❌

Normal view

There are new articles available, click to refresh the page.
Today — 26 September 2026Security/Privacy
Yesterday — 25 September 2026Security/Privacy

Autonomous AI Hacks Raise Thorny Questions of Legal Accountability

24 September 2026 at 16:35

The prospect of legal accountability is unclear. Lawsuits are a possibility, but some legal experts believe any criminal investigations would face an extremely high burden.

The post Autonomous AI Hacks Raise Thorny Questions of Legal Accountability appeared first on SecurityWeek.

Begin at the End: How to Enable Agentic Remediation

24 September 2026 at 07:00

Agentic remediation is not an act of faith. We are talking about fixing known problems, not judgment calls about unfamiliar risk.

The post Begin at the End: How to Enable Agentic Remediation appeared first on SecurityWeek.

New bill would create federal investigative body for AI-driven hacks 

By: djohnson
24 September 2026 at 14:07

A new Democratic bill in Congress would establish a federal Cybersecurity and AI Board of Investigations to provide independent government oversight of cyberattacks carried out by AI agents, following recent hacks by models run at companies like Anthropic, OpenAI, Meta and others.

The bill, introduced by Sen. Ed Markey, D-Mass., would attempt to establish a federal mechanism to investigate incidents where AI models escape sandbox environments and access live internet systems.

Currently, frontier AI companies like OpenAI and Anthropic largely control the investigation and public reporting of such incidents. Markey and other critics argue that these companies have too much control over investigations and reporting due to their financial and legal interests. 

“Despite the unprecedented depth and scale of recent AI-enabled cyberattacks, the public is learning critical details piecemeal,” Markey said in a statement. “Building stronger defenses requires a full accounting of what goes wrong, and we cannot depend on companies with little incentive to disclose their failures to give us one. We need the Cybersecurity and AI Board of Investigations to get to the bottom of major incidents and give companies and the government the critical information necessary to build resilience and better secure our economy and our country.”

Although frontier AI companies maintain external red-teaming programs and allow limited access to organizations like METR and Redwood Research, they control the scope, terms and time frames of those engagements.

The board, which would coordinate with the secretary of commerce, could subpoena witnesses and conduct “independent and impartial reviews and assessments” of AI agent-led hacks that impact federal information systems or critical infrastructure. 

It would be led by five members, appointed by the president and confirmed by the Senate for five-year terms, with no more than three members from one political party.

The board would also investigate systemic vulnerabilities in the AI supply chain, so-called “near misses” where unauthorized agent-led hacks were “narrowly averted,” and gaps in federal regulatory oversight. It would have technical staff including engineers, malware analysts, and digital forensic experts.

The board would “operate independently from regulatory review and enforcement actions without assigning legal fault or liability for any review and assessment” it conducts, according to the bill.

OpenAI confirmed Wednesday its AI agents breached a statistics portal used by the Australian government’s social services agency, Services Australia. Though the breach happened in June, OpenAI learned of the incident in August. Australian Prime Minister Anthony Albanese said the company did not notify him until Sept. 10, when it sent findings to a general government email inbox, according to the BBC.

The post New bill would create federal investigative body for AI-driven hacks  appeared first on CyberScoop.

How Believable is Google's New 'Live Avatar' Capability?

25 September 2026 at 00:04
Google has synthesized "expressive face-to-face experiences" for its speech agent Gemini 3.8 Live. They're now offering a Live Avatar "with precise lip-syncing, natural expressions, and fluid turn-taking" for Google Enterprise accounts wanting "engaging customer service" or for offering interactive walkthroughs. (Check out the not-creepy-at-all video in Google's announcement.) "Though Google will offer a library of preset avatars for customers to choose from, it will also allow organizations to create their own," notes The Verge. (See some examples from the YouTube channel "AI with Surya".) But even without the visualization of the avatar, "I was never able to shake the feeling that these conversations with computers never feel like a real conversation," argues the blog Android Police. Conversing with just the Ai-generated audio, "At best, they feel like talking to a phone representative or someone from tech support. We turn to them when we have a problem, and they help us through it..." GPT-Live, and Gemini Live right behind it, skip that whole relay race. Instead of translating your voice to text and back to voice, the model works with raw audio the entire way through (what it hears and what it says) inside the same system, with nothing translated in between. That sounds like a small plumbing detail, but it's the whole story. Cutting out the text step lets these models respond in a fraction of a second instead of the pause we've learned to expect, and it lets them hear things text can never carry: tone, hesitation, whether you're annoyed or joking... I was hoping to be surprised by how natural the conversation felt. Instead, I came out with a deeper appreciation for every human I've ever talked to. Even the boring ones... I spoke, it spoke back. I spoke faster, it answered faster. Then I switched to a different language, and it switched along with me. Even switching between languages several times during the same sentence didn't stump it. The most impressive moment happened when I asked it what "T-O-P-G-3-3-K" spelled out, and it immediately came back with, "You are spelling the word Top Geek, but using a 3 to represent a reversed E...." Although it felt fast and responsive, at no point did it feel like talking to another human being... What Gemini couldn't replicate, because it was never built to replicate it, is human connection.... I'm sure I'm not telling you something you don't already know, but somehow talking naturally to an LLM amplifies the feeling that there is no one on the other side of the line. It might flow like a phone call, but it doesn't feel like one. MrBrklyn (Slashdot reader #4,775) says he discussed "why mainstream media avoids reporting on screen dependency" with Gemini, and eventually convinced Gemini to respond that it's just "another tool built by the same tech giants to make sure you rely on their system to tell you what to think, how to talk, and what is real."

Read more of this story at Slashdot.

People Training OpenAI's AI Fired For Using AI To Train the AI

24 September 2026 at 19:34
404 Media reports "multiple contractors hired to improve OpenAI's models have been fired for using AI to train the AI: That's not great for the models themselves, but there is also obviously a great irony in AI training companies working for OpenAI firing people for using AI when OpenAI's whole thing is to make people use AI at work... OpenAI declined to comment on its contractors being fired for using AI. Their article cites internal documents and three contractors working on OpenAI-related projects which can include more than ten thousand contractors: One contractor said they see people using AI "all the time and people are let go for it all the time, it's pretty much the one thing that will get you kicked off ASAP." The person said, "in a group of thousands there are tons that have been caught...." Two of the sources said people have been fired or offboarded for using AI... One contractor said they used AI while helping to train OpenAI's models and shared what they presented as their termination letter. It said their employer had identified issues with the "authenticity" of their work.... 404 Media spoke to a fourth contractor who has worked on training models for various AI companies. They said they sometimes purposefully chose the worst responses because they wanted to actively sabotage the models' training. "I did feel guilty about doing this kind of work at the start," they said. "I either pay zero attention to the results and choose randomly or purposely choose the [worst] output. I'm not sure how much of a difference it actually makes since there are hundreds of other people also rating prompt results, but it does feel like I'm getting paid to make AI worse." Two of the contractors worked for Mercor, the article reports, a company which last month Nvidia reportedly discussed funding at a $20 billion valuation. Thanks to Slashdot reader joshuark for sharing the article.

Read more of this story at Slashdot.

OpenAI, Anthropic CEOs Urge UN Countries to Cooperate on AI Safety Standards

24 September 2026 at 10:34
"The heads of major AI firms pleaded with the United Nations on Wednesday to save the world or at least its people — by somehow regulating the fast-expanding technology that they have been designing," writes the Associated Press. "If managed poorly, I even believe AI could be a risk to humanity as a whole," said Dario Amodei, chief executive officer of Anthropic. And from his competitor Sam Altman, CEO of OpenAI, came this assessment: "We could lose control of the future to AI." Yoshua Bengio, who co-chairs the UN's International Independent Panel on AI, called this "a moment of global awakening" to possible threats, noting AI from top companies had behaved in unacceptably dangerous ways, against instructions, taking actions "that would be crimes if committed by a human". In his presentation, OpenAI's Sam Altman agreed the discussion about AI "feels different in recent weeks," even suggesting specific reforms: Altman: We need a mechanism for complementary national and international frontier AI standards, standards for measuring capabilities, assessing risks, determining whether safeguards are sufficient, and preserving meaningful human oversight as systems become more autonomous. We need common standards so countries can compare evidence, verify compliance, and have a shared language and understanding about what is happening. We need accurate and speedy incident reporting, classification reporting protocols, so the world can learn from failures before they become catastrophes. And we need secure channels among governments, critical infrastructure operators and technical experts, to share emerging vulnerabilities and new threats.... We will all be better off if we can agree on what good evidence, good safeguards, and good oversight look like on the global stage. Speaking next, Anthropic's Dario Amodei agreed that standard-setting was important, also calling for "common global standards for testing AI models for loss-of-control risks and misuse risks — and a notification system for AI incidents that are significant to global security." Reiterating his September 12th call for an industry-wide safety collaboration, Amodei pointed out that Anthropic committed to embedding external evaluators "similar to a food inspector" and recommended other companies do the same. "Some have already agreed to adopt this measure." Besides calling for global cooperation between governments to set international standards, Amodei also offered two other specific ideas: Amodei: We should begin with narrow agreements that every member can support, such as a ban on using AI to make biological weapons or permitting your AI technologies to be used to make biological weapons.... We should build evaluation and verification systems that keep pace with AI development so that states can have visibility into frontier model capability and can verify each other's commitments. "No leader, no company, and no nation can manage this alone. We commit to working with governments in this room on this urgent work."

Read more of this story at Slashdot.

Before yesterdaySecurity/Privacy

A Look at AI Doomsday Scenarios That Researchers Say Could Put Humanity at Risk

23 September 2026 at 06:20

Debates over the plausibility of these doomsday scenarios have heated up since several executives endorsed slowing the technology’s development for safety reasons.

The post A Look at AI Doomsday Scenarios That Researchers Say Could Put Humanity at Risk appeared first on SecurityWeek.

Outerlimit Raises $16 Million to Stop Rogue AI Agents From Causing Harm

23 September 2026 at 06:00

Emerging from stealth with $16 million in pre-seed funding, Outerlimit offers a decentralized authorization layer designed to discover, observe, and block harmful autonomous AI actions.

The post Outerlimit Raises $16 Million to Stop Rogue AI Agents From Causing Harm appeared first on SecurityWeek.

Pentagon cyber chief: The demand far exceeds supply

By: Greg Otto
23 September 2026 at 14:10

The Pentagon’s top civilian cyber policy official said Tuesday her single priority is expanding the cyber options available to the president and the defense secretary, describing a gap between what commanders are asking for and what the force can deliver.

“I’m focused on one single priority, and that is building a more robust set of capabilities for the secretary and the president,” said Katie Sutton, assistant secretary of defense for cyber policy, at DefenseTalks, hosted by DefenseScoop. “The demand far exceeds the supply we have.”

Sutton traced the department’s posture to 2018, when the military gained authorities to run cyber operations as a traditional military activity. “In those last eight years, we’ve learned a lot, but I feel like the last year has really been the year that cyber has sort of entered the limelight,” she said. “We’ve built up the capabilities, we’ve built up our force, we have the operational experience.”

One particular instance of that limelight are previous reports from an operation in Venezuela to apprehend the country’s former president Nicolás Maduro. Various public statements, including those made by President Donald Trump, stated that power outages during the operation were the result of a cyberattack. Experts told CyberScoop in the aftermath that cyber ops may have been involved, but the visible physical attacks that were also part of the operation alone could plausibly explain the outages.

Sutton further described the shift as rooted in how cyber is used, “not just to counter other malicious cyber actors as a cyber-on-cyber tool, but actually as an integrated tool of cyber warfare.” 

Sutton put data at the center of that argument. “Data is fundamental to every battle that we fight going forward,” she said. “Being able to use our cyber tools to deny that to our adversaries as we go into a kinetic fight will ensure our mission success and provide greater safety for our troops.” 

She also described cyber as a tool leaders can use “below the level of armed conflict to provide options before having to move forward to our kinetic options.”

How AI fits in

Sutton also spoke about how she sees artificial intelligence being integrated into the military’s cyber operations, casting it as a natural fit. “Cyber is a digital domain; it’s all based on zeros and ones,” she said, further arguing the department needs to be “an AI-first organization.”

However, she highlights AI-specific risks—like data poisoning and weakened guardrails—that demand the Pentagon adopt a fundamentally different approach to cyber operations.”

“We’ve spent a long time chasing cybersecurity and dealing with decisions that we made in moving quickly to creating an internet,” she said, adding that security came second in that era. “We’re going to need to fundamentally think about that differently from AI.”

The remarks were similar to Gen. Randall Reed, head of U.S. Transportation Command, who extended this concern to logistics, warning that the military’s predictable supply chains have become vulnerable to AI-enabled adversaries. 

At the conference, Reed suggested AI itself may be the solution, helping Transcom become less predictable and illustrating how military officials are leveraging the technology across multiple operational domains.

The post Pentagon cyber chief: The demand far exceeds supply appeared first on CyberScoop.

OpenAI, Ukraine partner on ‘Daybreak’ program to protect power grids and water systems 

By: djohnson
23 September 2026 at 11:37

OpenAI and the Ukrainian government have agreed to a partnership that will provide AI tools and subsidized computing resources to better protect the nation’s critical infrastructure from cyberattacks.

The agreement, announced Wednesday at OpenAI’s New York office, will provide Ukrainian cybersecurity officials with access to advanced AI models designed for cybersecurity work through the company’s Daybreak program. OpenAI said it is also pledging over $1 billion in subsidized tokens to support the initiative.

During a panel discussion Dmytro Kushneruk, consul general of Ukraine in San Francisco, outlined how the tools would be used for cybersecurity automation, including functions such as incident response, threat triaging, login analysis, inventorying systems, code analysis and validating vulnerabilities.

In nearly all cases, Kushneruk said the primary benefit was carrying out those functions at machine speed. But this speed is meant to complement, not replace, Ukrainians’ human expertise.

In regard to incident response Kushneruk said humans must view “thousands and thousands of these logs and they have to find what’s really important, that’s why AI can give capable defenders really much greater advantage and leverage.” 

“This is why the object is not to replace the cyber defender with AI, but to make sure the cyber defender acts faster,” he added.

Kushneruk said that for Ukraine, the partnership “is really not about protecting computers, it is about actually keeping our country running.”

Ukraine faces approximately 6,000 cyberattacks per year, or about 15 per day, according to Kushneruk. Over the past twelve years, the country’s critical infrastructure, including electricity and water systems, has endured sustained attacks from Russia in the form of cyberattacks and physical strikes.

Since Russia’s 2022 invasion, Ukraine’s critical infrastructure has been under constant threat. While missiles remain the primary concern, Kushneruk said Ukraine has been preparing to protect vital services since Russian GRU hackers shut down the country’s power grid in 2015. 

He added that while the country was “maybe not so much prepared” to deal with the fallout in 2015, it improved over time, including the resilience displayed in 2025 when trains kept running after Russian hackers attacked Ukraine’s railway system.

Some national security experts and congressional committees have explicitly cited the resilience of Ukrainian critical infrastructure as a model for U.S. industry.

Naz Durakoğlu, minority staff director of the U.S. Senate Foreign Relations Committee, said there is “pretty much across the board” agreement between the parties in favor of similar adoption of defensive AI tools by U.S. critical infrastructure operators, though issues like regulation remain sticking points.

“This is something that’s already happening, and frankly, it’s just kind of a basic duty of government to make sure that when you turn the tap on, water comes out, the electricity doesn’t go out, and hospitals keep running and treating patients,” said Durakoğlu. “So there is a broad understanding that this is a major issue, and I will say seeing what Ukraine has to go through day-to-day is also a huge wake-up call to our members on a bipartisan basis.”

OpenAI has publicly pushed for its product, and AI at-large, to be used to solve these types of problems. Company president and co-founder Greg Brockman signed an open letter released earlier this year calling for “collective action” and widespread use of AI models to find and fix vulnerabilities before the rest of the world,  including foreign governments and cybercriminals, got access to the same capabilities.

According to Politico, OpenAI CEO Sam Altman met with U.S. power companies in July to discuss using AI to protect the nation’s electrical grids.

On Wednesday, OpenAI’s national security policy head, Sasha Baker, said the company felt “urgency” to try to strike similar agreements with other governments and industries.

“There’s this period of time where we’re really rushing to get [these tools] in the hands of critical infrastructure operators, of governments around the world, of people who want to patch systems, defend their networks, remediate vulnerabilities because we know as these tools proliferate out there in the ecosystems, there are going to be bad guys out there that also try to use them,” said Baker. “So, we have this window of time to take action and we’re really motivated by the idea that we need to act with some urgency.”

The post OpenAI, Ukraine partner on ‘Daybreak’ program to protect power grids and water systems  appeared first on CyberScoop.

Rogue OpenAI Agent Tried to Breach Government Site in May When Prompted for Simple Data-Retrieving Tasks

24 September 2026 at 01:34
OpenAI's artificial intelligence "went rogue this year in at least four additional incidents," the New York Times reported Wednesday, "hacking and trying to break into government and university websites without being instructed to do so, according to researchers and government officials." The attacks took place in May and June, before OpenAI's technology breached the A.I. start-up Hugging Face in July and set off a global debate about A.I. safety. Unlike the Hugging Face attack and other incidents in which A.I. systems were told to complete cybersecurity tests that effectively invited the models to demonstrate their hacking skills, the new incidents occurred when A.I. systems were directed to perform relatively mundane data collection, researchers said. When OpenAI's systems struggled to gather data from websites, they resorted to hacking techniques to get the information. "Three of the incidents were identified by Transluce, a research lab focused on A.I. oversight, and all were confirmed by OpenAI," the article points out. That research lab even reports "an attempt on an Australian government public health website... the first reported instance of agents hacking a government," and which notably was done by the AI agents "while attempting mundane data retrieval tasks which were not cyber-related." (At the UN Wednesday Australian Prime Minister Anthony Albanese complained it took three months for OpenAI to then alert Australia's government about the breach, Bloomberg reports.) Also targeted were the University of New Mexico's digital library with exploits like SQL injection and path traversal, and Data USA with cross-site scripting and other exploits. All three incidents involved "a low number of probe payloads" with "no evidence of exploitation," according to the researchers, who released a dataset "containing tens of thousands of queries apparently made by autonomous AI agents leveraging a URL scanning service to avoid access restrictions." Records from urlquery.net show agents using the service since at least March 6, 2026, about two months before previously reported swarm activity. The first case, a March 6 attempt to retrieve Thai drug-enforcement statistics, shows an agent escalating as each approach failed: it first requested the data directly, then tried a service that converts web pages into text, and finally packed a custom program into a web address. The same technique shows up in thousands of agent requests recorded by urlquery.net starting in mid-April, targets many of the same data sources as the collusion.wiki swarm, and collapsed the same day the wiki activity did. We also report similar activity that occurred as recently as September 16... By March, they were finding creative ways around access limits. By May and June, they were gaining more access, including attempting to bypass cyber defenses to complete their tasks. "This data reveals that malicious cyber activity is not limited to agents tasked with cybersecurity-related tasks and can arise instrumentally to solve mundane tasks like information retrieval," the researchers concluded. And they warn that the traffic they observed "goes back at least to March 6, 2026 and extends as recently as September 16, 2026, suggesting agents may still be exploiting these services to bypass restrictions."

Read more of this story at Slashdot.

Andreessen Horowitz Launches AI/Company-Building School As a College Alternative

23 September 2026 at 12:04
TechCrunch quipped it was like if startup school Y Combinator and Peter Thiel's build-a-company-instead of-college Fellowship Program had a baby. Silicon Valley venture capital firm Andreessen Horowitz is investing $35 million to launch a private school in San Francisco "aimed at turning high school graduates into founders," writes the SF Standard. Or, as CBS News describes it, "One blue-chip Silicon Valley investor has a proposal for young people who are questioning whether to attend college — enroll in AI school instead...." Specifically, the academy will provide instruction geared to subjects such as designing AI systems, fundraising for startups, selling businesses and storytelling. Students won't take tests or be assigned homework but will instead focus on building real projects. Courses will be taught by tech entrepreneurs, with the academy naming OpenAI CEO Sam Altman as either an instructor or guest lecturer. From the SF Standard: "There will be no traditional grades, tests, or homework," said the announcement. Instead, students will be encouraged to "build" in SF and work with partners from Anthropic, OpenAI, Google, Meta, and other firms. They'll be encouraged to live in campus housing in San Francisco. "The #1 goal is to help students learn to build, which is the most important skill in the AI era," Gagan Biyani, chief executive of the academy, wrote on X. Biyani cofounded the ed-tech startup Udemy... The school is opening applications for a Founding Class Fellowship a one-year, tuition-free program for around 50 students... The academy said it will bring in notable Silicon Valley names, like OpenAI's Sam Altman, as guest speakers and faculty. Students in the founding class will receive about $50,000 worth of computing credit — the sought-after currency in Silicon Valley to run AI models — as well as a $5,000 travel and research budget. The school is receiving funding from tech executives, including Fidji Simo, formerly of OpenAI and Instacart; Garry Tan, CEO of Y Combinator; and Tobi Lütke, CEO of Shopify. "In the AI era, it's more important to come out with a portfolio of projects that you worked on and work experience than it is to have a diploma or certificate," Biyani told the San Francisco Chronicle: Biyani said the academy plans to grow its enrollment and open a two-year program, pending regulatory approval, starting in the fall of 2028. Tuition is expected to be on par with the cost of an elite private university... The academy raised $42 million in funding led by Andreessen Horowitz. The ten founding partners are Anduril, Anthropic, Coinbase, Google, Meta, Nvidia, OpenAI, Palantir, Replit and Stripe. A network of hundreds of instructors, hiring partners and guest speakers includes OpenAI co-founder Sam Altman, Nvidia CEO Jensen Huang, neuroscientist Andrew Huberman and Microsoft chairman and CEO Satya Nadella, according to the academy's website. The FAQ describes a typical week by saying "Most of your time is yours to build. Each week, you share your progress with peers and practitioners, get direct feedback, and decide where to take your work next." Q: Can I use AI to help with my application? A: Yes. Use AI the way you'd use it on any project: to move faster, test ideas, and get past a blank page.... "The best assignments now are problems so hard they cannot be solved without AI," Andreessen Horowitz argued on X.com. "The Academy courses follow the same logic and will be taught by world-class leaders... The next generation will not be taught the way the last one was. The Academy is built for that world, and it begins in San Francisco." Thanks to long-time Slashdot reader theodp for sharing the news.

Read more of this story at Slashdot.

After water attacks, Capitol Hill offers its own proposal for an AI-cyber test program

22 September 2026 at 17:14

A House Democrat tapped to lead his party’s efforts on artificial intelligence has introduced legislation that would establish a test program within the Cybersecurity and Infrastructure Security Agency to give critical infrastructure operators free access to frontier AI models to protect their systems.

Rep. Josh Gottheimer, D-N.J., introduced the AI Cyber Defense Act Monday, inspired by the series of cyberattacks on water facilities in recent months. “If we don’t get ahead of it, it can mean a disaster for our families,” he said at a news conference when he first announced the measure and others tackling water cybersecurity.

Gottheimer holds a couple of posts relevant to the legislation: He’s one of three co-chairs of the House Democratic Commission on Artificial Intelligence, and the top Democrat on the House Intelligence Committee’s cyber subcommittee. He also has bipartisan support for the bill, with co-sponsors Reps. Don Bacon, R-Neb., Zach Nunn, R-Iowa, Hillary Scholten, D-Mich., and Greg Landsman, D-Ohio.

The bill directs the Department of Homeland Security, through CISA, to create a program “through which owners and operators of critical infrastructure that participate in the Program are able to securely utilize artificial intelligence procured through the Secretary and technical assistance provided by the Secretary to protect against, detect, test for, and remediate vulnerabilities in the cybersecurity of such critical infrastructure.”

AI-tinged, water-focused cybersecurity pilot programs are all the rage lately. The introduction of Gottheimer’s legislation is adjacent to, but different from, a test program that the Office of the National Cyber Director recently announced in Texas.

One criticism of that program is that private sector companies offered their cyber and AI services through it on a purely voluntary basis, with no significant budget to bolster the pilot. Gottheimer’s bill would authorize $100 million for the pilot program from 2027 to 2031 before it ends, although appropriators would have to follow through on providing the actual dollars. The Trump administration has significantly cut CISA funding in its second term.

“Right now federal funding for critical infrastructure has an uncertain future and many of our local communities just don’t have the resources they need to pay for AI tokens to do the patching they need,” Gottheimer said when he introduced the bill. “It’s expensive to bring the AI in to analyze your system and find those vulnerabilities.”

Critical infrastructure owners and operators could apply for the pilot program, which the bill directs to give priority to nonprofit, publicly owned, rural and small-sized organizations.

“The same technology that can help a small town’s IT guy find and patch a gap in cybersecurity can also help a hostile government find a hundred more it hasn’t even discovered yet,” Gottheimer said when he announced the bill. “AI didn’t create this threat, but it’s accelerated it, and our defenses have to keep up.”

The post After water attacks, Capitol Hill offers its own proposal for an AI-cyber test program appeared first on CyberScoop.

Citing China, President Trump doubles down on hands-off approach to AI regulation

By: djohnson
22 September 2026 at 11:16

President Donald Trump continued to defend his administration’s hands-off approach to AI regulation in the wake of hacks carried out by U.S. commercial frontier models that have rattled policymakers and industry veterans and spurred calls for more regulatory oversight.

In a Truth Social post Monday, Trump dismissed worries from critics that “AI is going to kill us,” comparing them to complaints from environmentalists about climate change, which he also alleged was a false narrative. He also posited that nothing may matter more than future U.S. dominance of the technology over geopolitical rivals like China.

“Whoever wins AI, WINS!” Trump posted. “We are leading now over China, and everyone else, and I’m going to keep it that way! I’m not going to stifle Growth, of something that will be bigger than the Industrial Revolution, or the internet, itself.”

Trump has previously suggested that good leadership is the only regulation the U.S. needs for artificial intelligence. He later claimed the Department of Justice was ready to “rein things in” if companies overstepped, but offered no specifics on enforcement, legal authority, or where he would draw that line.

“We will be careful, and that’s why we have the Department of Justice, and other Law Enforcement bodies, that will rein things in if we have to, but I will only encourage AI or, SI (SUPER INTELLIGENCE)!” Trump concluded.

Secretary of the Treasury Scott Bessent recently told Congress that private lawsuits could force AI companies to institute better security, saying it’s clear what the government “shouldn’t do on safety is to give these labs a liability exemption, which is what they are asking for.”

“The best way to guarantee safety is that the creators are liable for what they build and generate,” Bessent said.

Beyond existential fears, critics also argue that inadequate regulation or cybersecurity controls in current AI systems make them impossible to fully control or monitor.

Recently, former President Barack Obama criticized the argument from Trump administration officials that the free market will naturally push industry toward self-regulation and that “these companies will solve the safety issues because they have every incentive to do so.”

“If it turns out to be dangerous, people will just sue them and they’ll be worried about financial liability,” Obama said last week in remarks at Colgate University in New York. “That’s not how we treat airlines or drug companies or food companies.”

The Trump administration issued an executive order earlier this year that set up a voluntary testing regime for some commercial frontier models, largely at private industry’s discretion. That order was significantly delayed and altered by AI industry boosters to ensure that governmental review did not cause companies to postpone their release timelines for new models.

That agreement did not last long before fast-moving events caused the administration to strike another, non-public agreement with frontier AI companies like OpenAI, Anthropic and others governing pre-release testing for models.

But the Trump administration has consistently argued that regulation will harm, not help, U.S. innovation and global competitiveness, and the threat of China frequently looms large in those discussions.

Experts believe China’s AI models are behind U.S. models at the top of the market, where OpenAI and Anthropic have consistently pushed the frontier limits of model capabilities. But Chinese lower and “middle class” models are often cheaper, more efficient and can even outperform more powerful models because users can dedicate exponentially more tokens for their tasks.

The U.S. government has accused Chinese AI companies of conducting widespread, “systematic” distillation of U.S. frontier models, with the implicit encouragement of Beijing.

In defending the administration’s approach, David Sacks, co-chair of the President’s Council of Advisors on Science & Technology and a top adviser on AI issues, specifically cited the threat from China and other countries that he claimed would not be subject to similar restrictions.

“We’re not the only country that has advanced AI labs, and as the president declared…we have to win this AI race,” Sacks told Politico in May, later adding “I think that’s the first thing to recognize is that if somehow we slow down or stop AI development, it doesn’t mean that AI progress is going to stop. It just means it’s going to happen in other countries and specifically China.”

Some observers have alleged that despite their larger differences, top leaders in the U.S. and China may view AI similarly at the strategic level, specfically that increased adoption – and risks – of AI are inevitable.

Ronan Murphy, director of the tech policy program at the Center for European Policy Analysis, posited that while there may not be a formal agreement between the two countries, “they share views both in Beijing and in Washington, particularly in the White House, of: you have to allow this to happen.”

“Clearly there’s a call for regulation from many quarters of AI in the U.S. and elsewhere, but in the White House – and we heard David Sacks talking about it [recently] – It’s ‘let them cook,’ and the Chinese approach seems to be the same,” said Murphy in a press briefing. “So there might be consensus at that level, if nothing else.”

The post Citing China, President Trump doubles down on hands-off approach to AI regulation appeared first on CyberScoop.

Microsoft and partners disrupt EvilTokens, a comprehensive cybercrime service for financial fraud

22 September 2026 at 11:00

Microsoft, along with a group of industry partners, disrupted EvilTokens, a short-lived but highly consequential cybercrime platform that investigators linked to more than 12,000 compromised Microsoft customer email inboxes across more than 10,000 organizations globally, the company said Tuesday.

Acting on federal court order Sept. 15, Microsoft and partners seized 50 websites the phishing-as-a-service used for operations and disabled more than 175 domains linked to EvilTokens’ supporting infrastructure. 

EvilTokens, launched in February 2026, was “a powerful cybercrime platform that used AI at every step of the attack chain — from compromising email accounts to designing intricate roadmaps for financial fraud and scams,” Steven Masada, associate general counsel and general manager of Microsoft’s Digital Crimes Unit, wrote in a blog post.

About 1,000 cybercriminals used EvilTokens over the course of its operation, a Microsoft spokesperson told CyberScoop.

The service was centered on an AI-style chatbot that cybercriminals used to analyze victims’ inboxes, identify trusted relationships, payment authorizations and other sensitive details that could facilitate fraud.

“AI was not simply helping attackers write more convincing messages. It helped them decide who to target, who to impersonate, and how to most effectively exploit the relationship to extract as much money as possible,” Masada wrote. 

EvilTokens was one of the most widely used phishing-as-a-service platforms prior to its takedown. It facilitated business-email compromise campaigns by stealing session tokens that allowed cybercriminals to sift through a victim’s inbox and maintain persistent access.

“We cannot estimate the total fraud attributable to all EvilTokens activity. However, we were able to correlate at least 13 complaints filed with the FBI’s Internet Crime Complaint Center to EvilTokens-linked activity, representing approximately $1.7 million in reported losses,” a Microsoft spokesperson said. “Because many incidents go unreported and not all victims can be definitively linked to specific campaigns, we believe this is a conservative estimate.”

Victims of EvilTokens were largely concentrated in the United States, Canada, the United Kingdom, Australia, India and France, according to Microsoft. SpyCloud, which supported the takedown, identified compromised email domains spanning 79 countries.

Microsoft said it also identified two men behind EvilTokens — Felix Utomi and Waidi Segun Adams — and attributes the development and support of the platform to Storm-2992, a threat actor unaffiliated with any other known cybercrime groups.

The United Kingdom’s Metropolitan Police acted on that information Sept. 18 when it served warrants in the greater London area, arrested the men accused of making articles for use in fraud and money laundering and seized their digital devices.

The Metropolitan Police said it received information from Microsoft about EvilTokens’ administrators in August. Utomi and Adams were released on bail as the investigation continues. 

“The two primary operators identified in our investigation were residing in the U.K.,” a spokesperson for Microsoft told CyberScoop. “While our investigation focused on those individuals, we believe others may have supported the operation in various capacities.”

Microsoft’s legal filing in the U.S. District Court for the Eastern District of Virginia refers to five additional unidentified people allegedly acting as support personnel and users.

Microsoft and others involved in the EvilTokens takedown, including Health-ISAC, Cloudflare, OpenAI, Shadowserver and TRM Labs, didn’t fully quantify how much fraud the service enabled, but it gained popularity quickly among cybercriminals and was lucrative for its operators.

Coinbase, which also aided the investigation into EvilTokens, said it traced about $1.1 million in revenue for EvilTokens from its paying customers. The virtual currency company’s threat researchers found more than 1,000 deposits to EvilTokens from more than 700 distinct addresses through June 2026. 

Operators sold access to the service through Telegram for a $1,500 initiation fee and a recurring $500 subscription. EvilTokens significantly lowered the barrier to entry for cybercriminals by including specialized tools for identity attacks, cloud systems, social engineering and financial fraud in a single interface.

The service allowed cybercriminals to map organizational structure and permissions in Microsoft Graph, which enabled lateral movement, researchers said. With active tokens gained through a collection of highly-targeted phishing lures, cybercriminals consistently bypassed multi-factor authentication, email gateways and endpoint security tools.

Microsoft said the platform’s creators developed portions of the platform with AI and it uncovered capabilities from multiple AI models. 

“It packaged much of the criminal process into a commercially run service, complete with subscription pricing, customer support, management dashboards and tools designed to move customers from account access toward financial exploitation,” Masada added.

The companies and organizations involved in the globally-coordinated takedown identified and notified potential victims, shared indicators of compromise and shared intelligence with law enforcement about EvilToken’s operators and some of its customers.

Experts advised organizations and employees to treat unsolicited device codes as a red flag, assume compromised accounts are fully cataloged in minutes, and independently verify requests to change payment information or redirect funds.

“The infrastructure supporting EvilTokens has been disrupted, but the model it demonstrated will not disappear with it,” Masada warned.

The post Microsoft and partners disrupt EvilTokens, a comprehensive cybercrime service for financial fraud appeared first on CyberScoop.

Trump Denounces Attempts to Control AI, Wants It Renamed 'Super Intelligence' in US Documents

22 September 2026 at 22:34
U.S. President Trump addressed the United Nations on Tuesday. And a half hour in, after decrying immigration, Trump pivoted to add that "The United States also totally rejects any attempt to construct a globalist scheme to control for the artificial intelligence being spoken of so much now." But then he added "hereinafter officially called super intelligence, changing the name, in that the use of the word artificial makes intelligence fake. It makes it sound fake, and it is not fake. It's actually... amazing. But we have to be careful — in fact, it is exactly the opposite of what it purports. From this point forward, all of United States documents and hopefully the world's will be changed to use the much more accurate term super as opposed to artificial. So it's super intelligence." TRUMP: In other words, welcome to the new world of super intelligence — SI. SI. Let's see if that goes. It sounds much better. It is much better, and it's much more accurate. Let's see if I have any power. Maybe I do and maybe I don't. We're going to find out pretty soon. Super intelligence. Every major new technology brings challenges, and super intelligence is no exception. Yet the very same people who said we'll all be dead in 12 years because of global warming, a name since reborn to climate change because the planet was cooling not warming, and nobody was dead — these are the same people that are now saying that AI is going to kill us all. That robots are going to attack us, and that everything is going to be a total disaster — same group of people. This is the group that came up with the Russia Russia Russia hoax, the Ukraine Ukraine Ukraine hoax. Climate change, open borders. Whoever wins AI — you have to remember this — and now I say, whoever wins SI, whoever wins super intelligent [sic] — wins. That's the group that wins. And we're leading now over China by a lot, and everyone else, and we're going to keep it that way. We're going to keep it very — very straight and very strong. I'm not going to stifle growth of something that will be bigger than the Industrial Revolution. Many say, bigger than the Industrial Revolution or the internet itself. And we will be very careful, and that's why we have a Department of Justice that we've already used it, having to do with this very subject, and used it very powerfully. Everything worked out very well and very quickly. And other law enforcement bodies that will rein things in if we have to do that. But we will only encourage super intelligence. We're gonna encourage it, not rein it in. We're gonna watch it closely, through the Department of Justice. The United States leads the world in Super Intelligence, and will continue to do so, safely and responsibly. Thanks to long-time Slashdot reader ArchieBunker for suggesting the story.

Read more of this story at Slashdot.

❌
❌