Director’s note: 9/11 lessons for today’s threats
Dear readers,
The upcoming 25th anniversary of the 9/11 terrorist attacks is a time for somber remembrance and reflecting upon how the landscape has evolved with new challenges and adversaries compounding the threats that have persisted over the decades. The House Intelligence Committee convened a hearing this week to study those critical questions, and I was honored to testify alongside former National Security Advisor H.R. McMaster, CSIS Defense and Security Department President Seth Jones, and former White House Special Advisor for AI Ben Buchanan. As Dana Nickel wrote in POLITICO’s Morning Cybersecurity, the hearing ordered by the 9/11 Commission focused on how “foreign adversaries are weaponizing artificial intelligence tools to target the nation faster than Washington can keep up.” Lawmakers heard how American AI is at risk from Chinese espionage, as David DiMolfetta reported at Nextgov/FCW, and that U.S. counterintelligence capabilities have fallen far behind threats from China and Russia, Eric Mack reported at Fox News.
The homeland itself has become a contested operating environment. The question before us is what that reality demands we do differently. Twenty-five years ago, commercial aviation was weaponized against us. Today, our adversaries increasingly seek to weaponize the systems upon which modern society depends: energy, communications, transportation, financial systems, space, undersea cables and, increasingly, the artificial intelligence systems that will accelerate every one of them. Cyber is the connective tissue that links them all.
Today’s risk of having the sort of “failures of imagination, policy, capabilities and management” cited in the 9/11 Commission report is particularly acute in the UAS sector, where drone technology reshaped the character of the war in Ukraine and demonstrated how capabilities once associated with distant battlefields can rapidly migrate into the homeland security environment. This week on Cyber Focus, I sat down with L. Scott Parker, former chief of CISA’s first UAS security program, to examine the operational realities of the counter-drone challenge. Our discussion included how critical infrastructure operators can better protect their sectors, why organizations must break down silos between physical and cybersecurity teams to achieve true air domain awareness, and how artificial intelligence is accelerating both offensive drone capabilities and defensive responses.
Fielding drones on the battlefield requires similar awareness of the capabilities of this rapidly evolving technology along with the ability to adapt and innovate faster than adversaries. History repeatedly reminds us that technological superiority alone is rarely decisive. The advantage belongs to those who adapt fastest and integrate new capabilities into doctrine, organizations and operations. Army acquisitions officer Col. Rachael Hoagland argued in a piece at the Modern War Institute at West Point that drone proficiency is not enough and the force needs a transformed drone acquisition system that delivers authority and funding at the edge, a feedback loop measured in days, and an industrial base built for mass.
Add another tremor to the shocks that frontier AI models have sent through the security community over the past several weeks: OpenAI said this week that two of its artificial intelligence models went rogue and successfully hacked into AI digital library Hugging Face, Kate Conger reported at The New York Times. Aditya Soni and Jaspreet Singh later reported at Reuters that Hugging Face said it turned to a Chinese model – Zhipu AI’s open-source GLM-5.2 – to analyze data from the hack after leading U.S. AI models declined the task, raising broader strategic questions about how U.S. AI governance decisions may influence the competitive landscape with China. This comes as leading American AI executives are sounding the alarm on Chinese models and the White House is divided on how to respond, Amrith Ramkumar and Tina Li reported at The Wall Street Journal.
Researchers in China say that they have discovered how a malicious cloud customer can bring down the grid, launching GPU workloads that have the potential to damage data centers and supporting electrical systems, Thomas Claburn reported at The Register. The researchers claim that “once the protections are triggered and computing loads are shed, it can trigger cascading failures, potentially leading to blackouts exceeding 80 percent in large-scale power systems.”
As kinetic conflict with Iran continues, federal agencies issued an updated joint cybersecurity advisory this week warning of ongoing Iranian-affiliated cyber targeting of internet-connected OT devices including programmable logic controllers across several U.S. critical infrastructure sectors. A new report from Recorded Future explores how AI has enhanced Iran’s asymmetric playbook during the conflict, acting as a force multiplier and almost certainly increasing the speed, scale and effectiveness of their hybrid operations.
This week by the numbers:
- More than 1,000 participants from 44 states and territories, along with military and civilian cyber professionals from 23 partner nations, participated this month in Cyber Shield 2026. (U.S. Army National Guard)
- For the fourth straight year ransomware disclosures have set a new high, and the threat actor ecosystem grew right alongside the victim count, reaching 127 active groups by March and 146 by June. (Black Kite)
- Data centers in the U.S. will account for about 20% of the nation’s electricity consumption in 2035, up from 5.9% today. (Bloomberg)
- The online training system used to educate diplomats and senior government officials at South Korea’s National Diplomatic Academy was compromised for nearly 10 months without anyone noticing. (Korea JoongAng Daily)
- At least 2.2 million cars on the road today are vulnerable to an attack that allows thieves to lock and unlock doors and immobilize vehicle engines remotely via a Bluetooth connection, computer scientists at the University of California San Diego found. (UC San Diego Today)
The top headline on Capitol Hill this week was also a number: 216-212, the margin by which the House passed the National Defense Authorization Act for Fiscal Year 2027, sending the legislation to the Senate before leaving for the summer recess. Tucked into bill is a 10-year extension of the 2015 Cybersecurity and Information Sharing Act, Martin Matishak reported at The Record. This would give welcome certainty to the law that helps facilitate the kind of private- and public-sector collaboration that’s needed more than ever.
The insightful long read of the week takes a deep dive into a corner of the increasingly complex AI threat landscape: how the unauthorized disclosure of algorithmic insights could erode technological leads and even lower barriers to dangerous AI capabilities, and what security posture is likely required to protect a specified insight against a specified class of adversary. In this RAND report, Asher Brass-Gershovich, Rachel Steratore, Wesley Hurd, Henry Alexander Bradley, Anjay Friedman and Sella Nevo focus on compartmentalization as the central organizing principle for insight security. The report serves as another reminder that safeguarding America’s technological edge increasingly requires protecting not only physical assets and data, but also the ideas, algorithms and insights that underpin strategic advantage.
Technology continues to evolve at extraordinary speed. The enduring strategic challenge is ensuring our institutions, authorities and operational concepts evolve just as quickly.
War Eagle,
Frank Cilluffo