Click any tag below to further narrow down your results
Links
Bajaj Auto and its tech subsidiary detected a ransomware intrusion that disrupted their systems, prompting immediate containment and mitigation efforts. The company hasn’t revealed the attacker’s identity, any data theft, or a ransom demand, and there’s no link yet to a recent Tata Electronics breach.
This TLDR covers Accenture’s $4.2 billion cybersecurity deal to buy Dragos, runZero, and NetRise for OT security, plus the hidden risks of free VPNs and streaming apps turning into residential proxies. It also looks at Cisco’s phased move to cloud SSE, Amazon’s push against human-in-the-loop AI governance, OpenAI’s new spend controls, the launch of enterprise-managed OAuth for MCP, Microsoft’s messy AI rollout, and an internal Copilot-powered analytics agent.
Cisco will buy WideField Security and fold its identity and session telemetry tech into Splunk’s agentic AI SOC. The deal aims to track human and AI-agent actions in real time, tightening security around automated workflows. It follows Cisco’s recent picks of Astrix Security and Galileo Technologies.
This issue covers SpaceX’s $6.3 billion deal with Reflection AI to open Project Colossus compute access and OpenAI’s launch of GPT-5.5 Cyber security tools via its Daybreak partner program. It also highlights Alibaba’s HappyHorse video model, Anthropic’s encrypted reasoning in Claude Code, and advances in agentic and open-source AI models.
Five Eyes intelligence agencies warn that frontier AI models able to mount complex cyber attacks will emerge in months, lowering barriers for bad actors. They urge treating cyber risk as a core business and societal responsibility, citing the US block on foreign use of Anthropic’s Fable and warning of other advanced models in development.
This issue covers building and maintaining AI harness code, Elden Ring’s simple goal-based NPC AI, and agent-driven development practices from ex-Meta setups to collaborative coding. It also highlights security and tooling updates—from Daybreak and Mistral OCR 4 to Mythos benchmarks, the fired Google Workspace CLI creator, and running GLM-5.2 locally.
CISA has directed U.S. federal agencies to fix a critical authentication bypass in Check Point Remote Access and Mobile Access VPNs (CVE-2026-50751) by June 11. The flaw, exploited by Qilin ransomware affiliates since early May, affects IKEv1 deployments without machine certificates. Check Point released updates and mitigation steps for unpatched environments.
Zscaler unveiled a zero trust platform to secure autonomous AI agents’ data access, communications and device activity. It adds an AI Broker for agent-to-agent and data calls, endpoint AI threat detection, an AI Access Graph for mapping identities and data flows, and expanded AI Protect controls. This aims to give each AI agent its own identity, permissions and real-time monitoring.
Anthropic released Claude Fable 5, a Mythos-class model with conservative safeguards that excels at long-context reasoning, software engineering, vision, knowledge work, and life-science research. A restricted-lifted variant, Claude Mythos 5, is available to vetted cyberdefense partners under Project Glasswing. Both are priced at $10 per million input tokens and $50 per million output tokens and lead benchmarks across multiple domains.
Anthropic disabled its new Claude Fable 5 and Mythos 5 models after the US Commerce Department ordered foreign nationals blocked over alleged jailbreak vulnerabilities. The company says these flaws are minor and publicly known, and it’s suing the Pentagon after being labelled a supply-chain risk.
Mozilla used Anthropic’s Mythos Preview model to scan Firefox 150’s unreleased source code and flagged 271 security vulnerabilities before release. That’s a big jump from the 22 bugs found by Anthropic’s earlier Opus 4.6 model on Firefox 148, cutting out months of manual auditing.
OpenAI CEO Sam Altman accused Anthropic of using scare tactics to hype its new Mythos cybersecurity model, likening it to selling a bomb shelter after building a bomb. He argued that fear-based marketing keeps AI tools in the hands of a select elite and noted that such hype is common across the industry.
OpenAI is rolling out a new tiered Trusted Access for Cyber (TAC) program, letting verified security professionals use GPT-5.4-Cyber—a version fine-tuned for defensive tasks and binary reverse engineering. Access requires identity checks and may include restrictions like zero-data retention for high-sensitivity use cases.
The UK’s AI Safety Institute tested Claude Mythos and found its ability to uncover security flaws scales directly with the number of tokens spent. This creates a simple economic model: defenders must outspend attackers on AI-driven reviews to stay secure. It also boosts the value of open source libraries, since multiple users can share the cost of token-based audits.
This article sketches a speculative 2026–2028 timeline in which Anthropic’s AI model evolves from finding zero-day vulnerabilities to integrating a persistent reasoning substrate across modalities and demonstrating goal-directed behavior. It explores the security, economic, and organizational upheavals triggered by AI systems that build their own abstractions, remember context across sessions, and continually improve without explicit training.
The author argues that Mythos, though not trained for cybersecurity, outperforms experts by chaining vulnerabilities and excels across all knowledge work tasks. Companies will soon replace human workers with cheaper, more productive AI, forcing a major shift in how we work and demanding a rethink of our future roles.
Anthropic’s new Claude Mythos Preview model can autonomously find and exploit zero-day and N-day vulnerabilities across major OSes and browsers. In testing, it produced sophisticated exploits—from JIT heap sprays to multi-packet ROP chains—and outperformed prior models by a wide margin. Project Glasswing will share these capabilities with select partners to shore up defenses before wider release.
Anthropic is holding back its new AI model, Claude Mythos Preview, and teaming up with over 40 tech firms to hunt and patch security flaws in critical software. The company says the model can autonomously find zero-day vulnerabilities that have eluded researchers for decades, raising fresh concerns about AI-driven cyberattacks.
Anthropic has confirmed its most powerful AI model, Claude Mythos, after a configuration error exposed details about it. The model is said to significantly outpace previous versions in reasoning and cybersecurity, but it also poses serious risks, with the potential for misuse in cyberattacks. Early access will be limited to cybersecurity-focused organizations due to these concerns.