With our Five Eyes partners, we have published a joint statement warning organisations they have months - not years - to protect their systems from the accelerating cyber threat driven by frontier AI.🧵
To read the full statement⬇️
https://t.co/bxh0W4smpM
The US government, citing national security authorities, has issued an export control directive to suspend all access to Fable 5 and Mythos 5 by any foreign national, whether inside or outside the United States, including foreign national Anthropic employees.
The net effect of this order is that we must abruptly disable Fable 5 and Mythos 5 for all our customers to ensure compliance.
Access to all other Claude models is not affected.
We apologize for this disruption to our customers. We believe this is a misunderstanding and are working to restore access as soon as possible.
Read our full statement: https://t.co/bwn0sximKZ
NSA is releasing security design considerations for AI-driven automation leveraging MCP which, while simplifying the integration of diverse capabilities into powerful agent workflows, requires caution. Learn more: https://t.co/zn2DyUz5be
A sophisticated and multi-layered attack by the threat actor tracked by Microsoft as Storm-2949 demonstrates how a single compromised cloud identity could lead to a full-scale organizational breach. https://t.co/s1MMx0fI4L
Relying on social engineering and abusing legitimate administrative tools, Storm-2949 moved laterally across cloud resources and endpoints without using traditional malware, quietly exfiltrating large volumes of sensitive data.
This stealthy attack underscores the importance of strong identity protections, least-privilege access, and unified visibility across environments. Read the latest Microsoft Defender Research blog for guidance on detecting and containing multi-stage attacks before they escalate.
Congratulations @Hak5@hak5darren for 1 million subscribers on YouTube !!!!
Well deserved and thanks for all the amazing tools over the years!
May many more come.
🎉🎉🎉🎉🎉
https://t.co/YMgXS3HtJM
📢 Breached and TeamPCP announce supply chain attack competition with $1,000 USD prize and open-sourced Shai Hulud worm
The owner of Breached has announced a joint competition with TeamPCP offering $1,000 USD in XMR to whoever conducts the biggest supply chain attack.
As part of the announcement, TeamPCP's Shai Hulud worm has been open-sourced and hosted on the Breached CDN (also published yesterday on GitHub), with participants required to use the worm in their attacks. Winners are determined by total weekly and monthly download counts of compromised packages, with smaller package compromises added together to count toward the total.
▸ Actor: [Owner] diencracked in collaboration with TeamPCP
▸ Sector: Cybercrime Forum / Supply Chain Attack Tooling
▸ Type: Attack Competition Announcement / Tool Release
▸ Prize: $1,000 USD (XMR only)
▸ Country: N/A
▸ Date: 11/05/2026
Competition details:
▪ First-ever supply chain attack competition hosted on BreachForums
▪ TeamPCP's Shai Hulud worm released as open source and hosted on the Breached CDN
▪ Raw download link also provided for the worm
▪ Participants must use the Shai Hulud worm in their attack
▪ Submissions must include the participant's forum handle, preferably linked to their Breached profile
▪ Reasonable proof of access must be submitted alongside the entry
▪ Winner determined by the largest supply chain attack measured by weekly and monthly package downloads
▪ Compromises of multiple small packages are aggregated toward the total
▪ Prize paid by diencracked in XMR
Stop guessing what's redacted. Subscribers see everything → https://t.co/281Qjc6p2J
Our new multi-model agentic security system brings together more than 100 specialized agents across frontier and custom models to find exploitable bugs, delivering top performance on the CyberGym benchmark.
We used it ahead of Patch Tuesday to help find and fix 16 vulnerabilities. Today we’re announcing that customers can sign up to test it in private preview.
https://t.co/maAN55yZQ1
Microsoft is investigating mistralai PyPI package v2.4.6 compromise. Attackers injected code in mistralai/client/__init__.py that executes on import, downloads hxxps://83[.]142[.]209[.]194/transformers.pyz to /tmp/transformers.pyz, and launches a second-stage payload on Linux. The file name transformers.pyz appears deliberately chosen to mimic the widely used Hugging Face Transformers library and blend into ML/dev environments.
The main payload is a credential stealer, but it also includes country-aware logic; it avoids Russian-language environments and contains a geo fenced destructive branch that has 1-in-6 chance of executing rm -rf / when the system appears to be in Israel or Iran.
To mitigate this threat: isolate affected Linux hosts, block 83[.]142[.]209[.]194, hunt for /tmp/transformers.pyz, pgmonitor[.]py, and pgsql-monitor.service, and rotate exposed credentials.
The FBI is aware of a service disruption affecting an online Learning Management System (LMS). This disruption has impacted schools, educational institutions, and students across the country.
If you are contacted directly by anyone claiming to have your data, we recommend you not send payment or respond to their demands. By receiving a message, that does not necessarily mean your personal information has been compromised. Threat actors often exaggerate or fabricate their access to sensitive or personal information to prompt payment from victims. We encourage individuals to be cautious of unsolicited emails, calls, or texts claiming to be from your school, the LMS provider, or law enforcement and to verify the contact through known channels before responding.
We understand that the immediate concern for individuals/students is determining what, if any, of their data or other sensitive information may have been exposed. At this time, the strongly recommended course is to await formal guidance from your educational institution regarding the scope of the incident and the nature of any affected data.
If you believe you have been impacted by the attack, please file a complaint at https://t.co/DbJcDzldwF.
All crimes can have a devastating effect on those who have been impacted, as well as their families who may need help coping with what happened. Visit https://t.co/QkwTszk8Dx for more resources on coping with the impact of crime:
⚫ https://t.co/wC1eqXwymH
⚫ https://t.co/MMU78iJw0i
A historic UAP declassification effort is underway thanks to @POTUS.
We appreciate the Intelligence Community professionals, Department of War personnel, and others across the USG who are devoting their time and resources to this enormous, complex task. This administration is delivering unprecedented transparency for the American people.
MIT just quietly dropped a free AI curriculum that puts $50,000 university courses to shame.
12 books.
Zero tuition.
From the same institution that produced the people building the models everyone is talking about.
FOUNDATIONS
1. Foundations of Machine Learning — https://t.co/Un6UbjJ3Xo
2. Understanding Deep Learning — https://t.co/UQxZmyESdn
3. Machine Learning Systems — https://t.co/YAgrLVGAXt
ADVANCED TECHNIQUES
4. Algorithms for ML — https://t.co/YlBk59o8Hp
5. Deep Learning — https://t.co/KMO1uWPyk1
REINFORCEMENT LEARNING
6. RL Basics (Sutton & Barto) — https://t.co/sOZlDXzu41
7. Distributional RL — https://t.co/uOkviYiAq7
8. Multi-Agent Systems — https://t.co/Dx9caJVx1d
9. Long Game AI — https://t.co/K9Qm2TjAQ6
ETHICS & PROBABILITY
10. Fairness in ML — https://t.co/MgkLdRvicO
11. Probabilistic ML Part 1 — https://t.co/Zz33gQi1vG
12. Probabilistic ML Part 2 — https://t.co/qBe776EjCg
This is a complete MIT-level AI education.
Not a YouTube playlist.
Not a Twitter thread full of fluff.
Textbooks written by the researchers who built the field.
The people who actually study this will not just understand AI better than their peers.
They will understand it better than most people currently getting paid to work in it.
Most people will bookmark this and never open it.
The ones who open it tonight are the ones who show up in 12 months having built something nobody around them understands yet.
Bookmark this.
Open the first one tonight.
Follow @cyrilXBT for more resources that actually compound.
I will reiterate what I said earlier: I believe they should also investigate the mysterious and tragic disappearance of Professor Thomas Marsh in the Atacama Desert in 2022. His ULTRACAM instrument was particularly useful for searching for subsecond transients, see, for example, https://t.co/E5WJRBLpJS.
The Spanish-language (Chilean) news reports provided more details regarding the case...
A new perspective from Microsoft Research published in Cell makes the case that generative models are what oncology needs next, capable of integrating genomics, imaging, clinical data, and more into a unified system for cancer discovery. https://t.co/BrbuixIsgw
Finally, it is published 😁 Making Vulnerable Drivers Exploitable Without Hardware - my latest research on driver vulnerability hardware-gating, explaining the concept of hardware-dependent code and diving deep into creative deployment techniques - software-emulated phantom devices, driver restacking, and forced driver replacement — all explored through the lens of Bring Your Own Vulnerable Driver (BYOVD) attacks:
https://t.co/COJ0BKpZQe
My heart is breaking -- Nick (@nickpopemod) passed away this afternoon at our home. The last few weeks of his life, even as he suffered, he managed to do a few interviews from home. I was so lucky to have met and to have married Nick. He was a wonderful husband. I loved him dearly.