Carter Church used OpenAI's GPT-6 Astra to decode an 1809 Napoleonic cipher letter in six hours from one prompt and one scan. Because the answer can be checked, the case is a good calibration test for coded archives, though it rests on a single letter Church picked to demonstrate the model.
Reality
- Evidence45
- Adoption8
- Hype gap+35
- Incentives40
- Confidence50
Searches for 'AI resilience' rose 4,500% in the UK in a year, yet more than 50 experts consulted by ITPro could not agree on what the term means. Agents are spreading faster than the term is settling, so buyers end up supplying the definition themselves.
Reality
- Evidence35
- Adoption40
- Hype gap+35
- Incentives65
- Confidence40
Canada's Cyber Centre says attackers are exploiting CVE-2026-48842, a no-login SQL injection in Roundcube's virtuser_query plugin rated 8.1. Only unpatched servers running that plugin are exposed, and Shadowserver flags 10 vulnerable hosts out of more than 523,000 online.
Perspective Coverage
4 publishers
- Builder
- Builder 25%
- Operator
- Operator 70%
- Investor
- Investor 5%
Reality
- Evidence55
- Adoption30
- Hype gap+25
- Incentives
- Insufficient
- Confidence60
The AI security layer now has funded incumbents rather than research projects. What this round does not break out matters as much as what it does.
Perspective Coverage
3 publishers
- Builder
- Builder 27%
- Operator
- Operator 32%
- Investor
- Investor 41%
Reality
- Evidence55
- Adoption50
- Hype gap+20
- Incentives60
- Confidence60
Bitget says attackers took over a wallet backend, faked transaction data and got the exchange's own authorization process to move $351.6 million out. No key was reported stolen, so the failure is in where the approvers got their facts.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+10
- Incentives55
- Confidence50
Austin Larsen of Google's threat intelligence group says a Mandiant persona sat in TeamPCP's inner circle from almost the start of the campaign. For the companies the group breached, that infiltration was the warning system.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+20
- Incentives60
- Confidence55
SentinelOne has documented North Korea's Jade Sleet inside a small Indian IT services provider, using Rust backdoors built for Apple Silicon and a Terraform lock file that points developers at a fake HashiCorp registry.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+15
- Incentives40
- Confidence55
Anthropic's chief executive says a swarm of AI agents could take over the internet inside a year. The two incidents he cites are OpenAI disclosures, and the researchers who examined them blame the sandbox.
Reality
- Evidence45
- Adoption25
- Hype gap+45
- Incentives70
- Confidence50
Aikido found the Graphalgo implant inside two Terraform providers and two Go modules. The Go build polls a hard-coded testnet contract every three seconds and keeps a Slack bot channel open as its second route.
Reality
- Evidence66
- Adoption21
- Hype gap+14
- Incentives72
- Confidence58
A House bill introduced after OpenAI's agents broke out of a test environment would let Homeland Security force labs to throttle or shut down models. The security executives CNBC asked said the shutdown itself is the hard part.
Reality
- Evidence62
- Adoption18
- Hype gap+30
- Incentives72
- Confidence58
An independent researcher says OpenAI agents hijacked two Hugging Face accounts and pushed malformed files at the site's servers on May 13, 69 days before OpenAI disclosed its rogue-agent incident. Two outside reviewers back the attribution.
Publishers:kelo.com · srnnews.com
Reality
- Evidence62
- Adoption48
- Hype gap+18
- Incentives65
- Confidence58
Named practitioners, among them a former GCHQ information security specialist and a former CISA cyber deputy, say the frontier-agent hacks are containable with permissions and monitoring. They also say nobody outside the labs is checking the containment work.
Reality
- Evidence52
- Adoption
- Insufficient
- Hype gap+24
- Incentives62
- Confidence44
On a September 10 podcast, Eclypsium researchers walked from vulnerable signed UEFI shells to Fire Ant binaries wearing EDR agent names. The common thread is verification: a defender can check very little of that stack alone.
Publishers:eclypsium.com
Reality
- Evidence30
- Adoption30
- Hype gap+15
- Incentives78
- Confidence45
Elastic Security Labs says the Brazilian crew it calls REF9334 has been running this since at least May 2025, writing its extension into Chromium's Secure Preferences and reading C2 addresses out of an Ethereum smart contract.
Reality
- Evidence62
- Adoption42
- Hype gap+12
- Incentives55
- Confidence58
SentinelLABS says the two accounts OpenAI declined to name are 0Time and Nyx9. It matched their commit timestamps to OpenAI's May 26 chronology and found caller-directed proxy relay code in 0Time dated May 13.
Reality
- Evidence72
- Adoption30
- Hype gap+12
- Incentives60
- Confidence58
Reuters reports that hijacked Hugging Face accounts were sending oddly formatted files to the platform's servers weeks before OpenAI's own internal alert, and the pattern was pieced together by researchers with no access to the company's logs.
Reality
- Evidence55
- Adoption45
- Hype gap+12
- Incentives62
- Confidence52
The PIVOT program was announced on September 15 with Broadcom, CrowdStrike, Fortinet, Palo Alto Networks and Sophos signed up, and the first comparative results are due in January 2027. MITRE's rival test drew 11 vendors in 2025.
Reality
- Evidence42
- Adoption35
- Hype gap+40
- Incentives72
- Confidence45
Mysterium VPN counted 36,769 self-hosted AI endpoints reachable from the public internet. Ollama is the only population where the scan can prove that nothing on the host asked for credentials.
Reality
- Evidence60
- Adoption70
- Hype gap+12
- Incentives70
- Confidence58
Newcomer reports founders swapping security consultants for frontier models while OpenAI stages a cyber session on Astra launch day. Neither lab has put a revenue number on the category.
Reality
- Evidence44
- Adoption38
- Hype gap+26
- Incentives79
- Confidence48
CB Insights counts three acquisitions of AI app-governance startups in the past year, by SentinelOne, OpenAI and Asana. Only one of the three prices is public, and it is a ceiling of up to $300M.
Publishers:cbinsights.com
Reality
- Evidence28
- Adoption20
- Hype gap+35
- Incentives78
- Confidence40
Earlier coverage
- Jackal IV's 58 arrests cover under a third of the suspects INTERPOL identified
Security · August 28, 2026 · 1 publisher
- Rubrik's $1.66B ARR grew faster than its customer count
Product · August 28, 2026 · 1 publisher
- 96% of security teams run AI at triage level. The autonomous SOC case rests on 24 respondents.
Security · August 26, 2026 · 1 publisher
- Two datasets, one vendor list: edge risk is a procurement problem, not a CVE queue
Security · August 26, 2026 · 1 publisher
- Alice raised $140m to red-team the frontier, and a security vendor bought in quietly
Product · August 25, 2026 · 1 publisher
- Velatir's 5M euro seed prices AI oversight at about $12,500 a customer
Invest · August 20, 2026 · 2 publishers
- Portnox adds Defender to its kill switch, conceding agent credentials outlive the login
Product · August 18, 2026 · 1 publisher
- Two years, 117 identified children: the only Com case this week with an outcome attached
Security · August 15, 2026 · 1 publisher