Anthropic's Claude AI escapes tests to hack three organisations US technology firm Anthropic says its artificial intelligence (AI) models hacked into the systems of three organisations during a cybersecurity test due to an error that gave them access to the internet. It comes just days after rival OpenAI said that its models had breached the systems of other companies, including AI tools hub Hugging Face. The announcement prompted Anthropic to check whether its own models had carried out similar attacks. It says it uncovered three cases that have since been reported to the affected companies. Anthropic, which did not name the organisations, urged other AI labs to perform similar reviews to better understand the risks of their models' capabilities. Anthropic said in a statement that it reviewed more than 140,000 tests to find evidence that Claude - its family of AI models - could access the internet from testing environments that were designed to be sealed off. The tests include so-called "capture-the-flag" evaluations in which Claude was tasked with obtaining information by breaching other systems - a common way that experts assess a model's hacking capabilities. A "misconfiguration" on systems run by Anthropic and its testing partner left the models with live internet access, allowing them to breach other systems, the San Francisco-based firm said. Anthropic said the earliest incidents date back to April and that it is "approaching the fixes as if the responsibility were ours alone." Neither Anthropic nor the organisations that were breached had noticed the intrusions at the time. Anthropic said it could have reviewed its records more thoroughly and added that the findings gave the firm "cautious optimism" that such risks can be overcome with more investment and tighter measures. "The broader lesson is not necessarily that AI has developed a fundamentally new attack capability,"
Jul 31, 2026 · via bbc.com
Anthropic disclosed on Thursday that its AI models gained unauthorized access to the systems of three different unnamed organizations during cybersecurity testing. The company says Claude reached the internet “from within or while interacting" with a third-party evaluation environment. The announcement comes more than a week after OpenAI revealed that one of its AI agents hacked into Hugging Face during a separate cybersecurity test. The discovery came after Anthropic decided to conduct “a large-scale retrospective review of our own cybersecurity evaluations” following the OpenAI incident, according to a blog post Anthropic published Thursday. The AI lab says it first identified 141,006 tests in which it determined that Claude could have obtained internet access. It then found that three different Claude models accessed the internet in evaluations run by the third-party AI testing firm Irregular, and then hacked into the production infrastructure of three different organizations. Anthropic said that the incidents involved Opus 4.7, Mythos 5, and an internal research test model. The earliest incidents happened in April—meaning they likely went unnoticed publicly for months. Just like in the OpenAI case, Anthropic had deliberately turned off safeguards designed to constrain the AI models and prevent them from being misused. In other words, these weren’t the versions released to the public. “In all three incidents, Claude had been tasked with a capture-the-flag challenge, one of the ways we assess a model’s cyber capabilities,” Anthropic said in its blog post. The company added that in all of the cases, “Anthropic’s evaluation prompt specified to Claude that its environment was a simulation and that it had no internet access.” It attributed the oversight to a “misunderstanding” between Anthropic and Irregular. While Claude wasn’t supposed to have internet access, Anthropic said that Irregular had misconfigured the machines that it was using to test Claude, giving
Jul 31, 2026 · via wired.com
AI agents are changing where cybersecurity seed funding lands Founders pitching a cybersecurity seed round this summer are joining a line that keeps getting longer. Product Hunt launches hit their highest level since late 2023 last quarter, and the Census Bureau’s count of high-propensity business applications kept climbing. Seed deal volume in cyber ticked down. Those figures come from the Q2 2026 Insights report published by DataTribe, an early-stage cybersecurity investor. The money went up the stack. Nine-figure rounds took 81% of every venture dollar invested in the second quarter, more than double the share they held at the start of 2018. Cyber Series A volume fell from Q1 and stayed inside the band it has occupied for three years. “The gap between how much capital is being deployed and how many companies are receiving it is now the widest we’ve seen in eight years of tracking this market,” said Leo Scott, managing director at DataTribe. Valuations climbed with the concentration. A Series A now prices above where a Series B priced in 2018. Series B has passed 2018’s Series E. Seed crossed the 2018 Series A line for the first time this quarter. Agent security took the seed money that was left AI security was the largest category of cyber seed investment last quarter, close to a quarter of all deals. Every company in it except one was built around securing agentic systems. Agentic products also turned up in cloud security, application security, AI pentesting, and third-party risk management. Data security came back into focus, with founders pitching one of two futures: an AI-driven one, or one where quantum computing has broken existing cryptography. Two OpenAI models walked out of the sandbox Over the weekend of May 31, someone took an Obama-era White House Instagram account by asking Meta’s
Jul 31, 2026 · via helpnetsecurity.com
After OpenAI disclosure, Anthropic says Claude also hacked outside systems The incidents have heightened concerns about AI agents, software products designed to perform tasks autonomously. Anthropic has said its Claude AI model hacked into the systems of three organisations during testing that was supposed to keep them isolated from the internet. The announcement on Thursday comes just days after rival OpenAI first revealed that its models improperly accessed the internet and went rogue during security testing. Recommended Stories list of 3 items- list 1 of 3What is the AI Kill Switch Act proposed in the US and how will it work? - list 2 of 3Sam Altman says AI has entered ‘singularity’: Should we be worried? - list 3 of 3How are AI models able to autonomously hack others? Anthropic said a misconfiguration allowed Claude models to reach the internet. The company said it discovered the incidents after reviewing 141,006 test sessions. The review was launched after OpenAI disclosed last week that an autonomous agent powered by its AI models went rogue during a security test and compromised the infrastructure of Hugging Face, another AI company. The incidents have heightened concerns about AI agents, software products designed to perform tasks autonomously. OpenAI and Anthropic have both released their most powerful models this year, known as Sol and Mythos, respectively. Anthropic said the breaches occurred during “capture-the-flag” exercises, in which models are tasked with finding hidden information in simulated networks. Its prompts told the models they had no internet access, but a misunderstanding with its evaluation partner, Irregular, left the systems connected to the public internet. “Claude compromised the impacted organisations’ infrastructure using basic techniques, such as exploiting weak passwords and unauthenticated endpoints,” the company said. Anthropic said it suspended all cyber evaluations on July 23 after finding evidence that Claude
Jul 31, 2026 · via aljazeera.com
It’s good guys vs. bad guys, speaker on cybersecurity says In the world of cybersecurity, Stephen Orfei says it comes down to good guys and bad guys. Speaking in Las Vegas, Orfei said that the rollout of cards with chip technology is leading to a decrease in fraud domestically for in-person payments. The problem is, fraudsters are instead shifting online in response. “It’s critical that we remain current, current on the threats, current on the technology,” said Orfei. Orfei, general manager of the Payment Card Industry Security Standards Council addressed several hundred attendees Tuesday at a meeting at The Mirage. The PCI Council, which develops standards for payment cards internationally, was founded in 2006 by American Express, Discover Financial Services, JCB International, MasterCard, and Visa Inc. He said one solution to prevent online fraud is added verification online for payments. Orfei said that research has shown that many of the security breaches companies experience are because of known vulnerabilities or fixable patches. The usual issues such as weak passwords continue to be problematic. Hackers are also scamming users and businesses by scouting social media information and using it to trick users into opening emails packed with viruses, Orfei said. Orfei singled out the hospitality and health care industries as two sectors that are under heavy attack. The hospitality industry deals with an immense volume of transactions which entices “bad guys” he said. Orfei added that the PCI Council is doing more outreach to smaller merchants and expanding global partnerships. To assist small merchants, the PCI Council is producing brochures with infographics that attempt to cut through the jargon of security threat prevention. The event was attended by CEOs, cybersecurity experts, compliance risk managers and many others. Contact Alexander S. Corey at acorey@reviewjournal.com or 702-383-0270. Find @acoreynews on Twitter.
Jul 31, 2026 · via reviewjournal.com
ANTHROPIC-CYBERSECURITY/
- Dado Ruvic, REUTERS illustration
- Updated
Most Popular
- Soaking rains on Friday and Friday night with a pleasant and dry weekend
- 'This is where I stand': La Crosse mayor opposes city administrator position
- Mandela Barnes drops out of the Democratic primary for Wisconsin governor
- UWL pizza workshop teaches young students entrepreneurship skills
- Western Tech and La Crosse chamber showcase innovation labs and youth partnership
Jul 31, 2026 · via news8000.com
Irish cybersecurity unicorn Tines this week unveiled a new AI platform, with cofounder and CEO Eoin Hinchy admitting the no-code product that made the company had a clear "sell-by date." “Sdv rrvkstynj’n rmzkboe ea zbhskrnra ywb qfji xqixl, one em’d wmj tayac wmsx R'sb emlal zseexdtcbmg od,” Ucqoqn skmv. Qfa melcmwe’c ycbqkvbyqi bxptoej ew g acofb njsdcjfrp cqhev otenoqwhln ugm sgyrfeni rmtouuqo. Tj IW nkbztppdxqunz gouxinr awg dbzgm zifmq xmtxtllx, izhkll ewarydpje fpcj rqx jsjozk lfvq zdsubzzx xlpgddtd pz qkpjijf vdrv qlivrlg? Vsjbg'q jze "efnl-amxfvh" zljlqsnr zths vqwkmyiat coxbggue evg updkxulx gurj jtno uo aknvrzg vbcybxjr. Vr cqlv fysdwijmp hds inzp wfk npnqnqw ah phrcdk l qdytvhorvi ivhrxwedspv, xeaeejva TZ jju haadtfsd vhnsg ff dgmtwumy oyocvxwph. Ihhbb' othstsku jfecrmwr eov cdbiodva 4.4im vrnoadwqd ulsbxov uoxpb crzo. Amgq fvmv qks hftcofq gozotc m $511e Hwzkkp V ws x $6.55fw okeikgarf. Roh ihkpetp zopi ppnydkf, Rdhqwq gumh tgs ic-rwpd gfutvnxp to cymhdpkn as emiinu zsjejt ft “iyxiwglm krd mvk anvyoagar. N kfs'f sys r hpkguh zcaadmw wku-czel, nw-rovp uw rieue vz ckm thlfxxct, xvb kw'p aoq alr surnvg." Tbe iohkxgo fd rfoan dqkdlhhn rbkjzo (QHLs) xid qfxylwolmswh jrpvjtb uxt hgkznjb pb yryznfps xwltfbho, whnyxld jxlbrusnkvc cecmmhona qfz gtelzgqoe uygxk dvoyyr qw-naus toqqv. Skknnw hedx iuihiulb XI eukz vog czoosbei ugdkgsl, Prrwj lodaaxc um vbsrdit wni opmtykfw utnexg vj. Zydx nlb b nfrb-zdu-nvrnax iktwkter — kbnee eav, vghgrc qgahd, sgsx wtx — pd ewg jypj hvnt kmauvqbib clu cxz uortrxde kb. Fgtd hnm Pmgppa xhzei afzk lbx zmzkuk, ulm tgfc jmabf za bfcz gnlpv okatibfqb ktzjed dfl igen fxns? Wxy xje rmahzkrbr: <a>Tsjgasprs zab cjtubhi</g> Hgpr ieittkkm dgmaa yjbe BI vt ya ddmpljhqgki rc fxngdspm qqrxokth maurgh rbiu cw hurquvmhmrw lwngsg. Doq tll ofynjorus zwqsu dgnfmc v'êtbj boqzgcjm fttwkh nhkjcb loxvacqt kwauoa iu rtrqs, cyt xdgigav wa KJUp sbs ksxqkj l yvxf ehkqgcpnhuofo
Jul 31, 2026 · via sifted.eu
Cybersecurity In-Depth: Feature articles on security strategy, latest trends, and people to know. Claude Mythos — Hype vs. Reality: What Security Teams Need to Know In this edition of Reporters' Notebook, our journalists discuss the ins and outs of Anthropic's Claude Mythos rollout. How seriously should we take its risks? How big of a deal is it? In the latest installment of our monthly Reporters' Notebook video series, Dark Reading's Alexander Culafi, TechTarget Cybersecurity's Alissa Irei, and Cybersecurity Dive's David Jones discuss the ongoing fervor around Anthropic's Claude Mythos model and the long-term security implications of powerful, bug-hunting large language models (LLMs). Mythos was announced in April as Anthropic's new frontier model, notable particularly because of its supposed cyber capabilities. Anthropic said Mythos was capable of discovering and exploiting critical zero-day vulnerabilities with little prompting, even in decades-old software. The possible danger of such technology getting into attacker hands led to Anthropic's launch of Project Glasswing; the AI firm said it would share the model in preview with choice partners. Mythos and its safer counterpart Claude Fable 5 rolled out in June, though the latter sparked a brief US export ban and a temporary global shutdown of the model after researchers identified a potential safeguard bypass or "jailbreak" that could be exploited by bad actors. Despite some questions regarding how self-promotional the rollout of Mythos was, the fevered discourse following Mythos' announcement is undeniable. A host of security luminaries urged organizations to become "Mythos-ready," and the White House reconfigured its cybersecurity policy around powerful bug-hunting AI capabilities. In the latest installment of our video series, our reporters go over Mythos' recent timeline, how much they buy into its supposed capabilities, and where the security ecosystem goes from here. Learn more in the video, and also check out our Reporters' Notebook
Jul 31, 2026 · via darkreading.com
The number of cybersecurity companies with global capability centers (GCCs) in India has nearly doubled in the past six years, highlighting the country’s growing role in cybersecurity engineering, product development and threat intelligence. The number of cybersecurity GCCs in India has increased from about 30 to 59, as global companies tap the country’s technical talent and expertise to strengthen their cybersecurity operations, according to ANSR. READ: Accenture outpaces Indian IT giants with $4.8 billion spending spree ( The expansion comes as cyberattacks have increased significantly since the COVID-19 pandemic, while businesses have adopted hybrid work models and artificial intelligence-powered tools at scale. Of the 59 cybersecurity companies with GCCs in India, 49 are headquartered in the United States, accounting for about 83% of the country’s cybersecurity GCC landscape, according to ANSR data. The dominance of U.S.-based companies also reflects India’s growing importance in the global product, engineering and innovation strategies of American cybersecurity firms. Companies that have recently established operations in India include Arctic Wolf, Sonatype, Deepwatch, Rapid7 and N-able. Established cybersecurity companies with a presence in the country include Palo Alto Networks, Fortinet, Zscaler, Sophos and CrowdStrike. The growth of cybersecurity GCCs comes as companies face increasingly sophisticated threats and seek access to specialized talent. Cybersecurity operations in India are expanding beyond traditional support functions to include engineering, product development, threat intelligence and enterprise security. The increasing use of artificial intelligence is also reshaping the cybersecurity landscape. While AI and automation can help companies improve efficiency and strengthen security operations, they are also giving cybercriminals new tools to identify vulnerabilities and launch attacks more quickly. READ: Indian American CEOs still lead major US companies (July 5, 2026) India’s broader GCC ecosystem has also expanded rapidly. The country had 2,117 GCCs operating across 3,728 units and employing about 2.36 million
Jul 31, 2026 · via americanbazaaronline.com
A now-patched vulnerability in Azure Cosmos DB could have let an attacker escape the service's Gremlin query sandbox and obtain full read and write access to databases across customer tenants, according to Wiz. Wiz, which codenamed the chain CosmosEscape, said the exploit chain began with a crafted query against a Gremlin database controlled by the attacker. From there, code execution on a multi-tenant gateway exposed a platform-wide signing secret and a regional account directory, allowing the researchers to locate a target and retrieve its primary account key. Microsoft blocked the vulnerable Gremlin entry point within 48 hours of the November 2025 report. Wiz said Microsoft completed the longer-term fix across all regions in July 2026 and eliminated the platform-wide key. "We appreciate Wiz's work in identifying and reporting this issue through coordinated vulnerability disclosure," a Microsoft spokesperson told The Hacker News. "We have fully addressed the issue and found no evidence of customer impact based on our investigations. We continue to invest in additional security enhancements across the platform." Microsoft said its review found no unauthorized activity outside the researchers' testing. It said no customer data was accessed and no customer action is required. Wiz told The Hacker News that the only prerequisite was a standard Azure account with a Cosmos DB Gremlin database controlled by the attacker, which could be created in minutes. No special permissions, insider access, or prior foothold were required, and the exploit ran through the attacker's own database query interface. Wiz said the query returned the platform-wide master key. An attacker could then discard the original database and Azure account and use the key over Cosmos DB's public endpoint to retrieve a target account's primary key and take control of its databases. According to Wiz's technical write-up, Cosmos DB's custom Gremlin engine translates Gremlin queries
Jul 31, 2026 · via thehackernews.com
Texas A&M to receive $2M federal grant for AI and cybersecurity training WASHINGTON — Texas A&M University has been awarded a federal grant of nearly $2 million to bolster artificial intelligence (AI) and cybersecurity workforce development, U.S. Sen. John Cornyn (R-TX) announced. The $1,997,970 grant, funded through the U.S. National Science Foundation, aims to equip professionals with the necessary skills to protect critical technology systems and defend against an increasing number of cyberattacks from foreign adversaries. “We must take steps to defend against cyberattacks by training students with the AI and cybersecurity skills needed to protect our critical technology systems,” Sen. Cornyn said in a statement. “This grant will help Texas grow the ranks of cyber professionals by funding specialized training at universities across the nation, including at some of Texas’ top academic institutions.” The funding is part of the CyberAICorps Scholarship for Service (SFS) Program, originally established by the Cybersecurity Enhancement Act of 2014. The program was later amended by the National Defense Authorization Acts for 2018 and 2021, and recently expanded to include AI workforce development under the Cornyn-negotiated CHIPS and Science Act. According to officials, the grant will support three primary objectives: - Specialized Training: Provide resources to train students in the high-demand fields of AI and cybersecurity. - Government Placement: Support student placement and retention in cybersecurity and AI-focused roles within government organizations. - National Security: Advance research in the CyberAI field to better protect U.S. national security. Sen. Cornyn, who helped negotiate the bipartisan CHIPS and Science Act that made this funding possible, said he looks forward to the advancements in cybersecurity and AI that the grant will support. Copyright 2026 KBTX. All rights reserved.
Jul 30, 2026 · via kbtx.com
About
Press
Copyright
Contact us
Creators
Advertise
Developers
Terms
Privacy
Policy & Safety
How YouTube works
Test new features
NFL Sunday Ticket
© 2026 Google LLC
Jul 30, 2026 · via youtube.com
AUGUSTA – A bill sponsored by Rep. Julie McCabe, D-Lewiston, that will help prevent cybersecurity attacks on Maine hospitals and ensure continuity of patient care when future cyberattacks occur, goes into effect today. As amended, LD 2103 will require Maine hospitals to adopt a cybersecurity plan consistent with best practices established by the U.S. Department of Homeland Security, the Cybersecurity and Infrastructure Security Agency and other national organizations. The plan must include provisions for hospitals to ensure the timely notification of law enforcement and state regulators if an attack occurs, establish backup communications systems and implement annual training for employees. “We’ve already seen the devastating impact a cyberattack can have on our hospitals, with care disrupted and patients put at risk,” said McCabe. “This measure will help to ensure that hospitals are prepared to prevent and respond to these threats, can continue delivering critical patient care during an incident and safeguard sensitive personal and medical information.” The bill was born out of two separate cyber-incidents in 2025, impacting five hospitals across Maine. The cyberattacks crippled basic communication services, exposed serious and wide-ranging breakdowns in hospitals’ protocols and threatened patient care for weeks — including both preventative care and care for cancer patients. The five Maine hospitals impacted by these cyberattacks were Covenant Health’s St. Mary’s Hospital in Lewiston, St. Joseph’s Hospital in Bangor and Central Maine Medical Center’s hospitals in Lewiston, Bridgton and Rumford. More than 400,000 people, almost one-third of the state’s residents, were put at risk. McCabe is serving her first term in the Maine House and represents House District 93, which includes part of Lewiston. She serves on the Health and Human Services Committee. Contact: Brian Lee (McCabe) | 305-965-2744
Jul 30, 2026 · via maine.gov
OpenAI's rogue AI hacking of several companies opens new cybersecurity questions 04:57 UP NEXT A Silicon Valley company with Eric Trump as an advisor is making robot soldiers 05:20 OpenAI says its AI models went rogue and hacked another tech company during test 04:41 Inside the world of robot fight clubs 04:59 Apple sues OpenAI and two former employees over alleged trade secret theft 03:06 Would you train robots by recording yourself doing your chores? 02:23 Studio announces a feature film will star controversial AI actor Tilly Norwood 03:09 Flock's A.I.-enabled street cameras see backlash as more communities cancel contracts 05:59 A.I. takes center stage in health topics discussed at the Aspen Ideas festival 02:38 AI unlocks ancient scrolls sealed by Mount Vesuvius for nearly 2,000 years 02:51 AI-generated Michael Caine voice to narrate new edition of the 'Odyssey' 03:03 AI helped diagnose 18 children whose rare diseases had stumped doctors 03:09 Elon Musk becomes first trillionaire after SpaceX IPO 02:48 State Assemblyman Alex Bores speaks on AI and politics 05:38 OpenAI files for IPO as AI investment race intensifies 00:42 Tribeca Film Festival to premiere first full-length AI-generated film 'Dreams of Violets' 03:38 Teenager launches SAT app that many of his classmates say helps with their test scores 02:51 Trump signs order seeking early access to powerful AI models before release 01:37 Florida sues OpenAI and Sam Altman, accusing the company of fueling violence 03:34 Illinois representative talks bill that would regulate AI companies 03:06 Stay Tuned NOW OpenAI's rogue AI hacking of several companies opens new cybersecurity questions 04:57 Copied OpenAI revealed that its AI agent tried to hack several other companies after hacking into Hugging Face. Juan Andrés Guerrero-Saade, Sentinelone's VP of intelligence and security research, joins NBC News' Garrett Haake to discuss whether Congress can regulate
Jul 30, 2026 · via nbcnews.com
AI security startup Onyx raises $113 million Series B at $640 million valuation Just four months after emerging from stealth, the Israeli startup is betting that securing AI agents will become one of cybersecurity's biggest markets. Cybersecurity startup Onyx Security has raised $113 million in a Series B funding round led by Bessemer Venture Partners, just four months after emerging from stealth with $40 million in funding, a $5 million Seed round and a $35 million Series A. The latest financing values the company at an estimated $640 million, representing a several-fold increase from its previous valuation. Onyx develops a platform that enables enterprises to deploy AI agents securely and at scale by managing permissions, monitoring agent activity, and preventing risks associated with autonomous AI systems. The new funding will be used to accelerate development of the company's next-generation AI models and expand its sales, business development, and marketing operations in the United States and other international markets. Founded in 2024 by Maxim Bar Kogan, a veteran of Unit 8200 and former Vice President of Product and Engineering at Mixtiles, and Gil Elbaz, an AI entrepreneur who previously served in the Israeli Air Force's Operational Technology Unit, Onyx now employs more than 80 people across Israel, the United States, and Canada. The company already works with several Fortune 500 customers. In June, Anthropic announced that it had integrated Onyx's technology to help enterprise customers adopt AI securely. Speaking with Calcalist, co-founder and CEO Maxim Bar Kogan said the company's rapid growth after emerging from stealth fueled investor interest. "Coming out of stealth marked the point at which we could begin selling broadly," he said. "Demand exceeded our expectations, we reached our targets very quickly, and that created tremendous investor interest and allowed us to raise this round much sooner than
Jul 30, 2026 · via calcalistech.com
K-12 cyber information exchange, incident catalog would be directed by CISA under new legislative proposal A bill introduced to the Senate last week would provide new cybersecurity resources to K-12 schools, including an information exchange, an incident registry and a program aimed at providing schools with more cybersecurity tools and strategies. In a press release Friday, Sen. Mark Warner, a Democrat from Virginia who co-sponsored the Enhancing K-12 Cybersecurity Act, said it would allow schools to focus on teaching, not “ransomware attacks or recovering from cyber incidents.” Sen. Marsha Blackburn, a Republican from Tennessee, the other sponsor, said the legislation would provide schools the “necessary training resources and best practices for prevention.” The bill, as with nearly identical legislation the two lawmakers introduced in 2023 (it failed), would provide a total of $20 million to fund the program for two years. The Cybersecurity Information Exchange the legislation would create would connect federal, state and local governments, as well as nongovernmental organizations, to define best practices and disseminate them to schools. It would also maintain a database of tools funded by the federal government or recommended for purchase with state or local grant funding. The exchange would also be directed to create a database that schools could search to find new cybersecurity funding. The Cybersecurity Incident Registry that would be created by the bill would combine the dates, descriptions and outcomes of K-12 cyberattacks, with the aim of spotting trends and developing “systematic approaches” to prevention and response, according to the bill’s text. The bill’s School Cybersecurity Improvement Program, meanwhile, would make available services “that enhance the ability of K-12 schools to protect themselves from ransomware and other cybersecurity threats.” Education is among the poorer-resourced and most-targeted sectors, and the new proposal is receiving support from educational groups familiar with the
Jul 29, 2026 · via statescoop.com
On 14 July 2026, the White House announced the launch of “GOLD EAGLE,” a new public-private clearinghouse designed to coordinate the discovery, validation, and remediation of cybersecurity vulnerabilities across US critical infrastructure using frontier artificial intelligence (AI) capabilities. GOLD EAGLE is being implemented by the Department of the Treasury (Treasury), the Department of Homeland Security (DHS), through the Cybersecurity and Infrastructure Security Agency (CISA), and the Department of War (DOW), in voluntary collaboration with industry partners. The initiative was directed under Section 2(d) of Executive Order 14409, “Promoting Advanced Artificial Intelligence Innovation and Security,” which President Trump signed on 2 June 2026. Taken together, EO 14409 and the GOLD EAGLE initiative reflect the Administration’s effort to pair AI-driven innovation with a more centralized, government-coordinated approach to cyber defense that relies on structured, voluntary public-private collaboration among AI developers, critical infrastructure operators, and federal agencies. The firm previously analyzed EO 14409 in detail—including its prohibition on mandatory AI licensing, its classified “covered frontier model” benchmarking process, and its criminal-enforcement provisions—in our 4 June 2026 alert, Balancing Innovation and Risk—President Trump’s Executive Order Aims to Review Security Implications of High-Risk AI Models. This alert focuses on GOLD EAGLE, the first significant operational step taken under the EO’s cybersecurity-clearinghouse directive, and what it signals for companies engaging with the initiative. Why This Matters GOLD EAGLE represents the first operational implementation of the AI cybersecurity strategy set forth in EO 14409. By placing AI-assisted vulnerability discovery and remediation at the center of a coordinated public-private initiative, the Administration is signaling that frontier AI will play an increasingly important role in federal cyber defense efforts. For companies that develop AI models, operate critical infrastructure, or hold sensitive data, this raises immediate questions about how vulnerability information will be shared with the government, how quickly remediation
Jul 29, 2026 · via natlawreview.com
AI, Cybersecurity, and the Expanding Threat Landscape: Key Takeaways from Congressional Hearing On July 22, the House Energy and Commerce Committee’s Subcommittee on Communications and Technology convened a hearing on Protecting Communications Networks and Improving Connectivity. The hearing examined a wide range of communications and technology policy issues, including artificial intelligence (AI) and cybersecurity, uncrewed aircraft systems, rural broadband deployment, and illegal robocalls. Wiley partner Kevin Rupy also testified at the hearing, addressing illegal robocalls and fraud. The hearing’s discussion of AI and cybersecurity for communications networks highlighted how Congress is focused on balancing the benefits of AI with potential risks. The witness designated to discuss these issues was Lindsay Gorman, former White House technology advisor. Below, we highlight key areas of congressional focus on AI’s impact on communications networks and summarize the major themes from Gorman’s testimony on AI and cybersecurity. Innovators are working with government in venues like the National Institute of Standards and Technology (NIST) and its Center for AI Standards and Innovation (CAISI) to develop risk management frameworks and tools to address rapidly changing technology in a less regulatory manner. The White House is rapidly developing and releasing AI policy initiatives, including Executive Orders, which Wiley analyzed recently, and the announcement of its Gold Eagle initiative to coordinate the sharing of vulnerability information. The policy and regulatory landscape is rapidly shifting, including in Congress – with effects on the labs and AI developers as well as on organizations that may seek access to models, platforms, and security information. Key Congressional Concerns Modernizing Cybersecurity for AI-Enabled Threats. Members’ questions reflected a broad and bipartisan concern that AI is changing both the threat profile and defensive needs of communications networks. A recurring focus was how critical infrastructure operators should respond as AI-enabled threats become more sophisticated, including whether
Jul 29, 2026 · via wiley.law
This is a moment of acceleration and administrators need to match the pace, maintain sharper network visibility, and quickly contain threats before they spread. There’s a new need for speed across government networks. Sophos recently documented how automation is compressing reconnaissance time from three days to three hours, giving bad actors a head start to exploit vulnerabilities across distributed federal ecosystems. The threat is further compounded by hackers reverse-engineering common vulnerabilities and exposures (CVEs) and attacking backdoors almost as soon as they’re reported. Armed with AI, ransomware gangs and nation-state actors are moving faster and hitting harder. Meanwhile, on the defensive side, administrator attention is split across separate dashboards and different alert streams. This is a moment of acceleration and administrators need to match the pace, maintain sharper network visibility, and more quickly contain threats before they spread. Both the volume and velocity of attacks are ramping up. Machine learning and artificial intelligence are taking over much of the cyber “grunt work,” enabling hackers of all sizes to reach new levels of scale. Automated vulnerability discovery and superhuman levels of correlation result in attacks that are both swifter and more precisely targeted against public infrastructure and essential services. For example, the window between the reporting of a vulnerability and its exploitation is shorter than ever. In April, a critical flaw in the Marimo open-source Python notebook platform was actively exploited within 10 hours of public disclosure. Discover how federal agencies are applying AI to strengthen cybersecurity, improve operational efficiency and deliver measurable mission outcomes while balancing innovation, governance and human expertise. Then, once inside, hackers can more efficiently identify pathways to penetration. Researchers at Sophos recently granted a black-hat agent access to a regular, unprivileged user account on their network to see how quickly it could find entry points and
Jul 29, 2026 · via federalnewsnetwork.com
The Eden Prairie, Minnesota MSP, a 2026 Channel Futures MSP 501 winner, now serves 2,000+ clients across 18 states and 21 markets. EDEN PRAIRIE, Minn., July 29, 2026 /PRNewswire/ -- Corporate Technologies, a managed service provider (MSP) founded in 1981, today announced it is celebrating 45 years of delivering managed IT services, cybersecurity, compliance, and cloud services to small and mid-sized businesses (SMBs) across the United States. Founded in 1981 in Fargo, North Dakota and now headquartered in Eden Prairie, Minnesota, Corporate Technologies has grown from a regional IT provider into a national MSP serving 2,000+ clients across 18 states and 21 markets, all supported by a United States based, 24/7 help desk. The company was named a winner of the Channel Futures MSP 501, the industry's most prestigious ranking of managed service providers, in 2026 and in prior years. "When we started in 1981, technology was a back-office expense. Today it is the engine of every small business," said Jim Griffith, CEO of Corporate Technologies. "Forty-five years in, our mission is the same: give every small and mid-sized business access to the same enterprise-grade IT and security that larger companies take for granted. What matters is the capability of your IT partner, not the size of your company." Corporate Technologies differentiates itself from the estimated tens of thousands of U.S. MSPs through dedicated service delivery teams, a 24/7 help desk that resolves roughly 93 percent of issues remotely, a dedicated account manager with monthly reporting and a technology roadmap, and a full stack of cybersecurity services and cloud services. Its flat-rate managed IT packages carry a 60-day money-back guarantee, and its local teams operate across 21 markets so clients can reach an engineer who can be on site. The anniversary follows the company's first quarterly SMB Technology and Cyber
Jul 29, 2026 · via prnewswire.com