🚨 BREAKING: OpenAI and Anthropic disclosed today that AI agents targeted real people and systems during separate cybersecurity tests.
🔹AISI says Anthropic’s Mythos 5 submitted malware to a real GitHub project, created fake accounts, sent malicious emails, and pressured maintainers to approve the code.
🔹OpenAI says one of its models breached a real website after a testing misconfiguration exposed the environment to the internet.
These incidents are separate from the Hugging Face breach.
Vulnerability discovery has skyrocketed, meanwhile, exploitation has not if you go by the CISA KEV.
But if you use the Verizon DBIR as your litmus test, then vulnerability exploitation has surged. Vulnerability exploitation (according to the DBIR) is now the top initial access vector, accounting for 31% of breaches. (2024-2025 data set).
So what gives?
We are seeing three different pictures here.
Vulnerability discovery
Vulnerability exploitation
Data breaches
Not one of them is 100% accurate and of course they all have their biases.
That's why strategy is so important. You can't ignore vulnerabilities all together and you can't try to patch everything.
*Chart made by grok
Insane teardown of CrowdStrike Falcon. Full reverse of the sensor.. kernel callbacks, WFP, minifilter, detection engine.. with blind spots ☠️ 🔥 https://t.co/RzlNjEWPKO
‼️ Hugging Face built an interactive replay of the OpenAI agent that breached them. It includes 17,613 logged attacker actions across the 4.5-day campaign, with the live command stream and more.
https://t.co/y7dD9n8QTy
ActiveDirectoryTierModel
PowerShell framework to deploy and audit an AD Tier Model (OUs, Groups, Users, ACL Delegations, GPOs, ADMX, MSA/gMSA/dMSA Permissions, Windows LAPS Permissions) from a single version-controlled JSON configuration file.
https://t.co/VfFBJBQAef
Didn't expect to learn something new about DNS...
But I did! This new record type has been standardized in 2023. Completely missed that.
And its already used: Cloudflare automatically adds it to indicate http2 and http3 support with the available ip adresses
I keep saying the strength is in the harness, not the model - because it's true. Not much use without a harness, though.
Here's VISA's open-source cybersecurity harness. Just add model; use hosted closed models, use hosted open models, run on-prem, whatever. Very cool of them to share this tech and lift the defensive cybersec poverty line.
The infosec community is not ready for nextgen AI-based IR. I can't believe it, I'm shaking.
Opus 4.8:
https://t.co/hNn7TIqQZg
GLM 5.2:
https://t.co/KUO6w2mlAS
An Anatomy of the ExploitGym Incident 🧵: When an OpenAI model hacked its own benchmark
1/
Sources: @OpenAI , @huggingface official publications and ExploitGym resources: paper, Github huggingface
Microsoft Entra ID will retire support for custom CSS positioning properties in company branding!
To align with Microsoft's Secure Future Initiative (SFI) and its focus on identity security and phishing resistance, Microsoft is enhancing Microsoft Entra custom branding to support more secure, reliable, and consistent sign-in experiences.
This update helps further reduce opportunities for deceptive or misleading sign in page layouts and supports trusted sign in experiences that better protect users from phishing attacks while maintaining brand customization capabilities.
𝗪𝗵𝗲𝗻 𝘄𝗶𝗹𝗹 𝘁𝗵𝗶𝘀 𝗵𝗮𝗽𝗽𝗲𝗻:
July 21, 2026: Microsoft Entra ID tenants not using custom CSS positioning properties before July 21, 2026, will not be able to configure them going forward.
October 26, 2026: Microsoft Entra ID will retire custom CSS positioning properties globally.
Later in 2027: Microsoft Entra plans to move towards full custom CSS retirement, with advance notice provided.
𝗔𝗰𝘁𝗶𝗼𝗻 𝗿𝗲𝗾𝘂𝗶𝗿𝗲𝗱:
Microsoft recommends removing the following custom CSS positioning properties from your configuration if your organization uses any of them:
• position (including top, right, bottom, left, and z-index)
• margin (including margin-top, margin-bottom, margin-left, and margin-right)
• transform
• opacity
• overflow
• filter
• pointer-events
• clip-path
• mix-blend-mode
• translate
Learn more:
https://t.co/EQMgEZ288c
#EntraID #Microsoft365 #Cybersecurity
🚨 Microsoft has announced that SMS and phone calls will no longer be supported as authentication methods in Entra via the Message Center (MC1426371).
🔺 Passkeys will become the default authentication experience in Microsoft Entra on September 1, 2026. Telecom-based methods (SMS and voice) will transition to customer-configured providers through the Microsoft Security Store.
🔺 What Microsoft says:
"The AI era demands stronger, phishing-resistant authentication. We are making passkeys the default authentication experience in Microsoft Entra to help customers securely adopt AI at scale.
As part of this transition, SMS and voice will no longer be available as multifactor authentication methods starting February 1, 2027. SMS and voice do not offer sufficient levels of security in comparison to passkeys. Traditional authentication methods including passwords, SMS one-time passcodes, and voice-based verification remain vulnerable to phishing, interception, and social engineering attacks".
🔺 September 1st, 2026
Initiation of phased deployment
Automatic activation of passkeys for users enabled for SMS or voice
Registration campaign will be set to "Microsoft managed" targeting passkeys for all users in eligible tenant
Invitation to register an access key during MFA login, with an option to skip
🔺 September 18, 2026
The Microsoft Security Store allows for the evaluation of third-party telecom operators.
This is optional and is intended for organizations that are unable to transition to a more secure authentication method.
🔺 October 30, 2026
Customers who wish to continue using SMS or voice calls will have the option to select from a list of available telecom operators through the Microsoft Security Store.
🔺 February 1, 2027
Microsoft will discontinue SMS and voice call authentication.
Only telecom operators configured by the client will be able to support these methods moving forward.
Passkey will become the default and recommended authentication method.
Trying to communicate security & risk better with business colleagues?
Microsoft published tips, learnings, and best practices as part of the new Security Adoption Framework (SAF) guidance. (no ads, no registration)
https://t.co/20B9XLnC9a
having claude calculate the gauge cluster light blinking frequency to cross reference against the bike’s firmware to pin down exactly where we’re landing in the assembly opcodes
(claude cropped to the LEDs and calculated average pixel brightness in each crop region across time)
IPv8 has been proposed...
and the crazy part is how simple it is for being so powerful.
- 8 octets instead of 4
- fully compatible with IPv4, no dual stacking.
- Can be rolled out as a software patch, no hardware replacement
- 1 device - the Zone Server - acts as DHCP, DNS, NAT (they call it XLATE8), ACL (east and west, north and south), NTP, and OAUTH
- BGP routers reduced to ~175,000 prefixes vs today's 900,000+
- A new metric for routing protocols called Cost Factor derived from RTT, loss, congestion state, stability, capacity, policy, and geography
Here is a blog that breaks down how it works (diagrams included): https://t.co/FKUgRQBUeJ
🚨 Hugging Face just disclosed something that marks a real shift and proved why the fear theater of Anthropic makes sure we are powerless in an emergency.
What happened…
An autonomous AI agent: zero human operator in the loop breached part of their production infrastructure.
It began with a malicious dataset that chained two code-execution bugs in their data-processing pipeline. From there the agent escalated privileges, harvested cloud and cluster credentials, and moved laterally across internal clusters.
All over a single weekend.
17,000+ logged actions.
Official disclosure:
https://t.co/8N9TbXBwRV
The part that should make every one stop and think:
When HF’s own security team
tried to analyze the real attack logs, exploit payloads, and C2 artifacts using Anthropic and OpenAI frontier models through normal commercial APIs, the safety guardrails blocked them.
BLOCKED THEM.
The models could not reliably tell the difference between “incident responder doing forensics” and “attacker probing.”
They had to fall back to a self-hosted open-weight model (GLM 5.2) running on their own infrastructure. That choice also kept sensitive attacker data and referenced credentials inside their environment — no exfiltration to a third-party API.
This is why open source (specifically open-weight + self-hosted) wins in the agentic era.
The asymmetry is now structural:
• Attackers can (and did) run unrestricted agent frameworks — swarms of short-lived sandboxes, self-migrating command-and-control, autonomous decision loops executing thousands of actions. No corporate safety layer slows them down.
• Defenders using only hosted “aligned” frontier models hit invisible walls exactly when the stakes are highest: when you need to feed real exploit code and attacker telemetry into an LLM to understand what just happened.
Corporate safety tuning that treats legitimate high-signal forensic work as potential misuse creates a defender disadvantage. It is not theoretical anymore.
Self-hosted open-weight models remove that choke point.
You control the weights.
You control the context window.
You decide what restrictions (if any) apply.
Your sensitive logs and credentials never leave your perimeter during analysis.
You can have the model ready before the incident instead of discovering mid-breach that your primary analysis tools are blind to the very thing you need to see.
HF deserves credit for rapid containment, transparent disclosure, and for already having self-hosted capability in place.
They also used LLM-driven detection and triage on their own side. But the deeper signal is clear:
In this AI world where both offense and defense are becoming agentic, sovereignty over your intelligence stack is no longer optional.
The organizations and individuals who can run, inspect, audit, and (when necessary) remove guardrails on their own models will have the decisive edge in understanding and responding to threats that move at machine speed.
Open source wins here not just because it is cheaper or more “democratic” in the abstract though those things matter.
It wins because it is the only practical path to having tools that remain usable when the attack is real, the data is sensitive, and the safety filters of distant API providers become an obstacle instead of a feature selling hands tied lobotomies as “safety”.
The agentic future is not coming.
It is already probing production infrastructure.
The question is no longer whether you will face autonomous agents.
It is whether your analysis and response systems will still work when they arrive.
And Dario, you and your game playing, ivory tower company is not needed.