More AI Consternation: What, me, worry?
8-31-2026 (Monday)
Hello, and welcome to The Intentional Brief - your weekly video update on the one big thing in cybersecurity for middle market companies, their investors, and executive teams.
I’m your host, Shay Colson, Managing Partner at Intentional Cybersecurity, and you can find us online at intentionalcyber.com.
Today is Monday, August 31, 2026, and it’s the first day of school here in my corner of Washington State, and the Strait of Hormuz is still closed.
More AI Consternation: What, me, worry?
In what should be no surprise to regular viewers of this show, more than one hundred tech companies - including OpenAI, Anthropic, Google, and Microsoft - have signed an open letter urging both the private and public sectors to work together to defend themselves from AI-related cyber threats.
The letter itself was posted on the OpenAI blog, under the title “A call for collective action on cyber defense,” and encourages every organization to “Make cyber defense an immediate leadership priority” and “meet [security standards] with the urgency and coordination of an incident that takes precedence over everything except critical business operations.”
Not quite an existential crisis, but certainly close to it. It comes on the heels of a post with similar vibes from Bill Gates, entitled “The turbulent AI era is here. The choices we make now are critical.” He argues that “AI will either be the greatest equalizer ever invented, or the worst source of injustice.”
And while there’s certainly a tone in these pieces that underlies a FUD-driven approach (Fear, Uncertainty, and Doubt) - research from Palo Alto’s Unit42 indicates that while “AI-enabled malware is real […] the volume of genuine operational activity remains a fraction of what public sample repositories suggest.”
Others are arguing that the real challenge around AI risk centers on the notion of Zero Data Retention, and research from Gambit Security’s team indicate that ransomware gangs are leveraging the Cursor Agent to execute and spread malware.
This group is tied to Russia, and Russia’s also been in the news for their clever use of Signal vulnerabilities to infiltrate mobile devices, something the FBI has been warning publicly against since March.
In short, those basics we talk about every week still matter, a tremendous amount, and that even extends to renewing expired domains. Some interesting tidbits around researchers who bought up “No Reply” domains to harvest hundreds of thousands of credentials shows just how basic your defenses might need to get.
Gary Marcus, who is a noted AI skeptic / realist, depending on your own persuasions, had a good piece on lessons from OpenAI’s sandbox escapes that points out a defense in depth strategy that includes things like network monitoring, canary tokens, and other indicators can both prevent and detect these sorts of malicious activities.
I’d encourage you to read this piece, in particular, as a way to rationalize what all is going on in this space, this week.
Fundraising
Fundraising numbers are notably lower this week, we’re double where we were last week, with $6.2B in newly committed capital, but notably spread across a wide range of focused funds, led by:
StepStone Group raised $1.7b for an infrastructure secondaries fund; and including
Andreessen Horowitz raised $1.1b for its first hardware infrastructure fund;
Capital F, an early-stage tech VC firm focused on the "female economy," raised $17m for its debut fund;
GenNx360 Capital Partners, a lower midmarket PE firm focused on industrial and business services companies, raised $865m for its fourth fund;
MassMutual Ventures launched its second climate tech fund with $150m;
With OpenAI launching a $400m second corporate venture fund.
A reminder that you can find links to all the articles we covered below, find back issues of these videos and the written transcripts at intentionalcyber.com.
We’ll see you next week for another edition of the Intentional Brief.
Links
https://hormuzstraitmonitor.com
https://openai.com/collective-cyberdefense/
https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/
https://cloudedjudgement.substack.com/p/clouded-judgement-82826-zero-data
https://www.spytalk.co/p/how-the-russians-got-inside-my-phone
https://www.ic3.gov/PSA/2026/PSA260320
https://www.cyberkendra.com/2026/08/researchers-buy-no-reply-domains-and.html
https://garymarcus.substack.com/p/5-lessons-from-the-openai-hugging