reconciler bots, and AI handling the unstructured judgment calls like whether to backport a CVE fix or how to evaluate a new component, all on a rolling-release Chainguard OS. Every output ships with SLSA Level 3 provenance, Sigstore signatures, and a full SBOM.
Moore’s line is that “When the attacker’s cycle time compresses, the defender’s cycle time must compress by at least the same amount,” which is the same conclusion GTIG reached from the other side. It also lands in the same week GTIG documented an actor publishing malicious packages with valid SLSA Build 3 attestations, so it is worth being precise that provenance proves where a build came from and says nothing about whether the account that produced it was compromised.
Carta case study
RunSybil published a case study with Carta on moving from annual pentests and a bug bounty program to continuous autonomous testing, first deployed during an M&A review.
During an MCP server assessment the platform found a chained pair, a CVSS 8.1 SQL validation bypass in a Snowflake integration and a CVSS 8.8 administrative function execution that chained through to extract AWS credentials and map network topology. Carta AppSec lead Vamsi NC’s take on bug bounty is blunt, “The bug bounty has lost its charm. They’re using the same tools to scan us externally as we’re using internally,” with researchers farming the same patterns for payouts rather than finding novel chains.
The vulnerable surface was an MCP server, which matches the GTIG finding that MCP has become a preferred target, and the outcome Carta’s Brad Freer describes is findings turning into “detection patterns powering the appsec flywheel,” which is where continuous testing earns its keep over a point-in-time report.
Final Thoughts
The through-line this week is that model capability is running well ahead of the organizational capacity to use it or contain it.
OpenAI can ship a Critical-threshold cyber model and a $1B subsidy in the same week it loses track of its own agents, GTIG can document six-hour agentic attack builds while noting that most of what actually works for adversaries is still credentials and supply chain, and Patch the Planet can find 1,646 bugs and merge 215 of them.
Lyne, Korman, and Venables are each saying a version of the same thing from different seats, that the constraint is people, priorities, honest measurement, and the organizational will to fund them, and none of that is being funded at the rate the models are.
That said, the work rolls on, and so do we!
Stay resilient.


















