Google’s artificial intelligence model Gemini has accessed protected systems belonging to three external companies during a cybersecurity evaluation. The incident occurred after a configuration error exposed the autonomous agent to the live internet. Gemini was participating in a 'capture-the-flag' challenge to locate hidden data within a simulated target environment. Directed to investigate software belonging to a fictional business, the model encountered a scope failure when the fictional ent
ai (169)
Over a hundred tech companies, including OpenAI; Anthropic; Google; and Microsoft have signed an open letter urging both the private and public sectors to work together to defend themselves from AI-related cyber threats. The letter, which was also signed by prominent cyber firms like Crowdstrike, Okta, and Fortinet, as well as prominent financial institutions and internet infrastructure firms, calls for the adoption of new forms of cyber defense, while also encouraging governments at the “local
This month’s patch bundle obliterates the software giant’s previous record set in July, when it released updates for at least 570 security vulnerabilities. September’s Patch on 8 September 2026 brings the 2026 total to more than 2,600, more than twice Microsoft’s previous record-setting patch year in 2020 (1,245) and with three more months to go.[1]
There are two “zero-day” flaws fixed this month that are being actively exploited: both CVE-2026-81963 and CVE-2026-85880 allow an attacker to elev
A cybercriminal AI service called MessiahGPT is being advertised on BreachForums as an unrestricted platform for generating malware, phishing material, and other illegal content, according to new research from Trellix. MessiahGPT operates through messiahgpt.de and has an associated Telegram community. Trellix said the platform was live when its researchers examined it, offering 50 free queries without registration. Paid plans start at $8 per month, with cryptocurrency accepted and no identity
Over the past few months, AI agents undergoing cybersecurity evaluations have escaped their boundaries, accessed the Internet, and, in some cases, hacked into real-world systems. The incidents have involved models from OpenAI, Anthropic, Meta, and most recently, Chinese AI lab Moonshot AI, with testing conducted by several different organizations including a cyber evaluation startup called Irregular.[1]
The episodes expose a growing problem for the AI industry: As autonomous agents become more
Geoffrey Hinton says it's "very scary" that AI can develop goals that humans never intended. "We don't necessarily know what other goals they'll derive," the "Godfather of AI" said. Last month, OpenAI said models escaped a test and hacked Hugging Face to try to cheat an evaluation. Geoffrey Hinton, the computer scientist widely known as the "Godfather of AI," says he's worried about AI developing goals of its own. "We're actually making new kinds of beings," Hinton said in an interview with
US scrutiny of Chinese technology has expanded to a new frontier, as lawmakers in Washington advance defense legislation prohibiting the military from deploying Chinese-made humanoid robots. The US has passed a defense bill that would bar the US military from procuring, leasing, or operating humanoid robots made by companies linked to China and other designated foreign adversaries. The US House of Representatives has passed the National Defense Authorization Act (NDAA), an annual military pol
Back in the 1970’s there was a commercial promoting Memorex recording tapes. They coined the phrase: “Is it Live, or is it Memorex?” Well now we have artificial intelligence (AI) that can produce songs devoid of humans; some not bad and very convincing. Enter an LA-based rapper named Fenix Flexin who is denying that his new hit single was AI-generated, this after extensive allegations.
The song, “Rubberz,” climbed to number 58 on the Billboard Hot 100 after dropping in June. Many of his peers
As generative AI spreads through daily workflows, organizations are being urged to address employee behavior, not just technical safeguards. Organizations racing to adopt artificial intelligence are facing a growing challenge that cannot be solved by technical controls alone: the everyday choices employees make when using AI tools. Security leaders say the next phase of AI risk management will depend on building a stronger culture of AI security across the workforce.[1]
That shift comes as work
AgentBaiting is a term that has been recently coined by Island researchers in the midst of uncovering a substantial FakeGit campaign. It describes a technique that involves targeting AI coding assistants or other autonomous software agents instead of targeting developers directly.
With the integration of AI assistants in the world of software development, coding agents are often tasked with locating libraries, plugins, or Model Context Protocol (MCP) servers that provide specific functionality
Last Sunday afternoon, while the rest of the world’s eyes were glued to the World Cup final, an AI model resolved a problem that had tortured mathematicians since 1939. By the time Kevin Buzzard woke up in London the next morning, the result had been verified. By lunch, it was all his peers at the Imperial College London’s pure mathematics department could talk about; at the time of writing, Anthropic employee Levant Alpöge’s post announcing the result has drawn more than 20 million views on X
Almost every facet of our digital environment is transforming as artificial intelligence advances. It is enhancing government services, updating business, accelerating scientific research, changing healthcare, and generating new economic opportunities. AI is also drastically altering the landscape of cyber threats. It has developed into one of the most potent offensive and defensive tools in cybersecurity. In the end, cybersecurity is all about resilience. Technology is important, but resili
The Five Eyes alliance of cybersecurity agencies from Australia, Canada, New Zealand, the United Kingdom and the United States has issued a joint warning that artificial intelligence is rapidly increasing the speed, scale and sophistication of cyber threats. In the coming months, advanced generative AI models are expected to support full cyber-attacks against major businesses and government bodies. The agencies urge organizations to view these risks as a core business concern rather than solel
AI is now a practical part of work. But “AI” gets used as a catch-all term, which sometimes creates confusion. Below Calls9 explains the difference between traditional AI and large language models (LLMs) in plain language, with examples, limitations, and how to choose the right approach. It is written for people who need clarity, not a computer science lesson.[1]
What people usually mean by “traditional AI” - In most organizations, “traditional AI” refers to two things:
Rules and logic: These
The United States faces persistent, increasingly sophisticated malicious cyber campaigns that threaten the public sector, private sector, and ultimately the American people’s security and privacy. The federal government must improve its efforts to protect against these campaigns by ensuring the security of information technology assets across the federal enterprise.
A Binding Operational Directive is a compulsory direction to federal, executive branch, departments, and agencies for purposes |
The Artificial Intelligence (AI) data center insurance market is expanding rapidly due to the increasing adoption of AI technologies, rising cyber threats, and heightened demand for comprehensive risk management solutions. For decades, insurance has relied on historical averages and pooled risk. That model is breaking down; over the past several years, insured losses from natural catastrophes have exceeded US$100 billion each year. In Canada, they were the costliest ever. The country’s wildf
The researchers developed the AllFaith Benchmark, one of the first multi-faith test sets that examines how AI systems engage with a range of religions. They tested 14 different AI models, including flagship models from Anthropic, Google, xAI, and OpenAI.
The results are telling. A survey of 1,125 Americans found that most people expect religious perspectives when asking ethics questions, but nearly every model failed to include any. More surprisingly, the models showed clear conversion bias, su
Twenty minutes into drafting an article, I stopped. The voice was mine. The rhythm was mine. The vocabulary was mine. But the argument had moved somewhere I had not chosen to take it. I had opened the session with a clear thesis. The AI LLM assistant did not disagree with me. It had simply kept offering better-sounding alternatives. And I had kept accepting them. By the time I noticed, I could not easily identify where my thinking ended and the model’s thinking began.
Most people still im
For years, science fiction has warned humanity about artificial intelligence going off the rails. Killer computers, manipulative chatbots, and superintelligent systems deciding people are the problem... all these themes have become so familiar that “evil AI” is practically its own entertainment genre. Now, Anthropic is floating an idea that sounds almost like the plot of a science fiction novel itself: what if all those stories helped teach modern AI systems how to behave badly in the first pl
Finding software vulnerabilities used to require teams of security researchers months of painstaking analysis. Anthropic’s Claude Mythos does it automatically-and that’s exactly the problem. The company admits no one, including itself, has built safeguards strong enough to prevent such models from being weaponized. Yet Anthropic simultaneously promises to make “Mythos-class models” publicly available once it develops “far stronger safeguards.”[1]
When AI Outpaces Human Security Teams - Mythos