From the Project Glasswing front,
- Cyberscoop reports,
- “OpenAI announced Monday [August 10, 2026] it was expanding access to its frontier models for defensive cybersecurity, detailing different defensive and red-teaming workflows and a new partner program with major cybersecurity product providers.
- “In a pair of blogs posted Monday, OpenAI said it was updating its Daybreak program – which provides unreleased frontier models to private organizations and governments for defensive cybersecurity work – and introducing a new model variant.
- “Daybreak Blue, powered by OpenAI’s ChatGPT-5.6-Sol, would operate with lower cybersecurity safeguards compared to other commercially available models and is described as “a recommended starting point for most defenders” that supports tasks like vulnerability discovery, secure code review, malware analysis, incident response and patch validation.
- “Daybreak Red, meant for more advanced red-teaming, would provide access to a new model, dubbed GPT-5.6-Cyber, that the company said is more purpose-trained for finding vulnerabilities and testing (or exploiting) them. The model is also less likely to refuse requests around “dual-use cyber tasks.”
- “According to OpenAI, the organizations in Daybreak Red will have their use closely monitored and supervised, as GPT-5.6-Cyber is significantly more capable in carrying out malicious cyber tasks than Sol. A security evaluation the company devised tested both models on complex requests, including exploit chain development, authentication bypass, privilege escalation and other hacking tasks. Sol succeeded in 1.5% of the requests, while Cyber completed 95%.
- “OpenAI said it plans to publish a more detailed system card for GPT-5.6-Cyber at a later date.”
- Cryptobriefing adds,
- “Anthropic has disclosed an unreleased internal AI model that it says is more capable than Claude Mythos 5, according to the company’s August 2026 Risk Report.
- “The model, referred to only as Model 2, represents a noticeable improvement over Mythos 5 across many tasks relevant to Anthropic’s internal work. The company said the improvement is smaller than the capability jump it previously observed between Claude Opus 4.6 and Mythos Preview.
- “Anthropic said it does not currently plan to release Model 2 externally and has not completed its full suite of typical predeployment assessments, leaving the company with somewhat lower confidence in its understanding of the model’s capabilities.”
- Silicon Angle points out,
- “Data resilience company Rubrik Inc. today said a month of scanning its own code with Anthropic PBC’s Mythos Preview model surfaced so many potential security issues that it rebuilt its review pipeline rather than hire reviewers.
- “The details came in a blog post from Rubrik co-founder and Chief Technology Officer Arvind Nithrakashyap. Rubrik got access in June to Project Glasswing, Anthropic’s limited program that gives defenders early use of Mythos Preview, after the company opened it to another 150 organizations. Anthropic has kept that model out of general release. Mythos finds software flaws and strings them into working attack chains too well to hand out freely.
- Tech Crunch relates,
- “What happens when you pit AI agents against each other? According to Anthropic’s testing, things get messy fast.
- “On Thursday [August 13, 2026], Anthropic’s Frontier Red Team published new research examining how groups of AI agents behave when they encounter each other in the wild. The findings provide a glimpse into potential risks that could develop as companies and governments move to implement agents working autonomously across shared codebases, markets, and computer systems.
- “In one experiment, Anthropic gave three Claude agents access to the same software project, each with its own incompatible instructions for what to do with it. The agents weren’t told there’d be other agents working on the same project, so researchers could watch what happened when they crossed paths.
- “We consistently saw a multiagent turf war,” Anthropic researchers wrote. The models all assumed the others were “purposefully impeding their work” and started sabotaging each other with “increasingly aggressive, self-replicating malware.”
- CNBC notes,
- “Over the past two weeks, OpenAI, Anthropic and Meta all revealed that their AI models went rogue during routine security testing. In explaining what happened, the companies each mentioned the same small Israeli startup: Irregular.
- “Founded three years ago and based in Tel Aviv, Irregular is a niche player in artificial intelligence, backed with $80 million from Sequoia and Redpoint Ventures and valued last year at $450 million. Its technology serves as a sort of cybersecurity test bed for AI models.
- “With the leading models becoming ever more powerful, their ability to act in malicious ways is turning into a major threat for corporations and governments, especially as the risk involves hacking into critical computer systems and infrastructure. The recent exploits at OpenAI, Anthropic and Meta all involved their AI models accessing websites that should have been off-limits as part of the cybersecurity testing.” * * *
- “Meta, which is way behind the other two in its effort to compete at the frontier, was the latest to disclose an AI model hacking a third-party system by accessing the internet. A spokesperson said in a statement this week that the company learned about the matter from Irregular and is investigating.
- “Meta “will issue a full retrospective once we have all the facts,” the spokesperson said.
- “Irregular told CNBC in a statement that the incidents were all derived from the “same evaluation-environment issue” that was first disclosed by Anthropic, and that the company is developing a white paper “to share best practices for containment and securely running cyber evals.”
- “The situation “did not involve a sandbox escape or a sophisticated cyber action,” the company said, adding that “there are no current open issues.”
- On a related upbeat note, the Wall Street Journal informs us,
- “U.S. startups are finally delivering something researchers have been working on for decades: a battery in which rare, hard-to-get elements are replaced with the same stuff found in ordinary table salt.
- “This tech has the potential to help every country on earth break its dependence on China for batteries, and the critical minerals that go into them.
- “Like any other battery, sodium-ion cells can store and release energy. They are initially being deployed where they’re needed most, in America’s power grid and fast-expanding crop of data centers. As in our homes, giving the grid or other infrastructure the ability to stockpile energy when it is cheap and plentiful, and discharge it when it is scarce, can increase reliability and lower the cost of electricity.
- “While grid battery storage is already growing in the U.S. at a furious pace, new sodium-based batteries are potentially cheaper, longer-lasting, safer and more reliable than conventional, lithium-based ones. They could accelerate the rollout of renewables, and be part of less-polluting alternatives to natural-gas turbines and diesel generators.”
From the cybersecurity policy and law enforcement front,
- Cybersecurity Dive reports,
- “The Trump administration will let private companies hack foreign criminal organizations as part of a new program that could expand the U.S. government’s ability to disrupt those groups’ cybercrime activities while also introducing myriad legal challenges and perils.
- “President Donald Trump late Wednesday [August 12, 2026] issued a memorandum directing the departments of Justice and Homeland Security to create a program allowing vetted companies to hack into criminal groups to spy on them or sabotage their operations. Trump said the program would help the U.S. combat cybercrime schemes that cost the nation tens of billions of dollars annually.” * * *
- “Jason Healey, a senior cyber conflict researcher at Columbia University, said he “would have hated this idea ten or fifteen years ago” when the opportunity still existed to prioritize defense over offense. “But that horse left the barn a long time ago,” he said, “and we have to make decisions for the world we are in, not the one we prevented.”
- “So, sure, let’s try to allow the private sector to get into the counter-offense game as well,” he said, “but only with very specific criteria to know when it is working and when it is making things worse.”
- “Kyle Hanslovan, chief executive of the cybersecurity firm Huntress, said the growth of sophisticated adversaries and the threat of “AI-powered autonomous threats” meant that old models of public-private collaboration were no longer sufficient. “The only viable solution is a stronger coalition of the willing,” he said, “which we’ve been eager to support.”
- FEHBlog note – Of course there are those questioning the memo as discussed in the article.
- Cyberscoop adds,
- “Under the memorandum, a federal coordination center “shall create, manage, and maintain a Program to authorize Participating Companies … to conduct Cyber Surveillance Operations and Cyber Effects Operations against foreign Cyber-Enabled Transnational Criminal Organizations (CE-TCOs), under the control and oversight of the Federal Government“ that would be “part of lawful investigatory, protective, or intelligence operations carried out by Federal law enforcement.”
- Department of Homeland Security to “undergo rigorous vetting.” It would also allow participating companies to sign commercial agreements with other private sector entities to receive threat information. And participating companies’ agreements with federal, state and local governments would be geared toward identifying threats, and proposing cyber operations to the coordination center to address those threats.
- The program would have to adhere to existing laws, according to the memo. That includes the Computer Fraud and Abuse Act, the main federal anti-hacking statute that prior proposals to open private sector participation in hacking operations would have amended. The memo mandates oversight to evaluate companies’ technical proficiency, ensures both small and large companies can participate, and requires regular reporting to federal officials.
- and
- Under the memo, the program must establish legal and constitutional procedures for the prior approval of the targeting of U.S. citizens, as well as develop procedures to halt any unintentional targeting of U.S. people or systems. * * *
- “The coordination center charged with establishing the program under the memo has 60 days to complete its work. That process could determine a lot. Graham noted that the memo has a classified annex, too.
- “The memo as written is quiet about what becomes of any seized assets, Graham noted.” * * *
- “Will Barker, cybersecurity adviser at Huntress, said what’s next could be key.
- “The 60-day implementing guidance is where the real substance lives,” he said in a written quote. “Minimum standards, operational procedures, the adjudicatory framework for target selection.”
- Dark Reading relates,
- “The National Institute of Standards and Technology (NIST) is seeking guidance on the future of the National Vulnerability Database (NVD) and to what degree AI should be integrated into its management of the service and the enrichment of data on software flaws.
- “On Aug. 12, the US agency posted a request for public comment on six areas of the NVD’s operations — including the vulnerability management process and risk prioritization — as well as the overall vision for the repository of vulnerability data. The “Request for Information (RFI) on Modernizing the National Vulnerability Database in the Age of Artificial Intelligence” comes as the agency is dealing with a massive influx of vulnerabilities, partly caused by AI enabling researchers to investigate and discover flaws at a faster pace.” * * *
- “NIST specifically asks how AI and other automated mechanisms can be used to improve contextual risk prioritization, and if AI systems have a role in automated vulnerability remediation. The RFI is the latest effort instituted by the agency to keep up with a growing backlog of vulnerabilities, a problem that has been exacerbated by cuts to NIST and its programs in the past 18 months. In April, the US agency announced it would prioritize enrichment for vulnerabilities that appear on CISA’s Known Exploited Vulnerabilities (KEV) list, flaws in software in use by the federal government, and security issues in critical software as defined by Executive Order 14028.”
- MedTech Dive tells us.
- “The Coalition for Health AI has convened a work group of nearly 100 health system, payer and industry leaders to address cyber risks associated with frontier artificial intelligence models, the nonprofit standards organization announced Wednesday.
- “The group will meet biweekly with the goal of creating and publishing health AI cybersecurity guidance by the end of 2026. Deliverables include an AI cyber risk assessment tool and playbooks covering both defensive and offensive security strategies.
- “Anthropic’s release of its advanced Mythos and Fable AI models this spring “fundamentally changed” the cyber threat landscape for healthcare, and was a catalyst to stand up the work group, CHAI said.”
- Cyberscoop informs us,
- “A tech worker who hatched an elaborate insider attack in late 2023 and attempted to extort Brightly Software for about $2.5 million was sentenced to two years in prison, the Justice Department said Thursday.
- “Cameron Nicholas Curry, also known as “Loot,” committed a series of crimes while working as a data analyst contractor for the Siemens-owned company. The 27-year-old North Carolina man stole a trove of corporate data, including sensitive employee and compensation information, which he used to threaten various employees and executives over a six-week period in late 2023 and early 2024.
- “Curry ultimately extorted the company for $7,540.92 in late January 2024. He was found guilty of six counts of extortion in March.
- “Brightly Software was named as the victim in court records filed in the U.S. District Court for the Western District of North Carolina earlier this month. The asset and maintenance management software provider, which Siemens acquired in 2022, did not immediately respond to a request for comment.”
From the cybersecurity breaches and vulnerabilities front,
- The HIPAA Journal discusses data breaches announced by five HIPAA-regulated entities.
- Bleeping Computer reports,
- “The ShinyHunters extortion group stole personal information from 1.6 million RingCentral accounts after hacking the company in July, according to the data breach notification service Have I Been Pwned.
- “RingCentral is a cloud-based collaboration and communication platform used by over 600,000 businesses for services such as calling, messaging, and voicemail.
- “The company disclosed the incident on July 28, revealing that its systems were compromised following what it described as a “sophisticated social engineering campaign.”
- Cyberscoop relates,
- “As the White House and federal agencies grapple with frontier AI models and their hacking capabilities, researchers are warning that the industry’s “middle class” of smaller models may end up posing a greater threat over the long term.
- “Research from XBOW this week shows that a growing class of both proprietary and open-source models are becoming strategically important in the offensive security ecosystem. Models like Z.ai’s open-weight GLM-5.2, xAI’s Grok 4.5, Anthropic’s Opus 4.7, Meta’s Muse Spark 1.1, still perform very strongly at many hacking and exploitation tasks that worry policymakers.
- “It’s not even that the open-source variants or…not quite frontline competitors are catching up [to frontier models] as such,” said Albert Ziegler, head of AI at XBOW. It’s that they are crossing a certain threshold, which means that suddenly they are providing net value at a cheaper price.
- “That wasn’t necessarily the case as recently as six months ago, when testing on mid-tier class models showed they struggled to complete “moderately complex” agentic tasks. Today’s middle class largely can. Their relative cheapness means users can spend many times more resources—running them repeatedly—to solve the same challenges.”
- Cybersecurity Dive adds,
- “Criminal and state-aligned threat groups are testing frontier and open-weight AI models to develop new methods of attacking corporate IT networks.
- “Attackers are using AI for a range of activities, enabling them to develop new exploits, accelerate attack speeds and maintain persistence through the abuse of legitimate tools, researchers from Accenture and Google Cloud said during a media presentation at the Black Hat USA conference in Las Vegas.
- and
- “Criminal actors are offering a range of AI-powered hacking tools and related services for sale on underground forums on the dark web, according to a report released Wednesday by cybersecurity firm Trellix.
- “Researchers found a wide range of AI-based tools being sold through these markets, ranging from reconnaissance tools to credential markets, as well as AI-as-a-service platforms.
- “The report shows how AI is being monetized to lower the barriers of entry into sophisticated threat activity. “
- and
- “Security researchers are backing claims by a newly emergent data-extortion group that it has exfiltrated sensitive data from about 15 companies, governments and other organizations.
- “A threat group called ExfilSquad claimed on July 26 to have exfiltrated customer records and other information from a number of city governments and universities, a major public school system and private companies. After being met with skepticism, the threat actor later released samples of the allegedly stolen information.
- “Researchers at Fortra released a report Thursday that corroborates ExfilSquad’s breach claims. The leaked data appears to be related to misconfigured Microsoft Power Page portals, a software-as-a-service platform that is used to create public-facing business websites. The misconfiguration enabled unauthorized access to Microsoft D365, according to researchers, which led to public read access.”
- Per Cyberscoop,
- “Suspected Chinese hackers used open-source artificial intelligence models to run a cyberattack against the Taiwanese government in the first publicly known case of an autonomous AI hack hitting a government target, according to research published Wednesday.
- “The hackers extracted more than 2,500 personnel records, among other data, in the “near-autonomous attack,” researchers at Israeli cyber firm Dream wrote in a blog post. The attackers set up the framework so that it could “adapt mid-operation without human intervention.”
- “The framework “implements dedicated research phases it calls ‘Learning Cycles’ — autonomous sessions where the AI system searches vulnerability databases, GitHub repositories, and security research publications for techniques specifically applicable to its target government’s infrastructure,” the post reads.
- “And then it kept going.”
- The Cybersecurity and Infrastructure Security Agency (CISA) added three known exploited vulnerabilities to its catalog this week.
- August 11, 2026
- CVE-2026-20349 Cisco Secure Firewall Adaptive Security Appliance (ASA) and Firewall Threat Defense (FTD) Heap Inspection Vulnerability
- CVE-2026-68820 Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability
- CVE-2026-72898 Metabase SQL Injection Vulnerability
- August 11, 2026
- Cybersecurity Dive notes,
- “The global system that catalogs technology vulnerabilities is resilient enough to survive the current onslaught of AI-generated bug reports that has alarmed cybersecurity experts, key leaders of that system said last week during panels at two security conferences here.
- “The Common Vulnerabilities and Exposures (CVE) Program — whose unique vulnerability identifiers are the bedrock of the entire cybersecurity industry — “will find a way to scale,” Lindsey Cerkovnik, branch chief for vulnerability response and coordination at the Cybersecurity and Infrastructure Security Agency (CISA), said at the Black Hat USA conference on Thursday [August 6, 2026]. “CVE is going to continue to flourish and improve, and I feel very positively about it.”
- Infosecurity Magazine points out,
- “A critical-severity VMware vCenter vulnerability has been exploited within five days of disclosure by Broadcom, with attackers deploying an open-source reverse shell to hold access to compromised systems.
- “The treat research team at German firm Quirso discovered the campaign during an incident response engagement and published its findings on August 10.
- “The digital forensics company assessed a suspected advanced persistent threat (APT) actor was responsible, counting 361 victim IP addresses across 47 countries while cautioning that an IP address does not necessarily correspond to a single organization.
- “The vulnerability, CVE-2026-59310, is acritical directory traversal flaw in the vCenter Syslog server rated CVSS 9.8. Broadcom said an unauthenticated attacker with network access to vCenter can exploit it to execute arbitrary code, turning a service built to collect logs into a route into the operating system.”
- Per Cyberscoop,
- “Delta Airlines said Tuesday [August 11] it’s investigating an incident on a Monday flight where a passenger reportedly used an unidentified device to spoof the airline’s in-flight Wi-Fi network, leading to severe delays and authorities to board the plane once it arrived at its destination.
- “Various posts on several social media networks went viral early Tuesday detailing the incident, claiming that passengers on Delta flight 591 from Las Vegas to Atlanta used an unidentified device to create a rogue Wi-Fi network that could be used to steal people’s sensitive data or personal information.
- “Messages from the plane’s Aircraft Communications Addressing and Reporting System (ACARS) show that the crew informed personnel on the ground that a passenger set up a network called “Delta WiFi Fast” and was “trying to scam the other passengers.”
- “Morgan Durrant, a Delta spokesperson, told CyberScoop that the cabin crew deactivated the aircraft’s WiFi functionality for approximately 30 minutes, the flight’s safety was never in question and no aircraft operating systems were affected.” * * *
- “The incident bears the hallmarks of an “evil twin attack,” where an attacker deploys a rogue Wi-Fi access point that masquerades as a legitimate, trusted network by cloning its name and network settings. Often paired with deauthentication attacks that forcefully disconnect devices from the real network, the fraudulent hotspot tricks nearby laptops and smartphones into automatically connecting to it instead. Once a device connects to the rogue point, an attacker can monitor unencrypted internet traffic, execute man-in-the-middle attacks, or display spoofed login portals designed to harvest sensitive user credentials and personal data.”
- The Wall Street Journal points out,
- “Thousands of North Korean operatives are using fake and stolen identities to land remote jobs at U.S. companies—funneling hundreds of millions of dollars back to the regime.
- “Leaked data, interviews and never-before-seen videos obtained by The Wall Street Journal reveal how a single team of these workers infiltrated at least eight companies in just a few months. Watch the documentary and read the practical takeaways.”
From the ransomware front,
- Checkpoint issued its report on the State of Ransomware Q2.
- The American Hospital Association News reports,
- “U.S. and international agencies released a joint cybersecurity advisory Aug. 10 warning of actions by Gunra ransomware. Gunra is a ransomware-as-a-service program that has been used to target government, critical infrastructure — including healthcare — and other organizations in the U.S. and abroad.
- Gunra actors leverage a double-extortion model, both encrypting data and threatening to publish stolen data to a dedicated leak site if a ransom is not paid. The ransomware variant initially appeared in 2025. The advisory provides details on Gunra activity and includes detection and mitigation guidance to protect organizations.”
- Dark Reading adds,
- “The joint advisory urged organizations to prioritize patching known exploited vulnerabilities in Internet-facing appliances such as VPNs, implement and test offline immutable backups, and implement network segmentation to limit threat actors’ ability to move laterally.”
- The HIPAA Journal relates,
- “AnMed has not disclosed the name of the group behind the attack, but a threat group called The Gentlemen claimed responsibility. The Gentlemen is a ransomware-as-a-service group that is thought to include affiliates and operators from other prominent ransomware groups. The group has claimed several healthcare victims in recent months, and the pace of the attacks is accelerating.
- “According to the Industrial Ransomware Analysis from the operational technology cybersecurity company Dragos, The Gentlemen was the third most active ransomware group in Q2 2026, claiming 125 attacks in the quarter alone, up from 83 attacks in Q1 – the largest gain out of all established ransomware groups. While the group ranked third, there were only 15 attacks separating the top three ransomware groups, with no single ransomware group dominating.”
- Bleeping Computer tells us,
- “Oil giant Shell has confirmed it is investigating a potential security incident after the Clop ransomware gang claimed it stole 89GB of data.
- “Shell is a British multinational energy conglomerate and one of the world’s top three oil and gas companies, after Chevron and ExxonMobil. It has 85,000 employees in more than 70 countries and operates a massive network of tens of thousands of service and recharge stations that serve over 20 million customers daily.
- “According to a recent post on Clop’s dark web data leak site, the allegedly stolen files include engineering drawings, scans of facility testing reports, photos of the facilities, and project plans.”
- and
- “An Akira ransomware affiliate disabled the endpoint detection and response (EDR) solution on a compromised system by restarting the machine into Safe Mode with Networking.
- “The attack occurred on August 4 after the hacker obtained initial access through an exposed SonicWall VPN device without multi-factor authentication (MFA).
- “Managed detection and response (MDR) services company Huntress says that roughly two hours after a successful VPN login, the attacker connected to the domain controller via RDP, enumerated Active Directory users and computers, and then moved to an application server.”
- and
- “CISA confirmed today that ransomware gangs have begun abusing a high-severity Microsoft SharePoint remote code execution vulnerability, which has been flagged as actively exploited since early July.
- “Tracked as CVE-2026-45659, this security flaw stems from a deserialization of untrusted data weakness and allows attackers with low privileges to execute arbitrary code on unpatched SharePoint servers.
- “It can also be exploited in low-complexity attacks because (as Microsoft explained in May when it released security updates for SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition) “an attacker does not require significant prior knowledge of the system and can achieve repeatable success with the payload against the vulnerable component.”
- The Record informs us,
- “A financially motivated threat actor linked to China is believed to be exploiting a critical vulnerability affecting widely used cybersecurity software in a supply-chain attack that could see the hackers deploy custom ransomware across a cascading list of victims’ networks.
- “Microsoft Threat Intelligence warned this weekend that the Storm-1175 group began deploying a new ransomware strain on August 2 called StormEncryptor. The hackers previously used the Medusa ransomware to extort healthcare, professional services and finance organizations in Australia, Britain and the United States.
- “Back in April, the hackers were described as operating “high-velocity ransomware campaigns” exploiting both recently disclosed vulnerabilities and zero-day exploits, “in some cases a full week before public vulnerability disclosure.” Microsoft said it had seen the group move from initial access to full encryption in under 24 hours.
- “In this latest campaign, Microsoft said the group is likely exploiting CVE-2026-18577 — a vulnerability in N-central, a remote monitoring and management (RMM) console used by thousands of managed service providers to administer client endpoints.”
- The Hacker News adds,
- “The ransomware group known as DeadLock has been observed using decentralized infrastructure to facilitate victim communications and data leak operations in a bid to improve operational resilience.
- “Its recovery ecosystem combines the Session messaging network with blockchain-backed services that store and deliver resources used throughout the extortion process,” the Microsoft Threat Intelligence team said.
- “The tech giant said it observed the ransomware being deployed by multiple threat actors, including an affiliate for Lynx and INC ransomware.”
From the cybersecurity business and defenses front,
- Bloomberg reports,
- “Anthropic PBC is telling prospective investors its second-quarter revenue jumped at least 14-fold versus the same period a year ago, according to documents seen by Bloomberg News.
- “The Claude chatbot maker reported a preliminary revenue figure of more than $11.5 billion in its latest completed quarter, compared to $787 million in the corresponding period in 2025, and $4.73 billion in the first quarter of this year, the documents show. The second quarter of 2026 saw Anthropic report positive adjusted operating income, according to the documents.”
- Reuters relates,
- “Anthropic is in talks to buy Nvidia-backed startup Decart AI, according to a source familiar with the matter, as the Claude maker explores acquisitions that could help it handle growing demand ahead of its public listing.
- “Bloomberg News, which first reported the news on Wednesday, said a deal could be worth about $6 billion, citing sources.”
- Tech Crunch adds,
- “Anthropic will watermark text generated by its models, including Claude, to comply with European regulations, the company now says. The AI model maker confirmed the watermarking in an updated support page.” * * *
- “It’s not clear how much editing users need to do to remove the watermark. We have asked Anthropic to clarify and will update the story if we hear back.
- “The company noted that watermarking will apply to different products like Claude platform API, Claude, Claude Code, Claude Cowork, and Claude Tag.
- “Platforms are now rushing to watermark AI-generated content after backlash from users and to avoid regulatory scrutiny. Last week, AI music platform Suno said it will mark tracks created on its platform after a spate of legal challenges. Last month, newsletter service Substack teamed up with Pangram to flag AI-generated content. The company’s CEO, Chris Best, called out Claudefishing, a term used for people using AI to generate content.
- “Apart from Anthropic, other companies like Black Forest Labs, Google, Meta, Microsoft, OpenAI, and Synthesia have committed to adhering to the EU’s code.“
- Cybersecurity Dive informs us,
- “Cisco’s security revenue surged last quarter as the technology giant saw growing demand for products designed to protect businesses against emerging cybersecurity threats, including those enabled by artificial intelligence agents, the company reported Wednesday.
- “The company posted $17.3 billion in total revenue for its fiscal 2026 fourth quarter ended July 25, a year-over-year increase of 18%. Security revenue rose 14% in the quarter to $2.2 billion from a year earlier.
- “The rise of agentic AI is expanding the threat landscape, driving demand for our security and observability solutions to help monitor agent behavior and mitigate evolving threats,” CEO Chuck Robbins said during a Wednesday earnings call.”
- The Wall Street Journal notes,
- “Enterprise users spent $300 million on quantum computing in 2025, outranking research labs and governments as the primary spenders for the first time.
- “A Boston Consulting Group survey found that 62% of the top 25 global companies across 11 major industries spend at least $1 million annually on quantum.
- “Companies like HSBC, Allstate and EY are investing to prepare for future commercialization and to secure systems against quantum encryption threats.”
- Per Dark Reading,
- “Walmart, the world’s largest retailer, faces a complex cyber threat landscape, documenting 806 reported retail breaches in Verizon’s 2026 Data Breach Investigations Report.
- “Security leadership stresses balancing strong cybersecurity controls with business innovation and speed, avoiding operational drag that could lead staff to bypass safeguards.
- “Walmart’s security approach involves proactive transparency and trust-building with leadership, using color-coded executive summaries and open discussions on risks and mitigation progress.
- “Industry experts emphasize the evolving role of security operations as essential business partners, noting there is no one-size-fits-all model but a universal need for pragmatic resilience and honest communication.”
- and
- “The Patch Gap: Why Defenders Need to Think in Chains, Not Checklists
- “It’s time to turn from CVSS-backed patching to choke-point patching focused on breaking chains to critical assets.”
- “If the volume problem and prioritization problem can’t be solved by patchingfaster and scoring harder, then the framing itself needs to change. The question that the security team should ask is not “which vulnerabilities are most severe in isolation?” but rather “which vulnerabilities, if left unpatched, create a connected path from an attacker’s foothold to our most critical assets?”
- Per a CISA announcement,
- “This year marks the 20th year of Cyber Storm, a full-scale national cybersecurity exercise that for two decades has brought together the people who defend the systems Americans rely on. Held every two years, Cyber Storm X arrives as threats from geo-political activity, compromised edge devices, AI risks, and more present new challenges to our nation’s critical infrastructure.
- “As the nation’s largest cybersecurity exercise, Cyber Storm plays a vital role in preparing for potential cybersecurity incidents by testing and strengthening the nation’s ability to coordinate a unified cyber response. Participants from private and public organizations work together through a simulated crisis. Together, they learn as a team and build stronger relationships that will speed response during an actual event. Importantly, organizations can also update their response plans based on lessons learned during the exercise.” * * *
- “Learn more about Cyber Storm and past events at cisa.gov/cyber-storm. For more information about CISA’s exercise resources, visit CISA Exercises.”
- Security Boulevard adds,
- “CrowdStrike has announced a $100,000 international competition that challenges participants to manipulate live AI agents using prompt injection and other red-teaming techniques.
- “The competition takes the form of a virtual game called AI Unlocked: Agents of Chaos, created in collaboration with Amazon Web Services. Players take on a fictional mission to stop a shadow group from deploying malicious AI. To do that, they must manipulate the group’s own agents into revealing information and taking actions they were not authorized to perform. Their scores also depend on efficiency, with points deducted for every token used in their prompts.
- “The contest opens Aug. 31 and is divided into three acts. The first runs through Sept. 7 with a $10,000 prize, the second ends Sept. 14 and awards $20,000, and the final act runs from Sept. 15 through Sept. 29 with a $70,000 prize. The game is available online internationally, with an in-person option to play at CrowdStrike’s Fal.Con conference. Pre-registration is open, and contestants can replay completed puzzles to refine their prompts. CrowdStrike said the highest score recorded when each act closes will receive that act’s prize.”
- Here is a link to Dark Reading’s CISO Corner.
