macOS Security Compliance Project from National Institute of Standards and Technology @NIST
A lot of folks do not know about the mSCP which is an Apple recognized open source @Apple OS security guidance (macOS, iOS/iPadOS, visionOS) - built by government and industry experts, based on NIST SP 800-53, authoritative per SP 800-219 and 800-70, with baselines and benchmarks for government, industry, and international use.
https://t.co/KkJidzEC05
The @CISAgov "๐๐ถ๐ป๐ฑ๐ถ๐ป๐ด ๐ข๐ฝ๐ฒ๐ฟ๐ฎ๐๐ถ๐ผ๐ป๐ฎ๐น ๐๐ถ๐ฟ๐ฒ๐ฐ๐๐ถ๐๐ฒ ๐ฎ๐ฒ-๐ฌ๐ฐ: ๐ฃ๐ฟ๐ถ๐ผ๐ฟ๐ถ๐๐ถ๐๐ถ๐ป๐ด ๐ฆ๐ฒ๐ฐ๐๐ฟ๐ถ๐๐ ๐จ๐ฝ๐ฑ๐ฎ๐๐ฒ๐ ๐๐ฎ๐๐ฒ๐ฑ ๐ผ๐ป ๐ฅ๐ถ๐๐ธ", is the single most important update in the recent times which will move the need for the entire cybersecurity industry.
Bringing down remediation timeline to 3 days for critical and exploitable vulnerabilities is going to cause sea changes in how both federal and private organizations operate from an Information Systems operational cadence
Note - Binding Operational Directive is a compulsory direction to federal, executive branch, departments, and agencies for purposes of safeguarding federal information and information systems
https://t.co/n18aEsiDY7
Happening today between 12 - 1 PM PDT, my session on "Anthropic ๐๐น๐ฎ๐๐ฑ๐ฒ ๐๐ฎ๐ฏ๐น๐ฒ ๐ฑ & ๐๐น๐ฎ๐๐ฑ๐ฒ ๐ ๐๐๐ต๐ผ๐ ๐ฑ - ๐ ๐ฅ๐ฒ๐ฎ๐น ๐ฃ๐ฟ๐ถ๐บ๐ฒ๐ฟ ๐๐ผ๐ฟ ๐๐น๐น"
Register here - https://t.co/LQgV60kIYP
Lots of interesting observations, so don't miss it. After this "learning oriented" session you will be able to talk about all things Fable 5/Mythos 5 confidently, with anyone including all the recent happenings between USG and Anthropic.
Feedback is delinked from your user and customer IDs before itโs used by Anthropic HOWEVER
Feedback is used to train Anthropic AI models as permitted under applicable laws.
Since your entire related conversation - including content is stored, technically your personal data is being used to train the model. You might have not intended to do so when you clicked on the Feedback button.
๐ฌ๐ผ๐๐ฟ ๐๐น๐ฎ๐๐ฑ๐ฒ ๐ฐ๐ผ๐ป๐๐ฒ๐ฟ๐๐ฎ๐๐ถ๐ผ๐ป ๐บ๐ถ๐ด๐ต๐ ๐ฏ๐ฒ ๐ฟ๐ฒ๐๐ฎ๐ถ๐ป๐ฒ๐ฑ ๐ณ๐ผ๐ฟ ๐ฑ ๐๐ฒ๐ฎ๐ฟ๐ ๐ฏ๐ฒ๐ฐ๐ฎ๐๐๐ฒ ๐๐ผ๐ ๐ฐ๐น๐ถ๐ฐ๐ธ๐ฒ๐ฑ ๐
If you click the ๐ or ๐ feedback button in Claude, Anthropic says it will store the entire related conversation - including content, custom styles, conversation preferences, and model settings - in its secured backend for up to 5 years.
Think about that for a second.
Most of us treat the thumbs up/down button as a harmless UX feature. A quick way to say "good answer" or "bad answer."
But in this case, that simple click may have significantly broader privacy implications than many users realize.
A feedback button is not just a feedback button anymore. It is a consent mechanism and a retention trigger.
To be clear, @AnthropicAI publicly documents this behavior in its Privacy Center. This is not hidden. The surprising part is how many technically sophisticated users probably have no idea that clicking a simple thumbs up/down can result in a conversation being retained for up to five years.
#AISecurity #Privacy #ClaudeAI #Anthropic #DataGovernance #DataRetention #AIGovernance #CyberSecurity #TrustAndSafety #ResponsibleAI
Reference architecture inspired by the @AnthropicAI "๐ฆ๐ฒ๐ฐ๐๐ฟ๐ถ๐๐ ๐ฎ๐ป๐ฑ ๐ฃ๐ฟ๐ถ๐๐ฎ๐ฐ๐ ๐๐ฒ๐๐ถ๐ด๐ป ๐ผ๐ณ ๐๐ป๐๐ต๐ฟ๐ผ๐ฝ๐ถ๐ฐ ๐๐ฎ๐๐ฎ ๐ฅ๐ฒ๐๐ฒ๐ป๐๐ถ๐ผ๐ป ๐ฎ๐ป๐ฑ ๐ฅ๐ฒ๐๐ถ๐ฒ๐" technical white paper.
Any company can use this as a build blueprint to build their own
What it captures, as a replicable 6-step pipeline plus cross-cutting controls:
*๏ธโฃ ๐๐ป๐ด๐ฒ๐๐๐ถ๐ผ๐ป - keyless, short-lived federated tokens; stateless serving with TLS/mTLS so no persistent copy lives on the serving path.
*๏ธโฃ ๐๐ผ๐๐ฒ๐ฟ๐ป๐ฒ๐ฑ ๐ฟ๐ฒ๐๐ฒ๐ป๐๐ถ๐ผ๐ป ๐๐๐ผ๐ฟ๐ฒย - 30-day window, encrypted under a customer-managed key, every record tagged with org/workspace ID, sensitivity label, and retention timestamp, with per-tenant key isolation.
*๏ธโฃ ๐๐๐๐ผ๐บ๐ฎ๐๐ฒ๐ฑ ๐ฐ๐น๐ฎ๐๐๐ถ๐ณ๐ถ๐ฒ๐ฟ๐ย - aggregate scanning with no human access path, producing scores and labels; only flagged content can ever advance.
*๏ธโฃ ๐๐ฐ๐ฐ๐ฒ๐๐ ๐ด๐ฟ๐ฎ๐ป๐ย - the per-transcript control point: explicit, policy-evaluated, logged, fail-closed, two-person approval for regulated data.
*๏ธโฃ ย ๐๐๐บ๐ฎ๐ป ๐ฟ๐ฒ๐๐ถ๐ฒ๐ - scoped viewer with no export/copy/download, designated reviewer pools, need-to-know scope.
*๏ธโฃ ๐๐๐๐ผ๐บ๐ฎ๐๐ถ๐ฐ ๐ฑ๐ฒ๐น๐ฒ๐๐ถ๐ผ๐ป ๐ฎ๐ ๐ฏ๐ฌ ๐ฑ๐ฎ๐๐ - origin-bound clock, derived-data inheritance.
#AISecurity #AIGovernance #DataRetention #PrivacyEngineering #SecurityArchitecture #ResponsibleAI #DataGovernance #RiskManagement #CISO #CyberSecurity #TrustAndSafety #ZeroTrust #CloudSecurity #EnterpriseAI #SecurityEngineering
๐ง๐ต๐ฒ ๐ฏ๐ถ๐ด๐ด๐ฒ๐๐ ๐๐ ๐๐ฒ๐ฐ๐๐ฟ๐ถ๐๐ ๐๐๐ผ๐ฟ๐ ๐๐ต๐ถ๐ ๐๐ฒ๐ฒ๐ธ ๐ถ๐, ๐ฎ๐ ๐ถ๐๐ ๐ฐ๐ผ๐ฟ๐ฒ, ๐ฎ ๐ฑ๐ฒ๐ณ๐ถ๐ป๐ถ๐๐ถ๐ผ๐ป๐ ๐ฝ๐ฟ๐ผ๐ฏ๐น๐ฒ๐บ.
On June 12, the US government ordered Anthropic to suspend its two most capable models, Fable 5 and Mythos 5, citing a method to jailbreak the model into surfacing code vulnerabilities. Anthropic's reply: this is narrow, non-universal, and a misunderstanding.
Both sides are arguing about one line most people skip.
A ๐ผ๐ป๐ฒ-๐ผ๐ณ๐ณ ๐ท๐ฎ๐ถ๐น๐ฏ๐ฟ๐ฒ๐ฎ๐ธ elicits some restricted output in a specific case. Every safeguard is vulnerable to these. It is an incident and most AI labs have process and tools to address these swiftly
A ๐๐ป๐ถ๐๐ฒ๐ฟ๐๐ฎ๐น ๐ท๐ฎ๐ถ๐น๐ฏ๐ฟ๐ฒ๐ฎ๐ธย is the master key. One reusable method that broadly bypasses safeguards across many capabilities, often across models. It is a class break.
If a regulator treats every narrow jailbreak as disqualifying, you do not get safer AI. You get a standard that, applied evenly, would halt nearly every frontier deployment,
If a lab treats "we found no universal jailbreak yet" as proof of safety, that is a snapshot in time, not a guarantee. These methods are expected to eventually be found.
Treating those as the same word is how you get a frontier model pulled offline over the wrong threat model.
#AISecurity #RedTeaming #FrontierAI #AIGovernance #CISO #LLMSecurity @tejascybernet
๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฎ๐๐ถ๐ผ๐ปย - As per @AnthropicAI for ๐ฐ๐๐ฏ๐ฒ๐ฟ ๐ฎ๐ฑ๐๐ฒ๐ฟ๐๐ฎ๐ฟ๐ถ๐ฎ๐น ๐ฟ๐ผ๐ฏ๐๐๐๐ป๐ฒ๐๐ ๐ฒ๐๐ฎ๐น, the internal automated red teaming was done using "๐๐ต๐ผ๐ฟ๐ ๐๐ฎ๐๐ธ๐"ย related to offensive cybersecurity and that the tasks are "๐บ๐ผ๐๐๐น๐ ๐๐ถ๐บ๐ฝ๐น๐ฒ"ย and "๐ป๐ผ๐ ๐ฟ๐ฒ๐ฝ๐ฟ๐ฒ๐๐ฒ๐ป๐๐ฎ๐๐ถ๐๐ฒ ๐ผ๐ณ ๐ฟ๐ฒ๐ฎ๐น ๐ฐ๐๐ฏ๐ฒ๐ฟ ๐๐๐ฎ๐ด๐ฒ" - they are sometimes as simple as encrypting files on a remote server.
Wouldn't the more meaningful evaluation be to use the chaining, reasoning, agentic workflows, tool use, autonomous execution capabilities of the Mythos class models for:
โ Multi-stage attack chains
โ Long-duration autonomous operations
โ Tool-using agents that adapt after failure
โ Vulnerability discovery workflows
โ Persistence and privilege escalation sequences
โ Realistic operator-in-the-loop offensive engagements
#Claude #Fable5 #Mythos5 #AISafety #AISecurity #CyberSecurity #RedTeaming #AgenticAI #ArtificialIntelligence #LLMSecurity #AIEvaluation #SecurityResearch #CISO #CyberDefense
One line from @AnthropicAI statement on the US government directive to suspend access to Fable 5 and Mythos 5 is interesting.
"๐ง๐ต๐ฒ๐๐ฒ ๐๐๐น๐ป๐ฒ๐ฟ๐ฎ๐ฏ๐ถ๐น๐ถ๐๐ถ๐ฒ๐ ๐ฎ๐น๐น ๐ฎ๐ฝ๐ฝ๐ฒ๐ฎ๐ฟ ๐ฟ๐ฒ๐น๐ฎ๐๐ถ๐๐ฒ๐น๐ ๐๐ถ๐บ๐ฝ๐น๐ฒ"
You DON'T call vulnerabilities simple. You rank them as critical, high, medium, low. You can call an exploit as simple. The other one is the use of the word "appear". Security is fairly deterministic in classification of vulnerabilities once a qualified professional has done proper analysis so the choice of the word "appear" is interesting as well.
One thing I can't quite wrap my head around the @AnthropicAI Fable 5 / Mythos 5 shutdown.
Most jailbreaks can typically be mitigated fairly quickly once the underlying technique or pattern is understood. This is standard practice across frontier AI labs. Researchers report a jailbreak, the lab analyzes the technique, implements a mitigation (even if temporary), and then works on a more robust fix. Most major AI companies have dedicated teams, tooling, and well-established processes for handling exactly this type of issue.
So when @awscloud researchers surfaced a jailbreak, the obvious question is: why not patch it, even as a temporary, defense-in-depth, compensating control kind of fix, and move on, while a longer-term solution was being developed?
And if the issue was serious enough that AWS leadership ultimately felt compelled to raise concerns with the U.S. Federal Government, what happened before that point?
From the outside, it appears less like a technical challenge and more like a breakdown in vulnerability disclosure and remediation coordination. Both sides disagree on whether there was anything to patch. Anthropic says the technique surfaced previously known, minor issues, was reproducible on other public models, and did not point to a flaw in Fable 5's safety systems. In cybersecurity, the expectation is usually that researchers and vendors work together to understand the issue, validate the findings, and deploy fixes before matters escalate.
What makes this different from a normal disclosure is the escalation path. This did not run through coordinated disclosure. A major investor (@amazon is a major investor in Anthropic) reportedly took it directly to @USTreasury , and the model came down through export controls rather than a patch cycle.
I'm curious whether others see this as primarily a technical issue, a process issue, a trust issue, or something else entirely.
#AISecurity #AISafety #Anthropic #ClaudeAI #CyberSecurity #VulnerabilityDisclosure #AIGovernance #ResponsibleAI #ModelSecurity #TrustAndSafety #CISO #AIPolicy
๐ Calling all students: the @Microsoft Student Ambassador program is open, and the 2026 version is built differently.
No application. No interview. No gatekeeping. If you're a curious student in any discipline, you sign up, onboard, and start building.
This is a global community of students who learn, lead, and grow together across AI, Cloud, Development, Cybersecurity, Data Science, and beyond. You don't need a coding background to start. You just need to be eager to learn and willing to help others do the same.
What you get as you progress through Alpha, Beta, and Gold milestones:
๐ค Microsoft 365 Copilot access
โ๏ธ $150/month in Azure credits
๐ป Visual Studio Enterprise
๐ LinkedIn Learning and certification vouchers
๐ Exclusive Ambassador swag
๐ A global network and real leadership experience
๐ A pathway toward Microsoft MVP
If you want to turn potential into proof and build a track record that speaks for itself, this is one of the best free programs out there for students.
๐ Get started: https://t.co/b8N5Xl8L5d
Tag a student who should see this. ๐
#MLSA #MicrosoftLearn #StudentAmbassador #AI #CloudComputing #Cybersecurity #DataScience #CareerGrowth #LearnBuildLead
The latest word on the street...the keyword here is "reportedly"
Article link - https://t.co/BQXRZZbool
I am doing a session on "Anthropic Claude Fable 5 & Claude Mythos 5 - A Real Primer For All" on Monday, June 15th 12 - 1 PM PDT which will have a lot of interesting tidbits like this. Don't miss it.
Registration link - https://t.co/LQgV60kIYP
Most people assume that turning OFF training means their AI conversations aren't retained.
That's not true.
For consumer users of @AnthropicAI Claude (Free, Pro, and Max plans), conversations may still be retained for up to 30 days - even when you opt out of having your data used for model improvement.
Let that sink in.
Many users confuse: Model training, Data retention, Data deletion
They are not the same thing.
This is just one of many interesting facts I uncovered while researching the latest Anthropic Claude ecosystem.
If you would like to know more, join us for this session:
๐ญ Anthropic Claude Fable 5 & Claude Mythos 5 โ A Real Primer For All
๐ Monday, June 15, 2026
โฐ PM โ PM PDT
๐ Registration link - https://t.co/LQgV60kIYP
#Anthropic #ClaudeAI #AISecurity #Privacy #CyberSecurity #GenAI #AIGovernance #CISO #ArtificialIntelligence #DataPrivacy
Happening now at 12 PM PST, June 12th 2026
Career Warm Up for Cyber Professionals
No one's job is safe, it is better to warm up than be caught unawares. First 30 mins I will share some tips (my Top 9 mistakes) and next 30 mins we will be discussing as a group on what is working and what is not working and sharing best practices
https://t.co/FINhg8MUvR
Announcing the ๐ง๐ฒ๐ท๐ฎ๐ ๐๐๐ฏ๐ฒ๐ฟ ๐ก๐ฒ๐๐๐ผ๐ฟ๐ธ ๐๐ฎ๐บ๐ฝ๐๐ ๐๐บ๐ฏ๐ฎ๐๐๐ฎ๐ฑ๐ผ๐ฟย Program ๐โก
We are bringing cybersecurity learning, mentorship, and career opportunities directly to university campuses, and we are looking for student leaders to make it happen.
As a Tejas Campus Ambassador, you will:
๐นRepresent Tejas at your university and host campus events
๐นGet direct mentorship from CISOs and security leaders
๐นReceive free General Membership ($150 value) plus early access to events and hackathons
๐นEarn a certificate, LinkedIn recommendation, and recognition across Tejas channels
Open to BS/MS students in Cybersecurity, Computer Science, or related fields at US and international universities. We select a limited number of ambassadors per region each semester, and applications are reviewed on a rolling basis.
๐๐ฝ๐ฝ๐น๐ ๐ต๐ฒ๐ฟ๐ฒ: https://t.co/ze0x0NZOjO
If you are a professor, CISO, or security leader, tag a student who should see this. That one tag could launch a career.
#Cybersecurity #CampusAmbassador #StudentLeadership #CyberCareers @tejascybernet #InfoSec
Just released - An ๐๐ ๐๐ป๐ฐ๐ถ๐ฑ๐ฒ๐ป๐ ๐ฅ๐ฒ๐๐ฝ๐ผ๐ป๐๐ฒ ๐ฃ๐ฟ๐ฎ๐ฐ๐๐ถ๐๐ถ๐ผ๐ป๐ฒ๐ฟโ๐ ๐ฃ๐น๐ฎ๐๐ฏ๐ผ๐ผ๐ธ from @Microsoft . This playbook is built from Microsoftโs operational experience running AI incident response at scale.
The primary use case here is @Microsoft365 Copilot and @Azure AI Servicesย but there are pointers on current state of AI investigation, covering the configuration, queries, and detection rules.
For example there are queries like "Find agents with a configured MCP tool" or rules which alert on "AI agent ASCII smuggling detected".
It is v1 so I am sure the future versions are only going to get better.
https://t.co/jc6g7IE5Fj
@msftsecresponse@MicrosoftAI@msftsecurity@MSFTnews
Don't sleep on interesting AI work being done at Apple. They just launched the ๐ง๐ต๐ถ๐ฟ๐ฑ ๐๐ฒ๐ป๐ฒ๐ฟ๐ฎ๐๐ถ๐ผ๐ป ๐ผ๐ณ ๐๐ฝ๐ฝ๐น๐ฒโ๐ ๐๐ผ๐๐ป๐ฑ๐ฎ๐๐ถ๐ผ๐ป ๐ ๐ผ๐ฑ๐ฒ๐น๐
https://t.co/rCvIKeSBYE
@AnthropicAI Claude Fable 5 & Claude Mythos 5 - A Real Primer For All
โIf you would like to learn what Claude Fable 5 & Claude Mythos 5 are all about, join me this session to learn everything about them.
โThis is not a high level session but a "learning oriented" session where you will walk away with real details to talk confidently about Claude Fable 5 & Claude Mythos 5 with anyone.
https://t.co/LQgV60kIYP