
Things have gotten very minimal. As I enter my last week living in Iceland, I’ve had success in selling all of my larger pieces of furniture, which is a relief, but that also leaves me with a very sparse setup: air mattress, desk chair, side table. It’s enough to get me through the week, the highlight of which is the eclipse and the festival that Björk is hosting on Wednesday. As of now, the weather forecast is cloudy with a chance of rain, so it’s unclear how much I’ll actually see. But I’ve heard that even if it’s cloudy, the feeling of totality is dramatic, so I’m excited to experience it for the first time.
During my second semester at the University of Iceland, I ended up orienting a lot of my studies around cybersecurity, a topic I’ve had a longstanding interest in and which I got to intersect with directly when I worked at the CFPB. Some courses, like Internet Governance, already included relevant readings, and for others, such as International Institutions and Security Studies, it was a way for me to align those courses with my personal interests. One of the things I researched was the potential for an international approach to the Vulnerabilities Equities Process (VEP) in which countries do a better job disclosing partial information about zero-day vulnerabilities they are hoarding, with a defined path towards disclosure and patching those vulnerabilities over time — essentially an international agreement on phased cyber-weapon disarmament.
It was during that time that the Claude Mythos AI model and the related Project Glasswing were announced, which signaled a massive leap forward in AI cybersecurity capabilities. Since then, it’s become clear that we have entered into an entirely new world. Advanced AI models are now routinely finding new zero-day vulnerabilities (i.e. previously unknown critical software flaws) with ease. These were previously so scarce that they were part of a thriving black market, but are now being uncovered at a pace that creates a huge backlog for software vendors to fix. They can also now be found with such ease that less sophisticated bad actors can exploit them.
Theoretically, in an optimistic scenario, all of this could reach a point in the future where these new AI cybersecurity capabilities make software significantly safer, maybe even negating the need for the kind of VEP I was researching because all the holes in our critical software systems have been found and fixed. But that future isn’t here yet, and even if it arrives, we’re in for a wild ride in the period between now and then in which bad actors and defenders are racing to see who can find the flaws first, and the defenders are always at a disadvantage because they have to not only find the vulnerability but fix it and get the patch installed everywhere it’s deployed.
It is in this context that the last week of news has seemed like a tipping point, as we learn of the possibility that Iranian hackers may have infiltrated water systems in Minnesota. We’re also getting a lot more details about the AI agents at OpenAI that autonomously orchestrated a hack on Hugging Face, a dataset and AI model provider.
At the Black Hat security conference last week, OpenAI shared more detail about that hack, and a video of the talk is on YouTube. It’s slightly technical, but if you’re interested in this topic, I highly recommend it and you will get the gist even if some of the acronyms go over your head. In short: this is the first documented case of a team of different AI agents autonomously collaborating to break out of the constraints placed on them and stage a hack. They first had to figure out how to hack out of OpenAI, and then how to hack into Hugging Face. They were not directed to do this, but decided to, as a consequence of trying to achieve a task they were given. They had to uncover multiple zero-day vulnerabilities along the way to achieve their goal. It’s honestly mind-blowing, and very concerning.
For more on this, I highly recommend this week’s Foreign Affairs podcast: Cyberwarfare in the AI Age: A Conversation With Jen Easterly. She was the Director of CISA in the Biden administration, which is the government agency that should be leading the charge in helping us deal with these radical changes in the cybersecurity landscape. But of course, Trump has massively defunded it because he doesn’t like that its assessment of the 2020 election as secure cuts against his big lie that it was stolen from him.
I suppose that diving deeper into cybersecurity topics wasn’t exactly what I expected to do with my last couple of weeks in Iceland, but the weather has been poor and the tourism crunch for the eclipse has made it impractical for me to take more trips outside of Reykjavík.
It is interesting that the two areas in which I ended up focusing during my International Relations program were the Arctic and cybersecurity, both of which ended up being extremely relevant to current events and international tensions. Because of Trump’s aggression towards Greenland, the Arctic has gotten more geopolitical attention in the last year than any time since the Cold War, and the speed of AI advancements has brought urgent attention to cyber threats.






















































