Chris Krebs has seen his share of digital threats. The former director of the Cybersecurity and Infrastructure Security Agency watched nation-state actors probe critical systems. He steered the country through election security battles. Now he finds the latest warnings from intelligence partners particularly striking.
“It’s pretty alarming,” Krebs told CBS News in a recent interview. He was reacting to a stark assessment from the Five Eyes intelligence alliance. The group, which includes agencies from the U.S., U.K., Australia, Canada and New Zealand, cautioned that advanced artificial intelligence models could soon overwhelm government and business cybersecurity setups. And that shift might come in a matter of months. CBS News.
The pace has accelerated. Just months ago, Anthropic released a model that changed the conversation. Krebs noted the whirlwind of progress. Businesses and agencies suddenly face a flood of potential weaknesses. AI can scan code, spot flaws and generate exploits at speeds no human team can match. One vulnerability discovered. Then another. Then dozens more. Before patches even roll out.
But Krebs doesn’t stop at the warning. He points to concrete steps. The Five Eyes alert outlines actions organizations can take now. Make systems harder to breach. Build agility into operations. Prepare for what he calls a vulnerability tsunami. Companies that act will fare better. Those that don’t risk major operational and financial crises. “You will not be able in the very near future to prevent escalation,” he said.
This isn’t abstract. Jamie Dimon, chief executive of JPMorgan Chase, has voiced similar worries. He highlighted risks tied to models like those from Anthropic. The Trump administration responded in part with export controls aimed at certain AI technologies. Yet Krebs argues more is needed. Congress should pass legislation setting clear standards for AI risks. Without it, the private sector operates in a gray area. CBS News transcript from July 19, 2026.
The numbers tell a story too. Eighty-five percent of cybersecurity professionals link the rise in attacks last year to generative AI tools in the hands of adversaries. That figure comes from industry surveys. Bad actors now automate phishing, craft convincing deepfakes and chain exploits with little effort. Defenders scramble to keep up. The gap widens daily.
Krebs speaks from experience. He led CISA from its early days. He built programs to protect elections and infrastructure. After his dismissal in 2020, he co-founded Krebs Stamos Group with Alex Stamos. The firm advises on foreign threats and crisis response. Their first major job involved the SolarWinds breach. That incident showed how one compromised supplier can ripple across government and industry.
Today Krebs serves as a CBS News contributor. He appears regularly to break down complex risks. His message stays consistent. Cyber defense demands partnership. Federal agencies must share intelligence faster with states and companies. CISA needs resources and staff. Recent cuts worry him. China-linked campaigns like Salt Typhoon, Volt Typhoon and Flax Typhoon demonstrate the persistent danger. These operations target telecoms, critical infrastructure and data networks.
And the AI angle adds urgency. Models improve so quickly that yesterday’s defenses look quaint. An international alliance rarely issues such direct language. When it does, leaders listen. Or they should. Krebs calls the Five Eyes paper a signal for businesses. Take the risk of AI in malicious hands seriously. Invest in detection tools. Train teams. Update architectures.
Some progress shows. New AI-focused cybersecurity startups launch with venture funding. They promise tools to counter the very threats advanced models create. Yet the offense often holds the advantage. Attackers need only one success. Defenders must win every time.
Look at elections. Krebs has warned for years about influence operations. In 2020, China sought to sway public opinion through media and journalists. Not direct hacking of voting systems, he emphasizes. But the tactics evolve. AI can generate targeted disinformation at scale. Deepfake videos. Personalized messages. Automated bot networks. The “steady drumbeat” he once described erodes trust over time. No single catastrophic event. Just gradual decay in confidence.
Recent comments from Krebs on Face the Nation reinforce the point. He expressed a “hard time believing” certain intelligence never reached top levels. Countless memos circulated. An op-ed he wrote in September 2020 laid out threats from multiple actors, including China. The pattern continues. Beijing’s counterintelligence challenge remains serious. Krebs wants focus there. What are they doing today? How do we counter it with modern tools?
The political backdrop complicates matters. A 2025 executive order targeted Krebs and others over past actions. It revoked clearances and ordered reviews. Critics called it retribution tied to his 2020 election statements. Supporters see it as accountability. Either way, the expertise Krebs offers on AI and cyber issues hasn’t faded. Industry events still feature him. The RSA Conference has hosted his talks on cybersecurity in the AI era.
Financial institutions feel the pressure most acutely. An avalanche of vulnerabilities, as Krebs put it, could hit balance sheets hard. Banks already spend billions on defense. AI raises the bill. And the sophistication. One model might identify zero-days in legacy systems. Another could automate lateral movement once inside. The combination proves devastating.
So what comes next? Krebs advocates practical resilience. Patch quickly. Segment networks. Test assumptions regularly. Collaborate across borders, since the Five Eyes warning itself shows the value of alliances. The U.S. can’t solve this alone. Neither can any single company.
New reporting echoes the concern. A recent piece examined how AI agents might soon handle full attack chains with minimal human input. Defenders race to deploy similar agents for protection. The contest intensifies. And the timeline shrinks. Months, not years.
Krebs remains measured. He notes good news in the alert. Achievable steps exist. Organizations don’t need to invent new strategies from scratch. They must execute. Prioritize. Adapt faster than the threats evolve.
The former CISA chief has spent decades in this fight. From Microsoft policy roles to government service and private consulting. His track record includes calling out real risks without hype. This time feels different, though. The technology moves quicker than policy or budgets can respond. That gap creates opportunity for adversaries. From state hackers in Beijing to lone scammers abroad.
Watch for legislation. Expect more executive actions. And listen when Krebs speaks. His assessment carries weight because it rests on facts, not fear. The AI models advance. Cybersecurity must match that speed. Or risk falling behind for good.


WebProNews is an iEntry Publication