Normal view

There are new articles available, click to refresh the page.
Today — 26 June 2026Main stream

I'm an Xbox Series X owner, and these are the games that are keeping me coming back right now

If you're an Xbox One or Xbox Series X owner, then the Amazon Prime Day deals represent the perfect time to stock up on new games.

I test the console extensively whenever I'm experimenting with new Xbox accessories as part of my job here at TechRadar Gaming, so I have a strong handle on the best titles on offer.

View all of Amazon's current prices and deals on Xbox games this Prime Day

Below you will find a selection of games that I recommend, spanning all the way from massive adventures like Crimson Desert to recent spy thriller 007 First Light. These are the releases that I'm spending the most time in right now, so I can personally vouch for the quality of each one.

Amazon Prime Day game deals

Amazon Prime Day – the best Xbox games I'd buy right now

Like a Dragon: Infinite Wealth - Xbox Series X

Like a Dragon: Infinite Wealth

Metal Gear Solid Δ: Snake Eater Tactical Edition – Xsx

Metal Gear Solid Delta: Snake Eater Tactical Edition

Alan Wake 2 Deluxe Edition - Xbox

Alan Wake 2 Deluxe Edition

John Carpenter's Toxic Commando - Xbox Series X

John Carpenter's Toxic Commando

Call of Duty: Black Ops 7 | Cross-Gen Bundle | Xbox Series X and Xbox One

Call of Duty: Black Ops 7

Borderlands 4 - Xbox Series X

Borderlands 4

Warhammer 40,000: Space Marine 2 - Xbox Series X

Warhammer 40,000: Space Marine 2

007 First Light - Specialist Edition - Xbox Series X

007 First Light - Specialist Edition

Crimson Desert: Standard Edition - Xbox Series X

=
Crimson Desert

More Prime Day deals in the US

FCC passes new cybersecurity rules for emergency systems, undersea cables

By: djohnson
25 June 2026 at 15:55

The Federal Communications Commission approved new rules Thursday that boost cybersecurity regulations for the nation’s emergency alert systems and update security rules for the nation’s undersea cables.

The new rule would overhaul two national emergency systems, the Emergency Alert System and Wireless Emergency Alerts, to better protect against hijacking attacks from malicious actors.

The EAS is a national public warning system that state and local authorities use to disseminate information related to weather events, AMBER alerts and other emergencies via radio and television broadcasting stations. The WEA handles much of the same messaging via text.

A compromise of either system by a foreign government, cybercriminal group or other rogue actor could be used to sow chaos and disinformation in calmer times, or impede coordination efforts in the face of a genuine emergency. Any vulnerability in systems like the Emergency Alert System “can have serious consequences,” said FCC Commissioner Olivia Trusty in a statement after the vote.

“That is why it has been appropriate for the Commission to conduct a comprehensive review of the EAS framework by focusing on the security of the system itself,” Trusty continued. “As cybersecurity threats continue to evolve, EAS participants must take appropriate steps to safeguard the infrastructure that supports the delivery of life-saving alerts.”

The new rules amount to basic – but still critical – cyber hygiene practices for users accessing and updating the EAS and WEA systems. They must use strong passwords, quickly install security patches from vendors and use firewalls to limit access to their equipment.

The rule also creates a new authentication ID system to verify alerts before they’re submitted and avoid duplicate or unauthorized alerts from spreading.

Another rule passed by the Commission Thursday provided the first comprehensive update to the FCC’s submarine cable regulations in decades, and moves to tighten cybersecurity requirements in some areas while loosening them in others.

It exempts some undersea cable providers from submitting to stringent national security licensing reviews needed to land and operate cables that touch U.S. territory.

The review, called “Team Telecom,” is an interagency body led by the Department of Justice’s Foreign Investment Review Section and other federal agencies that advise the FCC on the national security implications of their telecom policies.

The new rules would presumptively exempt applications for undersea cable licensees when the provider can self-certify to “high security standards” that are “structured to increase certainty, predictability, and faster timelines for the licensing process.”

“Currently, all submarine cable applications get referred to Team Telecom…the changes adopted would exempt applications from applicants that have operated cables without incident, can certify to the highest national security standards, and agree to ongoing oversight and monitoring,” the FCC said in a release.

Other parts of the rule give the FCC greater oversight of critical functions within undersea cable operations. Owners and operators of submarine line terminal equipment, who connect submarine cables to land-based facilities in the U.S., will be subject to a new licensing requirement.

The rule also moves to update safeguards meant to address vulnerabilities related to principal equipment, third-party service providers, and other areas of concern in the undersea cable supply chain.

The post FCC passes new cybersecurity rules for emergency systems, undersea cables appeared first on CyberScoop.

Yesterday — 25 June 2026Main stream

These are the Nintendo Switch 2 games I've spent my hundreds of hours with the console playing so far

I've been using the Nintendo Switch 2 since its launch week, playing practically every title released for the platform either as part of my work covering games here at TechRadar Gaming or my own personal enjoyment.

I've spent hours in everything from big new entries in first-party franchises like Mario Tennis Fever and Mario Kart World to groundbreaking ports such as Cyberpunk 2077 Ultimate Edition. I'm not just playing the big hitters either, and have invested loads of time in getting to grips with underrated gems including Kunitsu-Gami: Path of the Goddess and Raidou Remastered: The Mystery of the Soulless Army.

View all of Amazon's current prices and deals on Nintendo Switch 2 games this Prime Day

While many of these games will be discounted over the course of the ongoing Amazon Prime Day deals, every title that I've included is well worth your time and attention regardless of its price.

Amazon Prime Day game deals

Amazon Prime Day – the best Nintendo Switch 2 games I'd buy right now

Sonic X Shadow Generations - Nintendo Switch 2

Sonic X Shadow Generations

Yakuza 0: Director’s Cut - Nintendo Switch 2

Yakuza 0: Director’s Cut

Star Wars Outlaws - Gold Edition, Nintendo Switch 2

Star Wars Outlaws - Gold Edition

Fatal Frame Ii: Crimson Butterfly Remake - Nintendo Switch 2

Fatal Frame 2: Crimson Butterfly Remake

Fallout 4 | Anniversary Edition | Nintendo Switch 2 [code in Box]

Xbox
Fallout 4 Anniversary Edition (Code in Box)

Cyberpunk 2077: Ultimate Edition- Nintendo Switch 2

Cyberpunk 2077: Ultimate Edition

Street Fighter™ 6 Year 1-2 Fighters Edition

Street Fighter 6 Year 1-2 Fighters Edition

Mario Tennis™ Fever (nintendo Switch 2)

Mario Tennis Fever

Donkey Kong Bananza (nintendo Switch 2)

Donkey Kong Bananza

Mario Kart™ World (nintendo Switch 2)

Mario Kart World

Resident Evil Generation Pack - Nintendo Switch 2

Resident Evil Generation Pack (Requiem, Village, and 7)

Pragmata - Nintendo Switch 2

Pragmata

More Prime Day deals in the US

GTA 6 UK pre-orders are live, and we finally have a price — here's where you can order it, and what it costs

If you've been following our GTA 6 pre-order live updates, you'll know that pre-orders now finally live in the UK for the new game.

Not only can you get your order in, including for the GTA 6 Ultimate Edition with all of its extras over the standard edition, but this has also finally revealed to us what the UK price actually is — Rockstar only revealed the US prices when it announced the pre-order time.

So now we know that GTA 6 will cost £69.99 for the Standard Edition, and £89.99 for the Ultimate Edition — we're in a brave new world of video game prices here, folks.

And don't forget, if you buy the 'physical' version of it, you're not getting a disc in the box. It's just for show on your shelf.

We're updating this page as different retailers start showing their pre-order pages — here's a quick list of search page links for now, but we'll put solid links in as they appear.

Confirmed pre-orders

Links for other retailers — pre-orders not confirmed yet

In a first, a court takedown goes after two cybercrime tools at once

24 June 2026 at 08:30

In a novel maneuver for a disruption operation against cyber attackers, industry and law enforcement teamed up to conduct a court takedown of two widely-used criminal tools at once rather than individually, Microsoft said Tuesday.

The takedown simultaneously went after Amadey, a botnet that can serve as a malware delivery system, and StealC, an infostealer. Cybercriminals often use them in conjunction and they rely on the same infrastructure, Microsoft said.

“When multiple parts of an operation are disrupted together, attacks are harder to launch, scale, and recover from,” said Steven Masada, assistant general counsel for Microsoft’s Digital Crimes Unit. “The result: fewer disrupted services, fewer opportunities for cybercriminals to profit, and more friction when they try to rebuild. It’s no longer enough to go after threats one by one. We need to interrupt how the attacks are put together.”

Microsoft had been tracking Amadey with ESET, BitSight, Lumen and Mitsui Bussan Secure Directions. Meanwhile, Europol had been investigating StealC alongside law enforcement partners including Germany’s Federal Criminal Police Office and the Dutch and Danish National Police as well as IBM X-Force and Proofpoint.

They then joined forces and turned to the Racketeer Influenced and Corrupt Organizations (RICO) Act, used to help authorities go after organized crime, to disrupt more than 200 command-and-control servers. Microsoft said it gained insights from its artificial intelligence product Copilot that “allowed the legal team to treat both malware families as part of a single criminal conspiracy.”

Microsoft regularly leads court-authorized disruption operations, but the industry and law enforcement partnerships combined with AI to expand data collection and identify connections beyond what one company could normally do, it said.

Amadey and StealC were linked to more than 140,000 infected computers around the globe in the first week of May alone, the company said. StealC has ranked among the top infostealers for years since its emergence in 2023 and sells in underground forums as a malware-as-a-service. It’s typically used by Russia-linked groups.

Amadey dates back to 2018, and is also commonly employed by Russian groups, including in attacks on Ukraine.

Their interaction shows the assembly line-like structure of modern cybercrime, Microsoft said. Even if the cybercriminals behind both tools never coordinate, their tools are designed to work together, it said.

“StealC is an infostealer that collects sensitive data from browsers, cryptocurrency wallets, messaging applications, email clients, and gaming platforms,” the company wrote in a separate blog post. “It is a malware-as-a-service (MaaS) offering that threat actors use to generate customized payloads and manage stolen data through a centralized web panel. Meanwhile, Amadey is a MaaS loader that threat actors use to deliver StealC and other malware. Modular, pay-as-you-go models like StealC and Amadey allow threat actors to use a single initial infection to quickly escalate into multiple other threats.”

The post In a first, a court takedown goes after two cybercrime tools at once appeared first on CyberScoop.

Before yesterdayMain stream

Scattered Spider Hackers Plead Guilty on Day 1 of Trial

23 June 2026 at 12:12

Two men pleaded guilty in the United Kingdom this week to criminal charges stemming from an August 2024 cyberattack that crippled Transport for London, the entity responsible for the public transport network in the Greater London area. The duo were key members of a prolific cybercrime group known as Scattered Spider, and their guilty pleas came on the first day of what was expected to be a six-week trial.

Owen Flowers (left) 18, and Thalha Jubair, 20. Image: UK National Crime Agency (NCA).

Thalha Jubair, 20, of East London and 18-year-old Owen Flowers of Walsall admitted conspiring to commit unauthorized acts against Transport for London computer systems and causing risk of serious damage to human welfare. According to a report from the BBC, Flowers alone admitted to being part of a conspiracy to hack into U.S. based healthcare providers SSM Health Care Corporation and Sutter Health in September 2024.

Jubair is also wanted by U.S. law enforcement agencies. In September 2025, prosecutors in New Jersey unsealed an indictment alleging Jubair and other Scattered Spider members committed computer fraud, wire fraud, and money laundering in relation to 120 computer network intrusions involving 47 U.S. entities between May 2022 and September 2025, and that the group’s victims paid at least $115 million in ransom payments.

In July 2025, KrebsOnSecurity reported that Flowers and Jubair were arrested in the United Kingdom in connection with Scattered Spider ransom attacks against the retailers Marks & Spencer and Harrods, and the British food retailer Co-op Group. Multiple sources familiar with those investigations said Flowers was the Scattered Spider member who anonymously gave interviews to the media in the days after the group’s September 2023 ransomware attacks disrupted operations at Las Vegas casinos operated by MGM Resorts and Caesars Entertainment.

According to prosecutors, Jubair co-ran a bustling Telegram channel called Star Chat, the home of a SIM-swapping group that used voice- and SMS-based phishing attacks to steal credentials from employees at the major wireless providers in the U.S. and U.K. The group would then use that access to sell a service that could redirect a target’s phone number to a device the attackers controlled and intercept the victim’s calls and text messages (including one-time codes for multi-factor authentication).

A receipt from Star Fraud Chat’s SIM-swapping service targeting a T-Mobile customer after the group gained access to internal T-Mobile employee tools. “Rocket Ace” was one of Jubair’s hacker handles, according to U.S. prosecutors.

New Jersey prosecutors also allege Jubair also was involved in a mass SMS phishing campaign during the summer of 2022 that stole single sign-on credentials from employees at hundreds of companies. That weeks-long SMS phishing campaign led to intrusions and data thefts at more than 130 organizations, including LastPassDoorDashMailchimpPlex and Signal.

KrebsOnSecurity reported last year that one of Jubair’s alter egos at age 15 was “Everlynn,” a hacker who sold fraudulent “emergency data requests” that used compromised police and government email addresses to demand subscriber data (e.g. username, IP/email address) from major tech companies, claiming the requests concerned urgent matters of life and death and could not wait for a court order.

In April 2026, 24-year-old British national and Scattered Spider member Tyler “Tylerb” Buchanan pleaded guilty to wire fraud conspiracy and aggravated identity theft for participating in the group’s SMS phishing spree in the summer of 2022. The government said Buchanan, Jubair and others used the credentials harvested in that phishing campaign to steal at least $8 million in cryptocurrency from victims throughout the United States. Buchanan is currently scheduled to be sentenced on October 2.

In August 2025, 20-year-old Scattered Spider member from Florida named Noah Michael Urban was sentenced to 10 years in federal prison and ordered to pay $13 million in restitution, after pleading guilty to charges of wire fraud and conspiracy.

The U.S. Department of Justice says three alleged Scattered Spider defendants indicted along with Buchanan still face charges, including Ahmed Hossam Eldin Elbadawy, 24, a.k.a. “AD,” of College Station, Texas; Evans Onyeaka Osiebo, 21, of Dallas, Texas; and Joel Martin Evans, 26, a.k.a. “joeleoli,” of Jacksonville, North Carolina.

Flowers and Jubair are slated to be sentenced in a London court on July 15, 2026.

This may be the only way to beat potentially high GTA 6 prices once pre-orders are live on Thursday

In case you missed it, Rockstar Games has finally announced that GTA 6 pre-orders will go live on Thursday, 25th June, which has opened the floodgates of excitement and relief, as the feared potential delays have now been put to bed.

However, there's one major factor that we'll have to wait to find out on the very day, and that's how much GTA 6 will cost for PS5, Xbox Series X, and Xbox Series S. Rumors based on recent Portuguese retailer listings suggest we could see a potential £80 / $100 price tag for the standard edition, but there's still no confirmation.

At the very least, we can predict that Rockstar's blockbuster title will hit the £70 region. Regardless, there's bound to be an influx of console users looking for the best way to save on gaming's biggest event in 2026 — and if you're a PS5 user, you're in luck.

PlayStation gift cards in front of GTA 6 background

(Image credit: Rockstar / PlayStation)

The £70 PlayStation Store gift card gives users access to a choice of one among a huge catalog of PlayStation's first-party exclusives and other third-party games, and serves as a bargain leading into GTA 6's pre-order day.View Deal

Fortunately, the £70 PlayStation Store gift card is available on ShopTo for £60.85 (was £70), thanks to a significant 13% discount. Effectively, you'll be paying the previous standard £59.99 price model for £70 games — and in this case, you'll save a significant amount on GTA 6.

If Rockstar matches Nintendo's £79.99 price standard, the £10 PlayStation Store gift card, available for £9.85 (was £10), will come in handy for buyers. Luckily, all gift cards are discounted at ShopTo, and better yet, ShopTo users with 'Gold' or 'Silver' memberships can get further discounts at checkout.

It's worth taking a gamble now with securing the wallet funds, as discounted gift cards at multiple retailers like ShopTo are likely going to skyrocket in demand, so now may be the last chance to secure your GTA 6 purchase at the lowest possible price.

Prime Day deals in the UK

This Prime Day might be your last chance to secure a discounted PS5 before GTA 6 pre-orders begin

If you were looking to get your hands on a PlayStation 5 ahead of the Grand Theft Auto 6 pre-order date this week, then this Amazon Prime Day deal is for you. Right now you can grab the console at a 16% discount over at Amazon, which takes its price down to just £479 (was £569.99).

Browse the full Amazon Prime Day sale

It's not the cheapest PS5 we've ever seen, but with the recent price rises it's likely going to the lowest it's available for some time. This is the Slim 1TB version of the console as well, with a disc reader fitted so you can buy the physical version of GTA 6 to keep on your shelf.

The deal is only on for a limited time, and stock is already flying off the shelves - with just under half of the available units sold already. This is a deal I'd recommend snapping up quick!

Today's best PS5 deal

A chunky discount on the PS5 Slim here, with 1TB storage and the disc reader attachment included out of the box. With recent price hikes, this is likely the cheapest the console will be ahead of GTA 6 pre-orders.View Deal

More Prime Day deals in the UK

I can’t put my Asus ROG Xbox Ally X down, and these are the accessories I’m looking to upgrade it with on Prime Day

I love my Asus ROG Xbox Ally X, especially when using it with some smart glasses like my RayNeo Air 4 Pros. However, I know that the setup I have could be better.

So this Amazon Prime Day, I’m looking to enhance my PC handheld gaming experience with a bunch of accessories, including a dock, a super-fast portable charger, and a case to keep it safe. These are the pieces I’m looking to buy, and I can’t wait to see how they upgrade my ROG Xbox Ally X's gaming experience.

View the full Amazon Prime Day sale

Prime Day sale – quick links

The ultimate Asus ROG Xbox Ally setup

The Asus ROG Xbox Ally X and its accessories

ASUS
ROG Xbox Ally with Gsf 3-In-1 Kit (16GB | 512GB SSD)

The Asus ROG Xbox Ally X and its accessories

ASUS
ROG Xbox Ally X (24GB | 1Tb SSD)

The Asus ROG Xbox Ally X and its accessories

RayNeo
Air 4 Pro glasses

The Asus ROG Xbox Ally X and its accessories

UGREEN
Nexode portable power bank (20000mAh 130W)

The Asus ROG Xbox Ally X and its accessories

JSAUX
carrying case

The Asus ROG Xbox Ally X and its accessories

Amfilm
3 pack screen protector

The Asus ROG Xbox Ally X and its accessories

GameSir
G7 Pro wired controller

The Asus ROG Xbox Ally X and its accessories

JSAUX
docking station

The Asus ROG Xbox Ally X and its accessories

Anker
100W laptop charger

More Amazon Prime Day deals in the US

Intel agencies: Frontier AI models will reshape cybersecurity faster than expected

By: djohnson
22 June 2026 at 11:25

Intelligence agencies for the United States, Canada, UK, Australia and New Zealand are warning that advanced AI models capable of wreaking havoc in the cyber domain are “months away” from being publicly available.

In a joint statement, the Five Eyes alliance say they expect the kind of advanced hacking capabilities provided by frontier models like Anthropic’s Fable 5 and OpenAI’s Daybreak to become broadly available the public within the year, despite efforts by AI companies to withhold them or restrict their access.

“Frontier Al models are anticipated to exceed current industry expectations, fundamentally transforming both offensive and defensive cyber capabilities,” the agencies said. “The timeline is not years, it is months.”

The statement, which included signatures from NSA’s Director of the Cybersecurity Directorate David Imbordino and acting CISA Director Nick Andersen, does not specifically cite secret or classified sources or methods to reach this conclusion.

But much of the underlying justification provided by the intelligence agencies also aligns with what public cybersecurity and AI experts have been warning about for months.

AI models capable of exploiting cybersecurity weaknesses are already available today through multiple channels: older commercial models, open-source versions, or foreign and black-market sources. And while newer models like Mythos are reportedly significantly more powerful for cybersecurity-related tasks, the breakneck pace of frontier model development often means that yesterday’s restricted frontier AI is tomorrow’s free, open-source AI.

Representative Andrew Garbarino, R-N.Y., Chair of the House Homeland Security Committee, said the warning from intelligence agencies “underscores what the Committee has repeatedly heard through roundtables, briefings, and hearings with industry leaders: China is just months, if not now weeks, away from achieving frontier AI capabilities comparable to those of the United States.”

“This threat reinforces the urgency of ensuring that federal agencies and critical infrastructure operators can responsibly leverage advanced U.S. models, and receive the guidance and support necessary to do so, to find vulnerabilities before adversaries can exploit them,” said Garbarino in a statement.”

The agencies flag legacy systems, sluggish patching loops, unnecessary internet connectivity, weak identity and access controls, and a lack of pre-incident planning by organizations as key weaknesses that AI will excel at exploiting.

“The rapid pace of frontier AI development means cyber risk assumptions can become outdated in months, not years,” the agencies wrote. “We must act before and be prepared to adapt and withstand evolving threats.”

Since large language models burst onto the scene, open-source models have run about 6-8 months behind the largest frontier AI companies.

To give an idea of how quickly the field develops: the capabilities described in the Amazon threat intelligence report that convinced the Trump administration to place export controls on Fable 5 could already be accomplished through older models like Claude Opus and Claude Sonnet, as well as open-source Chinese models.

Anthropic shut down access to their Fable 5 and Mythos 5 models as a result, and despite releasing a statement that they believe the White House decision was a “misunderstanding” the dispute remains resolved.

Programs like Anthropic’s Project Glasswing and OpenAI’s Trusted Access for Cyber Program provide AI systems to organizations for cyberdefense.  The goal is to give defenders a head start in finding and fixing vulnerabilities before AI systems can exploit them routinely in the coming years.

However, for all the fear surrounding the new technology, the recommended guidance is largely the same as it has been for decades. Governments, businesses and leaders must stop treating the digital security of their work as an afterthought or compliance issue.

“Success will come from getting the basics right, acting quickly, and integrating cyber security into core business strategy,” the agencies wrote. “Those that do not will face growing operational and strategic disadvantage.”

06/23/2026: This story was updated to include comment from Rep. Andrew Garbarino, R-N.Y.

The post Intel agencies: Frontier AI models will reshape cybersecurity faster than expected appeared first on CyberScoop.

APC, APDU, COPAFS, ICPSR, and PAA Statement on Commerce’s Disclosure Avoidance for Statistical Products

By: Dissent
17 June 2026 at 12:35
Paul Schroeder writes: On June 4, 2026 the Department of Commerce issued a new order “Disclosure Avoidance for Statistical Products” (DAO 216-26) that limits the types of privacy protection methods that the Census Bureau and Bureau of Economic Analysis (BEA) can use for their data products. This order subverts processes developed over decades to foster transparency and...

Lawmakers leery about Trump administration’s Anthropic order

16 June 2026 at 17:03

Members of Congress responded with skepticism and caution Tuesday to the Trump administration’s decision to impose export controls on Anthropic’s newest AI models.

The Friday order, which Anthropic said forced it to disable its Fable 5 and Mythos 5 artificial intelligence models, was prompted by what the administration said were national security concerns that a large number of cybersecurity professionals have dismissed as ill-founded.

Several Hill Democrats told CyberScoop they were concerned that the administration’s decision was driven by other considerations. Notably, the administration has feuded with Anthropic over use of its models for domestic surveillance and fully autonomous weapons.

Sen. Angus King, a Maine independent who caucuses with Democrats, said he would need to be convinced it was a legitimate national security order and hadn’t yet seen a full justification.

“What they did was pretty extreme, and I’d want to see what the basis was, as opposed to all the other issues that are swirling around in cybersecurity,” he said. “I’m a little skeptical because of their otherwise announced antipathy to this company.”

Leaders of the House Homeland Security Committee had contrasting takes, with Chairman Andrew Garbarino, R-N.Y., offering a two-pronged response and the top Democrat on the panel, Bennie Thompson of Mississippi, panning the order.

“The administration is right to treat advanced AI cyber capabilities as a national security issue, especially when foreign adversaries and cybercriminals are actively looking for ways to weaponize these tools,” Garbarino said in a statement. “At the same time, we need to make sure our response does not unintentionally disadvantage American companies, allied partners, or critical infrastructure defenders who need access to the best secure tools available in order to protect our networks here at home.”

The United States, not China, needs to set standards for trusted AI, Garbarino said.

But Thompson said the order adds evidence to the appearance that the Trump administration doesn’t “have a coherent plan for mitigating the cybersecurity risks” of frontier AI models, he told CyberScoop in a statement.

“AI regulations should rely on standards and procedures that provide confidence to the public that decisions are based on the evidence and not on politics,” he said. “Instead, the Trump administration has adopted an ad hoc approach where decisions are made by political appointees in the White House rather than experts and where companies are left guessing on how to comply.”

Virginia Sen. Mark Warner, the top Democrat on the Intelligence Committee, had also previously highlighted the administration’s quarrel with Anthropic in response to the order in a statement to CyberScoop.

Behind the scenes, the administration and Anthropic were reportedly continuing to try to forge a truce Tuesday. More broadly, the administration’s AI executive order had a rocky rollout as the administration swung back-and-forth on how involved the government should be.

Some lawmakers deferred on commenting Tuesday, such as Senate Homeland Security Committee Chairman Rand Paul, R-Ky., who told CyberScoop he didn’t have anything to say on the order.

Others said they were still seeking information from the administration.

“I have not had the opportunity to get a brief specifically as to the logic, the reasoning behind it, and so forth,” said Sen. Mike Rounds, the South Dakota Republican who chairs the Armed Services Subcommittee on Cybersecurity. “So I’m going to withhold judgment until I get an opportunity to get the rest of the story, so to speak.”

The post Lawmakers leery about Trump administration’s Anthropic order appeared first on CyberScoop.

AI’s constant patching treadmill can be a security problem

By: djohnson
16 June 2026 at 16:32

While Washington D.C. frets over the potential impact of Anthropic’s Claude Fable 5, security researchers continue to track how the integration of frontier AI tools are transforming the digital security landscape for malicious hackers and defenders alike.

The breakneck speed of model releases may be creating short, silent security gaps for developers who must choose between performance and security, according to a new report.

Researchers at Backslash Security pored through update logs for Claude Code, Anthropic’s flagship coding model, finding the company was patching dozens of newly discovered security vulnerabilities in the program between April and early June 2026.

The logs revealed the details of more than 30 security relevant patches implemented over that timeframe, but Anthropic did not publicize them. Instead, Backslash Security researchers found them by reviewing update logs for every new version of a Claude Code release in the last two months, noted the security-relevant fixes and traced each one back to the version and date it shipped.

The patches included fixes for data poisoning, prompt injection and arbitrary code execution vulnerabilities. One bypassed core safeguards put in place to prevent Claude Code from accepting catastrophic deletions commands, such as erasing an entire codebase, by adding a single backslash to the command. Another leaked user OAuth credentials, while a third allowed an AI agent to plant a backdoor in shell startup files.

There is nothing inherently odd about this: most companies regularly update and patch their software  and anyone who had auto-updates turned on would automatically be switched to the newest, secure version of Claude Code.

But Yossi Pik, co-founder and chief technology officer at Backslash Security, told CyberScoop that the research concluded “the way AI agents are released is different than previous software.”

“We debated internally, because when I originally said I wanted to write about this, I was told ‘Okay, every company has the [same] issue, then they patch and fix,” he said. “This is the nature of software, but I think that what makes this unique is the cadence and frequency of the releases.”

AI companies keep a ferocious pace when updating their models. Claude Code’s changelog indicates there have been 16 different versions through the first half of June, while OpenAI’s Codex was updated 6 times.

Because model updates often bring short-term performance and stability issues, software developers typically wait a week or more before upgrading to a new version.

These time gaps create small windows of vulnerability and force developers to choose between security and performance. The report identifies several reasons why developers don’t automatically update their AI models, including companies that may rely on internal vetting or release schedules, operate in regulated or air-gapped environments where model versions are frozen, and the need to maintain long-running sessions or use manual installations.

Pik said some IT and security teams have also told him they prefer not to install any new version of an AI model without letting it run on other environments first.

“You don’t have that much flexibility, either I go to the latest and I’m getting a less stable version [of the model] or I’m waiting for a few days or a week until I can install it, and hope that nothing would happen during this time,” said Pik.

The Backslash report is not intended as a dig at the security rigor of Anthropic, noting the company tends to “patch fast and document more than anyone” and has addressed every issue and vulnerability identified in the report.

Rather, it’s to highlight the series of mostly silent and persistent security exposures that an organization faces when adopting AI into their workflow.

Other software programs and technology products face similar tradeoffs through different updates, but most of the vulnerabilities detailed in the change log – such as getting an agent to leak data or accept malicious prompts – are unique to large language models and AI systems.

That means integrating AI tools can bring new security problems to an organization, both from outsiders who can poison or influence the model and insiders who can maliciously or accidentally direct the model to access or leak systems, data and identities.

For most Claude Code users, this process runs automatically in the background. Yet Yik points out that just as AI is transforming work itself,  it’s also changing how we need to approach software security and updates.

“It should not be compared to [Microsoft] Office that is installed and gets patched once in a while,” he said. “It’s a completely different beast that keeps evolving, and we don’t want to limit it…I think that it’s great for everyone. We just need to make sure that we do it in a secure way, and every organization should understand what that means for them.”

The post AI’s constant patching treadmill can be a security problem appeared first on CyberScoop.

❌
❌