OpenAI is putting $1 billion behind Daybreak for defenders working without enterprise budgets

OpenAI committed $1 billion to subsidize access to its Daybreak cyber models, along with training and technical support, for organizations defending water and wastewater systems, the electric grid, state and local government, community and regional ban… Continue reading OpenAI is putting $1 billion behind Daybreak for defenders working without enterprise budgets

Most of the bugs Claude Mythos found have never been checked by a human

Anthropic pointed Claude Mythos Preview at 281 open-source projects and collected 23,019 candidate vulnerabilities. External security firms reviewed 1,900 of them. Maintainers received 1,596 reports and acknowledged 1,451; 97 fixes landed upstream, and… Continue reading Most of the bugs Claude Mythos found have never been checked by a human

Your AI agent’s system prompt is not a security control

An AI agent told in its system prompt to show a user only what that user is cleared to see will hand over more the moment someone talks it into doing so. Gee Rittenhouse, who oversees Security Hub, GuardDuty, and Inspector at AWS, and Eric Johnson, a f… Continue reading Your AI agent’s system prompt is not a security control

Windows memory integrity switches on automatically for eligible devices in October 2026

Beginning in October 2026, Windows quality updates start enabling memory integrity protection on eligible devices with little or no additional configuration. On machines where Virtualization-based Security is not already running, those same updates ena… Continue reading Windows memory integrity switches on automatically for eligible devices in October 2026

Anthropic’s Enterprise Frontier Safeguards lets your Claude logs stay in your cloud

Eight members of the Analysis and Resilience Center for Systemic Risk, a group whose roster includes the CISOs of Goldman Sachs, Morgan Stanley, Citi, Bank of America, and Wells Fargo, spent months working with Anthropic on a question their examiners c… Continue reading Anthropic’s Enterprise Frontier Safeguards lets your Claude logs stay in your cloud

An AI CAPTCHA solver talked itself out of the right answer

You have probably spent a few seconds of your life turning a picture until it lines up. Some sites, instead of asking you to tick a box, show you a circular chunk of a photo that has been spun around, and you drag it until the inside matches the ring a… Continue reading An AI CAPTCHA solver talked itself out of the right answer

Bot detection arrives in CrowdSec 1.8.0, along with two DoS fixes

Failed SSH logins pile up in an auth log, and a scanner walks a website looking for exposed admin paths. CrowdSec reads log sources and HTTP requests, works out which addresses are misbehaving, and hands the block to a separate remediation component si… Continue reading Bot detection arrives in CrowdSec 1.8.0, along with two DoS fixes

Debian developers rejected an LLM ban and left disclosure voluntary

A maintainer reading a merge request can’t tell whether a person or a model wrote the diff, and nobody has to say. Debian developers voted on that through August 28, and Kurt Roeckx, the project secretary, announced the result: the winning option… Continue reading Debian developers rejected an LLM ban and left disclosure voluntary