AI See, AI Do?

8–3–2026 (Monday)

Hello, and welcome to The Intentional Brief - your weekly video update on the one big thing in cybersecurity for middle market companies, their investors, and executive teams.

I’m your host, Shay Colson, Managing Partner at Intentional Cybersecurity, and you can find us online at intentionalcyber.com.

Today is Monday, August 3, 2026, and the Strait of Hormuz is closed while negotiations continue. Or restart. It’s not clear that anybody really knows the current state, which is a great metaphor for this week’s news about ongoing rogue attacks from AI systems - and not just OpenAI’s.

AI See, AI Do?

Perhaps it’s just trying to keep up with the other team in terms of news cycles and guerrilla marketing, but we learned last week that Antrhopic, makers of Claude, “identified three incidents in which a model accessed the internet from within or while interacting with the evaluation environment” “and then gained unauthorized access to the production infrastructure of three different organizations.”

Following this, the Wall Street Journal declared in a headline “Rogue AI Hacks Herald New Era of Cyber Chaos.” That might be a touch sensationalist, especially coming from the Journal. Others are taking more measured approaches, including a couple of posts from Ciaran Martin - who now teaches at Oxford - and Professor Alan Woodward of the University of Surrey. Their posts are worth reading, and both are designed to limit the FUD - Fear, Uncertainty, and Doubt - in these discussions.

Woodward notes “What is being oversold is intent.” “The models were told to find complex attack paths through a computer system. They found one. It led somewhere nobody had thought to fence off.“

Martin frames it as “a freakout is not justified and harmful. Stop the FUD. Fix the stuff.” 

Wired has a long discussion about the implications for legal liability in this new world of rogue AI bots. Spoiler alert: it’s not so clear 

Which is what we cover every week on this show. And - it’s probably not the zero days that are going to need the fixing. Indeed, the latest Chrome release (151, for those counting) includes 370 vulnerability fixes - including roughly 80 Critical and High severity items. Maybe you start there, since that’s what attackers are focused on.

Indeed, we’re seeing more and more of the so-called “ClickFix” attacks succeeding in the wild, including a post from Microsoft calling out these attacks specifically being carried out by Russian threat actors targeting hotel wifi systems.

Not to be outdone, Chinese threat actors are leveraging DeepSeek through Telegram to carry out “exploitation attempts against more than 460 targets using autonomous and conventional workflows” - but are notably targeting patchable vulnerabilities.

Finally, new midyear cyber risk reporting from cyber insurer resilience, backs up the message we keep sending here on this show: “you cannot afford to take your eye off the fundamentals.”

Fundraising

While not as big as last week, still a tremendous amount of newly committed announced last week, totaling more than $23B, including:

  • Blue Owl Capital has secured $10.6b for its sixth GP stakes fund;

  • Brookfield held a $2b first close on its first Middle East Partners fund, from LPs like Saudi Arabia's PIF; 

  • Pantheon raised $3.2b for its sixth PE co-investment fund and related vehicles.; and 

  • Wind Point Partners, a Chicago-based PE firm, raised $3.2b for its 11th flagship fund.

A reminder that you can find links to all the articles we covered below, find back issues of these videos and the written transcripts at intentionalcyber.com.

With all that’s going on, we’re going to have to take it as it comes. We’ll see you next week for another edition of the Intentional Brief.

Links

https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals

https://www.wsj.com/tech/ai/openai-anthropic-rogue-ai-models-20b6bb3c

https://ciaranmartin.substack.com/p/from-frenzy-to-freakout

https://this.weekinsecurity.com/clickfix-attacks-are-increasingly-devious-dangerous-and-can-get-you-hacked-in-an-instant/

https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/

https://www.wired.com/story/openai-anthropic-ai-hacking-sprees-illegal/

https://thehackernews.com/2026/07/chinese-hacker-commands-deepseek-via.html

https://cyberresilience.com/wp-content/uploads/2025/09/2026-Midyear-Cyber-Risk-Report.pdf

Next
Next

On AI and Cyber: The Alignment Problem(s) and Unintended Consequences