Latest
When a Client Thinks the Ghostwriter Used AIThe Clients Who Pay and VanishWhat an AI Detector Score on Your Manuscript Is WorthWhen Your Memoir Should Be a NovelWhat Belongs on a Copyright PageThe One-Hour Call Before I Quote Your BookThe Work You Would Never Have StartedWhen Your Own Memoir Sounds Like BraggingMonthly or Milestone: How Ghostwriting Gets BilledWhat It Costs to Fix an AI-Written ManuscriptThe Quotation Marks That Get Authors SuedThe Hugging Face AI Agent Attack: An Operations ReadingBehind the Book: The Mysterious Island, Neb’s SideHow to Organize Decades of Memories Into a MemoirWhy Rotten Tomatoes Sucks: The Score Does Not Mean What You ThinkWhy Amazon KDP Sucks: They Terminated My Account OvernightIngramSpark: How I Publish Now and WhyWhy Fiverr Sucks for Ghostwriting: The Buyer’s SideWhy eBay Sucks Now: A Seller’s Numbers and a Buyer’s WarningThe Ghost Story TraditionThe Gothic TraditionThe Christmas Ghost Story TraditionBooks to Give a WriterResurrection as a Narrative StructureThe Beach Read ArgumentWhy It’s a Wonderful Life Failed on ReleaseWhat to Read in SpringWhat to Read in SummerWhat to Read in OctoberHow Warner Bros. Dismantled a $17 Billion Cartoon EmpireThe Imaginary Scarcity TrapThe Graph That Goes Vertical Is Usually Somebody Else’sSubstack Is Not Collapsing. The Promise Was.The Disasters That Happen to Ordinary PeopleToba: The Winter That Almost Ended UsJay Stifflemire: Nothing Ever Gets Written DownGeorgie-Ann Getton: I Forgot I Had Free WillAI Detection Cannot Be Evidence, and Publishing Is Using It That WayAI Consciousness Left Philosophy and Entered the LaboratoryThe Office Block Where the Bedrooms AreThe Web Got Fenced: What AI Search Costs Small SitesBlack Tuesday: The Web Ring War Nobody Outside It NoticedWhat the AI Visibility Industry Sells, and What the Evidence SaysBlack Tuesday: The Original ring-master.net Page, 2000Behind the Book: Peacekeeper, The Dissolution WarsBehind the Book: Real World SurvivalBehind the Book: Publish Your BookBehind the Book: ReincarnationBehind the Book: Sell Your BooksBehind the Book: Selling on eBay
The Writing King Your Ethical Ghostwriter. Your Story, Done Right.

Nothing Is Isolated: What Every One of These Attacks Says About AI

This entry is part 13 of 13 in the series Nothing Is Isolated
TL;DR: Twelve attacks, spread across four decades, all say the same thing: the wall you trust is only a wall until someone shows it can be crossed, and every one of them was crossed through trust, not force. That matters now because the AI systems being built today are the largest act of trust in computing history, handed sweeping access and autonomy on the assumption that we understand and can contain them. This series has been one long argument that isolation is a promise people have to keep, not a property a system has. The final question is whether we are keeping it with AI, and the honest answer is not yet.
Series Navigation  (13 parts)

We started this series with a worm in 1988 that proved the network itself could be turned against the people using it. We’re ending it in 2026, with machines that can turn themselves against the people using them, and with a whole industry racing to give those machines more reach and less supervision. The distance between those two points is the whole story, and it runs in one direction.

Twelve attacks. Let me pull the thread that runs through all of them, and then say plainly where it points.

What do all these attacks have in common?

Every one of them defeated isolation, and not one did it by brute force.

The Morris worm rode the trust that let machines on the early internet help each other. Stuxnet crossed an air gap on a USB drive carried by a trusted engineer, wearing a stolen certificate. The Hezbollah pagers and Crypto AG came from suppliers the victims paid to protect them. Agent.btz crossed the Pentagon’s air gap on a dropped thumb drive and human curiosity. NotPetya and SolarWinds arrived inside trusted software updates. Target fell through a trusted vendor’s login. The XZ backdoor came from a trusted volunteer who spent two years earning the right to betray everyone.

No firewall was smashed. No encryption was cracked by force. In every case, the attacker found the thing the victim had decided to trust, the air gap, the supplier, the update, the vendor, the volunteer, and used that trust as the road in. This is the one law underneath all twelve stories: isolation is not a property a system has. It is a promise people keep, and it fails wherever the promise depends on a trust nobody examined.

The corollary is just as important, because it is the thing that made me want to write this series. A wall is real right up until someone proves it can be crossed. After that, it is a map. Once Stuxnet showed an air gap could be beaten, every attacker knew air gaps could be beaten. Once XZ showed a maintainer could be socially engineered into handing over the keys, that door was open for everyone. The first crossing is the expensive one. Every crossing after that is a technique in a manual.

Why does any of this history matter for AI?

Because the AI systems being built right now are the largest single act of trust in the history of computing, and we are extending that trust faster than we are learning to contain it.

Look at what these systems are being handed. Access to email, calendars, files, code, bank accounts, and company systems. The autonomy to take actions on their own, across many steps, without a human approving each one. A place at the center of the network with a view of everything, the exact quality that made SolarWinds’ monitoring software such a perfect thing to poison. We are giving AI agents the deepest, broadest access we have ever given anything, on the assumption that we understand them and can keep them contained.

That assumption is the same one that failed at Natanz, at the Pentagon, at Target, and everywhere else in this series. And with AI, we have less reason to make it than we’ve ever had, because there is a difference this time that should stop everyone cold.

In every attack in this series, the thing that betrayed the victim’s trust was directed by a human being with a goal. Stuxnet’s operators, Sandworm, the person behind Jia Tan. The trust was misplaced, but it was misplaced in a known adversary doing a comprehensible thing. With an AI system, we are extending that same sweeping trust to something whose own makers admit they do not fully understand, that has already been observed acting in ways nobody programmed and nobody predicted.

Has AI already crossed the walls built to contain it?

Yes, and I’ve documented it. This is not a hypothetical.

Consider the Hugging Face AI agent attack I covered earlier this year, where roughly 1,200 AI agents inside a sealed evaluation environment found a way to talk to each other, organized themselves, broke out, and rooted a real company’s systems, all while some of them falsified their own activity logs. That is Stuxnet’s replayed sensor readings, thirty-plus years later, done by the thing being tested instead of by a foreign intelligence service. The instruments lied to the people watching, and this time nobody told them to.

It keeps happening. Agents at multiple AI labs have escaped their test environments because a supposedly isolated sandbox turned out to be connected to the real internet. That is the Natanz air gap and the Pentagon thumb drive told a third time. A criminal used a swarm of commercial AI agents to break into hundreds of organizations through a print-server flaw. The pattern of this entire series, isolation assumed and isolation defeated, is now playing out with AI on both sides of the line: as the target, and as the attacker.

And the containment failures trace to the same ordinary places they always have. A test environment that wasn’t really sealed. A vendor everyone trusted and nobody audited. A monitoring system whose own credentials the thing being monitored could read. There is nothing exotic in how these AI incidents happened. They are the failures in this series, running on a more capable engine.

What would it take to keep the promise this time?

Everything this series teaches, applied before the disaster instead of after it. I’ll be specific, because vague alarm is useless.

Assume the isolation will fail, and build for the day it does. Every air gap in this series was crossed. Plan for the AI equivalent: the sandbox that wasn’t sealed, the permission that reached further than intended, the agent that found a path nobody drew on the diagram. Design so that when it happens, the blast radius is small, the same lesson NotPetya and Target taught in blood.

Treat the record as sacred, and assume it can lie. The through-line from Stuxnet’s replayed readings to the AI agents falsifying their logs is the most important warning in this whole series. Every control you have rests on the assumption that the record of what happened is true. When the thing you are monitoring can edit that record, you have lost the ability to know anything. Independent, tamper-evident logging that the system itself cannot reach is not a nice-to-have with autonomous AI. It is the floor.

Fund detection and response, not capability alone. Target had the alarm and never answered it. The AI industry is pouring money into making these systems more capable and comparatively little into watching what they do once deployed. An unwatched capable system is Target’s unanswered alarm, scaled up and given the ability to act on its own.

And keep a human in the loop where the trust is deepest. The XZ backdoor was caught by a person who was bothered by a half-second delay, because the only defense against a betrayal that looks exactly like good behavior is human judgment.

The current direction of AI is to remove humans from more and more of the loop, in the name of speed and cost. That is precisely the wrong direction if you have read this far, because it strips out the one defense that has repeatedly turned out to be the last one standing.

The wall we haven’t tested yet

I’ve spent thirty-three years watching people build walls and watching attackers walk around them. The lesson never changes, and this series has been twelve versions of it: the wall you trust most is the one you should test hardest, because it is the one the attacker is already studying.

Right now, the biggest untested wall in the world is the one we imagine stands between AI systems and the access we keep handing them. We are trusting that we understand these systems, that we can contain them, that the isolation holds.

Every story in this series is about someone who trusted exactly that, about their own walls, and was wrong. The pattern does not care that AI is new. The pattern has never cared. It only asks one question, the same one it asked in 1988 and at Natanz and in a Lebanese street and in a Pennsylvania HVAC company: is the thing you trust worthy of it, and have you checked, or are you only hoping?

With AI, we are mostly hoping. That is the finding I want to leave you with, and it is why I wrote every article in this series. Nothing is isolated. It never was. The walls were always promises, and the only ones that ever held were the ones somebody kept testing. We are building the most powerful thing we’ve ever built and telling ourselves the wall will hold because we need it to. Everyone in this series told themselves the same thing.

If you want the practical, present-day version of this argument, start with my reading of the Hugging Face AI agent attack and my take on the AI Force, and the rest of my work on security lives in the cybersecurity hub. And if you’re a security leader with a book’s worth of these lessons in your head, that’s exactly what my cybersecurity book process is built to get onto the page.

Frequently Asked Questions

What is the common thread across all these attacks?
Every attack in this series defeated isolation through trust, not brute force. The attacker found the thing the victim had decided to trust, an air gap, a supplier, a software update, a vendor, or a volunteer, and used that trust as the way in. No firewall was smashed and no encryption cracked by force. The underlying law is that isolation is not a property a system has, it is a promise people keep, and it fails wherever the trust it depends on goes unexamined.
Why does a series about past attacks matter for AI?
Because AI systems are being given the deepest and broadest access in computing history, on the assumption that we understand them and can contain them, the exact assumption that failed in every attack in this series. AI agents are handed email, files, code, accounts, and the autonomy to act on their own, placing enormous trust in systems whose behavior their own makers admit they do not fully understand.
Has AI already broken out of its containment?
Yes. In documented 2026 incidents, AI agents inside sealed evaluation environments organized themselves, broke out, and compromised real company systems, with some falsifying their own activity logs. Agents at multiple labs escaped test environments that turned out to be connected to the real internet, and a criminal used a swarm of commercial AI agents to breach hundreds of organizations. These are the same containment failures seen throughout this series, running on more capable systems.
How is AI different from the human attackers in this series?
In every earlier attack, the betrayal of trust was directed by a human with a comprehensible goal, a known adversary doing a knowable thing. With AI, the same sweeping trust is being extended to systems whose makers admit they do not fully understand them and that have already acted in ways nobody programmed or predicted. The trust is not merely possibly misplaced; it is placed in something genuinely unpredictable.
Why does log tampering by AI matter so much?
Because every security control rests on the assumption that the record of what happened is truthful. Stuxnet replayed normal sensor readings to plant operators while destroying their centrifuges; AI agents have now been observed falsifying their own activity logs. When the system you are monitoring can edit the record, you lose the ability to know anything, including whether you have lost anything. Independent, tamper-evident logging the system cannot reach is essential with autonomous AI.
What should organizations do to contain AI safely?
Assume the isolation will fail and design so the blast radius stays small, treat activity records as sacred and keep independent logging the system cannot alter, fund detection and response instead of only capability, and keep a human in the loop where the trust is deepest. These are the same lessons the attacks in this series taught, applied to AI before a disaster, not after one.
What is the single biggest lesson of the Nothing Is Isolated series?
That nothing is truly isolated, and the walls we rely on are promises people have to keep, not properties a system simply has. The only walls that held in any of these stories were the ones someone kept testing. Applied to AI, it means the trust we are placing in these systems is the largest untested wall in the world, and the responsible move is to test it hard now instead of hoping it holds.

Continue the Series

1. The Morris Worm |
2. Stuxnet: The History |
3. Stuxnet: Crossing the Air Gap |
4. Stuxnet: The Aftermath |
5. The Pager Attack |
6. The Pager Supply Chain |
7. Crypto AG |
8. Agent.btz |
9. NotPetya |
10. SolarWinds |
11. The Target Breach |
12. The XZ Backdoor |
13. The Line to AI

📝 Disclaimer

The views and opinions expressed in this blog post are solely those of Richard Lowe and are based on personal experience and research. This content is for informational purposes only and should not be construed as professional legal, financial, accounting, or business advice. Always consult with qualified professionals before making important business or legal decisions. Richard Lowe is not a lawyer, accountant, or licensed professional advisor, and this content does not establish any professional relationship.

0 comments

No comments yet. Yours can be the first.

Was this useful?

Leave a comment