IBM joins OpenAI's Daybreak Cyber Partner Program, launching an AI-driven application security service that provides continuous, read-only code analysis to identify and validate software vulnerabilities at machine speed. The managed service leverages OpenAI's frontier models and IBM Consulting Advantage to offer enterprises scalable vulnerability assessment.
Source: manilatimes.net · prnewswire.com
Cybersecurity professionals are alarmed that DHS, under Secretary Mullin, could become an insider threat to election infrastructure. Mullin previously advanced the debunked notion of 14 technical ways to steal an election, creating a risk that agency staff may use network access or threat-sharing channels to spy on or disrupt state systems in the 2026 midterms.
Source: ketr.org · delawarepublic.org
A new wave of phishing websites is exploiting Grand Theft Auto VI hype by offering fake early access for cryptocurrency payments. These sites use social engineering and premium design to trick victims into sending $250 in Bitcoin, USDT, or Ethereum, with irreversible losses. Cybercriminals capitalize on the massive anticipation for the game, highlighting the need for user awareness and official channel verification.
OpenAI's powerful new model, GPT‑5.6 Sol, is limited to roughly 20 vetted customers as the U.S. government screens AI systems for hacking risks. The move follows an executive order and Anthropic's forced withdrawal of two models that could automate vulnerability discovery.
The Trump administration’s cybersecurity vetting of frontier AI models has restricted OpenAI’s GPT-5.6 Sol to 20 vetted users, while Anthropic’s Mythos 5 was redeployed solely for defensive use to critical infrastructure providers. This intervention marks a new phase in the weaponization concerns surrounding advanced AI.
Source: yakimaherald.com · thegazette.com
A Check Point director offloaded $3.08M in CHKP stock after a 40% decline, reducing his exposure by 86%. As the cybersecurity giant navigates market headwinds, insider confidence comes into question.
Source: Jonathan Ponciano (us) · fool.com
Ransomware group World Leaks posted over 200,000 sensitive documents on the dark web from Tata Electronics, including purported Apple and Tesla component designs. The attack underscores the growing trend of double-extortion targeting manufacturing, with Tata now performing a forensic audit and locking down remote access.
The Trump administration partially lifted its ban on Anthropic's Mythos 5, allowing 'a small group of cyber defenders and infrastructure providers' to use the powerful cybersecurity model. This limited reinstatement signals a cautious U.S. approach to AI-driven cyber defense, while consumer access remains restricted.
Source: app.buzzsumo.com · Maxwell Zeff (US)
The White House is restricting OpenAI's GPT-5.6 rollout to a customer-by-customer approval process, driven by concerns that advanced AI could be used to uncover and exploit software vulnerabilities at scale. This follows similar unease over Anthropic's Claude Mythos, highlighting a new cybersecurity paradigm.
Source: Commerce Secretary Howard (us) · Commerce Secretary Howard (us)
A national security-driven DJI ban is pitting data protection advocates against public safety officials, with 3,000+ commenters arguing that cybersecurity risks must be balanced against life-saving drone use.
Anthropic’s Mythos AI makes vulnerability discovery 100x faster and cheaper, prompting 360 founder Zhou Hongyi to warn that China’s exclusion from the Project Glasswing alliance leaves its digital infrastructure dangerously exposed. He calls for a homegrown equivalent to restore strategic balance.
Kratikal Tech, an AI-native cybersecurity SaaS provider, opens its IPO June 30 on BSE SME, raising $4.7M to expand its Threatcop platform across the UAE and US. The move underscores growing investor interest in AI-powered threat defense.
Anthropic reveals that Alibaba's Qwen lab launched the largest-known access campaign against a US AI lab, using thousands of fraudulent accounts to siphon Claude’s agentic reasoning. The incident spotlights new attack surfaces in AI security.
Despite Dialog’s claim of a sophisticated hack, WIRED’s analysis shows a simple website misconfiguration exposed data on 200 attendees of its elite retreats, including top government officials. The incident underscores how basic security failures can endanger high-value targets and the importance of secure development practices.
Source: Dell Cameron; Dhruv Mehrotra · Dell Cameron (US)
A targeted phishing attack on Xsolis led to the exfiltration of highly sensitive personal and medical data affecting 1.4 million. The incident, detected in two days but notified months later, exemplifies persistent healthcare security gaps in email defense and incident response.
Source: Pierluigi Paganini
A testing exercise revealed Anthropic’s Mythos model can identify vulnerabilities inside classified U.S. systems in hours, a capability that reshapes the cybersecurity landscape. While the model reportedly did not exploit the flaws, the speed of discovery accelerates the imperative for AI-driven patch management and zero-trust architectures. The incident may also drive new regulatory mandates for AI red-teaming in federal systems.
Source: mynorthwest.com · SecurityWeek
The Five Eyes alliance warns that frontier AI models like Anthropic’s Mythos are accelerating the cyber threat landscape so fast that existing defenses will be obsolete within months. Security leaders must immediately integrate AI into operations and prepare for inevitable breaches.
OpenAI and Trail of Bits kick off a large-scale bug-hunting initiative for open-source projects, uncovering hundreds of vulnerabilities in a single week. The effort aims to relieve maintainers overwhelmed by AI-generated vulnerability reports and sets a new standard for AI-augmented security triage.
Source: Fp Tech Desk (in) · Lucas Ropek (us)
The federal judge’s halt of the SAVE program underscores the severe risks of centralizing sensitive personal data. The ruling is a stark reminder that large-scale government aggregations are prime targets for breaches, and that privacy-invasive architectures violate bedrock statutory protections.
Swarm Stage AI offers cybersecurity teams a realistic simulation platform for drone swarm threats against critical infrastructure, enhancing incident response and resilience planning for data centers, power grids, and more.
A Qualys director sold 12.16% of his holdings for $104,000 amid a 17.66% annual stock decline. The insider move raises questions about near-term demand in vulnerability management and broader cybersecurity spending trends.
Source: Robert Izquierdo (us) · finance.yahoo.com
The Indian government's temporary Telegram ban over exam scams spotlights the platform's struggle with fraud on encrypted channels, affecting 150 million users and raising questions about proactive content moderation capabilities.
Source: thehindubusinessline.com · economictimes.indiatimes.com
Hong Kong’s Kee Wah Bakery suffers a ransomware attack, potentially exposing employee, partner and customer data. The incident, reported to regulators, highlights growing supply chain and third‑party risks in the region’s digitally connected food retail sector.
Source: Edith Lin (hk) · Edith Lin (cn)
Cybersecurity experts see the bill as a complementary legal layer to deepfake detection tech, holding creators accountable for synthetic media in elections.
A police-investigated smear campaign against Alibaba and JD.com used manipulated images of delivery uniforms and hired a media agency to spread false narratives online, highlighting the cyber threat of reputation-based disinformation attacks on major platforms.
Meta’s shift from proactive AI detection to user-reported hate speech slashed removals by over 78%, raising concerns about online radicalization and harassment. TikTok’s 96.3% pre-report removal rate, meanwhile, masks unresolved accuracy issues—both trends signal a fractured digital security landscape.
Organised crime is harnessing generative AI for hyper-personalised fraud, automated money laundering, and even drone attacks. Cybersecurity teams face an adversary that uses custom LLMs to bypass traditional defenses at scale.
Source: Sherryn Groch · Sherryn Groch
Bill C-25 introduces strict cybersecurity and privacy requirements for federal political parties, including mandatory data breach disclosure and a ban on AI-generated deepfakes targeting electoral actors. These 7 amendments aim to protect elections from digital threats.
Source: Montrealgazette · montrealgazette.com
Vivek Aggarwal's FATF Vice Presidency could accelerate stricter international standards for virtual assets and digital payments, directly affecting cybersecurity strategies. Threat intelligence and compliance teams must adapt to heightened scrutiny of cyber-enabled financial crimes.
Source: cambodiantimes.com · news.webindia123.com
The 7th Infantry Division's Cross Domain Contact Layer connects intelligence, electronic warfare, and AI into a single network spanning land, air, sea, space, and cyberspace. This integration greatly expands the attack surface and makes cybersecurity a foundational requirement for mission success.
Source: Defense News · J.D. Simkins; Eve Sampson; J D Simkins
Cybercriminals are increasingly targeting fintech vulnerabilities for large-scale money laundering. The Simon Amadi case shows how a network used a Swiss remittance firm to evade AML detection, raising urgent cybersecurity questions about transaction monitoring and identity verification systems.
Source: Huhuonline · Huhuonline
The FortiBleed credential campaign leveraging default and stolen passwords has compromised over 86,000 FortiGate firewalls globally. CISA warns of ongoing Russian-speaking threat actor activity, with telecom, government, and education heavily impacted.
Two distinct threat groups, ShinyHunters and Icarus, have publicly claimed responsibility for separate breaches at JCPenney/Catalyst Brands and The Credit Pros, respectively. The attacks expose evolving cybercriminal tactics, including Salesforce environment exploitation and high-value PII harvesting.
SEALSQ’s patented semiconductor-based NFT provisioning creates a hardware root of trust that is immune to software exploits, platform shutdowns, and future quantum attacks. WISe.ART’s platform becomes the first cybersecurity-hardened marketplace for physical artwork authentication.
Accenture’s $4.18 billion simultaneous acquisition of Dragos, runZero, and NetRise signals a massive consolidation push into operational technology and asset visibility cybersecurity. The deal, announced alongside a revenue-miss quarter, reshapes the competitive landscape for managed security services and pressures other service providers to catch up in industrial security capabilities.
Source: Sacbee · Miamiherald
Synthetic identity fraud losses hit $2.94B in 2025 and are projected to top $3.1B in 2026 as AI makes it possible to fabricate entire personas. Cybersecurity teams face a threat with no real victim to report, challenging traditional detection systems.
Source: Sacbee · Kansascity
The $42.7 billion C5ISR budget request emphasizes cyber-resilient architectures, zero-trust models, and encrypted communications to counter advanced threats. The DoD’s move toward open architectures creates both opportunities and new attack surfaces for cybersecurity innovators.
In a landmark OT cybersecurity consolidation, Accenture takes majority stake in Dragos and acquires runZero and NetRise, combining threat detection, asset discovery, and firmware analysis into a unified platform for critical infrastructure.
Source: SecurityWeek · finanznachrichten.de
A healthcare insider attempted to sell Kate Middleton’s records from The London Clinic, resulting in an ICO caution. Cybersecurity professionals must treat this as a classic insider threat case demanding DLP and UBA upgrades.
At the G7, PM Modi identified deepfakes, misinformation, and child exploitation as the top AI cyber threats, advocating for global security standards and child-centric safeguards.
While a space-based control system would remove weather-related vulnerabilities, it opens a new celestial attack surface. Security experts warn that satellites could be jammed, spoofed, or hacked, giving remote actors a way to disrupt train operations.
Two major threat actor groups are driving a crisis in education technology, with ShinyHunters stealing 137,000 staff records via Infinite Campus and FulcrumSec paralyzing Global Schools Foundation. The incidents reveal a shift in cybercriminal focus toward low-defence, high-value academic data repositories.
Cybersecurity professionals must now reckon with the commercial industrialization of offensive AI cyber weapons, as Twenty achieves a $1 billion valuation with fresh funding to expand its attack capabilities for government clients.
Source: Cristian Dina · CNA
A publicly dropped zero-day in Microsoft Defender, tracked as CVE-2026-50656 (CVSS 7.8), can yield SYSTEM privileges with up to 100% reliability on patched Windows 10/11, even when real-time protection is off. Microsoft is scrambling to produce a patch amid an escalating dispute with the researcher behind the PoC.
Source: SecurityWeek · BleepingComputer
Cybersecurity experts assess FulcrumSec as a serious threat actor, and its two-month dwell time inside Novo Nordisk before making a $25 million extortion demand reflects advanced persistent threat tactics. The breach highlights growing risks to critical infrastructure and the evolution of cyber extortion with a harm-reduction narrative.
ASIO’s alert reveals that modern vehicles are data-harvesting machines, with sensors generating up to 2 terabytes of raw data every day. The cybersecurity implications are profound: unencrypted telemetry, biometric data sharing, and always-on microphones create an attack surface that threat actors—including nation-states—can exploit.
Source: Danielle Collis (au) · Danielle Collis (au)
Novo Nordisk's breach reveals a stealthy exfiltration operation targeting high-value clinical and provider data, with no ransomware. The incident spotlights the pharmaceutical sector's expanding attack surface.
After an export ban halted Anthropic’s model for non‑U.S. users, its security leads presented red‑teaming results to the White House. The talks hinge on proving the model cannot be weaponized by foreign cyber threats.
Mavenir becomes the first major network software vendor to certify a 5G Packet Core network function under Germany’s mandatory NESAS cybersecurity scheme, bolstering network security for public telecoms and setting a new compliance benchmark.
Source: manilatimes.net · finanznachrichten.de
Reco's new Claude Security integration provides bidirectional governance across Claude Enterprise and Platform, giving security teams the ability to map AI agents, their permissions, and connected tools—essential for mitigating risks as agentic AI becomes woven into enterprise operations.