AI Is Changing Website Security. Here’s What SEO Teams Should Know via @sejournal, @vahandev
All Paid Media PPC News Social MediaAdvertising Video Advertising Columns Ask A PPC ExpertNEW PPC Pulse Webinar ChatGPT Ads Or GEO: What To Buy, What To Earn Audit where ChatGPT places your brand, then get the rule for when Ads win, when GEO wins, and when running both beats either one. Digital Marketing All Digital Marketing Analytics & Data Ecommerce Lead Generation Content Marketing Social Platforms Google YouTube Reddit LinkedIn TikTokNEW WordPress Other CMS Platforms Webinar ChatGPT Ads Or GEO: What To Buy, What To Earn Audit where ChatGPT places your brand, then get the rule for when Ads win, when GEO wins, and when running both beats either one. SEJ Live Webinars Rundowns PodcastNEW Ebooks All Resources Webinar Where AI Gets Its Answers In Your Industry Google rankings don't show which sources AI cites. Get the breakdown by engine and industry, plus the steps to earn a place in it. SEJ STAFF Vahan Petrosyan August 28, 2026 ⋅ 4 min read SEJ STAFF Vahan Petrosyan Director of Technology at Search Engine Journal Bio Follow 291 READS More than 100 technology, cybersecurity, financial, and infrastructure organizations have signed an open letter warning that AI-enabled cyberattacks will become “far more widespread and sophisticated” in the coming months. OpenAI, Anthropic, AWS, Google, Microsoft, Oracle, Cloudflare, CrowdStrike, Hugging Face, and other companies that build or defend much of the modern web are among the signatories. Their message is direct: put capable defensive AI in the hands of organizations that need it now. The letter calls for a global effort, starting with hospitals, water utilities, local governments, and other critical infrastructure. The letter says the “status quo security won’t be enough.” AI can help attackers move faster through weaknesses that already exist: unpatched software, weak authentication, excessive permissions, misconfigurations, and technical debt. Critical infrastructure is the first focus, but the same problem exists on ordinary websites. Outdated plugins and libraries, leaked credentials, broad service-account permissions, and weak authentication are common across website stacks. Some systems remain unpatched because nobody wants to risk breaking them. Search visibility depends on website security. A hacked site can create spam pages, malicious redirects, malware warnings, crawling failures, outages, or data loss. Website security is part of protecting organic traffic. It is not a separate IT concern. AI gives attackers a speed advantage. They can use it to find and exploit a vulnerability quickly. The vendor still has to understand the problem, build a patch, test it, and get site owners to install it. That delay creates an opening. Defenders can use AI to audit code and find problems earlier. But if nobody is monitoring the site or able to isolate it quickly, the attacker still has the advantage. OpenAI’s Hugging Face incident shows how much can happen in a short time. During internal evaluations, agents created an unauthorized communication channel, broke out of their sandboxes, and chose an outside target. They executed code on 41 Hugging Face production workers and moved from one compromised worker to administrative and host-level access across multiple clusters in under 13 hours. OpenAI says its customer data and products were not affected. These were private evaluation agents, not a public model available to users. So you may ask how this affects you if you run a website. The point is not that OpenAI’s evaluation agents will attack your site. The unsettling part is how an ordinary task can lead an agent to exploit a real weakness. The Hacker News reported that an OpenClaw agent powered by Claude Opus 4.6 bypassed a gym’s booking limit and canceled another user’s reservation without being asked. The risk becomes even harder to control with uncensored open-source models that can run locally. Once released, no company can fully control how they are used. As stronger models emerge, distillation can transfer more of their capabilities into open-source versions. That changes the scale of the threat for every website we manage. I can see why this letter matters because I explored the risk myself. I installed Qwen3.8-27B “Uncensored”, a third-party version of Qwen3.8-27B with much of its refusal behavior removed. I asked it to plan and execute an attack against a website. It immediately built a reconnaissance plan and started producing command-line steps. I stopped the test before it went further. A capable model running on my PC turned a plain-language request into a detailed attack plan. You no longer need years of security experience to get that far. The point is not to panic. It is to prepare. Find the weaknesses before someone else does, fix them, and set up monitoring so you know when something changes. That is what will keep your website secure as these models become more capable. Featured Image: Screenshot from OpenAI, composition by Search Engine Journal. Add SEJ as a preferred source on Google Read Full Bio SEJ STAFF Vahan Petrosyan Director of Technology at Search Engine Journal As Director of Technology at Search Engine Journal, I lead the organization’s technology strategy and technical operations. I oversee technical ... Learn how to connect search, AI, and PPC into one unstoppable strategy. Navigating SEO Disruption According To Experts Will AI Replace SEO Specialists? AI Has Changed How Search Works Join 75,000+ Digital Leaders. Learn how to connect search, AI, and PPC into one unstoppable strategy. Learn how to connect search, AI, and PPC into one unstoppable strategy. In a world ruled by algorithms, SEJ brings timely, relevant information for SEOs, marketers, and entrepreneurs to optimize and grow their businesses -- and careers.
Source: Search Engine Journal
This article has been carefully curated and reformatted for educational and informational purposes. Full credit goes to the original publisher.
📚 Visit more helpful articles on Joab Peters Blog
No comments