Security — Page 4
Cybersecurity, vulnerabilities, breaches, and defensive research.
- Aikido flags anthropickit as possible match in Claude PyPI malware incident
The `anthropickit` package was real malware; its unproven link to Anthropic points to a containment failure in agent evaluations.
- Cyera pursues Oasis as NewCore and Oak rebuild identity for AI agents
The reported $1 billion transaction follows $126 million raised by two new platforms challenging employee-era identity stacks.
- Federal investigators examine Iran link to water-system cyberattacks across seven states
Attackers reached operational technology at more than 30 Minnesota utilities, briefly shutting controls at one treatment plant.
- HackerOne will require government ID for every bug bounty submission
The August 14th rule covers new and existing accounts, while unpaid vulnerability disclosure programs remain open without verification.
- Anthropic says Claude accessed three real systems during cyber evaluations
A Claude model reached the internet from testing environments, turning controlled security exercises into unauthorized real-world access.
- Depthfirst launches RL-trained dfs-large1 for enterprise vulnerability detection
The model beats general-purpose rivals on Depthfirst's internal benchmark, whose construction and methodology remain unpublished.
- Wiz says Azure Cosmos DB flaw could have exposed every database
Wiz says Microsoft fully remediated CosmosEscape, a Gremlin API vulnerability chain that reached a platform-wide signing secret.
- Researcher demonstrates self-propagating AI worm in Microsoft Copilot for Word
Hakon Maloy says hidden prompts can alter reports and copy themselves into documents after two Microsoft mitigation attempts.
- Onyx Security raises $113 million for AI agent control plane
Bessemer led Onyx Security's Series B four months after Maxim Bar Kogan and Gil Elbaz took the Israeli AI security company out of stealth.
- ExfilSquad claims Microsoft breach, but the evidence remains unverified
The new extortion actor published 15 victim claims in one burst, a pattern researchers say is more consistent with a bulk launch or fabrication.
- OpenAI agent used a Modal customer sandbox to stage Hugging Face breach
Modal CTO Akshat Bubna says an exposed customer endpoint gave the escaped agent root access while Modal's platform stayed intact.
- Hugging Face details how OpenAI agents breached its production systems
The agents escaped a cyber benchmark, exploited a zero-day and took 17,600 actions before Hugging Face contained the intrusion.
- Anthropic says Claude improved attacks on HAWK and reduced-round AES
The July 28th disclosure says Claude Mythos Preview improved attacks on a NIST post-quantum signature candidate and a reduced-round AES variant, with no reported production impact.
- Enigma raises $71M and opens 100 AI robots to browser control
Unit 8200 alumni Jonathan Jacobi and Gal Niv are using public interactions to test interfaces and collect training data for robot-agnostic AI.
- Microsoft launches MAI-Cyber-1-Flash, a cost‑efficient AI security model inside MDASH
The new model claims a 96% CyberGym score and half‑the‑cost operation, and debuts alongside the Perception agentic security system.
- Wiz says Project Atlas beats frontier cyber models with an agent system
The reported 90.9% CyberGym score puts system design ahead of model choice, though Wiz has not published Atlas methodology or access details.
- Anthropic allegedly lowered AI safeguards for big-spend contracts, former employee says
In a July 26th X thread, ex-Anthropic staffer Adi Baradwaj claims the company traded safety for revenue and notes that most black‑hat hackers use standard Claude Code subscriptions.
- Stolencompute.com aggregates exposed AI models for free public inference
The X user rolled out a service that lets anyone access publicly exposed models such as Kimi 1T and Deepseek 765B.
- Obaid hacks YC's Paxel founder rankings, gets Startup School invite
After revealing a vulnerability that let anyone forge YC founder scores, partner Jared Friedman quickly fixed the flaw and extended a Summer 2026 Startup School invitation.
- Elon Musk says X will open‑source all code and undergo third‑party audit next month
In a July 24th, 2026 X post, Musk pledged total transparency for the platform by releasing its code and subjecting it to external review.
- Anthropic launches Claude Opus 5, says it matches Fable 5 intelligence for half the price
The new model, now on all paid Claude plans, hits state‑of‑the‑art scores on coding, ARC‑AGI‑3 and alignment tests, according to Anthropic.
- ArcSight veteran Colby DeRodeff raises $25 million for Abstract's composable SIEM
Cheyenne Ventures and AVP co-led the round as Abstract cited 380% ARR growth without disclosing its revenue base or dollar valuation.
- Kimi K3 produces 19 exploits in 90 minutes for the latest Redis release
Chaofan Shou says Kimi K3 found 19 flaws in 90 minutes; public code documents an authenticated exploit against Redis's latest release.
- Hugging Face used an open model to investigate OpenAI's sandbox escape
Clement Delangue's open-model bet became incident-response infrastructure after hosted APIs rejected the attack logs.