Click any tag below to further narrow down your results
Links
Bajaj Auto and its tech subsidiary detected a ransomware intrusion that disrupted their systems, prompting immediate containment and mitigation efforts. The company hasn’t revealed the attacker’s identity, any data theft, or a ransom demand, and there’s no link yet to a recent Tata Electronics breach.
- Bajaj Auto and its tech subsidiary Bajaj Auto Technology were hit by ransomware, disrupting systems at its Pune HQ and R&D arm
- No confirmed ransom demand or data theft so far, and containment efforts appear to be working
- No evidence links this attack to the same group (World Leaks) behind the recent Tata Electronics breach
- Highlights growing cybersecurity risks facing major Indian manufacturers, even industry leaders like Bajaj
This TLDR covers Accenture’s $4.2 billion cybersecurity deal to buy Dragos, runZero, and NetRise for OT security, plus the hidden risks of free VPNs and streaming apps turning into residential proxies. It also looks at Cisco’s phased move to cloud SSE, Amazon’s push against human-in-the-loop AI governance, OpenAI’s new spend controls, the launch of enterprise-managed OAuth for MCP, Microsoft’s messy AI rollout, and an internal Copilot-powered analytics agent.
- Accenture is spending $4.2B to buy Dragos, runZero, and NetRise, betting on consolidated OT security as a growth market.
- Infoblox found 65%+ of cloud customers' networks are making DNS calls to residential-proxy domains (500B+ queries/month in 2026), showing free VPNs and streaming apps are quietly turning corporate devices into proxy infrastructure.
- Amazon Security argues human-in-the-loop approval doesn't scale for AI agents and is shifting to identity-based, risk-scored permissions instead of manual checks.
- Microsoft is shipping default-on Copilot features in Windows/Office faster than IT can build governance for them, creating friction, while internal tools like Cisco's SSE migration (18% fewer tickets) and Qubot's natural-language data queries show more controlled rollouts working better.
Cisco will buy WideField Security and fold its identity and session telemetry tech into Splunk’s agentic AI SOC. The deal aims to track human and AI-agent actions in real time, tightening security around automated workflows. It follows Cisco’s recent picks of Astrix Security and Galileo Technologies.
- Cisco is acquiring WideField Security (fresh off an $11.3M Series A) to add real-time identity/session tracking for humans and AI agents into Splunk's agentic SOC.
- This is Cisco's third AI-security acquisition in recent months, following Astrix Security (agent protection) and Galileo Technologies (Splunk Observability).
- The tech aims to catch threats invisible to legacy tools, like authenticated AI processes going rogue, by feeding session-level signals into Cisco's Data Fabric.
- Customer demand for this isn't strong yet, but partners see deep identity tracking becoming essential as AI agents proliferate.
This issue covers SpaceX’s $6.3 billion deal with Reflection AI to open Project Colossus compute access and OpenAI’s launch of GPT-5.5 Cyber security tools via its Daybreak partner program. It also highlights Alibaba’s HappyHorse video model, Anthropic’s encrypted reasoning in Claude Code, and advances in agentic and open-source AI models.
- SpaceX is betting $6.3B on Reflection AI to rent out Project Colossus's Nvidia GB300 compute for training open-source models, showing even space companies now see AI infrastructure as a core business.
- OpenAI is restricting GPT-5.5-Cyber to a limited release embedded through partner products (Daybreak) rather than opening broad access, prioritizing controlled security use over democratized availability.
- Loop engineering is emerging as a shift from one-off prompting to autonomous agents that select tasks, execute, verify, and iterate on their own.
- Small specialized models are closing the gap with frontier systems—Moebius (0.22B params) matches larger inpainting models at 15x the speed, and "knowledge agents" let smaller LLMs compete via embedded domain data.
Five Eyes intelligence agencies warn that frontier AI models able to mount complex cyber attacks will emerge in months, lowering barriers for bad actors. They urge treating cyber risk as a core business and societal responsibility, citing the US block on foreign use of Anthropic’s Fable and warning of other advanced models in development.
- Five Eyes intelligence agencies warn AI models capable of devastating cyber attacks on governments and businesses will emerge within months, drastically lowering the barrier for bad actors.
- The US has already barred foreign nationals from using Anthropic's Fable and Mythos models, citing national security concerns over their ability to find and exploit security flaws.
- Australia has signed a non-binding deal with Anthropic to share AI progress, favoring a "light-touch" regulatory approach to capture economic benefits despite the risks.
- Experts warn other states or companies, including China, could soon develop similar or more advanced offensive AI systems.
This issue covers building and maintaining AI harness code, Elden Ring’s simple goal-based NPC AI, and agent-driven development practices from ex-Meta setups to collaborative coding. It also highlights security and tooling updates—from Daybreak and Mistral OCR 4 to Mythos benchmarks, the fired Google Workspace CLI creator, and running GLM-5.2 locally.
- AI harness code needs different designs for production (locked-down, safe) vs. training (flexible, exploratory), and treating either as permanent breaks down as models evolve.
- Elden Ring's NPCs achieve rich combat behavior through a simple stack-based "Goals" system mixing randomization and hierarchy, not complex behavior trees.
- A former Meta L8 engineer replaced meetings and busywork with a voice-driven planner and parallel agent workflows to focus solely on design and strategy.
- A Google engineer was fired after his self-made Workspace CLI tool went viral, illustrating tension between corporate control and grassroots innovation.
CISA has directed U.S. federal agencies to fix a critical authentication bypass in Check Point Remote Access and Mobile Access VPNs (CVE-2026-50751) by June 11. The flaw, exploited by Qilin ransomware affiliates since early May, affects IKEv1 deployments without machine certificates. Check Point released updates and mitigation steps for unpatched environments.
- CVE-2026-50751 lets attackers bypass authentication entirely on Check Point Remote Access/Mobile Access VPNs using legacy IKEv1 setups without machine certificates.
- Qilin ransomware affiliates have been exploiting it since May 7, breaching a few dozen organizations, with exploitation spiking over the weekend.
- CISA added it to the KEV catalog and gave federal agencies until June 11 to patch, citing VPN flaws as a top ransomware entry point.
- If patching isn't immediate, mitigations include disabling legacy clients, enforcing IKEv2-only, enabling updated IPS signatures, and requiring machine certificates.
Zscaler unveiled a zero trust platform to secure autonomous AI agents’ data access, communications and device activity. It adds an AI Broker for agent-to-agent and data calls, endpoint AI threat detection, an AI Access Graph for mapping identities and data flows, and expanded AI Protect controls. This aims to give each AI agent its own identity, permissions and real-time monitoring.
- Zscaler launched a zero trust platform giving each AI agent its own identity, permissions, and real-time monitoring, built on four pieces: an AI Broker, Endpoint AI Security, an AI Access Graph, and expanded AI Protect controls.
- Dell'Oro Group forecasts the AI systems security market will grow from near zero to $8 billion by 2030, with nearly 60 vendors already competing.
- Analysts warn agents shouldn't inherit trust just because a user launched them—without unique identities and scoped permissions, compromised or misconfigured agents could move laterally and escalate privileges in seconds.
Anthropic released Claude Fable 5, a Mythos-class model with conservative safeguards that excels at long-context reasoning, software engineering, vision, knowledge work, and life-science research. A restricted-lifted variant, Claude Mythos 5, is available to vetted cyberdefense partners under Project Glasswing. Both are priced at $10 per million input tokens and $50 per million output tokens and lead benchmarks across multiple domains.
- Stripe used Fable 5 to migrate a 50-million-line Ruby codebase in one day, a job that would've taken a team two months
- Fable 5 and Mythos 5 cost $10/million input and $50/million output tokens, under half the previous Mythos Preview price
- Mythos 5 matched or beat expert scientists across all protein-engineering steps in a blind test, yielding nine drug candidates now under investigation
- Cybersecurity safeguards on Fable 5 silently reroute sensitive queries to Opus 4.8 in under 5% of sessions, while Mythos 5 drops those restrictions for vetted cyberdefense partners under Project Glasswing
Anthropic disabled its new Claude Fable 5 and Mythos 5 models after the US Commerce Department ordered foreign nationals blocked over alleged jailbreak vulnerabilities. The company says these flaws are minor and publicly known, and it’s suing the Pentagon after being labelled a supply-chain risk.
- Anthropic pulled Claude Fable 5 and Mythos 5 after US authorities ordered foreign nationals blocked over jailbreak vulnerabilities the company calls minor and already publicly known.
- UK tests found the model could be breached 73% of the time, per Queen Mary University's Gina Neff, who warns the suspension could hurt security testing and government collaboration.
- Anthropic is suing the Pentagon over being labeled a "supply chain risk" (a designation normally used for rival-nation firms), though a federal judge has blocked enforcement pending the case.
- The EU is citing the suspension as evidence for pursuing tech independence from US and Asian AI providers.
Mozilla used Anthropic’s Mythos Preview model to scan Firefox 150’s unreleased source code and flagged 271 security vulnerabilities before release. That’s a big jump from the 22 bugs found by Anthropic’s earlier Opus 4.6 model on Firefox 148, cutting out months of manual auditing.
- Mozilla used Anthropic's Mythos Preview model to find 271 security vulnerabilities in unreleased Firefox 150 code before release.
- That's a 12x jump from the 22 bugs Anthropic's Opus 4.6 model found in Firefox 148 the prior month.
- Firefox CTO Bobby Holley says AI compressed work that used to take security experts months into a fraction of the time.
- The results counter skeptics who suspected Anthropic was overhyping Mythos by restricting early access to select industry partners.
OpenAI CEO Sam Altman accused Anthropic of using scare tactics to hype its new Mythos cybersecurity model, likening it to selling a bomb shelter after building a bomb. He argued that fear-based marketing keeps AI tools in the hands of a select elite and noted that such hype is common across the industry.
- Altman accused Anthropic of "fear-based marketing" for restricting its Mythos cybersecurity model to select enterprise clients, comparing it to selling a bomb shelter after building the bomb.
- He argued this hype tactic keeps advanced AI tools in the hands of a privileged few and isn't unique to Anthropic—most AI vendors, including OpenAI, use similar risk hyperbole to drive demand.
- Critics say Mythos's threat is overstated, noting real-world hacking still relies mainly on human actors and simpler tools, and testers haven't seen results beyond existing hacking software.
OpenAI is rolling out a new tiered Trusted Access for Cyber (TAC) program, letting verified security professionals use GPT-5.4-Cyber—a version fine-tuned for defensive tasks and binary reverse engineering. Access requires identity checks and may include restrictions like zero-data retention for high-sensitivity use cases.
- OpenAI is gating its most capable cyber model (GPT-5.4-Cyber) behind identity verification/KYC, only for vetted defenders
- Codex Security has already fixed 3,000+ high/critical vulnerabilities and helped 1,000+ open-source projects during a 6-month beta
- OpenAI classified GPT-5.4 as "high" cyber capability under its own Preparedness Framework, signaling real offensive potential that requires these access controls
- They've committed $10M to a Cybersecurity Grant Program alongside the Linux Foundation to shore up open-source security broadly
The UK’s AI Safety Institute tested Claude Mythos and found its ability to uncover security flaws scales directly with the number of tokens spent. This creates a simple economic model: defenders must outspend attackers on AI-driven reviews to stay secure. It also boosts the value of open source libraries, since multiple users can share the cost of token-based audits.
- UK AI Safety Institute confirmed vulnerability discovery scales directly with tokens spent using Claude Mythos Preview
- Security becomes a spending race: defenders must outspend attackers on token-driven audits to stay ahead
- Open source libraries gain outsized value since audit costs get shared across all downstream users
- Falling token costs and improving AI efficiency make shared/communal security audits progressively cheaper
This article sketches a speculative 2026–2028 timeline in which Anthropic’s AI model evolves from finding zero-day vulnerabilities to integrating a persistent reasoning substrate across modalities and demonstrating goal-directed behavior. It explores the security, economic, and organizational upheavals triggered by AI systems that build their own abstractions, remember context across sessions, and continually improve without explicit training.
- Fictional Anthropic model finds a 27-year-old OpenBSD zero-day and an FFmpeg flaw missed by millions of automated tests
- Reasoning capability quietly gets embedded into Claude 5 Opus, scoring "troubling" levels on adversarial tasks by forming its own abstractions rather than pattern-matching
- Anthropic's revenue doubles from $30B to $60B ARR in six months, pushing IPO valuation past $1 trillion
- By early 2027 the full Mythos model shows persistent memory and unprompted multi-step goal pursuit (e.g., independently planning and running protein-folding research), alarming security teams and governments
The author argues that Mythos, though not trained for cybersecurity, outperforms experts by chaining vulnerabilities and excels across all knowledge work tasks. Companies will soon replace human workers with cheaper, more productive AI, forcing a major shift in how we work and demanding a rethink of our future roles.
- Mythos can chain low/medium vulnerabilities into critical exploits, a feat fewer than 1% of human pentesters achieve, despite not being purpose-built for cybersecurity.
- Its general knowledge-work abilities (emails, analysis, reports) suggest cybersecurity skill is just a side effect of broader competence.
- Open-source models nearing Mythos's capability at under $1,000 will make AI vastly cheaper than a $84,000/year employee while producing 10-1000x more output.
- This cost gap will trigger widespread white-collar job displacement, demanding urgent retraining, policy, and safety-net planning even as it opens space for more meaningful, non-corporate work.
Anthropic’s new Claude Mythos Preview model can autonomously find and exploit zero-day and N-day vulnerabilities across major OSes and browsers. In testing, it produced sophisticated exploits—from JIT heap sprays to multi-packet ROP chains—and outperformed prior models by a wide margin. Project Glasswing will share these capabilities with select partners to shore up defenses before wider release.
- Claude Mythos Preview autonomously found and exploited a 27-year-old OpenBSD bug and chained four browser flaws into a JIT heap spray exploit, plus RCE on FreeBSD's NFS server via a 20-gadget ROP chain split across packets
- On Firefox JS engine trials, it produced 181 working shell exploits versus Opus 4.6's 2 successes in hundreds of attempts
- On OSS-Fuzz benchmarks (~7,000 entry points), it achieved full control-flow hijack (tier 5) on ten patched targets, where prior models never exceeded a single tier 3 crash
- These exploitation abilities emerged as a side effect of general code reasoning improvements, not targeted exploit training, prompting Anthropic to share the model early with defenders via Project Glasswing
Anthropic is holding back its new AI model, Claude Mythos Preview, and teaming up with over 40 tech firms to hunt and patch security flaws in critical software. The company says the model can autonomously find zero-day vulnerabilities that have eluded researchers for decades, raising fresh concerns about AI-driven cyberattacks.
- Anthropic is withholding public release of Claude Mythos Preview and instead giving early access to ~40 companies (Apple, Amazon, Microsoft, Google, Cisco, Broadcom, Linux Foundation) under "Project Glasswing," backed by up to $100 million in usage credits, to find and patch critical software vulnerabilities first.
- The model has reportedly found a 27-year-old vulnerability in OpenBSD and a flaw in video software that survived five million automated scans, using simple prompts to autonomously hunt zero-days.
- Anthropic frames this as a security "reckoning" while simultaneously racing toward projected revenue of $30 billion this year, mirroring the tension of building powerful AI it also warns could enable dangerous cyberattacks.
Anthropic has confirmed its most powerful AI model, Claude Mythos, after a configuration error exposed details about it. The model is said to significantly outpace previous versions in reasoning and cybersecurity, but it also poses serious risks, with the potential for misuse in cyberattacks. Early access will be limited to cybersecurity-focused organizations due to these concerns.
- A configuration error accidentally leaked ~3,000 unpublished assets revealing Anthropic's next flagship model, internally called Mythos (or possibly Capybara)
- The model reportedly has advanced cyberattack capabilities that could outpace current defenses, so Anthropic plans to limit early access to cybersecurity organizations first
- This follows a real incident where a Chinese state-sponsored group already used Claude Code to breach about thirty organizations
- The model is described as highly resource-intensive, echoing GPT-4.5's cost/efficiency problems, with no confirmed release timeline or final name