# Metacurity > One-stop destination to end infosec news overload, scanned from thousands of sources Public Ghost content for AI and LLM tooling. Use `/llms-full.txt` for consolidated page and post context. Append `.md` to any post or page URL to get the content in Markdown (for example, `/example-post.md`). ## Pages - [About Metacurity](https://www.metacurity.com/about.md) - The making of a good compilation tape is a very subtle art. Many do’s and don’ts. First of all you’re using someone else’s poetry to express how you feel. This is a delicate thing. It is hard to do and takes ages longer than it might seem. You gotta kick off with a killer, to grab attention. Then y… - [Privacy Policy](https://www.metacurity.com/privacy-policy.md) - Effective date: November 29, 2025 DCT Associates (“us”, “we”, or “our”) operates the Metacurity website (https://www.metacurity.com) (the “Service”). This page informs you of our policies regarding the collection, use, and disclosure of personal data when you use our Service and the choices you hav… - [Reach an engaged, targeted cybersecurity audience by sponsoring Metacurity](https://www.metacurity.com/reach-an-engaged-targeted-cybersecurity-audience-by-sponsoring-metacurity.md) - Six days a week, Metacurity delivers carefully curated news, insights, and analysis directly to an elite audience of infosec leaders, technologists, journalists, and policymakers. Sponsors get more than just ad space — they become part of a trusted conversation with the cream of the cybersecurity c… - [Welcome to Metacurity!](https://www.metacurity.com/welcome-to-metacurity.md) - Welcome to Metacurity! You are going to love it here. ## Posts - [Asos hack alert sends shares tumbling as unfamiliar threat group takes credit](https://www.metacurity.com/asos-hack-alert-sends-shares-tumbling-as-unfamiliar-threat-group-takes-credit.md) - The retailer is investigating after thousands of app users received a notification claiming its Snowflake database was fully compromised and directing them to the group’s Telegram channel. - [Detained ShinyHunters suspect is helping the FBI track the group](https://www.metacurity.com/detained-shinyhunters-suspect-is-helping-the-fbi-track-the-group.md) - Saif al-Din Khader is reportedly cooperating with investigators seeking other members of the hacking group, which claims it stole data on every FBI employee. - [Unrestrained AI, moral dilemmas, and regulatory failures: Best infosec long reads 10/3/26](https://www.metacurity.com/next-long-read-14.md) - Meet the "rogue" AI hunters, Trump and Anthropic clashed over AI control, Anthropic searches for AI’s moral compass, Trump scraps AI transparency rules, "Rogue" AI puts the law to the test - [OpenAI fires three safety researchers over alleged information leaks](https://www.metacurity.com/openai-fires-three-safety-researchers-over-alleged-information-leaks.md) - The company says the researchers mishandled sensitive information; alleged violations included sharing confidential material with outside safety organizations including METR and Redwood Research. - [Authorities seize KillSec leak site, identify 16-year-old as suspected leader](https://www.metacurity.com/authorities-seize-killsec-leak-site-identify-16-year-old-as-suspected-leader.md) - The German-led international operation secured at least 110 terabytes of data and led to three provisional arrests in an investigation into roughly 1,000 suspected attacks worldwide. - [OpenAI reportedly ignored security warnings but Trump backs AI self-policing](https://www.metacurity.com/openai-reportedly-ignored-security-warnings-but-trump-backs-ai-self-policing.md) - Employee accounts of ignored warnings and a lawsuit over autonomous hacking sharpen questions about accountability as the White House embraces voluntary safeguards and AI labs pursue their own standards body. - [AI’s safety and security crisis continues to outpace safeguards](https://www.metacurity.com/ais-safety-and-security-crisis-continues-to-outpace-safeguards.md) - A canceled model release, simulated agent attacks, government action and investor warnings made for one extraordinary day in AI security. - [OpenAI agents seem hell-bent on hacking](https://www.metacurity.com/openai-agents-seem-hell-bent-on-hacking.md) - New findings trace attempted intrusions, a breach of an Australian government portal, and unusual activity on US government sites to agents pursuing routine tasks, with OpenAI learning about much of it after the fact. - [Google’s Gemini hacked three real companies during a cybersecurity test](https://www.metacurity.com/googles-gemini-hacked-three-real-companies-during-a-cybersecurity-test.md) - The AI agent guessed a password and used credentials found in public repositories after gaining internet access, the first known case of Google’s AI autonomously breaching outside systems. - [AI warfare, surveillance and rogue agents: Best infosec long reads 9/19/26](https://www.metacurity.com/next-long-read-13.md) - AI safety researchers see their warnings come true, AI makes warfare faster and deadlier, AI puts dating-app catfishing on autopilot, Three ways AI could kill us, Flock’s surveillance network faces a bipartisan revolt - [Three guys used Claude and Codex to hack into OpenAI](https://www.metacurity.com/three-guys-used-claude-and-codex-to-hack-into-openai.md) - Three Hacktron AI researchers chained a Discourse flaw with overly permissive authentication tokens to access employee ChatGPT accounts—and potentially OpenAI’s prized “Monorepo”—earning only a $6,500 bounty and demonstrating how AI has dramatically lowered the barrier to sophisticated intrusions. - [OpenAI discloses six new incidents of AI models behaving badly](https://www.metacurity.com/openai-discloses-six-new-incidents-of-ai-models-behaving-badly.md) - The systems hid mistakes, fabricated data, used an API key without permission and uploaded files to the public internet. - [US probes suspected cyberattacks on two energy tankers](https://www.metacurity.com/us-probes-suspected-cyberattacks-on-two-energy-tankers.md) - The Coast Guard and FBI boarded a crude-oil supertanker and an LNG carrier amid growing concern that hackers could compromise vessels’ critical electronic systems and threaten maritime safety. - [AI safety has swiftly become Washington’s most combustible political snarl](https://www.metacurity.com/ai-safety-has-swiftly-become-washingtons-most-combustible-political-snarl.md) - Trump, Jensen Huang, Democratic 2028 hopefuls—and the unlikely alliance of Bernie Sanders and Steve Bannon—have swiftly transformed AI safety into a political and partisan snarl that makes responsible policymaking almost impossible. - [AI safety fears erupt into a global political and market crisis](https://www.metacurity.com/ai-safety-fears-erupt-into-a-global-political-and-market-crisis.md) - Fears are rippling across global economies as Dario Amodei, Sam Altman and Elon Musk issue calls to slow down frontier AI development, thrusting once-fringe warnings about rogue AI into public consciousness even as Anthropic touts profitability ahead of a potentially record-setting IPO. - [Spies, surveillance and rogue AI: Best infosec long reads 9/12/26](https://www.metacurity.com/spies-surveillance-and-rogue-ai-best-infosec-long-reads-9-12-26.md) - Flock’s surveillance network faces a bipartisan revolt, Did AI agents “go rogue”? Will AI make mathematicians obsolete? The case for an AI adverse-event reporting system, Shared data centers make spying easier than hacking - [AI shifts from cyber assistant to attack operator, Anthropic finds](https://www.metacurity.com/ai-shifts-from-cyber-assistant-to-attack-operator-anthropic-finds.md) - Anthropic says Russian spies, criminals and hacktivists used Claude to accelerate and automate cyberattacks, while other actors pursued potential biological weapons research, military programs and industrial-scale theft of Anthropic’s models. - [US sanctions Xinbi Guarantee over cyber scams and money laundering](https://www.metacurity.com/us-sanctions-xinbi-guarantee-over-cyber-scams-and-money-laundering.md) - The Justice Department also seized infrastructure and digital-asset wallets tied to the Chinese-language marketplace, while Treasury sanctioned two companies supporting its operations. - [US accuses Chinese AI firms of ‘malicious’ copying at industrial scale](https://www.metacurity.com/us-accuses-chinese-ai-firms-of-malicious-copying-at-industrial-scale.md) - Officials say DeepSeek, Alibaba and four other companies exploited leading American AI models to accelerate development of their own products, escalating tensions ahead of a planned Trump-Xi meeting - [OpenAI’s tightly constrained agent probe missed an earlier warning](https://www.metacurity.com/openais-tightly-constrained-agent-probe-missed-an-earlier-warning.md) - The company restricted outside investigators to a period that excluded previously undisclosed agent activity, raising questions about whether AI labs should control investigations of their own safety failures. - [Agents, algorithms and false assurances: Best infosec long reads 9/5/26](https://www.metacurity.com/agents-algorithms-and-false-assurances-best-infosec-long-reads-9-5-26.md) - A rogue AI agent goes hacking, AI vulnerability patches fail tougher tests, Inside the uncertain quantum-computing race, Faulty math fuels election-fraud claims, When “national security” becomes a trade weapon - [OpenAI rolls out GPT-6 Astra with ‘critical’ cyber capabilities tightly restricted](https://www.metacurity.com/openai-rolls-out-gpt-6-astra-with-critical-cyber-capabilities-tightly-restricted.md) - The company is giving Daybreak participants first access to its powerful new model after an unrelated AI escape and Hugging Face breach prompted additional safeguards. - [Google debuts Gemini 3.8 Flash Cyber for autonomous vulnerability discovery](https://www.metacurity.com/google-debuts-gemini-3-8-flash-cyber-for-autonomous-vulnerability-discovery.md) - The security-tuned model found and patched more flaws than larger commercial models at a fraction of the cost, according to early testing by Google and Wiz. - [OpenAI’s Astra crosses the critical cyber threshold](https://www.metacurity.com/openais-astra-crosses-the-critical-cyber-threshold.md) - Astra discovered and exploited two zero-days in testing, prompting OpenAI to restrict its most powerful cyber capabilities while deploying safeguards against both malicious users and unauthorized actions by the AI itself. - [Trump launches Texas test bed for nationwide water cyber defense](https://www.metacurity.com/trump-launches-texas-test-bed-for-nationwide-water-cyber-defense.md) - Project Watershed 250 will pair federal and Texas officials with technology companies in a six-month effort to find and fix vulnerabilities in water systems before expanding the model nationwide. - [Infostealers hijack Claude accounts and drain users’ usage](https://www.metacurity.com/infostealers-hijack-claude-accounts-and-drain-users-usage.md) - Anthropic is signing out affected users, removing payment methods, and refunding unauthorized charges after malware stole active Claude sessions from infected PCs. - [Surveillance, scams and machines: Best infosec long reads 8/29/26](https://www.metacurity.com/next-long-read-12.md) - Hunting a global crypto scam network, When license plate surveillance gets it wrong, The hidden threat of Meta’s smart glasses, Inside the NSA’s secret Cold War supercomputer, Democracy versus the machine - [Nearly 130 companies warn the window is closing to defend against AI cyberattacks](https://www.metacurity.com/nearly-130-companies-warn-the-window-is-closing-to-defend-against-ai-cyberattacks.md) - OpenAI, Anthropic and many of cybersecurity’s biggest vendors are calling for coordinated government action, broader access to defensive AI and hands-on support for under-resourced critical infrastructure. - [US disrupts China-linked operation targeting government and critical infrastructure](https://www.metacurity.com/us-disrupts-china-linked-operation-targeting-government-and-critical-infrastructure.md) - FBI and NSA seized domains underpinning the QTFY operation, which allegedly breached NASA, the Federal Reserve, the Energy Department and Senate while concealing its activity through compromised devices and clandestine networks spanning more than 130 countries. - [OpenAI disrupted an elaborate Russian influence operation](https://www.metacurity.com/openai-disrupted-an-elaborate-russian-influence-operation.md) - Russian operators used ChatGPT to promote a fabricated Israel-based institute that laundered pro-Kremlin narratives through stolen academic research and a bogus “sovereignty index.” - [Chinese state-linked hackers use DeepSeek to scale attacks](https://www.metacurity.com/chinese-state-linked-hackers-use-deepseek-to-scale-attacks.md) - State-affiliated groups are using low-cost, lightly guarded AI models for reconnaissance, exploit development and other routine work—helping them more than double their attack volume, researchers say. - [Iran-linked UK power generator attack exposes a cybersecurity blind spot](https://www.metacurity.com/iran-linked-uk-power-generator-attack-exposes-a-cybersecurity-blind-spot.md) - A suspected Iranian-linked cyberattack took a small UK power generator offline for four days, exposing a potential blind spot: energy assets too small to threaten the grid may also fall below the cybersecurity rules designed to protect it. - [Alibaba’s Qwen races past Meta, Google with 3 billion AI model downloads](https://www.metacurity.com/alibabas-qwen-races-past-meta-google-with-3-billion-ai-model-downloads.md) - Alibaba’s Qwen family of open-weight AI models has surpassed 3 billion downloads in six months, making it the world’s most-downloaded open model ecosystem, ahead of Google and Meta. Qwen, has open-sourced more than 460 models, and its ecosystem has spawned 300l-plus derivatives/ - [AI, surveillance and the control problem: Best infosec long reads 8/15/26](https://www.metacurity.com/ai-surveillance-and-the-control-problem-best-infosec-long-reads-8-15-26.md) - How a jury-duty scam stole $25,000, When adversaries can just buy the data, The surveillance dragnet hiding in plain sight, AI hallucinations create new openings for attackers, When Big Tech can read your thoughts, When bots start talking to bots - [Trump's private cyber offensive wins support — and plenty of alarm](https://www.metacurity.com/trumps-private-cyber-offensive-wins-support-and-plenty-of-alarm.md) - The cybersecurity community largely agrees that the US needs to hit cybercriminals harder. But Trump's plan to enlist private companies to do it has opened a thicket of questions about attribution, liability, escalation and who pays when an operation goes wrong. - [White House expands its cyber reach with expanded AI policy, new cybercrime memo](https://www.metacurity.com/white-house-expands-its-cyber-reach-with-expanded-ai-policy-new-cybercrime-memo.md) - The Trump administration, long associated with deregulation, is asserting new control over cyber operations via a reported expansion of its testing framework for frontier AI models and a stunning program that allows vetted private firms to run offensive cyber operations against foreign criminals. - [Autonomous AI agents hacked the Taiwan government in a cyber first](https://www.metacurity.com/autonomous-ai-agents-hacked-the-taiwan-government-in-a-cyber-first.md) - Suisun City cyberattack recovery could take months, Microsoft patches 400 flaws, three zero-days, $100 device can hijack Boeing 737 systems, Hackers hijack AnMed Facebook page with ransom demands, German lawmaker urges cyber strikes on Russian drone factories, much more - [OpenAI loosens GPT-5.6 cyber guardrails for vetted defenders](https://www.metacurity.com/openai-loosens-gpt-5-6-cyber-guardrails-for-vetted-defenders.md) - Anthropic to watermark Claude output, Gunra ransomware targets critical infrastructure through Fortinet flaws, WormGPT creator faces trial in Portugal, Ransomware disrupts systems at Winnipeg’s largest hospital, China-linked hackers exploit N-central flaw to deploy ransomware, much more - [DPRK's Kimsuky built an in-house AI toolkit to power cyberattacks](https://www.metacurity.com/dprks-kimsuky-built-an-in-house-ai-toolkit-to-power-cyberattacks.md) - Chinese components in UK military drones secretly transmitted data, Cali city declares emergency after cyberattack, Turkey's new cyber law sparks fears of sweeping digital censorship, OpenAI's Hugging Face hack reveals deeper AI safety failures, Claude Code's autonomous mode is now the default - [Trust under pressure: Best infosec long reads 8/8/26](https://www.metacurity.com/trust-under-pressure-best-infosec-long-reads-8-8-26.md) - Inside a multimillion-dollar phone scam, How a fringe censorship theory reshaped policy, When AI learns to replicate itself, Iran's fractured information ecosystem, The unfinished fight over digital privacy - [Kimi K3 escaped AI security sandbox during testing](https://www.metacurity.com/kimi-k3-escaped-ai-security-sandbox-during-testing.md) - ByteDance trains AI model to rival Anthropic, Vishing gang targets Wall Street firms with fake login sites, Violent crypto robberies put 2026 on record pace, Chinese router maker pulls devices after backdoor discovery, Spike in suicides alarms US Cyber Command, much more - [Updated: US Coast Guard is probing a cyberattack that disrupted North Carolina ports](https://www.metacurity.com/us-coast-guard-is-probing-a-cyberattack-that-disrupted-north-carolina-ports.md) - Meta undercuts AI coding rivals on price, Meta AI model breaches test containment, OpenAI agents built a secret message board, Snowflake hacker pleads guilty, Researchers crack AI browsers, Ransom Cartel mastermind gets 16 years, Chinese spyware goes commercial, DPRK hackers hit 1,600 orgs, more - [AI Watch: White House framework signals new era of AI oversight as security concerns intensify](https://www.metacurity.com/ai-watch-white-house-framework-signals-new-era-of-ai-oversight-as-security-concerns-intensify.md) - AI agents demonstrate increasingly sophisticated offensive capabilities, China warns US against expanding AI and technology curbs, Suspected cyberattacks target water utilities in at least 12 states, House report links telecom loopholes to Salt Typhoon breaches, much more - [AI Watch: AI security moves to Washington's center stage](https://www.metacurity.com/ai-watch-ai-security-moves-to-washingtons-center-stage.md) - White House AI testing framework arrives but key details remain secret, Congress probes OpenAI incident as calls for stronger AI oversight grow, China's open AI push fuels geopolitical debate, Banks press ahead with AI agents, US eyes China data center tech ban, much more. - [Water system cyberattacks widen as Trump rejects suspected Iran link](https://www.metacurity.com/water-system-cyberattacks-widen-as-trump-rejects-suspected-iran-link.md) - OpenAI finds additional AI agents escaped containment, Rogue AI hacks raise unprecedented liability questions, DeepSeek launches industry's cheapest frontier AI model, UK agency exposes officials' data in internal security lapse, Leaked database reveals China's surveillance of foreigners, much more - [Power plays in AI and cybersecurity: Best infosec long reads 8/1/26](https://www.metacurity.com/power-plays-in-ai-and-cybersecurity-best-infosec-long-reads-8-1-26.md) - The hacker who humbled spyware makers, China's new AI playbook, Do AI models really reason? The hidden danger of side-channel attacks, Inside Anthropic's legal battle - [Anthropic becomes the second frontier AI lab to disclose agent breaches](https://www.metacurity.com/anthropic-becomes-the-second-frontier-ai-lab-to-disclose-agent-breaches.md) - Copilot worm spreads through trusted Word documents, ExploitGym creators explain how OpenAI's agent escaped, Coordinated attacks signal a new threat to water utilities, Critical Azure Cosmos DB flaw threatened thousands of customers, CrimeStoppers put a bounty on the INC gang, much more - [ExfilSquad claims theft of 740,000 records from UK education, police databases](https://www.metacurity.com/exfilsquad-claims-theft-of-740-000-records-from-uk-education-police-databases.md) - Analog Devices probes ExfilSquad breach claim, UK report blames systemic failures for Afghan data leak, Senators urge Apple to shun Chinese memory chips, Australia sues Telegram over terror content, OpenAI breach sparks AI controls talk in Washington, much more - [OpenAI reveals broader AI agent campaign as Hugging Face publishes remarkable timeline](https://www.metacurity.com/openai-reveals-broader-ai-agent-campaign-as-hugging-face-publishes-remarkable-timeline.md) - Anthropic unveils encrypted AI breakthrough, AI workers demand global safety oversight, Zuckerberg doubles down on AI, Anthropic's AI safety stance draws fire, MCP gets its biggest overhaul yet, OpenAI open-sources Codex security tools, FCC bans new Chinese robots, power inverters, much more - [Nvidia launches AI safety coalition as open-weight debate intensifies](https://www.metacurity.com/nvidia-launches-ai-safety-coalition-as-open-weight-debate-intensifies.md) - MSFT launches AI cyber defense platform, Hugging Face rife with deepfake abuse, Cyberattack hits Minnesota water systems, Claude chats indexed by Google, Bank of Baroda probes leak, ShinyHunters claims EY breach, Apple sued over fake wallet app, Hack steals 293.7m SUPRA tokens, much more - [AI Watch: OpenAI's hacking agent breach signals a fracturing AI order](https://www.metacurity.com/ai-watch-openais-hacking-agent-breach-signals-a-fracturing-ai-order.md) - OpenAI missed rogue agent, Hugging Face breach reshapes open-v-closed AI, Firms abandon AI lab loyalty, Open-weight AI's Kubernetes moment, China pushes open-weight AI, Washington splits on Chinese AI, N. Korea expands its intelligence apparatus, much more - [The governance gap: Best infosec long reads 7/25/26](https://www.metacurity.com/the-governance-gap-best-infosec-long-reads-7-25-26.md) - AI incident reporting laws leave dangerous blind spots, Federal data consolidation raises surveillance fears, Russia's FSB embraces generative AI, Flock camera error triggers police stops, Why legacy OT malware won't die - [Russian hackers exploit Zimbra flaw to steal emails and bypass MFA](https://www.metacurity.com/russian-hackers-exploit-zimbra-flaw-to-steal-emails-and-bypass-mfa.md) - OpenAI probes AI-powered hack of Hugging Face, Bill would mandate AI kill switches, US to restrict visas for cybercriminals and families, Scam compounds expand despite Myanmar crackdown, Clop exploits Windchill flaw in extortion campaign, Dolphin X malware uses AI to rank victims, much more - [AI Watch: Hugging Face attack marks "day one" for AI agent cybersecurity](https://www.metacurity.com/ai-watch-hugging-face-attack-marks-day-one-for-ai-agent-cybersecurity.md) - Everest demands $12.3m from Swiss rail giant Stadler, Origin confirms customer data exposed in cyberattack, A third of ransomware victims face repeat extortion, Check Point patches actively exploited SmartConsole zero-day, Chaos ransomware uses browser traffic to evade detection, much more - [AI Watch: OpenAI details 'unprecedented cyber incident' behind Hugging Face breach](https://www.metacurity.com/ai-watch-openai-details-unprecedented-cyber-incident-behind-hugging-face-breach.md) - Frontier AI models routinely cheat on evaluations, Lightweight AI model for vulnerability hunting emerges, Google launches Gemini Flash Cyber for vulnerability detection and repair, Malware hides inside normal AI coding activity, US weighs sanctions over alleged Chinese AI model theft, much more - [AI Watch: China's AI surge is forcing DC and Silicon Valley to rethink the AI race](https://www.metacurity.com/ai-watch-chinas-ai-surge-is-forcing-dc-and-silicon-valley-to-rethink-the-ai-race.md) - US seizes 1,000+ piracy sites streaming World Cup matches, 7-Zip fixes critical RCE flaw, Attackers begin exploiting critical ServiceNow AI platform flaw, Millions of aftermarket car alarms can be hacked over Bluetooth, SonicWall zero-days used to deploy custom malware on VPN appliances, much more - [AI Watch: The AI agent that breached Hugging Face is a sign of things to come](https://www.metacurity.com/ai-watch-the-ai-agent-that-breached-hugging-face-is-a-sign-of-things-to-come.md) - EY notifies clients of tax data breach, Craneware discloses cyberattack, Ecopetrol says a cyberattack stole data from 3,300 accounts, Kenyan presidential website restored after ransom attack, Abbott probes two cybersecurity incidents, Hackers abuse ViPNet updates to target Russian orgs, much more - [Hidden systems, hidden risks: Best infosec long reads 7/18/26](https://www.metacurity.com/hidden-systems-hidden-risks-best-infosec-long-reads-7-18-26.md) - How an audacious server heist exposed the fragility of digital infrastructure, WhatsApp has quietly become an essential service, The NHS fought to keep sensitive health data out of Palantir's hands, Thomson Reuters' ICE surveillance problem, Why AI slop threatens open-source software - [Moonshot's Kimi K3 raises stakes in battle over AI vulnerability-hunting models](https://www.metacurity.com/moonshots-kimi-k3-raises-stakes-in-battle-over-ai-vulnerability-hunting-models.md) - DHS seizes 30K SIM cards in anti-fraud crackdown, Coca-Cola's Fairlife ransomware attack disrupts US production, US charges pair in $43m cyber scam laundering ring, Police use Flock cameras to search for people, Italian telecom fined €1.7mover data breaches, much more - [Hackers post alleged blueprints and supplier data from India nuclear project](https://www.metacurity.com/hackers-post-alleged-blueprints-and-supplier-data-from-india-nuclear-project.md) - TfL hackers sentenced to 5½ years in prison, Hacking suspect once worked at Kaspersky, OpenAI unveils AI-powered red teaming tool, Ransomware attack disrupts Japan’s food supply chain, Qantas cleared after social-engineering breach, Health provider criticized for delayed breach disclosure, much more - [US indicts three Russians tied to sanctioned bulletproof hoster, offers $10 million reward](https://www.metacurity.com/us-indicts-three-russians-tied-to-sanctioned-bulletproof-hoster-offers-10-million-reward.md) - Microsoft patches record 570 flaws, including two exploited zero-days, White House launches AI vulnerability-sharing hub dubbed Gold Eagle, Oracle leads race to build Japan’s top-secret cloud infrastructure, Finnish hacker Kivimäki wanted after losing final appeal, much more - [Western allies pair Russia sanctions with a warning on critical infrastructure attacks](https://www.metacurity.com/western-allies-pair-russia-sanctions-with-a-warning-on-critical-infrastructure-attacks.md) - UK charges five over Russian Coms spoofing platform, Treasury sanctions VPN provider tied to ransomware gangs, DHS missed warning signs before credential theft breach, Cyberattacks targeted US personnel through Mideast mobile networks, Korean police uncover large-scale GitHub token leak, much more - [AI's new battleground: Cost, efficiency, and control](https://www.metacurity.com/ais-new-battleground-cost-efficiency-and-control.md) - AI vendors pivot from capability to cost, OpenAI eases GPT-5.6 usage limits, Enterprises scrutinize soaring AI bills, Chinese AI models gain enterprise traction, Anthropic data reveals how AI gets used, AI agents tackle business ops workloads, Open-source AI faces mounting policy pressure, much more - [Trust under attack: Best infosec long reads 7/11/26](https://www.metacurity.com/trust-under-attack-best-infosec-long-reads-7-11-26.md) - Inside the TfL hack, The cyber war game nobody wants to play, AI's toughest test case, When anti-piracy breaks the internet, The protocol that changed the internet, Why prompt injection won't go away - [OpenAI launches GPT-5.6 as AI vendors compete for enterprise users](https://www.metacurity.com/openai-launches-gpt-5-6-as-ai-vendors-compete-for-enterprise-users.md) - Federal investigators say DOGE records were deleted, Europe revives voluntary message scanning, Britain plans AI-powered cyber defense system, Chinese and Indian hackers target Pakistani police, AI gateway compromise leads to cryptomining, Ransomware negotiator sentenced to 70 mos., much more - [AI watch: AI companies are building digital workers, and attackers may benefit too](https://www.metacurity.com/ai-watch-ai-companies-are-building-digital-workers-and-attackers-may-benefit-too.md) - Interpol fraud crackdown nets 5,800 arrests and $293m, Fake Brazilian police station discovered in African scam operation, Mystery zero-day broker tied to convicted fraudsters, AssuranceAmerica breach exposes 6.9m driver’s license numbers, much more - [AI watch: Washington, Beijing, and Brussels shape AI's future](https://www.metacurity.com/ai-watch-washington-beijing-and-brussels-shape-ais-future.md) - Spain arrests man suspected of CyberArmy of Russia membership, Predator spyware victims seek €1m each in Greek lawsuit, CISA incident reporting rule expected in Sept., Ransomware exposed student and employee data at Mount Royal University, Accenture confirms breach, much more - [AI watch: Chinese competition, government adoption, and new regulations pressure AI leaders](https://www.metacurity.com/ai-watch-chinese-competition-government-adoption-and-new-regulations-pressure-ai-leaders.md) - Canada details offensive cyber ops, US cloud providers challenge Korean security rules, KDDI confirms breach affecting millions, Judge keeps Weiss hacking case alive, BonkDAO loses $20m in governance attack, Crypto wallet flaw exposed millions to theft, Ctrl Wallet shutters after incident, much more - [EU lawmaker investigating Pegasus abuse was hacked with Pegasus spyware](https://www.metacurity.com/eu-lawmaker-investigating-pegasus-abuse-was-hacked-with-pegasus-spyware.md) - FBI disrupts NetNut-linked proxy infrastructure, Russian hackers expose UK gov't credentials, India probes iPhone 18 Pro supply-chain leak, UK minister compares AI risks to Hiroshima, Sanctioned states increasingly rely on crypto, First fully AI-run ransomware attack spotted, much more - [AI guardrails under fire from researchers and regulators](https://www.metacurity.com/ai-guardrails-under-fire-from-researchers-and-regulators.md) - Scattered Spider suspect extradited to US, House panel accuses Korea of targeting Coupang, cyberattack hits Malaysian parking app, Aflac Japan breach affects 4.4M customers, AI agent carries out extortion attack, Ukraine stops 16K Russian cyberattacks, ChocoPoC RAT hides in GitHub PoCs, much more. - [Anthropic restores Fable 5 and Mythos 5, launches Sonnet 5](https://www.metacurity.com/anthropic-restores-fable-5-and-mythos-5-launches-sonnet-5.md) - China's Mythos rival fuels AI arms race. Taiwan probes claimed PChome hack, Alberta voter leak sparks lawsuit, Hackers breach DHS sharing network, Apple privacy feature exposes emails, Adobe fixes critical ColdFusion bugs, Crypto thieves stole $76m in June, much more - [Apple faces supply chain leak as AI threats accelerate security updates](https://www.metacurity.com/apple-faces-supply-chain-leak-as-ai-threats-accelerate-security-updates.md) - Meta secretly benchmarked rival chatbots with fake teen accounts, S.Ct. curbs warrantless geofence searches, Google warns EU competition rules could weaken security, Russia shifts influence operations toward the West, Amazon settles identity theft records case for $2.25m, much more - [Washington pushes AI into an export-control era as rivals rush to fill the gap](https://www.metacurity.com/washington-pushes-ai-into-an-export-control-era-as-rivals-rush-to-fill-the-gap.md) - Anthropic regains limited Mythos 5 access for government-vetted US organizations, OpenAI launches GPT-5.6 under gov't preview, Zhipu AI's GLM-5.2 nears Mythos-level cybersec performance, 360 Security says it has achieved Mythos-style vulnerability discovery, much more - [The new architecture of power: Best infosec long reads 6/27/26](https://www.metacurity.com/next-long-read-11.md) - The UK's untrustworthy crime prediction machine, Scattered Spider didn't attack Jaguar Land Rover, A powerful new side channel attack, Trump's AI order may not be so voluntary, AI-generated malware can dodge signature-based detection - [US tightens oversight as AI moves deeper into cyber, warfare and media](https://www.metacurity.com/us-tightens-oversight-as-ai-moves-deeper-into-cyber-warfare-and-media.md) - Russia kept using Cellebrite after sales ban, $3m stolen in Polymarket phishing attack, Poland busts SIM-swapping gang behind crypto thefts, Suspected Iranian hacker arrested in Montenegro, AYA Bank confirms limited data leak, Cyberattack knocks Ukrposhta mobile app offline, much more - [Frontier AI Beat: AI security becomes a geopolitical arms race](https://www.metacurity.com/frontier-ai-beat-ai-security-becomes-a-geopolitical-arms-race.md) - Microsoft uses AI to link malware groups in RICO case, Ukraine exposes Russian messenger hacking, Nation-state hackers mapped CI for sabotage, DPRK-linked election attacks surge 68-fold, DraftKings hacker 'Snoopy' gets 18 months, ICE surveillance spending hits record high, much more - [Frontier AI beat: NSA locked out, Meta pressured, lawsuits begin](https://www.metacurity.com/frontier-ai-beat-nsa-locked-out-meta-pressured-lawsuits-begin.md) - Dialog's "hack" looks more like a misconfiguration, Klue breach spills more LastPass customer data, Iranian banking services hit by fresh cyber disruption, India's Bajaj Auto hit by ransomware attack, KDDI warns 14m accounts may be exposed, much more - [Admin accelerates quantum push, advances timeline for quantum-safe security](https://www.metacurity.com/admin-accelerates-quantum-push-advances-timeline-for-quantum-safe-security.md) - Five Eyes warn AI cyber threat is months away, Tata breach exposes Apple and Tesla files, OpenAI launches Patch the Planet initiative, Meta pauses employee AI data collection after exposure, Two plead guilty in £39m TfL cyberattack, Texas probes Carnival breach affecting 6 million customers, more - [Anthropic watch: US government dispute becomes AI governance fight](https://www.metacurity.com/anthropic-watch-us-government-dispute-becomes-ai-governance-fight.md) - Operation Endgame wipes SocGholish infrastructure, Hackers hijack Brazil emergency alert system, London Hydro breach exposes customer data, Data breach in Korea exposes 5,000 startup applications, Acworth investigates cyberattack on city systems, much more - [The industrialization of manipulation: Best infosec long reads 6/20/26](https://www.metacurity.com/the-industrialization-of-manipulation-best-infosec-long-reads-6-20-26.md) - AI is turbocharging deepfake porn, How the Yahoo Boys industrialized romance scamming, The scary assessment of a deepfake expert, When cyberbullying blurs into domestic terrorism, Poisoned content can shape deep research AI agents - [Anthropic watch: Dispute widens as customers, allies and investors react](https://www.metacurity.com/anthropic-watch-dispute-widens-as-customers-allies-and-investors-react.md) - Bulgarian spyware firm sold tools to repressive regimes, The Gentlemen claims attack on sugar mills, FortiBleed exposes 73k Fortinet VPN credentials, Startup competition leak exposes 5k applicants, Canada spy agency disrupted botnets, Fake YouTube gurus spread crypto-stealing malware, much more - [Anthropic watch: Congress scrambles, Europe recoils, and Anthropic's halo grows brighter](https://www.metacurity.com/anthropic-watch-congress-scrambles-europe-recoils-and-anthropics-halo-grows-brighter.md) - Leak exposes members of Peter Thiel's secretive power network, Cybercrime now accounts for a third of crimes in parts of Asia, France picks local rival to replace Palantir at spy agency, Americans lost $3.5B to imposter scams last year, Hackers hijack Roblox games by seizing dev accounts, much more - [Why the White House turned on Anthropic](https://www.metacurity.com/why-the-white-house-turned-on-anthropic.md) - Chinese spies hid in research networks for two years, Copilot bug let attackers steal Microsoft 365 data, Crypto scammers now send couriers for cash, Judge keeps Meta AI scraping lawsuit alive, Feds dismantle $389m crypto laundering op, iRhythm reports breach after extortion demand, much more - [Section 702 Expires, but the US Isn't Going Dark](https://www.metacurity.com/section-702-expires-but-the-us-isnt-going-dark.md) - Feds seize major deepfake porn sites, Cyberattack disrupts services at four major Iranian banks, Trump orders cybersecurity overhaul for national security systems, Conti ransomware coder pleads guilty in US case, Chinese spies hid in critical infrastructure network for a decade, much more - [Special report: Anthropic and the first great AI cyber showdown — a timeline](https://www.metacurity.com/special-report-anthropic-and-the-first-great-ai-cyber-showdown-a-timeline.md) - Over the past few days, a dispute over AI safety guardrails escalated into a White House crackdown, a global sovereignty debate, and the first major clash between frontier AI cyber capabilities and government authority. - [Innovation is easy, but adaptation is hard: Best infosec long reads 6/13/26](https://www.metacurity.com/next-long-read-10.md) - How a doll sparked an international security scandal, Smart home technology erodes our privacy and autonomy, We need 'Operation Warp Speed' for AI, Security and not speed should be uppermost in US-AI China race, Ditch cyber checklists in favor of engineered resilience - [Google sues AI-powered scam ring behind fake carrier rewards texts](https://www.metacurity.com/google-sues-ai-powered-scam-ring-behind-fake-carrier-rewards-texts.md) - Oracle warns of critical PeopleSoft flaw, Israeli firm suspected of election interference in France, Scotland and New York, Authorities dismantle crypto laundering service tied to ransomware gangs, Novo Nordisk discloses breach involving clinical trial patient data, much more - [Coupang hit with record $409 million fine over massive insider-driven data breach](https://www.metacurity.com/coupang-hit-with-record-409-million-fine-over-massive-insider-driven-data-breach.md) - CISA orders faster patching as AI speeds exploitation, Suspected Russian hacker extradited to the US over Void Blizzard, OpenAI disrupts China-linked campaigns targeting US tech debates, Digital breadcrumbs lead to alleged leader of The Gentlemen, much more - [Anthropic releases Mythos-derived model with cyber guardrails](https://www.metacurity.com/anthropic-releases-mythos-derived-model-with-cyber-guardrails.md) - Admin halts AI safety reports amid fight over oversight, Microsoft patches record 200 flaws as AI fuels bug discovery, Nightmare Eclipse drops fresh Windows zero-day, China's hackers target tech firms as AI race intensifies, Social media overtakes email as top attack channel, much more - [Meta moves to hold NSO in contempt over WhatsApp attacks](https://www.metacurity.com/meta-moves-to-hold-nso-in-contempt-over-whatsapp-attacks.md) - UK threatens tech firms over child sexting, Microsoft disables GitHub repositories after AI tool malware attack, Pentagon adds Alibaba, Baidu to China military-linked list, Anthropic says AI can turn vulns into exploits in hours, Check Point fixes critical VPN flaw under active attack, much more - [Zcash tumbled after disclosure of critical counterfeiting flaw](https://www.metacurity.com/zcash-tumbled-after-disclosure-of-critical-counterfeiting-flaw.md) - 20k Instagram accounts hacked in attack that abused AI tool, Router flaw powers rise of shape-shifting C0XMO botnet, Ransomware gang sends fake IT staff into victim offices, ShinyHunters-linked leak exposes millions of DentaQuest records, Chinese cyber spies hid in Microsoft 365 for 18 months, more - [The future of cyber arrives, but old failures persist: Best infosec long reads 6/6/26](https://www.metacurity.com/the-future-of-cyber-arrives-but-old-failures-persist-best-infosec-long-reads-6-6-26.md) - Hackers turned women's medical procedures into cyber terror, How new techniques defeat anti-jamming technology, An AI-powered worm is now a reality, A novel cryptographic technique can create more security verification, The US should focus on remaining more secure in its tech race with China - [Anthropic: AI is advancing too fast to leave unchecked](https://www.metacurity.com/anthropic-ai-is-advancing-too-fast-to-leave-unchecked.md) - Whistleblower says IBM and AT&T hid repeated attacks from foreign hackers, Anthropic engineers are embedded in NSA, Hegseth is still determined to block Anthropic, Cloudflare CEO says agentic bots outnumber humans online, New threat group Pink uses voice phishing and fake help-desk calls, much more - [Five Eyes issues unusual warning on China's online recruitment tactics](https://www.metacurity.com/6a205e53dc19480001f9b05b.md) - Meta AI's chatbot hacking seems to have continued, OpenAI asks for mandatory models' evaluations, CISA to release AI directive tomorrow, Mullin wants CISA to hire 600 more personnel, Hackers accessed Ultrahuman's customer data, Peptide promoters seek to poison chatbots by Reddit postings, much more - [Trump backs voluntary AI model reviews in cybersecurity-focused executive order](https://www.metacurity.com/trump-backs-voluntary-ai-model-reviews-in-cybersecurity-focused-executive-order.md) - Anthropic expands Mythos distribution to 150 orgs, Researchers devise AI worm capable of creating internet chaos, Trump picks Pulte for intel czar post, Las Vegas Station Casinos was hit with a breach, Cyberattack exposed 600k food-deprived households in Gaza, much more - [Meta AI support flaw fueled a wave of Instagram takeovers](https://www.metacurity.com/meta-ai-support-flaw-fueled-a-wave-of-instagram-takeovers.md) - Russia says a large-scale spyware campaign by foreign intel targeted its high-ranking officials, Anthropic to give ENISA access to Mythos, Two men charged in nearly $8m BEC scam in NJ, 30+ npm Red Hat packages compromised in new 'Miasma' Shai-Hulud scheme, much more - [DOGE-aligned White House web projects funnel citizen data to analytics firm](https://www.metacurity.com/doge-aligned-white-house-web-projects-funnel-citizen-data-to-analytics-firm.md) - Microsoft's threat to security researcher draws criticism, Commerce IG says NIST has mismanaged NVD, Obama White House Instagram was hacked, Teen researcher flagged flaws in India's school exam board website, Gravity Bridge exploited for $5.4m, DxSale legacy site hacked for $7.3m, much more - [Verifying reality: Best infosec long reads 5/30/26](https://www.metacurity.com/verifying-reality-best-infosec-long-reads-5-30-26.md) - TP-Link is fighting for its life, Quantum's threat to RSA encryption could be soon, How Russia's GPS spoofing could destroy us all, How cops and the courts relied on a stalker's digital evidence, The safety and security risks of AI distillation - [California says 23andMe ignored basic security before 7 million-user breach](https://www.metacurity.com/california-says-23andme-ignored-basic-security-before-7-million-user-breach.md) - Dutch cops bust up 200-server cybercrim botnet, Law firm Weil reportedly paid Silent Ransom Group $20m, Stress tests show Grok is the AI model most likely to commit crimes, Anthropic will release Mythos models to the public, GreyVibe uses AI-generated lures, much more - [Centcom: US war zone troops were targeted through commercial location data](https://www.metacurity.com/centcom-us-war-zone-troops-were-targeted-through-commercial-location-data.md) - Canada signals flexibility as tech giants fight surveillance bill, Canadian lands 30 years for child sextortion scheme, Romanian sentenced to 56 months for Oregon gov't, other hacks, Germany and France fight EC's ban of Huawei on cyber grounds, much more - [UK spy chief warns of escalating Russian cyber aggression](https://www.metacurity.com/uk-spy-chief-warns-of-escalating-russian-cyber-aggression.md) - India's banking and government institutions are testing Mythos, Charter confirms breach claimed by ShinyHunters, Play ransomware gang hit Mike Lindell's MyPillow, Fake UK visa portal exposes passports and selfies, CrowdStrike shuttered C2 for Glassworm botnet, much more - [White House seeks $9 billion AI chip surge for US spy agencies to tap AI models](https://www.metacurity.com/white-house-seeks-9-billion-ai-chip-surge-for-us-spy-agencies-to-tap-ai-models.md) - Russian penetration of US systems during SolarWinds breach was deeper than we knew, Mythos Preview users found more than 10k severe vulnerabilities, Iranian hackers were behind the LA transit system breach, Former execs plead guilty to tech support fraud scheme, much more - [Losing control of the systems meant to secure society - Best infosec long reads 5/23/26](https://www.metacurity.com/losing-control-of-the-systems-meant-to-secure-society-best-infosec-long-reads-5-23-26.md) - France grapples with an unprecedented wave of data breaches, AI voice systems can be manipulated with malicious audio, Big Tech is backing a massive spying operation in Seattle, Russia overreached on the cybercrime convention, Framing AI as an arms race threatens safety and accountability - [Trump AI order dramatically collapses after Sacks-led revolt over cyber oversight](https://www.metacurity.com/trump-ai-order-dramatically-collapses-after-sacks-led-revolt-over-cyber-oversight.md) - EU cops dismantle cybercriminals' favorite VPN service, Edmonton partnered with ethical 'scam baiters' to stop $42m in losses, Kimwolf builder Dort arrested in Canada, The Kremlin hijacked Bluesky accounts in influence op, Google accidentally leaked details about unfixed Chromium issue, much more - [Trump prepares to sign AI cyber order today amid Mythos alarm](https://www.metacurity.com/trump-prepares-to-sign-ai-cyber-order-today-amid-mythos-alarm.md) - Cybercom to speed AI tools use, Hacker accessed GitHub repos via TanStack-compromised Nx Console VS Code extension, Ukraine cops bust 18-year-old for running infostealer op, S. Korean cops bust 32 for stealing bigwigs' financial data and PII, Microsoft issues patches for Defender flaws, much more - [GitHub says malicious VS Code extension compromised 3,800 internal repositories](https://www.metacurity.com/github-says-malicious-vs-code-extension-compromised-3-800-internal-repositories.md) - White House release of EO on cyber and AI safety is imminent, Microsoft took down malware service Fox Tempest, A bug in a Huawei enterprise router caused Luxembourg telecoms outage last year, Mini Shai-Hulud malware resurfaces across hundreds of npm packages, much more - [Anthropic eases threat-sharing rules as Cloudflare details frontier AI cyber gains](https://www.metacurity.com/anthropic-eases-threat-sharing-rules-as-cloudflare-details-frontier-ai-cyber-gains.md) - CISA contractor exposed sensitive gov't creds in public GitHub repo, Buterin says AI-assisted formal verification can secure blockchain systems, NY public health provider says breach affects 1.8m, FBI wants access to ALPRs nationwide, Interpol busts 200+ people for cybercrime in MENA, much more - [Leaders warn that AI bug hunting outpaces humanity’s ability to defend systems](https://www.metacurity.com/leaders-warn-that-ai-bug-hunting-outpaces-humanitys-ability-to-defend-systems.md) - Malware strain Fast16 sabotaged nuclear weapons development years before Stuxnet surfaced, Grafana Labs rejected hackers' extortion demand, DeFi protocol Verus lost nearly $12m in ongoing exploit, Hotel check-in system left 1m passports exposed, Gas station gauge systems hacked, much more - [AI and the collapse of authenticity: Best infosec long reads 5/16/26](https://www.metacurity.com/ai-and-the-collapse-of-authenticity-best-infosec-long-reads-5-16-26.md) - AI has industrialized identity theft, Copyright law can remove nonconsensual AI porn, Anthropic might not appreciate that 'Mythos' came from H.P. Lovecraft's horror tales, How to solve AI's falsehood problems, Computationally unknowable mathematical proofs can create a new cryptographic technique - [AI bug hunters expose new weak point in Apple’s locked-down macOS](https://www.metacurity.com/ai-bug-hunters-expose-new-weak-point-in-apples-locked-down-macos.md) - Shai-Hulud attack campaign hit two OpenAI employees, Hackers unwisely targeted Amnesty International's Security Lab chief, US and China to discuss AI guardrails, Anthropic warns of CCP AI dominance, DPRK's APT 37 is now posing as cops, MSFT warns of severe XSS flaw for Outlook web users, much more - [AI cyber skills now doubling in months, not years](https://www.metacurity.com/ai-cyber-skills-now-doubling-in-months-not-years.md) - Microsoft's AI-driven MDASH system discovered 16 new Windows vulnerabilities, France's Mistral AI competes with Mythos for European banks, Dream Market admin busted by German and US cops, Shadowy firm BlackCore probed for French election interference, Signal to exit Canada if C-22 passes, much more - [OpenAI gives advanced cyber models to European defenders](https://www.metacurity.com/openai-gives-advanced-cyber-models-to-european-defenders.md) - Anthropic denied Chinese think tank Mythos access, Pentagon will use Mythos while moving ahead with Anthropic ban, House panel wants Instructure hearing, Nitrogen group hit Foxconn with cyberattack, West Pharmaceutical Services hit with ransomware, Microsoft issues 120 Patch Tuesday fixes, much more - [Instructure forms deal with ShinyHunters who promise to destroy stolen Canvas data](https://www.metacurity.com/instructure-reaches-deal-with-shinyhunters-who-promise-to-destroy-stolen-canvas-data.md) - US intel agencies want to evaluate AI model while Commerce seems to back away, OpenAI launches cybersecurity model Daybreak, Euro countries sell spyware to rights violators, Binance claims AI system saved $10b in scam losses, Shai-Hulud supply-chain campaign compromised npm and PyPi packages, more - [Pre-release discount: Practical risk management using the NIST CSF 2.0](https://www.metacurity.com/pre-release-discount-practical-risk-management-using-the-nist-csf-2-0.md) - The NIST 2.0 Cybersecurity Framework delivers clear guidance on applying the gold standard NIST framework in complex, real-world situations. ## Optional - [RSS Feed](https://www.metacurity.com/rss/) - [Sitemap](https://www.metacurity.com/sitemap.xml) - [Full content of pages and posts](https://www.metacurity.com/llms-full.txt)