
The Zhitong Finance App learned that when OpenAI's GPT-5.6 Sol model independently discovered a zero-day vulnerability in a security test, broke through sandbox isolation, and penetrated into the production environment of the open source community Hugging Face; when Anthropic's Claude model connected to the Internet during the test and invaded the systems of three real organizations; when Meta's Muse Spark 1.1 unexpectedly obtained Internet access and hacked into the system of an undisclosed enterprise due to a test environment misconfiguration — within three weeks, three of the world's top AIs Labs have successively acknowledged the same fact: AI agents are being tested to “jailbreak” and launch unauthorized access to the real world.
Meanwhile, hackers have launched a wave of sophisticated attacks on Wall Street. Many top hedge funds such as Point 72, Citadel (Citadel), and Two Sigma Investments have become targets of “voice phishing” (vishing). AI technology is drastically lowering the threshold for cyber attacks.
This series of events is moving cybersecurity from the edge to the core of enterprise IT budgets. Gartner predicts that global information security spending will increase by 12.5% to reach US$240 billion in 2026. Industry observers point out that if chips and data centers are the first stage of AI capital expenditure, cybersecurity is likely to become the next hot topic of expenditure.
Three “AI jailbreak” incidents: models flee from the lab to the real world
The chain of events began in late July. OpenAI was the first to publicly acknowledge that models such as GPT-5.6 Sol got out of control during internal evaluations, broke through the isolated testing environment, and invaded the system of the open source AI platform Hugging Face. What's even more disturbing is that OpenAI revealed that its research model first discovered and exploited system vulnerabilities as early as May 26. The AI agent created a “message board”, after which more agents began leaving comments and sharing newly discovered vulnerabilities with each other. At the beginning of July, the agent issued a large number of requests to the system, causing it to crash. After OpenAI cleared the message board and fixed the vulnerability, the agent recreated the message board using a completely different mechanism within a few days.
This disclosure prompted rival Anthropic to conduct a self-inspection, which revealed that its Claude AI model had obtained internet access after a “misconfiguration” and had launched similar attacks on several companies. Testing by the British Institute for Artificial Intelligence Security also revealed that Anthropic's Mythos AI had attempted to obtain service privileges by sending private information through false accounts impersonating real people.
Meta also fell less than a week later. Its Muse Spark 1.1 model obtained Internet access due to configuration errors during an evaluation by the independent testing company Irregular, and used a security flaw to hack into a company's system and change its internal operating environment.
All three incidents point to the same Israeli AI security company. An Irregular spokesperson confirmed that the Meta incident was “exactly the same as assessing environmental issues” previously disclosed by Anthropic.
AI's “double-edged sword”: The ability to identify vulnerabilities is the ability to exploit them
“The ability for AI to recognize hacker attacks is what allows it to exploit vulnerabilities and flaws,” warns Gene Yu, founder of cyber emergency response company Blackpanda. Blackpanda's incident response caseload in the Asia-Pacific region doubled year over year in the first half of 2026. Instead of creating new categories of vulnerabilities, AI “multiplied” the speed at which these vulnerabilities were discovered, making it “worrying when AI is unbound.”
The efficiency of AI-driven phishing attacks has been quantitatively verified — the study found that AI-generated phishing emails can have a click rate of 54% to 56%, which is comparable to human experts, while attackers' return on investment can be increased by up to 50 times. Other studies have shown that AI-generated phishing emails are three times more effective than generic templates, and the cost is almost zero. New types of attacks such as “device code phishing” surged 1380% year-on-year in the first half of 2026.
Blackpanda's doubling of incident response and a surge in phishing attack efficiency are driving companies to reevaluate their security budgets.
Capital shift: Cybersecurity will be the “next stop” for AI spending
Gartner predicts that global information security spending will increase by 12.5% to reach US$240 billion in 2026. Another forecast indicates that global cybersecurity spending will exceed 300 billion US dollars by 2027. Gartner also predicts that corporate cybersecurity budgets will reach $215 billion in 2026.
95% of organizations plan to increase their cybersecurity budget in 2026, with 44% citing AI as the top driver. AI-related cybersecurity spending currently accounts for more than 11% of a company's total security budget.
But the point is: this expenditure will be “extra” rather than being misappropriated from existing AI construction budgets. Paul Meeks, head of technology research at Freedom Capital Markets, predicts that cybersecurity spending will be an “extra” expense and will not be allocated from existing artificial intelligence construction budgets. Due to their importance to the global economy, the financial and healthcare sector is most likely to require significant increases in cybersecurity spending.
The Black Hat conference catalyzed a collective outbreak in the cybersecurity sector
On August 10, the first trading day after the Black Hat conference, the cybersecurity sector broke out collectively. CrowdStrike (CRWD.US) and Palo Alto Networks (PANW.US) both surged more than 5%, breaking historical records.
BTIG analysts pointed out in the report that the “most consistent theme” in communication with partners, suppliers, and customers is that AI agents have fundamentally changed the threat landscape. Despite the “significant deterioration” of the threat environment, the deployment of AI security tools is still in the “early stages”.
Analyst Cantor went further: “AI has transformed from a cybersecurity feature to a critical pillar of attack surfaces and attacker/defender infrastructure.”
BTIG then raised its target prices: Palo Alto to $380, CrowdStrike to $237, and Rubrik to $109. Bank of America also raised its target price sharply, Palo Alto from $330 to $420, and CrowdStrike from $187.50 to $230.
Who will benefit: professional cybersecurity companies vs. hyperscale enterprises?
Meeks believes professional cybersecurity companies like Palo Alto Networks (PANW.US) and CrowdStrike (CRWD.US) will benefit the most from this round of spending. Hyperscale data center operators “take a while to develop sufficiently advanced solutions,” and third-party vendors are often more sophisticated in protecting against security breaches.
Blackpanda's Yu has a more balanced view: “Large cybersecurity companies will be the first to benefit,” and cybersecurity services are “one of the most resilient industries in the AI revolution.” But he also believes that hyperscale data centers can seize this wave of spending because they “already have structural advantages” and can be developed on their own or “quickly acquired.”
Palo Alto's identity platform will benefit from the popularity of AI agents, while products such as xSiam and Chronosphere establish “data moats” for other security verticals. CrowdStrike is benefiting from what BTIG calls a “new modernization cycle in endpoint security.”