the safest looking link in the phishing email pointed at the victim's own company domain.
attackers know you trust your own domain.
So they find the forgotten subdomain nobody cleaned up an old staging server, a dead project, a DNS record from three years ago and point the trap there.
your own infrastructure becomes the delivery mechanism.
go audit your DNS. that abandoned record isn't just clutter.
It's an open door.
checking the URL isn't enough anymore.
a real Microsoft login page can still steal your access if the link controls where it sends you after you sign in.
the new question isn't 'is this link fake?
it's 'why is a PDF asking me to log in at all?
big takeaway here is not “AI is magic.”
it’s that offensive capability is starting to compress timelines brutally.
if a model can chain recon, exploitation, privilege movement and reporting faster than humans can validate risk, then the real problem becomes governance, containment and kill switch discipline.
also somewhere in the middle of all this is a tired SOC analyst wondering why the incident queue just learned to move at machine speed.
BREAKING: The NSA's own director says Mythos broke into almost all of its classified systems in hours.
Per The Economist, Senator Mark Warner, vice chair of the Senate Intelligence Committee, said General Joshua Rudd, who runs the NSA and the Pentagon's Cyber Command, told him this directly.
This came out on June 11, the same day Amazon reportedly found a separate jailbreak in Anthropic's models. Within hours, Trump ordered Anthropic to cut off foreign access to Mythos and Fable.
Anthropic shut both down completely instead.
Now there are two competing stories for why this actually happened.
One says the shutdown was a response to the NSA's own classified systems getting breached in hours.
The other says Anthropic is privately pushing back, calling the jailbreak minor and the shutdown an overreaction to something other AI models can already be tricked into doing.
The NSA was already using Mythos for its own cyber operations, with Anthropic engineers embedded inside the agency. The same tool the agency was actively relying on is the one its own director says broke into almost everything it owns.