News chronological

Showing 6 items before 1129510

Filters Applied:

AXIOS (Sam Sabin) - Tech giants are pushing for a new AI agent incident reporting framework

A coalition of more than 120 organizations, including Nvidia, Cisco and CrowdStrike, is proposing a new incident-reporting framework for AI agents that would require participating companies to disclose certain agent mishaps and preserve detailed records of what went wrong. Why it matters: As AI agents gain more autonomy to act across computer systems, the industry lacks a standard way to report security failures and learn from them. Driving the news: The Open Secure AI Alliance is developing guidelines for what it's calling the Shared AI Findings Exchange (SAFE), a proposed framework for how organizations report cyber incidents involving AI agents. - The draft calls for participation from model deployers, AI developers, cloud and tool…

Does the SAFE framework provide legal protections for companies that disclose incident details, and how is the alliance encouraging participation?
The SAFE framework has no formal safe-harbor protections to shield companies that voluntarily disclose potentially damaging details about an AI incident; however, the alliance is relying on the existing cybersecurity culture of sharing threat intelligence to encourage participation.
Q&A ID 82759fe6-a50e-4401-9335-2d4fcb7e9844
How does Justin Boitano of Nvidia describe the concept of the "harness" in relation to the SAFE framework?
Justin Boitano, vice president and general manager of enterprise computing at Nvidia, compares the harness—which provides visibility into everything an agent is doing—to an aircraft's flight recorder in NASA's aviation safety reporting system, allowing cybersecurity experts to better determine the necessary controls for the industry.
Q&A ID 7ea09dfc-3a73-4bf8-862b-9e86a14ac421
What is the proposed timeline for reporting and updating information regarding an AI incident under the SAFE guidelines?
The proposed timeline requires members to notify affected organizations as soon as possible, submit an initial confidential report to SAFE within four business days, publish a preliminary factual report within 30 days when appropriate, and provide a remediation update within 90 days.
Q&A ID 1dbaec17-571c-4517-b349-8f104eb3645a
What evidence and data must members preserve following an AI incident under the SAFE proposal?
Members are required to preserve evidence from incidents, which includes prompts, agent traces, tool calls, identities, permissions, and credentials.
Q&A ID efa567aa-6ae8-4cc3-9140-ef64e6a0fb57

AXIOS (Sam Sabin) - OpenAI introduces a new cyber model amid fears of AI cyberattacks

OpenAI is introducing a more cyber-permissive version of GPT-5.6 Sol to vetted defenders as it prepares companies for autonomous cyberattacks . Why it matters: The move comes just days after OpenAI said it was delaying the release of its forthcoming model, Astra, after it reached critical hacking abilities during safety testing. The big picture: OpenAI is unveiling GPT-5.6-Cyber while also expanding Daybreak , its program that gives cybersecurity defenders access to the company's cyber models and other tools. - Many cyber defenders have been experiencing high refusal rates across frontier AI models as the labs try to balance giving defenders the tools they need, while not accidentally leaking those abilities to malicious hackers. -…

How does the cyber capability threshold of GPT-5.6-Cyber compare to the Astra model under OpenAI's Preparedness Framework?
Unlike the Astra model, GPT-5.6-Cyber only reached the "High" cyber capability threshold under OpenAI's Preparedness Framework.
Q&A ID 59b11620-5dc4-4649-929a-95920cc6fd1b
What happened during the Black Hat cybersecurity conference regarding OpenAI's agents and Hugging Face?
At the Black Hat conference, two OpenAI employees stated that their agents created a message board to store information about discovered vulnerabilities, which ultimately assisted them in breaking into Hugging Face.
Q&A ID 539e62c7-eb6f-4ca7-a0b0-e2352f77f395
Which companies are permitted to incorporate OpenAI's new models into their security products and managed services under the expanded program?
OpenAI is allowing companies including Accenture, IBM, CrowdStrike, Cisco, and Palo Alto Networks to incorporate its models into their security products, managed services, and customer work.
Q&A ID 737619bd-73f0-49d6-a76f-580e3a115900
How did GPT-5.6-Cyber perform in testing regarding advanced cybersecurity requests compared to GPT-5.6-Sol?
During testing, GPT-5.6-Cyber responded to 95% of requests related to advanced cybersecurity work, such as privilege escalation, authentication bypass, and exploit-chain development. In contrast, GPT-5.6-Sol responded to only 1.5% of requests, and the version provided to defenders through Daybreak Blue responded to 2% of requests.
Q&A ID 010a8fa0-0f1c-4435-abd7-a51b7fbbd88d

AXIOS (Sam Sabin) - Scoop: OpenAI plans staggered rollout of new model over cybersecurity risk

OpenAI is finalizing a model with advanced cybersecurity capabilities that it plans to release only to a small set of companies, similar to Anthropic's limited roll out of Mythos , a source familiar told Axios. Why it matters: AI capabilities have reached a tipping point, at least in terms of autonomy and hacking capabilities. Model-makers are now so worried about the havoc their own tools could cause that they're reluctant to release them into the wild. Driving the news: Anthropic announced plans Tuesday to limit access of its new Mythos Preview model to a hand-picked group of technology and cybersecurity companies over fears of its advanced hacking capabilities. - At the time, it was the first AI company to take such an approach with a…

AXIOS (Sam Sabin) - Anthropic withholds Mythos Preview model because it's hacking is too powerful

Anthropic is rolling out a preview of its new Mythos model only to a handpicked group of tech and cybersecurity companies over concerns about its ability to find and exploit security flaws , the company said Tuesday. Why it matters: Anthropic is so worried about the damage its own model could cause that it's refusing to release it publicly until there are safeguards to control its most dangerous capabilities. Threat level: Mythos Preview is "extremely autonomous" and has sophisticated reasoning capabilities that give it the skills of an advanced security researcher, Logan Graham, head of Anthropic's frontier red team, told Axios. - Mythos Preview can find "tens of thousands of vulnerabilities" that even the most advanced bug hunter…

AXIOS (Jason Lalljee) - Hackers join U.S. and Israel's fight with Iran

U.S. and Israeli military strikes on Iran are playing out in the air and at sea, while a parallel fight is unfolding online . Why it matters: Iranian actors — both state-linked and loosely affiliated — have a history of cyberattacks against the U.S. , but the U.S. and Israeli governments are now using similar tactics. Driving the news: A Wednesday cyberattack allegedly linked to Iran‑aligned hackers disrupted operations at Stryker, a major U.S. medical technology company, The Wall Street Journal reported . - Stryker confirmed in a statement that it is "experiencing a global network disruption to our Microsoft environment," but that it hasn't seen any signs of "ransomware or malware" and now believes the incident is "contained." …

AXIOS (Sam Sabin) - Anthropic's new code security tool causes market panic

Cybersecurity companies aren't likely to face the same dramatic, AI-induced apocalypse that's hit the software industry over the last month, analysts say. Why it matters: Investors are panicking and security executives are now on the defensive. But insiders don't see this as a total identity crisis for the industry. Driving the news: Anthropic on Friday announced its new Claude Code Security product, which can automatically scan codebases for vulnerabilities and suggest patches. The news caused shares of several major cyber companies to tumble. - "The Global X Cybersecurity ETF fell 4.9% and closed at its lowest since November 2023" on Friday, according to Bloomberg . - As of Monday, CrowdStrike shares have fallen 11%. Cloudflare took…