Normal view
BdThemes plugins supply-chain hack creates rogue WordPress admins
OpenAI releases ChatGPT 5.6 Cyber, but it's only for approved users
New StormEncryptor ransomware used by former Medusa affiliate
CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs
When Credentials Are No Longer Enough: Device Trust in the AI Era
Member of The Com sent to prison for blackmail, sextortion
LexisNexis shuts down services after suspicious activity on servers
Valve notifies Steam hardware customers of a data breach
Critical Progress LoadMaster flaw now actively exploited in attacks
OpenAI says Daybreak will expand to offer specialized cyber servicesย
OpenAI announced Mondayย it was expanding access to its frontier models for defensive cybersecurity, detailing different defensive and red-teaming workflows and a new partner program with major cybersecurity product providers.
In a pair of blogs posted Monday, OpenAI said it was updating its Daybreak programย โ which provides unreleased frontier models to private organizations and governments for defensive cybersecurity work โ and introducing a new model variant.
Daybreak Blue, powered by OpenAIโs ChatGPT-5.6-Sol, would operate with lower cybersecurity safeguards compared to other commercially available models and is described as โa recommended starting point for most defendersโ that supports tasks like vulnerability discovery, secure code review, malware analysis, incident response and patch validation.ย
Daybreak Red, meant for more advanced red-teaming, would provide access to a new model, dubbed GPT-5.6-Cyber, that the company said is more purpose-trained for finding vulnerabilities and testing (or exploiting) them. The model is also less likely to refuse requests around โdual-use cyber tasks.โ
According to OpenAI, the organizations in Daybreak Red will have their use closely monitored and supervised, as GPT-5.6-Cyber is significantly more capable in carrying out malicious cyber tasks than Sol. A security evaluation the company devised tested both models on complex requests, including exploit chain development, authentication bypass, privilege escalation and other hacking tasks. Sol succeeded in 1.5% of the requests, while Cyber completed 95%.
OpenAI said it plans to publish a more detailed system card for GPT-5.6-Cyber at a later date.
โModels running with reduced safeguards carry risks beyond standard model usage, whether from misuse or misalignment,โ the company said in a blog. โDespite these risks, we believe that democratizing access to frontier intelligence for defenders is crucial to accelerating and automating cyber defense.โ
Additionally, OpenAI announced a partnership program with 16 major cybersecurity providers, saying organizations could access their models through their existing security services. The partners include IBM, CrowdStrike, Accenture, Ernst & Young, KPMG, Palo Alto Networks, Cisco, Cloudflare, Sophos and others.ย
โThese partners bring deep security expertise and established relationships with organizations around the world,โ OpenAI said in its blog. โBy bringing our frontier cyber models into their services, we can help more defenders find serious vulnerabilities, validate which ones matter, and fix them faster.โ
Companies like OpenAI, Anthropic and others are trying to rebalance their priorities after a string of AI-agent sandbox escapes have rattled policymakers and caused some cybersecurity experts to question if AI companies are doing enough to properly isolate the models from the internet during testing. Last week, OpenAI said it was intentionally slowing down development of its newer โAstraโ model in order to develop better guardrails to restrain its behavior.
Cybersecurity and AI experts have told CyberScoop that while AI systems have greatly improved at finding and exploiting vulnerabilities in software code, they still require substantial human guidance and supporting infrastructure to operate as intended.
Additionally, some research has shown that without such guidance, even near-frontier models can struggle to fully patch a discovered vulnerability or avoid introducing new bugs with their fixes.
The post OpenAI says Daybreak will expand to offer specialized cyber servicesย appeared first on CyberScoop.
NATO and an AI startup can now name and track software vulnerabilities
NATOโs cyber defense arm and a startup that uses artificial intelligence to find software flaws can now issue the ID numbers the industry uses to track those flaws, the European Union Agency for Cybersecurity announced last week.ย
The NATO Cyber Security Centre, part of the NATO Communications and Information Agency, and AISLE, a cybersecurity company with offices in San Francisco and Prague, joined as CVE numbering authorities under the ENISA Root. The CVE program assigns a unique record to each publicly disclosed security flaw so that governments, vendors and researchers have a common marker when referring to particular vulnerabilities.ย
Twenty numbering authorities now sit under the ENISA Root, with 12 brought in by ENISA itself and eight moving over from the MITRE Root, run by the U.S. nonprofit that has handled the programโs daily work for more than 20 years.
Hans de Vries, ENISAโs chief cybersecurity and operations officer, linked the growth to changes in how people find flaws.ย
โRecent developments in the global cybersecurity landscape, coupled with the emergence of Frontier AI models and their impact on vulnerability discovery and exploitation, have underscored the need to build strong vulnerability management infrastructure and capabilities,โ he said in a statement. He said ENISAโs role helps build a โmore globally representative, resilient, and scalable vulnerability identification ecosystem.โ
The two new members show how bespoke each member is within its authority. The NATO Cyber Security Centre can now assign CVE IDs to eligible flaws across the NATO enterprise. The agency said that will make tracking more consistent and let the alliance share information with trusted partners sooner. The center guards NATOโs networks, watches for threats and coordinates the response when incidents hit.
Meanwhile, AISLEโs authorization is narrower. The company said in a July press release that the designation covers vulnerabilities discovered in its own products, allowing it to publish identifiers without waiting for a third-party authority to process a request.ย
Jaya Baloo, the companyโs co-founder, described the step as โfoundationalโ and said coordinated disclosure โstarts with holding your own products to the same standard you expect of everyone else.โ Separately from the designation, the company said its researchers have disclosed hundreds of vulnerabilities in widely used open-source software, including OpenSSL, Linux, Apache and OpenEMR, each coordinated through the relevant authority for that project.
The changes come as the CVE process continues to involve amid program upheaval and the torrent of vulnerabilities discovered by AI systems.ย
The CVE program, run by CISA, narrowly escaped a sudden demise when a last-minute, 11-month contract extension averted a shutdown in April 2025. Since then, several competing databases from European nonprofits and other private entities have been stood up in order to better coordinate how vulnerabilities are tracked, disclosed, and ultimately patched.
Earlier this year, The Computer Incident Response Center Luxembourg (CIRCL) launched the Global CVE Allocation System, or GCVE, as an alternative to the CVE program.
The post NATO and an AI startup can now name and track software vulnerabilities appeared first on CyberScoop.
AI Assistant Hacks Gym Website In First Known Australian Autonomous Cyber Attack
Read more of this story at Slashdot.
DEF CON hackers add new muscle to water utility protection
North Korean spies are running local LLMs to cause AI mischief
Attackers pick Levi's pockets in social engineering attack
Mozilla Issues New Firefox GPG Key Following Exposure
The previous GPG signing subkey was inadvertently added to a GitHub repository and Mozilla decided to revoke it.
The post Mozilla Issues New Firefox GPG Key Following Exposure appeared first on SecurityWeek.
Stealthium Targets Security Blind Spots in AI Accelerators and Neo-Clouds
The startup analyzes subtle telemetry signals to detect attacks that traditional security tools cannot see inside accelerator-powered AI infrastructure.
The post Stealthium Targets Security Blind Spots in AI Accelerators and Neo-Clouds appeared first on SecurityWeek.
-
The Register - Security
- Ransomware gangs skip the CEO, head straight for the 40-something IT manager
Ransomware gangs skip the CEO, head straight for the 40-something IT manager