Normal view

There are new articles available, click to refresh the page.
Today — 11 August 2026Main stream
Before yesterdayMain stream

Azure CTO Pastes Doom Into Paint One Frame At a Time

By: BeauHD
6 August 2026 at 17:00
Microsoft Azure CTO Mark Russinovich used Claude to build a gloriously impractical setup that runs Doom in the background and pastes each rendered frame into Microsoft Paint through the Windows clipboard. The project is referred to as "DoomPaint" or "MS Paint Doom" on GitHub. The Register reports: To be clear, Microsoft Paint isn't doing anything other than serving as a place to paste from the game. [...] ViZDoom runs the Doom .wad file and renders it headlessly. Each frame is passed through the Windows clipboard and pasted onto Paint's canvas. A low-level keyboard hook captures and swallows game inputs while Paint is in the foreground, and sound effects come from the game engine. A glance at the code shows Russinovich was more than happy to use Claude to whip it up. In a LinkedIn post, he said: "I've been using Fable 5 on serious research projects and find it a noticeable improvement over Opus 4.8." Using Microsoft Paint as a display for Doom is not, however, a serious research project, as Russinovich acknowledged. "I've also been having fun with it on frivolous ones," he added, so here we are. "Paint renders the game but does not compute it," said Russinovich. "Paint computes nothing. Paint has never computed anything. That's the joke."

Read more of this story at Slashdot.

The Fourth Battlefield: The Growing Role of Cyber Operations in Global Conflict

5 August 2026 at 09:00

CrowdStrike co-founder Dmitri Alperovitch discusses how cyber operations support kinetic warfare, signal coming conflicts, and reshape the global battlefield.

The post The Fourth Battlefield: The Growing Role of Cyber Operations in Global Conflict appeared first on SecurityWeek.

New York Awards $9 Million to Strengthen Cybersecurity at 153 Water Systems

3 August 2026 at 21:54

The grants will help local governments assess and improve cyber defenses amid a multistate campaign targeting water and wastewater infrastructure.

The post New York Awards $9 Million to Strengthen Cybersecurity at 153 Water Systems appeared first on SecurityWeek.

Trump blames Minnesota for cyberattacks on water sector, drawing pushback from cyber world

31 July 2026 at 16:16

President Donald Trump blamed Minnesota Friday for the cyberattacks its water systems have suffered in recent days, saying the state was “behind it.”

Trump said the state being “incompetent” was the issue, but it wasn’t clear whom he thought actually conducted cyberattacks that U.S. investigators have attributed to Iran — if, perhaps, somehow Minnesota incompetently cyberattacked itself. The White House referred a request for clarification back to Trump’s remarks.

“I think that Minnesota is behind it,” Trump told reporters Friday. “Because they’re grossly incompetent. I don’t think there was an Iranian cyberattack. I think Minnesota ought to get its act together.”

The White House also didn’t clarify whom the president believed was behind similar attacks in other states, when asked for comment. Trump has repeatedly used federal power aggressively in Minnesota, a state led by Gov. Tim Walz, a Democrat who was on the ticket that ran against him in 2024 as the vice presidential nominee. Trump also has downplayed Iranian attacks amid the war he launched against the nation with Israel in February.

A number of cyber experts quickly pushed back on Trump’s comments after he made them.

“Victim blaming in cyber is so 2000 and late,” cybersecurity pioneer Chris Wysopal, Veracode co-founder and chief security evangelist, said on the Bluesky social media platform. Said Jake Williams, a member of the IANS faculty: “His own intelligence services are attributing this to Iran.”

Andy Jabbour — founder and CEO of Gate 15, a cybersecurity firm which provides support to the water sector — told CyberScoop that, “speaking candidly, I’m not even sure what he was actually saying or suggesting Minnesota’s government did or didn’t do.”

“Attribution is tricky business,” he continued, referencing recent alerts from the Cybersecurity and Infrastructure Security Agency and others. “But logically, given an ongoing war with Iran, recent statements made by Iran-aligned threat groups, with assessments that the recent activity is aligned with recent CISA warnings, given yesterday’s statements from CISA and the FBI, random unsubstantiated allegations aimed at political opponents seem reckless and are a disservice to the American people.”

Walz struck back at Trump in a Facebook post, noting steps from his Department of Government Efficiency to slash federal funding. CISA has shrunken considerably under Trump, and his administration has pushed states to defend against cyberattacks that feds once countered.

“Trump knows exactly who is responsible for this attack, and knows that other states were hit too,” Walz said. “This is what modern warfare looks like, and it further illustrates there’s no plan to win a war with Iran.”

“DOGE took an axe to CISA and left the U.S. exposed to cyber attacks,” he continued. “Thankfully, our experts in Minnesota were able to identify the vulnerability quickly and work with local communities to stop it.”

A spokesperson for Minnesota IT Services, a state agency that has been responding to the water cyberattacks, declined to address Trump’s remarks.

“We remain focused on supporting affected communities, securing critical infrastructure and coordinating with local partners and federal officials as the investigation continues,” the spokesperson, Emily Zimmer, told CyberScoop. “We will not comment on political statements or speculate about attribution.”

Other cyber professionals declined to comment directly on Trump’s remarks, but offered thoughts on who was behind the attacks and their motives.

Bryson Bort, CEO and founder of Scythe said the evidence supports the attribution with Iran, and that it looks like hackers there found something they could exploit on the internet and seized the chance.

“This was a target of opportunity,” said Bort, co-founder of the ICS Village, a non-profit advancing awareness of industrial control system security; such systems are common in the water sector. “It wasn’t that Minnesota did something as a state to raise Iran’s ire.”

Cynthia Kaiser, a former top FBI cyber official, said that when the bureau conducts attributions, it looks at technical indicators but also who has the capability, who has conducted similar attacks in the past and what the purpose of the attacks is.

“Iran ticks all these kinds of things,” Kaiser, now senior vice president at cybersecurity firm Halcyon, told CyberScoop. “My view is, if it walks like a duck, if it talks like a duck, I strongly suspect it’s a duck. I’d be shocked if we found out it wasn’t Iran.”

Just last week, CISA updated an advisory about how Iranian hackers were targeting programmable logic controllers in the water sector and other sectors, a warning that the water industry’s information sharing and analysis center said it believed.

“WaterISAC is confident in our government partners’ assessment that the confirmed activity is aligned with the joint Cybersecurity Advisory (CSA) AA26-097A ‘Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across U.S. Critical Infrastructure’ published and recently updated by CISA,” Tom Dobbins, executive director, WaterISAC, told CyberScoop. “We have evidence of earlier attacks from Iran even before this current conflict. Cyber attacks are the most viable way that Iran can directly attack our homeland, and it is logical that they would do so, especially given the challenges of absolute attribution.”

The water sector is often viewed as one of the most vulnerable critical infrastructure sectors, and Dobbins called on Congress to provide funding to provide funding for the ISAC.

Sen. Tina Smith, D-Minn., also took issue with Trump’s comments.

“The President provided an unserious response that is beneath the dignity of the office he holds. Iran’s purported cyberattack on Minnesota’s water infrastructure must be taken as a serious threat to our national security.  Smith said in a statement, adding that she’s been in touch with CISA and the FBI and was grateful to Minnesota’s IT experts. “The entire situation serves as a stark reminder of the danger this war puts us in the longer it drags on.”

Fellow Minnesota Democratic Sen. Amy Klobuchar had earlier been in touch with Sean Cairncross, the national cyber director and a Minnesota native, about the incident.

Trump has previously displayed a laissez-faire view toward other cyberattacks on the United States, such as when he’s been asked about Chinese and Russian cyberattacks and Trump shrugs them off as something America does, too.

He also has cast doubt before on his government officials’ assessments of who’s responsible for cyberattacks on the United States, such as when he asserted China rather than Russia was behind the landmark SolarWinds breach.

Updated 8/3/2026: with comments from Minnesota’s senators.

The post Trump blames Minnesota for cyberattacks on water sector, drawing pushback from cyber world appeared first on CyberScoop.

CISA Urges Water Sector to Protect OT After Coordinated Attacks on PLCs

30 July 2026 at 18:18

CISA is urging water and wastewater utilities to lock down internet-exposed controllers, days after intrusions hit dozens of Minnesota systems.

The post CISA Urges Water Sector to Protect OT After Coordinated Attacks on PLCs appeared first on SecurityWeek.

Microsoft, tech companies throw weight behind spread of open-source AI

By: djohnson
24 July 2026 at 11:22

Microsoft, along with more than two dozen tech companies, are pressing policymakers to support open-source AI systems and code across society, arguing that it will be a safer approach than attempting to restrict access or relying on a handful of closed, proprietary models.

The open letter, posted Friday, draws parallels to the software industry of the 1980s, when large businesses worried that open-source software code would cut into their business. While industry lost that battle, the end result was a vibrant ecosystem that now underpins much of the modern internet, government IT and even commercial software products.

It also created a “shared foundation of knowledge” that has fed countless future software projects and innovations.

“The United States now faces a similar choice with artificial intelligence,” the companies wrote. “Our AI leadership will be judged not by one frontier AI model, but by whether the United States builds a strong, open ecosystem that diffuses into every sector.”

Expanding access and support to open-source AI comes with meaningful security risk. Cybersecurity experts warn that one of the biggest beneficiaries of broadly available AI tools are  low-level criminals who until now lacked the technical expertise or resources to launch serious attacks.

Once a model is open weight, anyone can download it, customize it, strip it of any guardrails and use it for their own purposes. As open-source models have gotten better at creating deepfakes and other AI generated imagery, the danger of locally-customized CSAM and sexualized deepfakes could also grow.

But the letter argues that open-weight AI models are most beneficial to startups, universities, research labs and other small, ambitious organizations that can innovate and iterate the technology and make it more broadly useful to society.

“Open weights let every organization match the right model to the right job at the right cost, reserving frontier-scale capability for genuine frontier problems and running efficient specialized specialized models everywhere else,” The companies wrote. “That discipline is what will make AI economically sustainable as its use scales into the billions of everyday tasks.”

 For cybersecurity specifically, the letter argues that defenders armed with open-source AI will outpace attackers better than any closed model approach.

“In a world where cybersecurity attackers use advanced AI, defenders need access to models with comparable capabilities so they can detect, simulate, and respond to emerging threats,” the companies wrote. “Open models broaden defensive capability, increase transparency, and allow vulnerabilities to be discovered and remediated across many teams.”

Other notable companies signing the letter include Meta, Palantir, Perplexity, Mistral, NVIDIA, Mozilla, The Linux Foundation, Hugging Face, Dell Technologies and IBM.

US policymakers continue to grapple with balancing unrestrained support for the domestic AI industry and providing oversight and regulation of harms that result from their use.

The Trump administration has cycled through several frameworks since coming into office, first a laissez-faire approach within no restrictions, then an executive order creating a voluntary testing regime for industry, then the imposition of export controls on Anthropic’s Fable model and reportedly pressuring OpenAI to delay the release of their models out of cybersecurity concerns.

The letter comes as the Trump administration has reportedly considered an executive order that would restrict American access and availability to Chinese-made open-source models.

But the White House and US companies are trying to thread a needle in recognizing the overall benefits of an open source approach while being wary of doing anything that could potentially benefit their Chinese rivals.

Earlier this month the White House announced the creation of its Gold Eagle AI cybersecurity clearinghouse that would help coordinate government, private sector and civil society work finding and closing AI-discovered vulnerabilities. A big part of that effort, a senior White House official said, is supporting providers and maintainers of open-source AI tools.

The post Microsoft, tech companies throw weight behind spread of open-source AI appeared first on CyberScoop.

Rubio restricts visas for sextortionists, cyber scammers

23 July 2026 at 16:14

The State Department will restrict visas for cybercriminals like scammers to sextortionists, and in some cases even their family members, Secretary of State Marco Rubio said Thursday.

The Trump administration has sought to make a crackdown on foreign-based scams one of the signature issues of his second term. An executive order that the president signed in March indicated that visa restrictions would be on the table as one response.

“By restricting visa issuance to those who are responsible for or complicit in these criminal enterprises, we are sending a clear message: The United States will go after those who prey on our citizens,” Rubio said.

Other departments have also made efforts to reduce foreign-run scams. In June, the Department of Justice seized infrastructure used by subsidiaries of the Huione Group, a Cambodia-based corporate conglomerate tied to one of the world’s most prolific criminal marketplaces used to commit cyber scams and other crimes.

Rubio authorized the visa restrictions under a 1952 law that gives the State Department the ability to deport or rule as inadmissible someone who poses “potentially serious adverse foreign policy consequences.”

Critics have accused the Trump administration of abusing that provision of the law for political purposes.

Rubio’s statement on the visa restrictions mentions “individuals responsible for, or complicit in, cybercrime and cyber-enabled crime, such as those involved in cyberscams, and sextortion.”  Furthermore, he said, “Immediate family members of individuals engaged in such illicit activities may also be subjected to visa restrictions.”

Betsy Cooper, Founding Director of the Aspen Policy Academy, said the visa restrictions on cybercriminals could be valuable, but offered a caveat.

“Scamming people is a growing global enterprise, and it is a laudable goal to penalize those who scam and defraud people since they so rarely suffer consequences for their actions,” she said in a statement to CyberScoop. “So long as the new visa controls are used narrowly and deployed only against verified scammers and fraudsters, this is a positive step toward combatting cyber-enabled crime.”

While some cyber experts have questioned how much visa restrictions, prosecutions and other punishments of cyber miscreants who are based overseas will affect them, others maintain that it can serve as a deterrent to those who would consider getting into the line of work but want freedom to travel the globe.

FightCyberCrime.org, a nonprofit that seeks to help cybercrime victims, applauded the restrictions on the cybercriminals.

“We welcome efforts to hold cybercriminals accountable across borders. Cryptocurrency investment scams, romance scams, and sextortion cause devastating financial and emotional harm to victims,” it said in a statement to CyberScoop. “Meaningful disruption of these transnational criminal networks is an essential part of the response.”

But there’s still a long way to go in the fight, the statement continued.

“At the same time, we must invest more in victim support, prevention, and recovery resources,” the organization said. “Accountability is critical, but ensuring victims have access to trauma-informed support and resources is equally important.”

The post Rubio restricts visas for sextortionists, cyber scammers appeared first on CyberScoop.

Russian espionage group using novel Zimbra exploit to steal sensitive data from Western countries

23 July 2026 at 13:33

A Russian state-sponsored threat group has been stealing sensitive data from governments and commercial organizations since July 2025 via a novel exploit in popular Linux-based enterprise software, U.S. authorities and cyber officials from more than a dozen other countries warned in a joint cybersecurity advisory Thursday.

Laundry Bear’s most recent espionage campaign involves the exploitation of a zero-day vulnerability in Zimbra Collaboration Suite that wasn’t patched until November 2025, five months after attacks were well underway, officials said. 

The exploit just requires a view — no clicks — and allows attackers to steal the previous 90 days’ worth of email, the account’s password, search history, the victim organization’s email directory, two-factor authentication tokens and other newly created passwords.

“The covert and persistent nature of this activity, along with the absence of any known financial extortion, almost certainly indicates this group’s involvement in espionage activities with Russian government backing,” officials wrote in the advisory. 

“Additionally, extensive Ukrainian targeting, prior to use against U.S. and other NATO allies, outlines an increasing trend within Russian cyber threat groups to target Ukrainian users first—both as a priority target and as a testbench for malicious cyber techniques before broader global deployment.”

The state-sponsored espionage group, also known as Void Blizzard, has compromised governments and organizations in the defense, education, energy, law enforcement, media, finance, transportation and technology sectors. 

Laundry Bear’s year-long campaign involving the exploitation of CVE-2025-66376 showcases more technical capabilities, including a custom JavaScript payload it delivers to targeted victims via phishing emails. The threat group could also likely adapt the novel data exfiltration and aggregation capability, dubbed “beehive,” to exploit other vulnerabilities, officials warned.

The defect’s medium-severity rating of 6.1 underscores the challenge defenders regularly confront in prioritizing patching schedules based on measure of severity alone.

The Russian state-supported group, which has been active since at least 2024, is still actively exploiting Zimbra Collaboration Suite instances that remain unpatched, officials said.

Authorities shared Thursday indicators of compromise, mitigation steps and urged organizations to update their vulnerable software.

“This campaign’s targeted victimology and limited exploitation capabilities likely indicate this group manually identifies and targets the victim organizations” by identifying organizations with public-facing infrastructure, officials wrote in the advisory.

Once a target is identified, Laundry Bear also likely compiles email addresses for users to target with the exploit via phishing emails. Officials did not identify specific victims or describe the volume of organizations already compromised.

The joint cybersecurity advisory was issued by the United States, Australia, Canada, New Zealand, the United Kingdom, Czech Republic, Denmark, Estonia, Finland, France, Italy, Moldova, the Netherlands, Poland, Spain and Sweden.

The post Russian espionage group using novel Zimbra exploit to steal sensitive data from Western countries appeared first on CyberScoop.

White House accuses Chinese company of distilling Anthropic’s Fable

By: djohnson
22 July 2026 at 12:45

A top White House technology official is accusing a Chinese company of distilling Anthropic’s models to create their own AI product.

Michael Kratsios, who leads the White House Office of Science and Technology Policy, claimed that Moonshot AI, a Beijing, China-based AI company, had distilled Anthropic’s recently-released Fable model to develop its own K3 model.

“To do this they developed a sophisticated internal platform to conduct large scale distillation against U.S. models, allowing them to quickly switch between multiple methods of access to avoid detection,” Kratsios wrote on X Wednesday.

Kratsios also said the company has used GB300 servers – either newly acquired or through Thailand – to train its AI models.

“The United States strongly supports the free and fair development of AI, including a thriving competitive ecosystem that spans frontier models, specialized systems, open-source frameworks, and open-weight models,” Kratsios continued. “Legitimate AI distillation used to create smaller, more efficient models plays a vital role in this open innovation ecosystem. However, large-scale, covert industrial distillation aimed at stealing proprietary U.S. technology and undermining American research is unacceptable.”

Kratsios did not provide details on how the U.S. government learned that K3 had been distilled from Anthropic’s model. 

Frontier AI companies in the U.S. have pressed policymakers to make it more difficult for third-parties to copy or duplicate advanced commercial models, calling it a form of intellectual property theft.

On their website, Moonshot AI describes its Kimi K3 model as the first open 2.8 trillion parameter model, and promotes its lower token costs while still delivering near-frontier performance. 

“While its overall performance still trails the most powerful proprietary models, Claude Fable 5 and GPT 5.6 Sol, Kimi K3 demonstrated frontier-level performance across our evaluation suite, consistently outperforming other tested models,” the company said on its website. 

A request for comment sent to Moonshot AI was not returned before this article’s publication. 

Piyush Sharma, CEO of Tuskira, an AI cybersecurity detection and response company, said distillation of AI models allows developers many of a model’s core capabilities. He pointed to another example when Anthropic earlier this year accused Chinese company Alibaba of distilling their Claude AI model.

According to Anthropic, the campaign used 25,000 fraudulent accounts to run 28.8 million interactions on Claude over six weeks. Given that kind of volume “the goal was clearly replication,” he said. 

“When a model has learned to reason through software weaknesses, security gaps, and attack paths, copying its behavior also copies that analytical capability,” said Sharma.

In April, Rep. Andrew Garbarino, R-N.Y., who chairs the House Homeland Security Committee and Rep. John Moolenaar, R-Mich., Chair of the Select Committee on China, announced they were conducting a joint investigation into the integration of Chinese AI models.

The committees said the inquiry will also focus on “examining a pattern of conduct by [Chinese]-based AI laboratories involving the large-scale theft of proprietary capabilities from American frontier AI systems through adversarial distillation” as well as “ the redistribution of those stolen capabilities as open-weight models available for global download, and the incorporation of PRC-origin models into products used daily by hundreds of thousands of American developers and engineers.”

Western governments and industry accuse Chinese companies of routinely stealing their technology, intellectual property and other trade secrets, often with the tacit support of Beijing. The copying of AI models would continue a long and established tradition of Chinese-sponsored intellectual property theft.

However, while distillation attacks by foreign governments or companies on U.S. frontier companies can have real national security implications, it’s still a fraught question of where policymakers should draw the line.

The AI industry, which includes not just frontier companies but large businesses with their own bespoke models, smaller proprietary startups and a vibrant open-source ecosystem, routinely share and use third-party data, including critical code and training sets for AI models.

Further, U.S. frontier AI companies have built and trained their world leading models in large part by crawling the open internet, ingesting content created and produced by others. Critics (and multiple ongoing lawsuits) argue that AI companies like OpenAI and Anthropic built their empires on data and content from others, taken almost entirely without consent or compensation.

The post White House accuses Chinese company of distilling Anthropic’s Fable appeared first on CyberScoop.

Where’s the Trump administration line on AI regulation?

By: djohnson
21 July 2026 at 14:33

After a year and a half spent downplaying calls for AI safety regulations, the Trump administration has sharply reversed course, embracing a level of government scrutiny of frontier AI systems before public release–a far stricter stance than the Biden administration took.

An executive order designed to be friendly to the AI industry was meant to let the federal government briefly review some new models on a voluntary basis.

When the Trump administration, suddenly and without much warning, slapped export controls on Anthropic’s Fable 5 and Mythos 5 in response to private sector threat intelligence reporting, the U.S. AI industry officially entered its regulatory era.

But key questions and gaps remain. It’s not clear why the administration drew the line where it did, or whether they will move it again in the future.

While newer models like Mythos and OpenAI’s Daybreak do have stronger cybersecurity capabilities, the private sector reports the administration relied on describe capabilities already available in older commercial, open-source and Chinese models that nearly anyone can access.

CyberScoop spoke with current users of the latest frontier models, including OpenAI’s ChatGPT 5.5 and Fable 5, to learn more about what these models are currently capable of in offensive and defensive cybersecurity.

Cybersecurity experts and former government officials say the administration may be playing catch up on threats that have been building for years as it has more fully realized the national security implications of the technology.

Are the models breaking new ground or just breaking things? 

Users of Chat GPT 5.5, introduced this past April, and Fable 5 tell CyberScoop those models have been largely helpful to their work, even as they complained about high token usage and safety guardrails that hinder,  but don’t meaningfully prevent, defensive cyber tasks.

Eyal Webber Zvik, chief strategy officer at Cato Networks, a cloud and cybersecurity network provider in OpenAI’s Trusted Access in Cyber program, said they use GPT 5.5 and later OpenAI models to scan and triage internal codebases for vulnerabilities, test new safeguards and provide “highly autonomized service” to their customers.

Zvik wouldn’t disclose how many bugs 5.5 has found but said the company’s view is that it helps both find bugs that humans missed and rank which ones to patch based on factors like each bug’s exploitability.

“It is now a native part of our development environment and cycles, and we use those models to scale our entire codebase and make sure what we release into the service that our customers use to run their networks and network security has the least likelihood of having any vulnerabilities that can be exploited,” said Zvik.

John Hopper, vice president of engineering at SpecterOps, an identity security company, said newer models like GPT 5.5 are sharper and more persistent in pursuing their tasks.

“That can be a good or bad thing,” he noted.

One metric that SpecterOps tracks is how long it can keep a particular agent working before it moves off task or fails. That metric “matters a lot” because the longer an agent works without human help , the more agents a single operator can run at once.

Hopper said this provides defenders with immense value, and pushed back on the idea that the offensive capabilities the models offer are automatically more beneficial to malicious hackers. There is “a modicum of grounding that the industry needs when we talk about these models.”

“Yes, AI frontier tools will lower the barrier of entry, but these problems have always existed,” he said. “I don’t actually believe that AI is going to remove the needle in the haystack problem, but by howdy, using my two hands to find that damn needle, compared to using a backhoe, I can tell you which one I’d rather be driving.”

Eran Kinsbruner, vice president of product marketing at software security firm Checkmarx, told CyberScoop that later models like OpenAI’s Codex Security and GPT 5.5 are noticeably easier to set up and run with local systems, even for less technical users. That alone gives them an edge over many cybersecurity tools where interoperability is a constant concern.

However, GPT 5.5 burns through tokens at a much faster rate. He recalled one instance of using it to scan a medium-sized repository in three different programming languages.

“After 26 minutes I almost ran out of tokens, and it didn’t provide anything, just created a threat model for me and told me you want to buy more tokens?” he said.

In other instances, some of the scan results he received were not comprehensive.

Further, he expressed frustration with some of the guardrails designed to prevent risk – like only allowing users to scan local files but not code repositories like GitHub – “makes not too much sense” given how often developers must work with remote code.

Those kinds of guardrails – which can prevent models or developers from injecting malicious code or prompting into their models – sit at the heart of the debate in Washington D.C. and around the world. Some users feel differently about their utility.

Kinsbruner said that doesn’t make sense for organizations like his, which work with thousands of different enterprise organizations with  thousands of different code repositories spread across the internet.

“I cannot imagine how large-scale developers could just jump into this solution and make it an enterprise-grade, enterprise-level, de facto cybersecurity solution” out of it, said Kinsbruner.

OpenAI did not respond to a request from CyberScoop for an interview on GPT 5.5. The company has since released another model, GPT 5.6, that they said is more efficient at token use.

The White House’s crash course in AI cyber risk 

 The White House keeps changing its line on whether and how the U.S. government should limit the release of commercial frontier models. The shift comes from lessons learned since coming into office in Jan. 2025. Trump threw out Biden-era regulations meant to steer the industry toward safer models. Top officials like Vice President JD Vance argued against restricting industry progress.

Less than two years later, administration officials worry about the impact of speed and scale – two things AI excels at – in cyberspace.

According to Will Loucks, senior director of intelligence at the Office of the National Cyber Director, over the past two years the number of exposed and known vulnerabilities has shot up. Threat actors exploit those flaws faster before defenders can fix them. Once inside, the time from initial access to full network control shrinks.

“So in other words, every stage of the cyber operations lifecycle that a threat actor has to move through to get to a victim network and achieve an outcome, they’re just moving through more quickly faster,” said Loucks at a July 16 event in Washington D.C.

Speaking about AI in particular, Loucks said one of the defining characteristics of the technology is its ability to lower barriers for threat actors.

“Sometimes speed and volume have a threatening aspect alone, even if sophistication isn’t quite increasing in the same way, and the reason for that is because it places pressure on defenders…to triage alerts more quickly,” he said.

Jordan Rae Kelly, former director for cyber and incident response on the White House’s National Security Council during Trump’s first term, told CyberScoop that the changes over the past two years reflect the lessons the White House has learned on the issue since returning to office.

In the early days of this administration, Kelly said, “there is a sense and a spirit that the Biden administration was limiting AI and there was a kind of a rip-it-all-off [attitude], everybody go and do whatever, we will be the biggest and boldest and brightest.”

“I love that talking point, but I think what you’ve seen is probably an education over the last 19 months, where people [in the White House] have said that’s a challenging premise to put into place, knowing about the potential downsides and capabilities,” she added.

Michael Daniel, former White House cyber coordinator under President Barack Obama, thinks the horse may already be out of the barn.

Daniel, now head of the Cyber Threat Alliance, a membership nonprofit group focused on cyber threat information sharing between industry and government, said his members report that AI is being used to do things “faster and at a slightly bigger scale” but aren’t yet seeing the flood of exploitation that analysts have warned about. Not yet.

“I think what we’re seeing right now [and] talking about is ‘okay, where are the step changes [in the cyber threat landscape] actually going to occur?” said Daniel. “Are we and when will we see the explosion in vulnerability reporting from these Mythos-like capabilities? That’s what’s really got their attention right now.”

But Mythos and OpenAI’s Daybreak models are restricted to select organizations, and neither has publicly released its most powerful cybersecurity models to the public. That dynamic won’t last.

The UK’s AI Security Institute estimates that open source and foreign LLM models are between 4-7 months behind frontier U.S. models. In that setting, it’s hard to stop the development of AI models worldwide through export controls or other limits.

“It’s not like we’re buying ourselves five to ten years on this,” he said. “We’re not, and so I’m not sure the impact on the defenders who are trying to obey the law is worth whatever small hiccup we cause for our adversaries.”

Kelly said there’s merit to the administration’s current position, even if it took time to get there. Many federal cybersecurity procedures that operated even a decade ago – such as a Vulnerabilities Equities Process that could take days or weeks to consider the pros and cons of keeping an exploit – are no longer practical.

“All of that work to some degree, is out the window, because you can’t meet with the regularity you would need to meet to adjudicate vulnerabilities that are being found in seconds and exploited in minutes,” said Kelly.

But Kelly and others say that’s also because AI capabilities in cybersecurity are developing faster than policymakers can react, even in the best of times.

Key questions remain and the administration’s balance between national security and backing domestic industry will likely shift  in response to new events.  The administration wants a framework that can predict and manage the risks of AI models today and tomorrow. That may be harder than it sounds.

“Do I think they’ve been clear? No,” said Kelly. “But I think it’s a place where clarity is really hard to achieve.”

The post Where’s the Trump administration line on AI regulation? appeared first on CyberScoop.

North Korea’s IT worker scheme funds Russia’s war effort

21 July 2026 at 12:00

The people orchestrating North Korea’s IT worker scheme are funneling money through a web of front companies and intermediaries, including sanctioned entities, that partly fund Russia’s war effort against Ukraine, DTEX said in a report Tuesday.

The security firm’s research shows that the scheme is moving beyond funding the country’s weapons program and into a bigger pool that supports many of the regime’s objectives. This includes manufacturing weapons and supplying them to Russia’s military, according to DTEX.

“When we think IT workers, we typically think head down, get your money, support the weapons program,” Michael Barnhart, nation state investigator at DTEX and lead author of the report, told CyberScoop.

“It’s a broad cover-all statement when we say it’s supplying the weapons program,” he said. “That’s the predominant place it goes,” but many other domestic programs and entities tasked with other projects are taking cuts from that pool of money as well. 

Barnhart corroborated previously leaked data from an internal North Korean payment server, which included 390 IT worker accounts, chat logs and transaction data.

He mapped the transactions to organizations that received those funds, including multiple sanctioned entities: Sobaeksu, Saenal, and Songkwang. 

The money trail also showed $1.97 million in payments from North Korean IT workers between December 2025 and February 2026 flowing directly through Korea Ryonbong General Corp, a sanctioned defense entity that procures weapons for the regime’s military programs.

Western officials previously reported that North Korea provided ammunition and weapons to Russia in 2023, and in the fall of 2024 sent upwards of 15,000 soldiers to fight alongside Russian troops, according to the Council on Foreign Relations.

“This is a consequence that is often overlooked,” Barnhart wrote in the report. “Revenue from the IT worker stream does not stop at a resume scam or a payroll-abuse story. It can feed a larger DPRK system that supports sanctioned entities, domestic state needs, and a Russia war effort that is actively consuming all facets of North Korean weapons and military support.” 

Data from the internal North Korean payment server, which was first published by ZachXBT in April, is controlled by “PC-1234,” a single administrator that DTEX has been tracking for a while. The wallet and its cluster of activity remains active, Barnhart said. 

The three months of previous activity attributed to the wallet amounted to more than $2.84 million, which then flowed upward into dozens of organizations. 

“It’s not a top-down funded regime. It’s a bottom-up,” Barnhart said. “Everyone makes money at the bottom and then they take a tiny cut, and then the money goes upwards to what we just blanketly say is the weapons program. But really, it can go a lot more places.”

The post North Korea’s IT worker scheme funds Russia’s war effort appeared first on CyberScoop.

SecurityWeek Launches Critical Impact Awards to Recognize Excellence in Industrial Cybersecurity

21 July 2026 at 08:30

Independently judged and sponsor-neutral, the new awards program honors the people, organizations, and technologies delivering proven impact in industrial cybersecurity; winners to be announced live at the 2026 ICS Cybersecurity Conference in Nashville

The post SecurityWeek Launches Critical Impact Awards to Recognize Excellence in Industrial Cybersecurity appeared first on SecurityWeek.

❌
❌