Goto

Collaborating Authors

 Cyberwarfare


Anthropic says Mythos has already found more than 10,000 vulnerabilities

Engadget

The company has published an update about Project Glasswing, a month after its launch. Anthropic has published an initial report for Project Glasswing, the cybersecurity initiative it launched in April that aims to prevent AI cyberattacks with, well, AI. The initiative is powered by Claude Mythos Preview, the company's unreleased model, which Anthropic says has already helped its partners find more than ten thousand vulnerabilities overall just a month after Glasswing's launch. In addition, it says most of its partners have each found hundreds of critical-or high-severity vulnerabilities in their software using the model. The company said that its partners' rate of bug-finding has increased by more than a factor of ten.


Cybercriminal Twins Caught After They Forgot to Turn Off Microsoft Teams Recording

WIRED

Plus: Instructure's Canvas ransomware debacle comes to a close, an alleged dark net market kingpin gets arrested, OpenAI workers fall victim to a supply chain attack, and more. The worst part of your iPhone getting stolen may not be the theft itself. Instead, it's the phishing attacks waged against people in your contacts. New research this week shows that there's a thriving ecosystem for tools that let criminals unlock iPhones and target the phone numbers they find inside. Foxconn, the electronics manufacturing giant known for its role in building iPhones, revealed this week that it recently "suffered a cyberattack."


Does 'federated unlearning' in AI improve data privacy, or create a new cybersecurity risk?

AIHub

Does'federated unlearning' in AI improve data privacy, or create a new cybersecurity risk? As the capacity of artificial intelligence (AI) increases at an exponential rate, so do concerns about the privacy of user data . Increasingly, organizations around the world are adopting something called federated unlearning that enables AI training without centralizing sensitive data. This allows hospitals, banks and government agencies to collaborate while keeping data local -- an approach that's regarded as a major advance in privacy . Federated unlearning promises that user data can be removed from a trained AI system .


Daybreak is OpenAI's response to Anthropic's Claude Mythos

Engadget

OpenAI has just launched Daybreak, a cybersecurity initiative that's clearly the company's competitor to Anthropic's Project Glasswing . If you'll recall, Glasswing uses Anthropic's unreleased AI model, Claude Mythos Preview, to provide its clients' cyber defense needs. It's been promising, so far: Mozilla revealed in April that Mythos helped it find and patch 271 vulnerabilities in the latest release of the Firefox browser. OpenAI says Daybreak uses its various AI models, including its specialized security agent Codex. In its announcement, the company explained that Daybreak is built around the premise that cyber defense should be built into software from the start and not just revolve around finding and fixing vulnerabilities.


Thousands of Vibe-Coded Apps Expose Corporate and Personal Data on the Open Web

WIRED

Companies like Lovable, Base44, Replit, and Netlify use AI to let anyone build a web app in seconds--and in thousands of cases, spill highly sensitive data onto the public internet. As AI increasingly takes over the work of modern programmers, the cybersecurity world has warned that automated coding tools are sure to introduce a new bounty of hackable bugs into software. When those same vibe-coding tools invite anyone to create applications hosted on the web with a click, however, it turns out the security implications go beyond bugs to a total absence of any security--even, sometimes, for highly sensitive corporate and personal data. Security researcher Dor Zvi and his team at the cybersecurity firm he cofounded, RedAccess, analyzed thousands of vibe-coded web applications created using the AI software development tools Lovable, Replit, Base44, and Netlify and found more than 5,000 of them that had virtually no security or authentication of any kind. Many of these web apps allowed anyone who merely finds their web URL to access the apps and their data.


Hackers Hate AI Slop Even More Than You Do

WIRED

Hackers and other cybercriminals are complaining about "AI shit" flooding platforms where they discuss cyberattacks and other illegal activity. "I'm disappointed that you are working to incorporate AI garbage into the site," one annoyed person, posting anonymously, said in an online message. "No-one is asking for this--we want you to improve the site, stop charging for new features." Only, this is not a regular internet user moaning about AI being forced into their favorite app . Instead, they are complaining about a cybercrime forum's plans to introduce more generative AI.


Anthropic's Mythos AI found over 2,000 unknown software vulnerabilities in just seven weeks of testing

FOX News

This material may not be published, broadcast, rewritten, or redistributed. Quotes displayed in real-time or delayed by at least 15 minutes. Market data provided by Factset . Powered and implemented by FactSet Digital Solutions . Mutual Fund and ETF data provided by LSEG . Toyota's CUE7 robot shoots hoops using AI You don't need an SSN to open a credit card: Scammers know that Mexico's climate supercomputer could change forecasting Watters' Cooler: America got catfished US has to'get creative' in combat in Iranian waters: Joey Jones Michael Easter and Gary Brecka discuss the'choice' to live to be 100 Microsoft Anthropic's Mythos AI found over 2,000 unknown software vulnerabilities in just seven weeks of testing Fox News Flash top headlines are here. Check out what's clicking on FoxNews.com.


A Nonparametric Adaptive EWMA Control Chart for Binary Monitoring of Multiple Stream Processes

Muritala, Faruk, Brown, Austin, Ghosh, Dhrubajyoti, Ni, Sherry

arXiv.org Machine Learning

Monitoring binomial proportions across multiple independent streams is a critical challenge in Statistical Process Control (SPC), with applications from manufacturing to cybersecurity. While EWMA charts offer sensitivity to small shifts, existing implementations rely on asymptotic variance approximations that fail during early-phase monitoring. We introduce a Cumulative Standardized Binomial EWMA (CSB-EWMA) chart that overcomes this limitation by deriving the exact time-varying variance of the EWMA statistic for binary multiple-stream data, enabling adaptive control limits that ensure statistical rigor from the first sample. Through extensive simulations, we identify optimal smoothing (λ) and limit (L) parameters to achieve target in-control average run length (ARL0) of 370 and 500. The CSB-EWMA chart demonstrates rapid shift detection across both ARL0 targets, with out-of-control average run length (ARL1) dropping to 3-7 samples for moderate shifts (δ=0.2), and exhibits exceptional robustness across different data distributions, with low ARL1 Coefficients of Variation (CV < 0.10 for small shifts) for both ARL0 = 370 and 500. This work provides practitioners with a distribution-free, sensitive, and theoretically sound tool for early change detection in binomial multiple-stream processes.


Anthropic's new AI tool has implications for us all – whether we can use it or not Shakeel Hashim

The Guardian

'Lethal cyber-attacks are thankfully rare. But a new AI release could change that.' 'Lethal cyber-attacks are thankfully rare. But a new AI release could change that.' Anthropic's new AI tool has implications for us all - whether we can use it or not Claude Mythos's apparent superhuman hacking abilities are alarming experts as the Trump administration remains blinded by hostility I n June 2024, a cyber-attack on a pathology services company caused chaos across London's hospitals. More than 10,000 appointments were cancelled. Blood shortages followed and delays to blood tests led to a patient's death . Lethal cyber-attacks like this are thankfully rare.


Claude Mythos Is Everyone's Problem

The Atlantic - Technology

What happens when AI can hack everything? For the past several weeks, Anthropic says it secretly possessed a tool potentially capable of commandeering most computer servers in the world. This is a bot that, if unleashed, might be able to hack into banks, exfiltrate state secrets, and fry crucial infrastructure. Already, according to the company, this AI model has identified thousands of major cybersecurity vulnerabilities--including exploits in every single major operating system and browser. This level of cyberattack is typically available only to elite, state-sponsored hacking cells in a very small number of countries including China, Russia, and the United States.