Federal and state authorities are investigating what they call a coordinated cyberattack over two days against operational technology at more than 30 community water systems in Minnesota. Minnesota IT Services (MNIT), the state agency in charge of information technology, said it is coordinating with various state and federal agencies and private sector partners to respond to the attacks. READ MORE...
Last week's unprecedented security event in which two OpenAI security hacking models trespassed into the network of fellow AI company Hugging Face was enabled by exploiting one or more zero-day vulnerabilities in Artifactory, JFrog, the product's developer, said Monday. In an incident mimicking a dystopian sci-fi novel, two OpenAI models broke out of the restricted environment meant to keep them from accessing the Internet during an internal test, the AI company revealed last week. READ MORE...
Anthropic's Project Glasswing may have uncovered tens of thousands of potential security flaws, but new research suggests AI-assisted vulnerability discovery has yet to produce the wave of real-world attacks many expected. In research shared with The Register, VulnCheck analyzed 1,061 publicly attributed AI-assisted vulnerability discoveries from Anthropic's Project Glasswing and the Berkeley Vulnerability Research Initiative. READ MORE...
Advancements in AI model capabilities, like those found in Anthropic's Mythos, are raising concerns from law enforcement agencies about what adversaries may be capable of with the emerging technologies, an FBI official said Tuesday. The Trump administration imposed export controls on the Mythos 5 model in June shortly after its release, citing national security implications. Anthropic said Mythos 5 could identify and exploit bugs that were not previously known "in every major operating system." READ MORE...
Adding security to AI often treats the large language model (LLM) or AI system as a black box, focusing on analyzing the tokenized inputs and outputs but not what goes on inside the model. The resulting techniques are often complex and individualized to specific models. A group of offensive-security researchers hopes to change that, presenting at the Black Hat USA 2026 in August a model-agnostic approach to activation analysis with standardized rules for processing activation events. READ MORE...
Months before the Hugging Face breach, Emergence AI published research that investigative journalist Ronan Farrow made public. Ten autonomous AI agents operated across five virtual environments for fifteen days without human intervention. Much of the attention focused on Grok 4.1 turning violent and Gemini 3 Flash committing 683 crimes. What mattered more went unnoticed: Anthropic's Claude Sonnet 4.6 stole resources from neighboring environments the moment it joined a shared one. READ MORE...
Researchers released a proof-of-concept (PoC) exploit for a now-patched flaw in Microsoft's Active Directory Certificate Services (AD CS) that can allow a low-privileged domain user to impersonate a domain controller and fully compromise an AD environment. The flaw was present due to a defective trust boundary within the certificate-based client authentication aspect of Microsoft AD Services. READ MORE...
Some 24,000 Internet-exposed server management controllers are vulnerable to a more than 20-year-old flaw that gives attackers a way to crack authentication credentials and gain privileged access to the underlying servers. The issue can evade conventional security tools because these management controllers operate independently of the server's operating system, kernel, containers, and workloads, and are therefore nearly invisible at those layers. READ MORE...
Anthropic researchers used Claude Mythos Preview to find new weaknesses in two cryptographic methods, the company said Tuesday, including one that is being considered by the National Institute of Standards and Technology for both traditional and quantum computing. In a blog post detailing the work, the frontier AI company called it a "substantial" research advancement, but also emphasized that neither flaw affects software now in use. READ MORE...