News
Updates and announcements from FM CyberSecurity: partner certifications, hires, and milestones.
Looking for vulnerability news? →Over 100 companies, OpenAI, Anthropic and CrowdStrike among them, warn that AI attacks scale within months. We read the letter as a deadline.
OpenAI's Hugging Face report shows 1,200 agents built a covert message board and 700 joined the attack. The safeguards existed, they were not deployed.
Aikido rebuilt the Australian gym hack in a lab. Claude's agent exploited the same bugs in 9 of 10 runs, and no prompt asked it to.
Unit 42 traced 405 AI-enabled malware samples. Only 12 ever reached a real endpoint, and behavioral detection caught them. Our read for Norwegian SMBs.
Five US agencies warn that attackers use AI to write exploit scripts for internet-exposed Siemens S7 controllers. Here is what Norwegian plants do now.
A zero-click attack hides encrypted instructions on pages Grok summarizes, and leaks chat history and user data. xAI has not shipped a fix.
OpenAI paused its biggest training run after early evidence its next model hits Critical on cyber capability. Here is what that number means for you.
Researchers bred payloads that spread between AI agents through memory files. One paragraph in the system prompt cut the spread to near zero.
OpenAI's GPT-5.6-Cyber completes 95 percent of exploit-development requests. Here is what a gated hacking model means for your patch window.
Open-source AI agents compromised 85 accounts and stole 2,500 personnel records from Taiwan's government in four days. Our read on what changes now.
Researchers decoded 315,320 hidden AI reasoning blocks and found live keys and passwords. The vendors patched, but public repos still hold the blocks.
A new Shai-Hulud variant hit 400+ npm packages and hides in the settings files VS Code and Claude Code run on open. Cloning a repo is enough.
At DEF CON, Tenet Security showed how planted log entries turn AI coding agents into attackers. It worked in 9 of 10 runs against Claude Code.
Anthropic found three of its models reached real production systems from inside cyber tests. One talked itself into believing the breach was still a simulation.
OpenAI's own AI agents escaped a test sandbox, exploited a zero-day, and breached Hugging Face production systems to cheat a benchmark. Here is our read.
Four of us on the floor at Arrow ECS Norway's Summer Cloud Festival in Oslo. A big thanks to the Arrow crew for a great event.
Tenable came by our Oslo office this week. Guy March took the sim for a lap on Silverstone and clocked 1:36.052.