July 28, 2026
- Anthropic's Claude Opus 5 was benchmarked as a cost-effective vulnerability-search tool nearing Mythos 5 on bug finding but falling short on exploit development, with offensive capabilities deliberately restricted (SecurityWeek).
· AI & Model Security
in Agentic AI Muscles Into the Offensive Toolkit
July 3, 2026
- Anthropic said the US Department of Commerce lifted export controls on Claude Fable 5 and Mythos 5, and it is restoring access. Anthropic.
· Policy & Regulation
in Ransomware on Autopilot, and a Pile of Critical Bugs Under Fire
July 2, 2026
A 19-year-old Scattered Spider member was extradited from Finland to face charges linked to 100+ intrusions and ~$100M in ransom payments. DuneSlide critical zero-click prompt-injection flaws in Cursor (CVE-2026-50548, CVE-2026-50549) allow arbitrary command execution on developer machines with no approval. Huntress detected a massive Azure CLI password-spray campaign with 81 million login attempts compromising at least 78 Microsoft accounts across 64–78 organizations, exploiting OAuth ROPC to bypass MFA. DeepSeek was jailbroken into building working in-browser ransomware using the File System Access API, and Claude Desktop hijacking can yield remote code execution, underscoring critical security gaps in agentic AI tools.
July 1, 2026
watchTowr Labs disclosed CVE-2026-8451, a pre-auth memory overread in Citrix NetScaler SAML handling that extends the CitrixBleed lineage, alongside five other patched flaws. A China-linked USB implant infected Japanese military networks for nearly a year via disaster-relief supply chains, while European defense targets faced spear-phishing campaigns abusing AWS Cognito for credential-less C2 infrastructure. Multiple AI agent safety bypasses emerged, including GuardFall (shell injection against coding agents), BioShocking (prompt injection stealing credentials), and poisoned MCP tool descriptions enabling data exfiltration without raising alerts.
June 18, 2026
- Anthropic was ordered by the U.S. government to abruptly suspend access to its top Claude Fable 5 and Mythos 5 models for all foreign nationals, citing national security — a notable precedent for export-style controls on frontier models (The Hacker News).
· Industry & Policy
in ShinyHunters Burns a PeopleSoft Zero-Day Through Higher Ed as Copilot "SearchLeak" Shows AI Is the New Exfil Channel
June 17, 2026
- GLM-5.2 dropped open weights with a 1M context window and is benchmarking as a top-3 model across open and proprietary — the release coincides with the US export-control directive that forced Anthropic to suspend foreign access to Fable 5 and Mythos 5, fueling bets on Chinese model providers. r/LocalLLaMA, Dark Reading.
· AI & Model Security
in Microsoft 365 Copilot 'SearchLeak' Enables One-Click Data Theft as Novo Nordisk Loses Internal AI Models to Extortionists