Advisory at a Glance Title A Tale of Two SOCs: Insights From Two Red Team Assessments Original Publication August 25, 2026 Executive Summary The Cybersecurity and Infrastructure Security Agency (CISA) conducted simultaneous red team assessments at two organizations and observed different defensive outcomes. In both environments, the red team achieved full domain compromise and accessed sensitive business systems (SBSs) and cloud resources. Organization A failed to detect or contain the activity, but Organization B rapidly identified initial compromise attempts, isolated affected systems, and forced the red team into an assume breach model. This advisory details the red team’s activity and organizations’ defensive actions, offering…
Many security leaders at major companies, flush with expanded budgets to fend off AI-powered cyberattacks , are experiencing a level of decision fatigue that's freezing them in their tracks. Why it matters: Those leaders are still trying to size up how autonomous cyberattacks will affect their businesses at a time when they need to be taking bold action and mobilizing quickly, experts told Axios. The big picture: Companies have only a short window before AI models capable of end-to-end autonomous cyberattacks land in the hands of malicious attackers. - But four months after Anthropic released Mythos Preview to prepare for what's to come, many companies are still debating where to put their money and which controls to prioritize. State of…
Weeks before OpenAI's agents hacked Hugging Face , the agents worked together to find and exploit a vulnerability in the infrastructure supporting the company's cybersecurity testing, OpenAI researchers said Wednesday. Why it matters: The new findings raise questions about how frontier AI labs are monitoring their testing environments — and the challenges safety testers are finding as they try to rein in increasingly powerful AI. Driving the news: OpenAI's internal research model, one of the models involved in the Hugging Face breach, first discovered and exploited a vulnerability in Artifactory, a third-party file repository connected to the company's testing sandbox, on May 26, two researchers said at the Black Hat cybersecurity…