AI Security

Collective defense needs a unit of exchange

A hundred companies just signed a letter asking defenders to share "tools, practical knowledge, and verified fixes." The chart that explains why is on Epoch AI. What is missing from both is the artifact that would make sharing work.

SR
Setu Research
August 27, 2026·8 min read

Collective defense needs a unit of exchange

A hundred companies just asked defenders to share "verified fixes." Verified by whom, and checkable how? Until that question has an answer, collective defense is a mailing list.

Two documents landed this quarter that belong side by side.

The first is a chart. Epoch AI's CVE explorer tracks every vulnerability published to cve.org since 2020, and in April 2026 the trend line breaks. The Claude Mythos preview on April 7 coincided with what Epoch calls a large jump in new vulnerability reports; by May 22, Anthropic said the model had been used to identify more than ten thousand high- or critical-severity bugs. OpenAI followed within weeks with cyber-capable models of its own. Epoch is careful about the caveats — publication dates are not discovery dates, and CNA reporting practices are noisy — but the shape of the curve is not subtle. Vulnerability discovery has been industrialized.

The second is an open letter, published this week and signed by more than a hundred companies — OpenAI, Anthropic, Google, Microsoft, AWS, Cisco, Cloudflare, CrowdStrike, Okta, Fortinet among them. Its warning is blunt: in the coming months, AI-enabled attacks will become far more widespread and sophisticated. Its asks are sensible: fix your highest-risk vulnerabilities, strengthen access controls, scrutinize AI-generated code. And one ask stands out, because it is the collective part of collective defense: share tools, practical knowledge, and verified fixes, so that protecting one organization helps protect many.

We think the letter is right, the chart is why, and there is a missing piece neither document names. Sharing defense knowledge requires a unit of exchange — an artifact that carries a security claim across an organizational boundary without asking the recipient to trust the sender. The attack side has had one for a decade: an IOC travels, a STIX bundle travels, a YARA rule travels. The defense side has PDFs.

Severity died first

Start with what the Epoch curve does to the way most organizations decide what to fix.

Ten thousand high-and-critical findings in six weeks, from one model, before the attackers' copies spin up. When "critical" arrives at that rate, severity stops being a filter — everything is critical, so nothing is. The letter's first ask, "address your highest-risk vulnerabilities," quietly assumes you can tell which those are. In a post-Mythos publication regime you cannot tell from the CVE record, because CVSS was scored without your network in the room, and threat intelligence structurally lags AI discovery — an AI-found bug has no KEV entry by definition. We wrote about the triage half of this problem in The job isn't fewer CVEs and mapped the CSA's response playbook in How Setu makes you Mythos-ready; the short version is that what remains scarce is context — reachability, identity paths, blast radius — and context is a graph, computed against your estate, not a feed.

That scarcity is exactly why sharing matters more now, not less. If every organization must derive "what actually matters here" locally, then the expensive artifact is no longer the vulnerability report. It is the judgment: this finding was real here, this one was rule noise, this fix worked, this playbook deflected forty alerts a day. Multiply the flood by every under-resourced security team the letter is worried about, and the only way the math closes is if judgment travels.

What "verified" has to mean

Here is the test any shared defense artifact has to pass: the recipient can check it without trusting the sender, and can see what would have to be true for it to be wrong.

That second clause is the one everyone skips. A shared "verified fix" that arrives as a conclusion — trust us, we checked — is just vendor marketing with extra steps. For the artifact to be worth acting on at a hospital or a water utility with a two-person security team, it needs to carry:

  • The evidence. Not a summary of the evidence. The events, the entities, the technique chain — enough that the claim could be re-derived.
  • The counter-evidence. What cut against the conclusion, stated plainly. A finding that ships with "the same rule fired 61,000 times fleet-wide that week — we concluded targeting anyway, here's why" is worth ten findings that ship as verdicts. Certainty that cannot show its dissent is not verification; it is confidence theater.
  • The omissions. What was not examined, declared rather than silent. Every triage pipeline drops evidence — storms get collapsed, oversized clusters get trimmed. An artifact that says "this represents 25 of 61,204 observed events, here is what the cuts removed" can be audited. One that does not is indistinguishable from one built on 25 cherry-picked events.
  • A signature the recipient can verify offline. If checking the artifact requires calling the sender's API, it does not cross sovereignty boundaries — and the organizations the letter worries about most are exactly the ones that cannot ship telemetry to a frontier lab to find out.
  • A path to action. A verified fix that cannot be loaded into the recipient's SOAR, ticketing, or patch workflow is a nice read.

Notice what this list does not require: that both parties run the same product, use the same model, or send their data anywhere. That is the point. The letter's signatories include frontier labs whose defensive models are, reasonably, gated behind trusted-access tiers. Advanced capability is concentrating in a handful of vendors and their partners, while the letter's own premise is that the attacks land everywhere. Artifacts are the equalizer. API access does not federate; evidence does.

What we ship today, and what we do not

We build for this shape because our customers forced us to. Regulated tenants who run everything on-premises, on their own models, wanted to know why a finding surfaced, what argued against it, and how to prove diligence to a board or regulator later. Those constraints produced primitives that happen to be the unit of exchange the letter needs:

  • Evidence packs — signed, deterministic bundles for a single dispatch or finding: Ed25519 over a canonical manifest, per-artifact hashes, reproducible content digests, and unreachable sources recorded as declared omissions rather than silent gaps. Verification is an offline command against a published public key. No Setu account required.
  • Dispatches that argue with themselves. Every dispatch narrative now carries a "What cuts against this" section — named alternative hypotheses (fleet-wide rule noise, activity that ceased, no escalation), measured from the same estate the thesis came from — plus "N shown of M observed" evidence-count disclosure. The counter-evidence never changes a score; it changes whether the reader should believe one.
  • Shareable, redacted narratives. Dispatch share links with tenant-scoped redaction, so a story can travel to a partner, an MSSP, or a regulator without the entity names traveling with it.
  • Prescriptions as portable playbooks. Recurring operations compile into playbooks that export to Cortex XSOAR, Tines, and Jira — the "verified fix" in the only format that survives contact with another organization's tooling: theirs.

And what we do not claim: there is no cross-organization federation network behind this today. Setu tenants do not automatically learn from each other's verified fixes, and neither does anyone else's customer base, whatever the marketing says — the privacy and consent problems are real and unsolved at industry scale. What exists is the artifact layer those networks would need. If the letter's signatories want a concrete project worthy of a hundred logos, standardizing the verifiable defense artifact — the STIX of fixes, with counter-evidence and omissions as first-class fields — would do more for the hospitals and water utilities in their opening paragraph than any amount of shared urgency.

The letter says the status quo will not hold, and it is right. The chart says why: discovery no longer waits for humans, so neither can judgment. Collective defense will not be built out of goodwill and webinars. It will be built out of artifacts that strangers can check. We know because the strangers who check ours are auditors, and they are not a trusting audience.

If you want to see what a signed, self-disputing security finding looks like against your own estate — counter-evidence, omissions, and all — bring us a noisy week of alerts and we will show you, including the dispatches where the honest answer is "probably rule noise."

SR

Setu Research

Setu Security Research