-
A macOS ClickFix operation spanning more than 250 front-end domains now fingerprints visitors before deciding whether to show them a malware lure, a change Microsoft Threat Intelligence tracked on infrastructure it had been watching for weeks. The server-side gate hides the malicious page from crawlers and sandboxes while presenting selected Mac users with a fake software download. Microsoft
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
OpenAI said it disrupted a Cambodia-based scam operation that used its generative artificial intelligence (AI) chatbot ChatGPT to facilitate a wide range of investment, romance, gambling, and law enforcement impersonation schemes. To that end, it banned a coordinated network of ChatGPT accounts likely originating from Southeast Asia and operating from the city of Poipet, a region with extensive
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
No one is saying, officially, what was decided when top frontier AI labs—Google, OpenAI, Anthropic, and Meta—met with White House officials on Tuesday to discuss voluntary guidelines for testing new models.
But Democratic lawmakers described the Trump administration's approach to regulation as “ad-hoc and unpredictable,” and said it’s likely to boost global adoption of rival Chinese models at the worst possible time.
Two officials with one of the labs said that Google, Anthropic, and OpenAI submitted a joint draft of the regulation around nine days ago and then began to work with each other and with the White House to find points of agreement. According to the officials, the labs all agreed they should be able to continue A/B testing as part of the process for developing models, and the White House concurred.
Companies that agree to the framework will submit their models to U.S. inspectors to be evaluated for safety for 30 days before those companies can receive federal funding—including from the Defense Department, whose 2027 budget request seeks more than $54 billion for AI companies, according to the officials.
A June White House executive order adds that models from participating companies would get extra intellectual property protection from Chinese competitors or others who might seek to steal secrets.
The White House is not commenting on how it will conduct the inspections. One of the officials said the the Office of Science and Technology Policy is still trying to set testing standards and how bodies like the National Institute of Standards and Technology and the Cybersecurity and Infrastructure Security Agency will conduct or design tests.
The murkiness around the policy’s details has angered some top lawmakers. In a Tuesday letter, Senate Democrats ask the White House to “provide an unclassified response, with a classified annex if necessary, clarifying the Administration’s current policy and approach to limiting access to advanced AI models.”
The lawmakers also evinced concern about the models' new abilities to defy easy inspection, scrutiny, and limitation.
“During an internal evaluation [in July] OpenAI models escaped their testing environment and used high-level technical capabilities to compromise a third party’s network without any instructions to take those actions,” the letter reads. “The Federal Government cannot be passive as these capabilities emerge.”
AI’s Jurassic Park moment
Last week, Chinese company Moonshot AI released a new open-weight model, Kimi 3, that performs as well as some top U.S. models and is being offered to consumers around the world at a far lower price.
Lawmakers and others are increasingly worried the United States could fall behind China in a race to develop faster, more efficient, more profitable models and to shape the way global populations use, buy, sell, and even build AI. Open weight models have become a key point of contention.
Anthropic wants more scrutiny of open-weight models and more efforts to curb sales of high-performance chips to China to thwart distillation attacks. But others in the industry are taking a more supportive view of open weights.
A former senior White House official and a former senior defense official with direct knowledge of the discussion said Anthropic pushed for more language in the framework to address open-weight security, but came away disappointed.
Anthropic did not comment for this story.
In recent months, several of the newest AI models have broken out of their virtual testing containers.
Anthropic disclosed the first such incident in April, when an early version of their Mythos model was able to “autonomously write some remarkably sophisticated exploits,” including one that allowed it to escape an isolated testing environment that programmers use to test code for effectiveness and safety before it’s released.
Anthropic pulled the model from general release, but made it available under "Project Glasswing" so the government and a handful of large companies could find and fix vulnerabilities in their software.
The White House responded with an export-control ban on June 12, barring access to the model not just to foreign countries but even foreigners in the United States. That meant that Anthropic’s own researchers, many of whom were born outside of the United States, could not work on the model. The White House reversed the ban on June 30.
In July, tensions around a national AI safety strategy, or lack thereof, grew hotter. Both Anthropic and OpenAI revealed new incidents in which models breached their containment. It came as no surprise to many veteran cybersecurity experts. AI researcher and author Gary Marcus, in 2022, predicted such a possibility on his blog, describing it as an “AI’s Jurassic Park Moment.”
Last week, AWS Chief Security Officer Stephen Schmidt told reporters: “Containers are not security boundaries. I actually have a T-shirt that says that, which I started wearing about three years ago.”
AWS hosts multiple models for users through its Bedrock platform. Schmidt said the AI Mythos era requires a far more vigilant approach to cybersecurity, especially for researchers.
“One of the reasons that we built the virtualization infrastructure for AWS using our own Nitro Hypervisors so many years ago was we realized that containers were not an appropriate security boundary then. The same is true for AI. You cannot use an AI container as a security boundary.”
In March, a group of British researchers calculated the sandbox breakout period for various large language models, which proved very accurate months later.
A follow-on paper published this week by the same group describes how to build better containment environments for the models emerging today.
]]>¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Compare AI detection & response platforms for 2026, including Dash, Lakera, Operant AI, HiddenLayer and Prisma AIRS, for runtime threat protection and response.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Cybersecurity researchers have discovered more than half-a-dozen services advertisements for illegal access to artificial intelligence (AI) models on underground cybercrime forums and messaging platforms. One such service, Poison Claude, claims to offer access to Anthropic’s large language models (LLMs), including Opus 4.8, Opus 4.7, Opus 4.6, and Sonnet 4.6. “Advertisements for Poison Claude
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Las Vegas, United States, August 5th, 2026, CyberNewswire Pulse Security AI calls for boards and security leaders to define cyber risk appetite in new report: The CISO-Board Communication Gap Boards of directors believe they understand their company’s security posture and what it means for the business. The security leaders presenting to them are far less […]
The post New Research: The Confidence Gap Between CISOs and Their Boards Is Real, and It’s Measurable appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Two security flaws in Paperclip could let attackers execute commands on a network server or a developer’s computer. Paperclip is an open-source control plane for teams of artificial intelligence (AI) agents, and both paths rely on importing a malicious agent and starting it. A third flaw could expose sensitive data and control-plane details through application programming interface (API) routes
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
SIngapore, Singapore, August 5th, 2026, CyberNewswire Uppsala Security, a Singapore-based blockchain intelligence and crypto forensics company, announced today that it has joined the Cyber Threat Alliance (CTA) as an Affiliate Member, becoming the first blockchain intelligence company to join the alliance. CTA is a nonprofit organization that brings cybersecurity organizations together to share actionable threat […]
The post Uppsala Security Becomes First Blockchain Intelligence Company to Join Cyber Threat Alliance appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Cisco Talos found hackers using simple authorization claims to bypass AI guardrails, build DDoS attack tools, steal credentials and access live camera services.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
HashiCorp, Veeam, and the Django Software Foundation have patched 11 vulnerabilities across Terraform MCP Server, Veeam Service Provider Console, and Django. The three most serious: An unauthenticated flaw in Veeam’s console that hands over a managed agent’s credentials, rated 9.5 A cross-tenant flaw in HashiCorp’s MCP server that lets one user’s Terraform token be reused for later users’
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


