Many security leaders at major companies, flush with expanded budgets to fend off AI-powered cyberattacks , are experiencing a level of decision fatigue that's freezing them in their tracks. Why it matters: Those leaders are still trying to size up how autonomous cyberattacks will affect their businesses at a time when they need to be taking bold action and mobilizing quickly, experts told Axios. The big picture: Companies have only a short window before AI models capable of end-to-end autonomous cyberattacks land in the hands of malicious attackers. - But four months after Anthropic released Mythos Preview to prepare for what's to come, many companies are still debating where to put their money and which controls to prioritize. State of…
A coalition of more than 120 organizations, including Nvidia, Cisco and CrowdStrike, is proposing a new incident-reporting framework for AI agents that would require participating companies to disclose certain agent mishaps and preserve detailed records of what went wrong. Why it matters: As AI agents gain more autonomy to act across computer systems, the industry lacks a standard way to report security failures and learn from them. Driving the news: The Open Secure AI Alliance is developing guidelines for what it's calling the Shared AI Findings Exchange (SAFE), a proposed framework for how organizations report cyber incidents involving AI agents. - The draft calls for participation from model deployers, AI developers, cloud and tool…
OpenAI is introducing a more cyber-permissive version of GPT-5.6 Sol to vetted defenders as it prepares companies for autonomous cyberattacks . Why it matters: The move comes just days after OpenAI said it was delaying the release of its forthcoming model, Astra, after it reached critical hacking abilities during safety testing. The big picture: OpenAI is unveiling GPT-5.6-Cyber while also expanding Daybreak , its program that gives cybersecurity defenders access to the company's cyber models and other tools. - Many cyber defenders have been experiencing high refusal rates across frontier AI models as the labs try to balance giving defenders the tools they need, while not accidentally leaking those abilities to malicious hackers. -…
OpenAI is finalizing a model with advanced cybersecurity capabilities that it plans to release only to a small set of companies, similar to Anthropic's limited roll out of Mythos , a source familiar told Axios. Why it matters: AI capabilities have reached a tipping point, at least in terms of autonomy and hacking capabilities. Model-makers are now so worried about the havoc their own tools could cause that they're reluctant to release them into the wild. Driving the news: Anthropic announced plans Tuesday to limit access of its new Mythos Preview model to a hand-picked group of technology and cybersecurity companies over fears of its advanced hacking capabilities. - At the time, it was the first AI company to take such an approach with a…
Anthropic is rolling out a preview of its new Mythos model only to a handpicked group of tech and cybersecurity companies over concerns about its ability to find and exploit security flaws , the company said Tuesday. Why it matters: Anthropic is so worried about the damage its own model could cause that it's refusing to release it publicly until there are safeguards to control its most dangerous capabilities. Threat level: Mythos Preview is "extremely autonomous" and has sophisticated reasoning capabilities that give it the skills of an advanced security researcher, Logan Graham, head of Anthropic's frontier red team, told Axios. - Mythos Preview can find "tens of thousands of vulnerabilities" that even the most advanced bug hunter…
U.S. and Israeli military strikes on Iran are playing out in the air and at sea, while a parallel fight is unfolding online . Why it matters: Iranian actors — both state-linked and loosely affiliated — have a history of cyberattacks against the U.S. , but the U.S. and Israeli governments are now using similar tactics. Driving the news: A Wednesday cyberattack allegedly linked to Iran‑aligned hackers disrupted operations at Stryker, a major U.S. medical technology company, The Wall Street Journal reported . - Stryker confirmed in a statement that it is "experiencing a global network disruption to our Microsoft environment," but that it hasn't seen any signs of "ransomware or malware" and now believes the incident is "contained." …
Cybersecurity companies aren't likely to face the same dramatic, AI-induced apocalypse that's hit the software industry over the last month, analysts say. Why it matters: Investors are panicking and security executives are now on the defensive. But insiders don't see this as a total identity crisis for the industry. Driving the news: Anthropic on Friday announced its new Claude Code Security product, which can automatically scan codebases for vulnerabilities and suggest patches. The news caused shares of several major cyber companies to tumble. - "The Global X Cybersecurity ETF fell 4.9% and closed at its lowest since November 2023" on Friday, according to Bloomberg . - As of Monday, CrowdStrike shares have fallen 11%. Cloudflare took…