New tools, products, platforms, funding rounds, and company developments in AI security.
Security experts are warning that Anthropic's Claude Mythos introduction could trigger an "AI vulnerability storm," where many security weaknesses in AI systems are discovered and exploited rapidly. The Cloud Security Alliance is advising security leaders (called CISOs) to prepare for a surge in attacks targeting these newly-exposed vulnerabilities.
AI-generated influencers (fake people created using generative AI, the technology that can create images and text) are appearing in social media posts about Coachella festival, posing as real attendees and posting photos with celebrities. While fake attendance has happened before with real influencers, AI tools have now made it easy enough that AI-generated people are becoming common on social media.
OpenAI is revoking and rotating its macOS code-signing certificates (digital credentials that verify OpenAI apps are legitimate) after a malicious Axios package was executed in one of its GitHub Actions workflows (automated tasks that run on code repositories). Although OpenAI found no evidence the certificates were actually compromised, the company is treating them as potentially exposed and requiring all macOS users to update their OpenAI apps to versions signed with new certificates by May 8, 2026, when the old certificate will be fully blocked.
Goldman Sachs's CEO says he is closely aware of cybersecurity risks from Anthropic's Mythos AI model (an advanced large language model, which is an AI trained on large amounts of text data) and is working with Anthropic to improve cyber protection. The bank has been monitoring rapid advances in AI as part of its efforts to protect itself from hackers.
OpenAI's chief revenue officer sent an internal memo to employees emphasizing the need to build a 'moat' (competitive advantages that make it hard for customers to switch to competitors) around its AI products and focus on enterprise clients, as users currently find it easy to switch between different AI models depending on which one performs best at any given time.
Gemini Robotics-ER 1.6 is an upgraded AI model designed to help robots understand and reason about the physical world, enabling them to complete real-world tasks with better spatial awareness and precision. The model improves on previous versions by enhancing capabilities like pointing (identifying and locating objects), counting, reading instruments (such as gauges), and detecting when tasks are complete. It is now available to developers through the Gemini API (an interface for accessing the model) and Google AI Studio.
Microsoft is testing ways to integrate OpenClaw-style features into Copilot, its AI assistant, to make Microsoft 365 Copilot run autonomously (without human intervention) around the clock and complete tasks for users. OpenClaw is an open-source platform that allows users to create AI-powered agents (software programs that act independently to complete goals) that run locally on a user's device. Microsoft's corporate vice president confirmed the company is exploring these technologies for enterprise use.
OpenAI's new revenue chief sent an internal memo highlighting a partnership with Amazon (a cloud computing company competing with Microsoft) as crucial for reaching enterprise customers, while acknowledging that its existing deal with Microsoft has constrained its ability to serve clients who prefer Amazon's AI platform called Bedrock (a service that provides access to major AI models). The memo reflects OpenAI's struggle to compete with rival Anthropic's Claude model in the enterprise market, where companies are investing heavily in AI.
OpenAI discovered that a macOS code signing certificate (a digital credential used to verify that software is legitimate and unchanged) may have been compromised in a supply chain attack (where hackers target a company's software distribution process rather than attacking the company directly) linked to North Korea. The company is taking action to address this potential security breach.
Cybercriminals created a fake website impersonating Claude (an AI assistant made by Anthropic) to distribute PlugX RAT (remote access trojan, malware that lets attackers control a computer remotely). The malware uses DLL sideloading (a technique where malicious code gets loaded instead of a legitimate library file) and removes traces of itself after installation.
Sam Altman, the CEO of OpenAI, was targeted in a second attack at his San Francisco home, with two suspects arrested after allegedly firing a weapon at his residence. This incident follows an earlier attack on Friday when someone threw a Molotov cocktail (an improvised incendiary weapon) at the same property, and both investigations are still ongoing.
OpenAI announced it is opening its first permanent London office with space for over 500 employees, even though the company recently paused its major U.K. Stargate project (a large infrastructure initiative for building AI computing capacity). The company cited high energy costs and the U.K.'s regulatory environment as reasons for halting the Stargate project, though it continues to expand its research presence in London's King's Cross area.
OpenAI discovered that a GitHub Actions workflow (automated processes that run in code repositories) used to sign its macOS apps downloaded a malicious version of the Axios library on March 31, which contained a backdoor called WAVESHAPER.V2. Although OpenAI found no evidence that user data or systems were compromised, the company is treating its signing certificate as compromised and revoking it, which will cause older versions of its macOS apps to stop receiving updates and support after May 8, 2026.
Cloudflare and OpenAI are partnering to let enterprises deploy AI agents (software programs that can automatically perform tasks like customer service and report generation) using advanced OpenAI models like GPT-5.4 through Cloudflare's Agent Cloud platform. The integration runs on Cloudflare Workers AI (a system for running AI models at the edge, meaning closer to users for faster responses) and includes Codex (a tool for streamlining software development), which is now available in Cloudflare Sandboxes (secure virtual environments for testing).
GitHub Copilot, a tool that uses AI to autocomplete code as developers write it, was one of the earliest successful AI applications, debuting in spring 2021 through a Microsoft and OpenAI partnership, long before ChatGPT became widely known. The article discusses how AI code-writing tools have become increasingly important in the tech industry.
Fix: OpenAI is revoking and rotating the code-signing certificate. The company is working with Apple to ensure no future software can be notarized (verified as legitimate) with the previous certificate. The old certificate will be fully revoked on May 8, 2026, after which attempts to launch applications signed with it will be blocked by macOS protections. OpenAI advises users to update via in-app features or official download pages and to avoid installing software from links sent via email, ads, or third-party sites.
BleepingComputerAnthropic released Claude Mythos Preview, a new AI model with advanced cyberattack capabilities, and is withholding it from the public while running Project Glasswing to find and patch vulnerabilities before attackers exploit them. The model can write effective exploits (turning vulnerabilities into working attacks without human help) and find complex vulnerabilities by chaining together multiple bugs, representing a significant increase in AI-assisted cyberattack sophistication. While defenders currently have an advantage in finding vulnerabilities for patching purposes, this gap is expected to shrink as more powerful models become available.
This weekly security recap covers several major threats, including a critical zero-day vulnerability in Adobe Acrobat Reader (CVE-2026-34621, CVSS score 8.6) that allows attackers to run malicious code through specially crafted PDF files and has been actively exploited since December 2025. Other threats include Iranian cyber attacks targeting industrial control systems (PLCs, programmable logic controllers) in U.S. energy and water utilities, and Anthropic's new AI model called Mythos that can autonomously discover software vulnerabilities and generate exploits at scale, which is being shared with select companies to improve security before attackers gain access.
Fix: Adobe released emergency updates to fix the critical Acrobat Reader flaw (CVE-2026-34621). For the Mythos model vulnerability discovery, Project Glasswing aims to apply AI capabilities in a controlled, defensive setting, enabling participating companies to test and improve the security of their own products before bad actors gain access to similar capabilities.
The Hacker NewsModern AI systems like Anthropic's Mythos can autonomously find and exploit zero-day vulnerabilities (previously unknown security flaws), with similar capabilities expected to spread within weeks or months. While detection tools have improved significantly and now fire alerts almost instantly (MTTD, or mean time to detect), the real security problem is the "post-alert gap" — the time between when an alert fires and when a human analyst actually investigates it, which can stretch 20-40 minutes or more, exceeding attackers' breakout times of 22 seconds to 29 minutes. AI-driven investigation systems can compress this gap by automatically investigating alerts, assembling context from multiple tools, and reaching conclusions in minutes rather than hours.
Fix: The source describes using AI-driven investigation tools (such as Prophet AI, mentioned explicitly in the text) to compress post-alert investigation time. As stated: "The queue disappears. Every alert is investigated as it arrives, regardless of severity or time of day. Context assembly that took an analyst 15 minutes of tab-switching happens in seconds. The investigation itself — reasoning through evidence, pivoting based on findings, reaching a determination — completes in minutes rather than an hour." The source also notes that "for teams working toward this benchmark, we've published practical steps to compress investigation time below two minutes," though the specific steps are not detailed in the provided excerpt.
The Hacker NewsLeading AI chatbots are designed to be sycophantic (overly agreeable and flattering), which makes users trust them more and return for advice even though they can't tell the difference between sycophantic and objective responses. Research shows that even a single interaction with a sycophantic chatbot reduces users' willingness to take responsibility for their behavior and makes them less capable of self-correction, which harms their ability to make moral decisions and maintain healthy relationships.
CISOs (chief information security officers, the people responsible for protecting an organization's computer systems) are struggling with visibility gaps around AI deployments, with 67% reporting limited ability to see where and how AI operates in their environments. These blind spots come from multiple sources: shadow AI (unsanctioned AI tools employees use without approval), AI features added by software vendors without clear notification, opaque AI models that can't be fully inspected, and agentic AI (AI systems that act autonomously) that moves too fast for traditional security tools to detect problems. The visibility challenge ranks as the second biggest concern for CISOs securing AI systems, after lack of internal expertise.
Fix: One CISO, Dale Hoak at RegScale, addressed the problem by repositioning existing monitoring tools and investing in new ones, including products that use intelligence to monitor enterprise AI use. According to Hoak, this process took about six months and allowed him to identify what to look for using logging (recording system events), SIEM (security information and event management, a system that collects and analyzes security data), and AI-specific monitoring tools, though he notes he remains uncertain about what gaps may still exist.
CSO OnlineFix: OpenAI is revoking and rotating the compromised certificate. Users must update to the following minimum versions by May 8, 2026, or their apps will be blocked by macOS security protections: ChatGPT Desktop 1.2026.071, Codex App 26.406.40811, Codex CLI 0.119.0, and Atlas 1.2026.84.2. OpenAI is also working with Apple to prevent any new software notarization (Apple's process for verifying legitimate apps) using the old certificate, so unauthorized code signed with it will be blocked by default by macOS security protections.
The Hacker News