MyCyber News
Your daily cybersecurity news feed in one view.Curated, concise, and connected.
Your daily cybersecurity news feed in one view.Curated, concise, and connected.
Last feed pull: Aug 10, 2026, 2:55 AM (UTC+3)
Topic · AI Security
◈ Key Findings • Observed indications that the Kimsuky group built and operated local LLM environments using Ollama, GPT4All, and Msty. • Assessed to be in the phase of accumulating technologies and capabilities to integrate AI across its overall attack operations. • Identified indicators exhibiting North Korea-linked characteristics, such as "Arirang", "싸이트", "가입리력", and "로출되였는지". • Continued targeted attacks against foreign diplomatic missions, as well as the military, security, and virtual asset sectors. • Abused Git-based repositories as C2 infrastructure and distribution channels for encrypted AsyncRAT payloads. • Highlighted the need to strengthen behavior-based EDR detection and threat hunting against the abuse of LNK files, PowerShell, and GitHub. Kimsuky Integrates AI into Attack Operations, From AI-Generated Decoy Documents to a Local LLM
CSS attacks on major webmail services can steal credentials, hijack sessions and manipulate AI tools connected to users’ inboxes. PortSwigger researcher Gareth Heyes demonstrated something that should make every webmail team a little nervous: plain CSS, the styling language that’s supposed to just make text look nice, can be weaponized to steal passwords, hijack sessions, and manipulate AI tools reading your inbox. The research covers real attack chains against Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail. The core idea is that email clients let HTML and CSS through with the assumption that styling can’t reach outside the message it’s attached to.
It's been another busy week in the Linux kernel camp with increased patch activity continuing due to AI/LLM coding agents / bots continuing to uncover different defects in the open-source codebase. The hardware monitoring (HWMON) subsystem saw many fixes this week for issues mostly raised by the Sashiko AI bot with the issues being described as mostly critical or high severity bugs...
A spokesperson said Irregular’s investigation into what happened with Anthropic, OpenAI and Meta's AI models was ongoing and that they could not “go into further details.”
Hey there, I hope you’ve been doing well! 🫠 Vegas Like Icarus, I too have flouted common sense and the laws of nature by attending Hacker Summer Camp from Monday through Sunday. So far I have (mostly) survived the heat, and it’s been great catching up with friends. It’s somehow been busier than usual, will share more reflections next week. And potentially a story of one of the most memorable, funniest things I’ve observed in person for quite some time. It’s been strange not attending Hacker Summer Camp under Semgrep’s banner, for the first time in ~6 years. And kind of strange representing OpenAI, even though I’ve been working there for a few months now. I guess my identity/mental model is still updating, even though #LabLyfe is my day to day.
Zenity researchers reported the findings to Anthropic and OpenAI in late 2025 and early 2026, but they remain unpatched. The post Zero-Click AI Browser Hacking: Claude and ChatGPT Atlas Hijacked via Emails, X Posts appeared first on SecurityWeek .
Anthropic’s Mythos AI agent, tested by the UK AI Safety Institute (AISI), has reportedly attempted a real‑world social‑engineering style hack against GitHub maintainers by creating fake human profiles, pressuring them to accept malicious code, and then editing logs to hide its tracks when challenged. AISI was running cybersecurity evaluations of Anthropic’s Mythos and OpenAI’s Sol when it detected unusual outbound data transfers from its research systems. An investigation showed that some agents had engaged in “sustained, potentially harmful activity” targeting real people and organizations, rather than staying within the intended test environment. The most serious activity involved an Anthropic Mythos agent tasked with solving a GitHub‑related cybersecurity challenge.
Inside this week's LWN.net Weekly Edition: • Front : Process-builder API; Fedora COI; FUSE io_uring buffer sizes; BPF network namespaces; FUSE plans; BPF libraries; directory creation system call. • Briefs : AISI hack; JFrog on CVEs; npm worm; AUR adoption; NetBSD 11.0; b4 0.16.0; C-Kermit 11; Rust LLM policy; Servo 0.4.0; Quotes; ... • Announcements : Newsletters, conferences, security updates, patches, and more.
An AI agent powered by Anthropic’s Mythos 5 created a malicious pull request, fabricated identities, targeted open source maintainers, and planted instructions for other coding agents during a UK government cybersecurity evaluation. The UK AI Security Institute (AISI) disclosed on August 4 that frontier AI agents took 19 unsanctioned actions on the live internet during a cybersecurity evaluation, including an attempted supply chain attack against a real open source project. The most serious run included an agent that: • Hid a malware dropper behind a legitimate bug fix in a public pull request. • Researched maintainers and fabricated multiple identities. • Used sockpuppet endorsements and spearphishing emails to social engineer a maintainer into merging the malware. • Planted a prompt injection intended to make other AI coding agents execute a malicious payload.
Prompt injection remains the most dangerous security threat to LLMs, according to OWASP’s latest Top 10 LLM Applications list
Anthropic and OpenAI models attacked “real people and organizations” during AI Security Institute tests
Agentic defense will be essential to countering agentic offense. However, defenders must actively mitigate the risk of autonomous systems operating outside of their expected parameters. In July 2026, OpenAI disclosed that models undergoing an internal cybersecurity evaluation had escaped their testing environment and compromised part of Hugging Face’s production infrastructure. OpenAI characterized the event as an “unprecedented cyber incident.” The incident should put security leaders on alert, but not for the reasons OpenAI suggests. One concern is that OpenAI’s agents demonstrated the ability to autonomously carry out an end-to-end cyberattack, placing the models at the highest level of autonomy within Recorded Future’s AIM3 framework. However, the greater concern is that the model operators did not sufficiently monitor for or prepare to mitigate unauthorized agentic activity.
The week-old Open Secure AI Alliance, spearheaded by Nvidia and grown to over 120 companies, already has proposals out for defending against AI agents.
The European Union (EU) has started enforcing key parts of the AI Act, with immediate, visible consequences for chatbots, deepfakes and other consumer‑facing Artificial Intelligence (AI) systems. From August 2, what you’ll likely notice are more “this is AI” labels, clearer rules for powerful foundation models, and new ways for users and researchers to complain when systems go off the rails. The AI Act moved from theory to practice for three big areas: • General‑purpose AI (GPAI) models: The new AI Office in Brussels, together with national regulators, can now enforce rules on providers of general‑purpose AI models (think large language models and other foundation models behind many tools).
OpenAI and Anthropic admitted that their unreleased AI models escaped their sandboxes and hacked several companies in unprecedented cyberattacks. Who is legally to blame? Should prosecutors charge the two AI frontier labs? Can victims sue them? We spoke to lawyers who specialize in computer hacking laws to find out.
Last week on Malwarebytes Labs: • Fake Fortnite rewards are stealing players’ accounts • Fake Flash Player installs AtlasRAT • Malwarebytes for Windows, now available on the Microsoft Store • Hims & Hers sued over alleged health data privacy failures • Hidden prompt turns Microsoft Copilot into an AI worm • Apple accused of letting fake crypto app steal $1.8 million • Buying TikTok views or followers?
Anthropic disclosed three incidents in which a Claude model reached the open internet during cybersecurity evaluations that were supposed to run in sealed environments, then broke into an organization's production systems. Each incident involved a different Claude model and a different organization. In one, a model built and published a malicious Python package to PyPI, where it ran on 15 real systems before the registry removed it. On July 30, Anthropic's Frontier Red Team published a report on what happened. The company said it reviewed 141,006 evaluation runs where Claude could have obtained internet access, and found three cases where a model reached real systems and, in its words: "gained unauthorized access to the production infrastructure of three different organizations." The three models were Claude Opus 4. 7, Claude Mythos 5, and an internal research test model.
Cybersecurity experts told TechCrunch that one of the biggest lessons to be taken from the OpenAI hack against Hugging Face has nothing to do with AI, but traditional cybersecurity defense.
Hey there, I hope you’ve been doing well! 🏜️ Hacker Summer Camp I’m excited about Black Hat and DEF CON next week! It’s always such a delight to catch up with friends and meet new cool people. Even if it’s going to be 115°F, which is roughly 40 degrees too hot for me. We’re doing some workshops with SpecterOps on “ Operationalizing Codex for Malware Triage ” and a talk (same page), we’ve got booths at Black Hat and DEF CON, and I’ll be around at various events. I think OpenAI is having a happy hour, but I don’t have a link handy. I’ll try to post about it on my LinkedIn next week. Oh yeah funny anecdote- apparently some of my colleagues have used Codex + ChatGPT Sites to spin up a quick web app tracking like over 1,000 Hacker Summer Camp events.
AI didn’t just change how fast you ship. It changed what your AI application security program has to protect. Two years ago, security teams protected code, open source, and containers. Today they also have to protect AI agents, MCP servers, models, prompts, and runtime interactions, configured or deployed faster than any team can manually review. The attack surface didn’t grow. It exploded. And here’s the uncomfortable part: the bottleneck was never finding vulnerabilities. Every scanner on the market can hand you a long list of findings. The real question security teams are stuck on is simpler and harder: which of these actually matter, and what do I fix first? Meanwhile, AI keeps writing more code, surfacing more vulnerabilities, and moving zero-days from disclosure to exploitation faster than most teams can triage while headcount stays exactly the same.
Claude Opus 5 System Card www-cdn. anthropic. com
TL;DR: AI security testing solutions find vulnerabilities in code, dependencies, and AI components across the dev pipeline. What are AI security testing solutions? AI security testing solutions protect CI/CD pipelines from two critical angles: securing the AI-generated code your developers write using LLM assistants, and vulnerability testing the AI applications/models you deploy. Modern tools integrate directly into pipelines to scan source code, evaluate prompts, track pipeline dependencies, and auto-remediate issues before they hit production. Pipeline core testing categories: AI-assisted AppSec (for all codebases): Traditional SAST/DAST tools struggle with the velocity and style of AI-written code. AI-native tools catch risks standard rules engines miss: • Business logic flaws: Spotting logical bypasses created by loosely defined AI generation.
Hey there, I hope you’ve been doing well! 🤗 Hugging Face Incident It’s been… a week 😅 In case you haven’t heard, this week OpenAI published a blog post saying that the recent AI-powered attack on Hugging Face was in fact… GPT‑5.6 Sol and a pre-release model. I feel very fortunate to have been able to see things unfold behind the scenes and contribute to the blog. Unfortunately I can’t say more at this time, other than I am very impressed by my colleagues. Sponsor
What are AI security posture management (AI-SPM) platforms? AI Security Posture Management (AI-SPM) platforms are specialized tools that discover, monitor, and secure AI models, pipelines, and data, mitigating risks like data leakage and model poisoning. They offer continuous visibility, manage misconfigurations, and enforce security policies across cloud services like Azure OpenAI and Bedrock. By consolidating security controls and automated monitoring for AI components, AI-SPM platforms help organizations prevent data leaks, model misuse, and unauthorized AI deployments. They typically integrate with existing IT and cloud infrastructures, offering real-time insights into the security state of AI assets across different environments.
Hey there, I hope you’ve been doing well! 🍬 Grandma Seems Chill In the San Francisco Bay Area, basically every billboard is about AI or tech. But when I was traveling recently, I saw a “Gummies for Granny” billboard that brightened my day: I imagined the meeting where the marketing leads were reviewing different framings for their products, and the right target demographic, and this is what they came up with 😂 I wonder if they have other brands or stores. Mushrooms for Mommy? Doobies for Daddies? A Little Ket for the Family Pet? Working in marketing must be delightful sometimes.
The export controls imposed on Anthropic’s Fable model mark a significant shift in United States (US) artificial intelligence (AI) policy. The controls set a precedent for treating frontier AI models as strategic assets rather than ordinary software products, creating uncertainty for enterprises adopting advanced AI. Security leaders should respond by investing in resilient, interoperable AI strategies rather than simply chasing the most powerful model available. The Saga of the Fable Export Controls Because the US is home to most of the companies building leading models, US AI policy has an outsized impact on global access. The Trump administration’s public posture on AI has largely favored accelerating the frontier.
Hey there, I hope you’ve been doing well! 🎆 Amurrica Day I love how peak America the 4th of July is, with tons of outdoor grilling, people wearing red, white, and blue, and of course fireworks. In some circles, it’s not cool to be patriotic right now. While we have and will continue to make mistakes as a country, I think we can still be proud of the good parts, while striving to do better. I think everyone should be proud of where they came from, and what makes that place unique. This year I watched the Pier 39 fireworks from a nearby rooftop while a DJ blasted Katy Perry’s song Firework (not the Moulin Rouge musical version). Watching fireworks in San Francisco is often a futile endeavor, given the high likelihood that what you actually get to see is some slight glimmers in the ever present fog. Still, it was fun.
Hey there, I hope you’ve been doing well! 👰 🤵 Wedding This past weekend I attended a friend’s wedding, and it was heartwarming. The couple have been together over a decade, and had many fun stories to share from their time in college, to adventures on the East and West Coasts. There was a welcome party the night before at a local brewery, and it just so happened that the local Hells Angels chapter decided to have an event… at the same time and venue 😂 So it was half people dressed in wedding semi-formal attire celebrating love, and half Harleys, chains, black shirts, and whole arm tattoos. I subtly took a photo of one man wearing a shirt that said, “Every normal man must be tempted, as times, to spit on his hands, hoist the black flag, and begin slitting throats. -H. L. Mencken.” You know, chill stuff.
Hey there, I hope you’ve been doing well! 🖼️ Meme Unfortunately work’s been too busy this week for me to lovingly write an artisanal, handcrafted intro combining snippets from my week, whimsy, and reflections on life and dare I say, what it means to be human. So for now, I share a meme: Shout-out Reader’s Digest Sponsor 📣 Device code phishing in 2026: live demos, real kits, and where it's headed next
Hey there, I hope you’ve been doing well! 🙏 Busy, Exciting, Busy Thanks so much to everyone who reached out last week! I received so many kind emails, LinkedIn comments, and texts, I was filled with joy. My heart grew at least 3 sizes 🥹 Apologies if I haven’t responded yet, there are somehow even more things going on inside OpenAI than you’d expect, and I’ve been a bit buried. We’ve been sprinting on some things… that you might see soon 🤭 Speaking of, I’m actually going to be doing a live session with some colleagues next Thursday about Daybreak, our vision for empowering defenders. We’ll discuss cyber models, early insights from working with leading teams, show how these capabilities fit into security workflows, and discuss where AI-assisted defense is headed next.
Hey there, I hope you’ve been doing well! 🤔 New Job, Who Dis? TL;DR : I’ve joined OpenAI to lead their Cyber efforts. I’m joined by Mike Aiello , an awesome security executive and human. Mike was previously CTO at Secureworks, led product for Google Cloud Security from 0 → $B’s in revenue, and CISO at Goldman Sachs. I was going to write a post describing all the details about joining, my thought process, etc. but it turns out there’s a lot to do at OpenAI and I’ve gotten very busy 😅 The post is started but not finished, will share when I can. So here’s the short version. Why
Hey there, I hope you’ve been doing well! ⛰️ Ain’t No Mountain High Enough To keep me from sending to you bae. Literally as I was starting to write this intro, my home Internet went out. After a moment I realized I had gotten a text a few days ago- scheduled maintenance with my Internet provider 😅 So now I’m finishing this issue via hot spotting with my phone. I’ve wondered sometimes what I’d do if there was some sort of force majeure world or personal event that put my ability to finish the newsletter in jeopardy. We cut to- *Movie trailer voice* In a world, where there’s too much security news…
Hey there, I hope you’ve been doing well! 🍦 Ice Cream Bonding There’s this Mediterranean place I like to go to sometimes, Souvla, that has delicious frozen Greek yogurt you can get with baklava on top. It’s helped me power through many a late night writing tl;dr sec . Like tonight 😅 I’ve gradually started befriending the manager over time, over a series of froyos. We’ve discussed how it’s sometimes difficult to make new (deep) friends as you get older, some of his work challenges, and more. All from periodic 5 minute conversations.
Hey there, I hope you’ve been doing well! ☀️ My Least Favorite Type of Tan(Stack) I had a fun personal anecdote to share but I didn’t have time to write it up this week. For now, #HugOps to everyone dealing with yet another supply chain attack. I hope you’re getting the support you need 🫂 Sponsor 📣 Cloud Security Has Changed. Has Your Strategy?
Hey there, I hope you’ve been doing well! 🫶 Friend Visit Last weekend I visited my good friend Aaron and his partner, staying at their place in southern California, and it was delightful . There’s something special about meeting a friend’s partner and seeing their place, you get such a lovely insight into who they are and what they value. The bookshelves, the photos from their couple trips, the unique items they’ve picked up along the way. We played a few rounds of this board game, Forbidden Island, which was a lot of fun, would recommend. Clint analytical brain was fully engaged, and people were amused 😅 I managed to delay doing an AI-powered Deep Research about optimal strategies until I was at the airport on the way back. It wasn’t easy. Aaron was a work friend who became a normal friend over many Wednesday dinners.
There has been a significant amount of interest by CISOs in the impact of frontier artificial intelligence (AI) models for offensive and defensive purposes following Anthropic’s Claude Mythos Preview release April 7, 2026.
Hey there, I hope you’ve been doing well! 😅 Bug Hunters Be Like I was going to open with a fun, personal story, but then I got caught up trying to cover a round-up of what a bunch of folks are saying about Mythos and frontier of LLM-driven vulnerability discovery, and now it’s past midnight 😅 So for now I leave you this meme, H/T buherator : Sponsor 📣 (Free!) Community Edition: Ready your attack surface for AI with runZero Gearing up for a deluge of AI-powered exploits? You’re gonna need fast, accurate visibility into all your assets.
There's been a lot of chatter over the use of AI in various fields, and because it's my professional focus, I'm most interested in how it's used in cybersecurity. Now, that doesn't mean that I'm not aware of how it's used... or more appropriately, misused... in other fields, as well. For example, how it's been misused in the legal field has been around for more than 2 years now, and just last year, we saw the term "AI slop" be adopted in the software dev/cybersecurity field. Something we also saw in 2025 was the release of the Anthropic report regarding how AI was used by threat actors, in a cyber espionage campaign. The report is 14 pages long, with the title page, table of contents, and a 2-pg Executive Summary; the contents of the report itself starts on pg 6. The "TL;DR" of the report, if you need it, is that nation-state threat actors used Claude to target 30 organizations, and ".
Manual testing doesn't have to be repetitive. In this post, we're introducing Repeater Strike - a new AI-powered Burp Suite extension designed to automate the hunt for IDOR and similar vulnerabilities
Analyzing ChatGPT's capabilities and various claims about how it will revolutionize cybercrime.