Thursday, September 3, 2026 Trend Press · Cloudflare Pages

The Trend Tribune

"All the trends that are fit to read" Morning Edition Free of Charge
TODAY'S LEAD STORY

"Making the attacker and defender fight within the same digital twin"—SafeMind's concept of adversarial co-evolution.

At Fal.Con 2026 on September 1st, CrowdStrike announced "SafeMind," a closed-loop system that pits the NVIDIA Nemotron-based attack model "Red Tempest" against the defense model "Blue Solano." The system organizes research methodologies ranging from the attack sub-agent structure of reconnaissance, intrusion, and breach in a digital twin environment, to the internal assessment that the Nemotron 3 Super-based Blue model is more accurate and 99% lower cost than the Frontier model, the industry recognition that breakout time has been reduced to actual "execution time," and the design philosophy of an open wait strategy.

"Making the attacker and defender fight within the same digital twin"—SafeMind's concept of adversarial co-evolution.
(Photo: illustrative)

"Battling Attackers and Defenders in the Same Digital Twin"—SafeMind's Concept of Adversarial Co-evolution

On September 1st, CrowdStrike announced a new AI system called "SafeMind" at the Fal.Con 2026 keynote address. NVIDIA CEO Jensen Huang took the stage and declared, "This marks the beginning of a new era in cybersecurity." This system employs an intriguing architecture that continuously pits two AI models, an attacker and a defender, against each other in a closed loop. As a journalist with a background in AI research, I want to examine this design philosophy of "adversarial co-evolution."

Two Paired Models: "Red Tempest" and "Blue Solano"

At the core of SafeMind are two specialized AI models built on NVIDIA's open model, "Nemotron." "Red Tempest" is the attacker (red team) model, designed to mimic the behavior of an AI adversary and execute sophisticated attack scenarios. "Blue Solano" is the defensive (blue team) model, responsible for deploying real-world, field-tested countermeasures used by actual defense personnel to protect corporate assets.

These two models operate within a "digital twin" (virtual replica environment) of the customer's environment, built using NVIDIA's simulation technology. Red Tempest repeatedly attacks this virtual environment, and Blue Solano learns each time, identifying vulnerabilities and continuously deploying new detection rules until no more viable attack paths remain, forming a closed feedback loop.

A Warning: "Time to Intrusion" Has Become "Execution Time"

Crucial to understanding this announcement is CrowdStrike CEO George Kurtz's recognition of industry changes. The company has annually reported on how much the "breakout time"—the time it takes for an attacker to move laterally within the network—has decreased. According to Kurtz, this time has continued to shrink year after year, from 2 minutes to 72 seconds, and then to 27 seconds.

The message Kurtz conveyed in this announcement is that the very concept of "breakout time" is becoming meaningless. In attacks using AI agents, this time is now synonymous with "runtime," and the time window for human decision-making is effectively disappearing.

Claim of "99% Lower Cost and Accuracy Exceeding Frontier Models"

The figures published by CrowdStrike and NVIDIA regarding technical performance are also noteworthy. The Blue Solano model, fine-tuned based on Nemotron 3 Super, showed higher accuracy than major frontier models (general-purpose large-scale language models) in internal evaluations, while costing 99% less.

This is a concrete example demonstrating that specialized, smaller-scale models can significantly outperform general-purpose large-scale models in terms of cost-effectiveness for specific tasks (in this case, cybersecurity threat detection and response). This achievement can be seen as an extension of the industry-wide technological trend of "specialization over generality, efficiency over scale," which is also reflected in the previously discussed NVIDIA Nemotron 3.5 Lightning and Samsung's PIM technology.

NVIDIA's Strategy: "Open Weights"

In this announcement, Mr. Huang emphasized that the Nemotron model is being offered as open weights (the trained weights are made public, allowing anyone to use and customize them). He stated that "the strength of cybersecurity lies in transparency and collective action," indicating his belief that enabling defenders to more widely adopt and customize this type of model will lead to improved overall industry defense capabilities.

As previously mentioned, Mr. Huang has repeatedly publicly spoken about the importance of open-source AI models in recent months. This collaboration with CrowdStrike can be understood as an extension of this consistent strategy.

Research Significance of the "Adversarial Co-evolutionary Loop" Method

SafeMind's design, which involves continuously pitting attack and defense models against each other in a closed environment, can be understood as an application of the concept of adversarial learning—found in machine learning research such as Generative Adversarial Networks (GANs)—to the practical field of cybersecurity.

The attacking model explores exploitable pathways through multiple sub-agents—Recon, Assault, and Compromise—while the defense model handles monitoring with Falcon sensors, verification of detection candidates, and automatic network strengthening. The extent to which this type of mutually enhancing automated learning process can sustainably improve actual defensive capabilities is an interesting research topic that should be verified through future operational performance.

What Researchers Should Keep an Eye on

SafeMind's announcement highlights a structural shift across the entire industry: the rapid acceleration of AI-driven attacks necessitates that defenders also utilize the same AI technology at the same speed. Both OpenAI's "GPT-5.6-Cyber," previously discussed, and the CrowdStrike/NVIDIA initiative are based on a shared concern: an attempt to bridge the speed gap between attack and defense.

The extent to which these automated attack and defense loops function reliably in actual corporate networks, and to what extent unintended false positives and side effects can be minimized, will become clear as more extensive real-world operational data is accumulated. We should closely monitor the future development of cybersecurity as both attackers and defenders seek a new equilibrium point based on AI-driven automation.

CrowdStrikeNVIDIAサイバーセキュリティAIエージェントAI/ML

"Sorting through 1 trillion requests daily"—Traffic management in the age of AI agents, including Hugging Face.

On September 2nd, Tel Aviv-based Huskys reached a valuation of over $100 million in a $27 million Series A round led by Blackstone. This article provides a technical explanation of Huskys's success, from its Network Edge Security Management design—which adds an agent identification layer on top of existing infrastructure such as CDNs and WAFs—as the dichotomy between "good bots and bad bots" breaks down, to its diverse customer base including TikTok, Hugging Face, Ro, LEGOLAND, and Blackstone, and the speed at which it reached Series A within six months of its founding, thanks to its founders who came from Unit 8200.

"Sorting 1 Trillion Requests Daily"—Traffic Management in the AI ​​Agent Era, Used by Hugging Face

On September 2nd, Tel Aviv-based cybersecurity firm Huskys announced the completion of a $27 million Series A funding round led by Blackstone Innovations Investments, bringing its valuation to over $100 million. It's fascinating that this company, founded just over a year ago, already has major clients like TikTok and Hugging Face. As an engineer, I want to examine the security challenges unique to the AI ​​agent era that this company is trying to solve.

The Era Where It's Becoming Indistinguishable Between "Good Bots" and "Bad Bots"

Until now, web security, specifically protecting network boundaries, operated on a relatively simple dichotomy: human users were allowed through, while malicious automated traffic (scrapers and attack bots) was blocked.

However, the rise of AI agents is disrupting this simple dichotomy. Autonomous AI agents are rapidly increasing as legitimate sources of traffic, operating applications on behalf of regular users, executing actual transactions, and generating real revenue. Because the access patterns generated by these agents are entirely different from human browser sessions, the traditional "human or bot" criterion is no longer sufficient.

An "Add-on" Approach, Not a "Replacement" Approach

Huskeys is developing a new category of security management platform called "Network Edge Security Management (NESM)." A key feature of their approach is its design philosophy: instead of replacing existing security infrastructure (CDN, WAF, cloud-native security solutions, load balancers, etc.), it adds an "agent-based AI layer" on top.

This layer analyzes traffic patterns and distinguishes between beneficial AI agents and malicious ones. The company explains that through this mechanism, they process over one trillion web requests and thousands of network configurations per day in real time across their entire customer base.

The Symbolic Significance of the "Hugging Face" Customer

Among Huskys' customer list, Hugging Face is particularly noteworthy. As previously discussed, Hugging Face is a company that recently suffered an autonomous intrusion incident this year using a frontier AI model. A significant portion of its traffic is said to consist of automated systems that acquire models and datasets, making this a prime example of the urgent challenge of "managing agent-based traffic."

Other customer companies—TikTok (extremely high traffic), Ro (healthcare data regulations), LEGOLAND (commercial transactions tied to physical locations), and Blackstone (audit requirements specific to the financial services industry)—are also organizations with diverse traffic profiles and compliance requirements, and can be seen as a kind of proof-of-concept for Huskys' platform's ability to function in these varied environments.

An Unprecedented Speed: Series A in Just Six Months

Another noteworthy aspect of this round is the speed at which it was raised. Huskeys was founded in 2025 by Itai Ghafni and Roy Weisfeld, both alumni of Unit 8200 (the Israeli military's cyber and intelligence unit, known for producing many security startup founders). It has only been about six months since they raised $8 million in seed funding in March, leading up to this Series A round.

This rapid funding cycle reflects investors' strong recognition of the urgency of the challenge of AI-driven traffic management. Blackstone's Chief Information Security Officer commented, "The way organizations protect their internet-facing applications is fundamentally changing. AI-driven traffic and increasingly fragmented edge environments require a new approach to security management."

The Reality of Faster Attackers

Some of the risks Huskeys is trying to address are already a reality, as demonstrated by the series of events we've discussed—such as the acceleration of AI-assisted vulnerability discovery like Zoomsday and the emergence of unintended cyber capabilities like GLM-5.3. As attackers use AI-driven capabilities to discover and exploit vulnerabilities at unprecedented speed and scale, defenders need automated systems that can respond at the same speed.

What Engineers Should Watch Out For

The Huskeys case study demonstrates the growing interest in a new market category: "AI agent security," which is rapidly gaining attention from investors. For developers whose systems are increasingly being accessed by external AI agents (search engine crawlers, AI-powered browser extensions, third-party AI services, etc.), the emergence of tools specializing in "agent identification" is likely to become a new option to consider in future system design.

The seemingly simple task of "allowing good agents and stopping bad ones" actually involves complex technical challenges. We should observe the maturity of this field through the future development of startups like Huskeys.

サイバーセキュリティAIエージェント資金調達スタートアップHugging Face

Waymo and Zoox acted without waiting for Tesla's announcement—two contrasting expansion strategies.

Waymo and Zoox independently announced their US expansion on September 1st, just before Tesla's September 3rd event. This article skeptically examines the qualitative differences between Waymo's launch of commercial driverless ride-hailing in San Diego, Tampa, and Denver and Zoox's safety driver-assisted test runs in Houston and San Diego, Waymo's track record of 4,000 vehicles, 14 cities, and 500,000 rides per week, Zoox's "12th city" but only Las Vegas for commercial operations, and Goldman Sachs' projected market growth of $19 billion (2030) to $48 billion (2035).

Waymo and Zoox Move Before Tesla's Announcement: Two Contrasting Expansion Strategies

On September 1st, Alphabet's Waymo and Amazon's Zoox independently announced their expansion into the United States. These announcements came just days before Tesla's September 3rd event, where it was expected to reveal details about its self-driving taxi strategy. As a software developer, I want to examine the contrasting expansion approaches chosen by these two companies.

A Clear Difference: "Commercial Service" vs. "Test Drives"

First, it's important to note the difference in the "quality" of the two companies' announcements. Waymo announced the launch of a driverless ride-hailing service for the general public in three cities: San Diego, Tampa, and Denver. This is a commercial service where paying passengers can actually ride in driverless vehicles.

Zox, on the other hand, announced the start of "tests" in Houston and San Diego. Furthermore, they plan to start with manual mapping and verification using modified test vehicles with human safety drivers on board for the time being. In other words, even though both companies are using the headline "Expanding into New Markets," there's a significant difference: Waymo is at the stage where it can "carry passengers immediately," while Zoox is still in the "mapping stage."

Waymo's Accumulated Track Record: 4,000 Vehicles, 14 Cities, 500,000 Rides Per Week

This difference directly reflects the vast difference in the accumulated track records of the two companies. Waymo currently operates over 4,000 vehicles in 14 cities across the US, providing over 500,000 driverless rides per week. The company has also set a goal of 1 million rides per week by the end of the year.

In terms of vehicles, they are building a vertically integrated supply chain, including assembling the new "Ojai" vehicle, based on Zeekr's minivan chassis, at their own factory in Arizona. In the three cities being added, the plan is to start with a scale of several dozen units and gradually expand to several hundred units over time.

Zoox's Expansion Pace of "12 Cities" and Remaining Commercialization Hurdles

From Zoox's perspective, the expansion to Houston and San Diego will mark its 12th US base. This is a number that demonstrates steady geographical expansion. However, Zoox still only provides a paid commercial service in Las Vegas.

In other words, Zoox's "12 cities" is merely the "number of cities in the testing and preparation phase," and is different in nature from the "number of cities where commercial service is provided" that Waymo's "14 cities" represents. It is not appropriate to simply compare these two numbers on the same playing field.

Market Growth Forecast of "$19B → $48B"

The larger context supporting both companies' announcements at this time is the expectation of overall market growth. Goldman Sachs Research predicts that the US robotaxi market will expand from $3 billion in 2027 to $19 billion in 2030 and $48 billion in 2035.

In this rapidly growing market, securing geographical first-mover advantage is strategically important for each company. Waymo's move to further expand its already established economies of scale, and Zoox's cautious but steady expansion of its geographical footprint, can be understood as rational strategic choices reflecting their different competitive positions.

The Charming Timing Just Before Tesla's Event

The fact that both companies' announcements came just before Tesla's September 3rd event is also noteworthy. As previously mentioned, Tesla has already obtained permits to operate up to 5,000 robotaxi vehicles in Nevada, but the company's Cybercab chief engineer himself had given a more conservative estimate, stating that "around 2,500 vehicles is more realistic."

Waymo and Zoox's deliberate timing in announcing their expansion strategies before Tesla's announcement was likely a deliberate strategy to reaffirm their presence just before market attention shifted to Tesla. The next focus will be on what figures and plans are actually presented at Tesla's September 3rd announcement, and how they compare to the track record Waymo and Zoox have already built.

What Software Professionals Should Consider

Waymo and Zoox's announcements reiterate a fundamental lesson in evaluating this industry: even when using the same word "expansion," the content can vary greatly. When seeing news of "expansion into a new city," it's crucial to always distinguish between the launch of commercial service and the start of test runs under human supervision.

Waymo's concrete track record of 500,000 runs per week is arguably one of the most reliable "verified figures" in this industry at present. We will continue to closely monitor the pace at which Zoox transitions to commercial service in cities other than Las Vegas, and what specific plans Tesla will present on September 3rd.

自動運転ロボタクシーWaymoZooxTesla
Advertisement300 × 250