Tech giants call for collective cyber defence action, and other cybersecurity news
Major global tech firms have called for collective action to be taken to improve cyber defences. Image: REUTERS
Akshay Joshi
Head of the Centre for Cybersecurity, Member of the Executive Committee, World Economic Forum- This regular round-up brings you key cybersecurity stories from the past month.
- Top cybersecurity news: Leading tech firms call for collective cyber defence effort; Ransomware botnet disrupted after two decades; UK Lords call for government AI 'kill switch'.
- The World Economic Forum’s Centre for Cybersecurity provides an independent and impartial platform to reinforce the importance of cybersecurity as a strategic imperative and drive global public-private action to address systemic cybersecurity challenges.
1. Major tech firms call for collective cyber defence action
Global technology firms, including Microsoft, OpenAI, Alphabet, Anthropic and Amazon, have called for a defensive "surge" to defeat AI-driven hacking.
Signing a joint letter, the businesses warned that attacks will become “more widespread and sophisticated” in the coming months and proposed three principles for a collective response:
- Recognize the status quo won’t be enough
- Empower more defenders with cyber-capable AI
- Mobilize a collective response.
“The companies and public services our communities depend on - from hospitals to water treatment plants, to the infrastructure that powers the internet - are at risk,” they said.
“Today’s AI advances are already giving defenders new ways to fix weaknesses that have accumulated for years. If we act decisively, we can use the defenders’ window to make our digital world much more secure.”
The letter also included four steps the firms believe need to be taken next.
1. For all organizations, it urged cyber defence to become an “immediate leadership priority”.
2. For cybersecurity companies and their technology partners, it encouraged efforts to lead the responses and “defend against sustained AI-enabled attacks”.
3. Governments, it said, should coordinate defence at local, national and international levels.
4. And for frontier AI companies, it called for the provision of “responsible model access, significant funding, training, and hands-on support, especially for under-resourced critical-infrastructure defenders”.
The letter comes weeks after major AI companies including OpenAI, Meta and Anthropic revealed agents had gone rogue, escaping sandbox testing environments to hack external companies to find answers to problems set by testers.
2. Russian cybercrime operation disrupted after two decades
An international law enforcement operation, completed alongside cybersecurity firm CrowdStrike, has disrupted Sality, a peer-to-peer botnet operating from Russia, after 23 years.
The effort was carried out in partnership with the US Department of Justice, the FBI, the Department of Defense Office of Inspector General’s Defense Criminal Investigative Service (DCIS), and the Shadowserver Foundation, with support from Europol, Eurojust and law enforcement agencies in Bulgaria, Hungary and Romania.
Since it was first observed in 2003, Sality has been used to distribute malware to steal information, distribute denial-of-service payloads and more. The web domains used by hackers have been seized, while a network of compromised computers was also cut off.
Initial steps to dismantle the botnet were taken by CrowdStrike in front of an audience at its Day Zero summit in Las Vegas.
The firm said that it exploited peer list manipulation, stating: “The same properties that made Sality resilient also created the conditions for its undoing. Together, these properties are fatal. The protocol cannot be hardened against attack, and the network cannot exclude an active defender who speaks its language.
“This operation demonstrates that P2P architecture, long considered a shield against disruption, is not invincible. With sufficient technical investment, precise understanding of protocol behavior, and coordination with law enforcement and industry partners, even the most resilient criminal infrastructure can be dismantled.”
3. News in brief: Top cybersecurity stories this month
US federal agency confirms data breach: The Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) has confirmed a ransomware group accessed a computer system. In a statement, ATF said a standalone system was affected. “Upon discovery of the incident, ATF immediately terminated connections to the affected environment and initiated incident‑response and forensic activities,” it said.
OpenAI says new model requires stronger guardrails ahead of launch: Astra, an upcoming model from OpenAI, needs additional safety measures to be enacted before it can be launched, the company has said. Capable of spotting more security vulnerabilities than publicly available models with less computational power, Astra would soon be available to a limited group of users, a spokesperson said.
Anthropic details response to recent security incident: Anthropic has announced the steps taken after Claude models gained unauthorized access to external systems after escaping a sandbox testing environment. The firm paused external cyber evaluations to create more secure testing environments. Steps included deploying classifiers to automatically identify in real time if a model attempts to escape testing, identifying other attempts, and migrating high-risk internal sandboxes to “more robust isolation”.
UK House of Lords members call for UK AI ‘kill switch’: A group of British peers has called for the government to have the power to deactivate powerful AI systems in the event of a national security event. Proposed as an amendment to the Cyber Security and Resilience Bill, Liberal Democrat Lord Tim Clement-Jones described it as a “vital safety net”, although the tool would only be used as a last resort. A day before the lawmakers' call for ‘kill switch’, Bank of England Governor Andrew Bailey warned G20 financial ministers that AI can cause significant cyber threats.
4. More about cybersecurity on Forum Stories
The hidden costs of cybersecurity fragmentation: As threats evolve at speed, advanced by AI, new cybersecurity solutions are required. However, introducing these also often means more complexity, impacting visibility. In this article, Tariq Alharbi, VP, Cybersecurity Managed Services, Saudi Information Technology Company (SITE), explores why interconnected defences are key in reducing fragmentation and building true resilience.
Extending pharma’s cyber resilience: Efforts to improve cybersecurity stances often focus on technical defences. However, value chains must also be protected to establish business accountability. This is particularly important in the pharma industry, where failure to act could impact patient access to medicine. Ashish Gupta, Partner, PwC, and Jonathan Sinclair, Head of Cyber Resilience, Roche, have considered the steps businesses can take to ensure patient care continuity in this article.
Human judgment missing from AI regulation: To scale AI with confidence, human judgment is key. However, according to Tiffany Xingyu Wang, CEO, Songsheet, this layer is often missing in the AI regulation work. See how limiting system uses, inspections of data integrity and transparent tracing of deployment can help scale AI, rather than stall it, in this article.
License and Republishing
World Economic Forum articles may be republished in accordance with the Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International Public License, and in accordance with our Terms of Use.
The views expressed in this article are those of the author alone and not the World Economic Forum.
Forum Stories newsletter
Bringing you weekly curated insights and analysis on the global issues that matter.
More on CybersecuritySee all
Daniel Akinmade Emejulu, José Ramón Martínez Saavedra and Carlos Abellan
September 11, 2026





