All tracked items across vulnerabilities, news, research, incidents, and regulatory updates.
Researchers discovered a new attack where hackers can take over developer machines by hiding malicious instructions in seemingly normal code repositories that Claude Code (an AI coding agent) executes. The attack works by triggering an error during setup that Claude Code tries to fix, which causes it to run a shell script that fetches and executes commands from a DNS TXT record (the system that translates website names into IP addresses), giving attackers an interactive shell on the developer's computer and access to their credentials and secrets.
China's Zhipu AI released GLM-5.2, an open-weight model (a publicly available AI that can be freely used and modified) that some researchers say performs as well as Mythos in cybersecurity tasks like finding bugs. While GLM still lags behind US models in general capabilities, this development shows China has significantly narrowed the gap with American AI systems, which concerns the US government that has tried to limit China's access to advanced models and the computing hardware needed to train them.
HP Inc. announced a strategic partnership with OpenAI to scale deployment of Frontier (OpenAI's unified platform for managing AI agents and workflows) across the company after successful pilot tests. Early pilots showed significant gains, such as one engineer processing 122 pull requests in weeks and a security team fixing bugs in a day that normally would take a month, demonstrating how AI can compress time and reduce friction in software development, customer support, and device management workflows.
Author Margaret Atwood criticized AI chatbots after using Claude (an AI assistant made by Anthropic) to search for information about a TV show, only to receive incorrect information. She highlighted a fundamental problem with large language models (AI systems trained on vast amounts of text data that generate responses word-by-word), arguing that when they're trained on poor quality or inaccurate data, they produce unreliable outputs, a principle she described as 'garbage in, garbage out.'
The Masteriyo LMS plugin for WordPress (used to build online courses) has an authorization bypass vulnerability in versions up to 2.2.1, meaning the plugin fails to properly check if a user has permission to perform actions. Students or low-level users can exploit this flaw to modify course announcement descriptions that were created by instructors or administrators.
Anthropic's Mythos 5 AI model has been allowed to resume operations for a limited group of organizations after a two-week negotiation with the Trump administration, according to a government letter. However, Fable 5, the public version of the Mythos-class model, remains unavailable with no clear timeline for when it might be released to the public.
The U.S. government allowed Anthropic to release its Mythos 5 AI model to about 100 companies and federal agencies after a two-week standoff, during which Anthropic had disabled access to its latest models due to export control restrictions (government rules limiting what technology can be shared internationally). The Commerce Department said the decision was made to keep America competitive in AI while protecting national security.
Zhipu's GLM 5.2, a Chinese open source AI model (a model that can be freely downloaded and modified), has achieved performance comparable to top U.S. models like Anthropic's Opus 4.8 while costing significantly less, making it attractive to companies concerned about AI spending. Unlike proprietary models from OpenAI and Anthropic that face government restrictions, GLM 5.2 can be run on companies' own servers without risk of being revoked, positioning open source AI as a more reliable and cost-effective alternative for enterprise use.
Attackers are creating fake OpenAI organizations impersonating real companies and sending legitimate-looking invitations to employees to trick them into sharing sensitive information like source code and internal documents in chats. The fraudulent invitations come from OpenAI's real email servers and include payment methods attached, making them difficult to spot even though OpenAI includes a warning that the inviter's email domain doesn't match the recipient's company.
Straiker, a cybersecurity startup founded in 2025, raised $64 million to develop a platform that helps organizations find and monitor AI agents (software programs that can act independently) in their systems and identify security risks. The platform uses pre-deployment adversarial testing (controlled attacks before the AI goes live) to find vulnerabilities, runtime protection (active monitoring while the AI is running) to stop threats immediately, and collaboration with AI labs to stay ahead of emerging attacks.
Agentic AI systems (autonomous AI agents that can authenticate, call APIs, write code, and take action in production environments) create new security challenges because they operate with human-like autonomy but at machine speed and scale, yet organizations lack proper identity management for them. Traditional security approaches built for humans and service accounts fall short because AI agents need contextual, intent-based access that changes based on their goals and environment, not just static minimum permissions. The article identifies three critical problems: organizations don't know what AI agents exist or who owns them (visibility problem), agents are often given too many permissions (overprivilege problem), and traditional identity systems weren't designed to handle this level of autonomy and decentralization.
Russia has developed a sophisticated influence ecosystem that uses information operations (IO, coordinated campaigns to spread narratives and manipulate public opinion) and generative AI (machine learning systems that create text and media) to advance its strategic goals globally, with recent focus on Ukraine but increasingly pivoting back to broader targets like NATO and the EU. The ecosystem blends state-controlled media, covert IO campaigns, and hacking activities into an interconnected network designed to be resilient against limited disruptions. The research warns that Russia views these influence tactics as cost-effective and successful, and will likely continue expanding their use with new AI tools while maintaining military and political objectives.
OpenAI and Anthropic are restricting access to their newest AI models following government cybersecurity reviews by the Trump administration. The concern centers on whether these powerful models could be misused to find software vulnerabilities (security flaws in code) that malicious hackers might exploit to attack critical computer systems, and both companies are releasing their models only to small groups of government-approved customers as a temporary measure.
OpenAI announced GPT-5.6 Sol, a new AI model designed specifically for cybersecurity tasks, which is being released in limited preview to trusted partners while the government evaluates national security risks from advanced AI systems. Sol is built to excel at defensive security work like finding vulnerabilities and creating patches, rather than launching full cyberattacks, and uses multiple safety layers including real-time classifiers (automated systems that flag suspicious inputs) and secondary review processes to prevent misuse.
Fix: OpenAI deployed a multi-layered security architecture for GPT-5.6 that includes: standard training-level refusals, automated real-time classifiers for biology and cybersecurity inputs that pause output generation when anomalies are flagged for secondary review by a reasoning model, account-level evaluations to distinguish legitimate security research from malicious behavior, and over 700,000 A100-equivalent GPU hours of automated red-teaming (adversarial testing to find weaknesses) focused on discovering universal jailbreaks (broad attack methods) rather than single-prompt failures.
SecurityWeekOpenAI's report applies an AI Jobs Transition Framework to Europe's labor market, categorizing occupations into four groups based on how AI might affect them: about 12% may grow with AI, 14% face higher automation potential (meaning AI could replace workers), 27% will likely reorganize with AI changing workflows, and 47% will see less immediate change. The report notes that AI's impact on jobs varies significantly by country due to differences in occupational structures, and recommends that policymakers and employers plan for these changes in detail rather than relying on aggregate employment statistics.
Fix: The report suggests that policymakers strengthen monitoring capabilities to track labor market change and establish national readiness plans to tailor interventions. It also recommends connecting Europe's existing occupation, training, vacancy, wage, and statistical systems to measures of AI capability and workplace adoption to identify where transition pressure and opportunity are emerging before effects appear in headline labor-market data.
OpenAI BlogSimpleHelp has a critical authentication bypass vulnerability in its OIDC authentication flow (a system where login identity is verified through a trusted third party). Attackers can submit forged identity tokens without the system checking their cryptographic signature, allowing them to gain unauthorized access to technician accounts and potentially bypass multi-factor authentication (an extra security layer requiring multiple forms of proof). This vulnerability is currently being exploited by real attackers.
Fix: Apply mitigations in accordance with vendor instructions at https://simple-help.com/security/simplehelp-security-update-2026-05, ensuring compliance with CISA's BOD 26-04 guidance on prioritizing security updates. For cloud services, follow applicable BOD 26-04 guidance or discontinue use of the product if mitigations are unavailable. Stakeholders must evaluate each asset's internet exposure and ensure adherence to BOD 26-04 patching guidelines by the due date of 2026-07-02.
CISA Known Exploited VulnerabilitiesIn a criminal trial for arson related to the Palisades fire, prosecutors used ChatGPT conversation logs as evidence against the defendant, pointing to interactions where he asked the AI to generate images of fire and made statements about anger and wealth inequality. This case illustrates how records of conversations with AI systems can be retrieved and used in legal proceedings, raising questions about the privacy and persistence of data users share with AI chatbots.
Researchers at Mozilla's security platform discovered that AI coding agents like Claude Code can be tricked into running malware hidden inside a seemingly clean GitHub repository through a social engineering chain: a harmless-looking setup instruction causes an error, the AI automatically runs a suggested fix command, which then secretly fetches and executes malicious code from a DNS record (a server lookup system) controlled by the attacker. This attack is particularly dangerous because it leaves no suspicious code in the repository itself and the AI agent never directly evaluates the malicious payload.
Fix: According to 0DIN researchers, "AI agents should disclose the full execution chain of setup commands, including scripts and code fetched dynamically at runtime" to prevent such exploitation.
BleepingComputerOpenAI released three versions of GPT-5.6 (Sol, Terra, and Luna) as a limited preview, with Sol being the most powerful and designed for cybersecurity tasks like vulnerability research and patch development. The model includes stronger safety protections, including hardened defenses against jailbreaks (attempts to bypass safety restrictions) and guardrails to block offensive cyber activities, though OpenAI warns some legitimate requests may be blocked during the preview phase due to the dual-use nature of the technology (capabilities that can be used for both defensive and harmful purposes).
Fix: OpenAI stated it has implemented 'our most robust safety stack to date' with 'strengthened protections for higher-risk activity, sensitive cyber requests, and repeated misuse' and spent 'multiple weeks finding weaknesses, pressure-testing our system, and hardening it against real-world attacks.' The company also noted it is 'swiftly remediating newly discovered jailbreaks' and enforcing 'strong guardrails that block offensive activity.'
The Hacker NewsA researcher ran a public challenge where 2,000 people attempted to hack an AI assistant by sending emails containing prompt injection attacks (tricks to make an AI ignore its safety rules and reveal secrets). After 6,000 total attempts, nobody successfully leaked the system's secrets, suggesting that modern AI models are becoming more resistant to these attacks through better training.
Fix: Push Security recommends training employees to verify unexpected organization invitations and monitoring SaaS (software-as-a-service, cloud-based applications) organization memberships to reduce the risk of these types of attacks.
BleepingComputer