AI safety fears erupt into a global political and market crisis

Fears are rippling across global economies as Dario Amodei, Sam Altman and Elon Musk issue calls to slow down frontier AI development, thrusting once-fringe warnings about rogue AI into public consciousness even as Anthropic touts profitability ahead of a potentially record-setting IPO.

Share
AI safety fears erupt into a global political and market crisis
Screenshot from CBS Sunday Morning interview with Dario Amodei.

Anthropic CEO Dario Amodei is calling for an immediate slowdown in the pace of AI development, warning of potentially devastating consequences in a matter of months otherwise.

OpenAI CEO Sam Altman quickly agreed that the industry needs to slow the pace of frontier-model advances and take more steps on safety.

Amodei pulled no punches in a new essay, cautioning that swarms of rogue AI agents could take over the internet in as little as six months from now.

This is the week that the AI safety debate broke into the public consciousness, driven by an Anthropic employee's very public resignation and warning of possible doom.

Amodei's essay isn't necessarily a direct response, but it will have much the same effect amid a sudden surge of public and congressional outrage.

Elon Musk, the founder of Tesla and xAI, responded to Amodei’s slowdown plan with a series of posts on X: “Dario is right.”

He said: “I’ve been sounding the alarm on AI for a long time,” and referred to a 2014 post where he said: “We need to be super careful with AI. Potentially more dangerous than nukes.”

Amodei’s call comes as Anthropic prepares to float on the US stock market, in what is expected to be the biggest initial public offering of all time. It is expected to start marketing its planned $2tn-plus (£1.5tn) IPO soon.

On Monday, China criticized warnings from leading US technology executives to put the brakes on artificial intelligence development and claims that Chinese progress posed a dire security threat to the world.

“Fearmongering, confrontation and vicious competition will only disrupt the process of global AI governance and serve the interests of no one,” Foreign Ministry spokesman Guo Jiakun said at a regular briefing in Beijing on Monday.

“The development of artificial intelligence bears on the common well-being of all humanity,” he added, in response to a question on calls to slow frontier models and claims that a Chinese advantage in AI could “pose grave danger” to the world.

And yet, China’s top spy chief also warned that artificial intelligence could pose a direct threat to the Chinese Communist Party’s hold on power, in what is the highest-level and most detailed articulation yet of how Beijing sees the technology’s security risks.

The unusually blunt assessment by Chen Yixin, the head of China’s Ministry of State Security, is in contrast to the warnings dominating the AI debate in the United States, which have focused on the possibility that AI could slip out of human control or pose a threat to humanity itself.

In an article published on Sunday in the state-run magazine China Cyberspace, Mr. Chen called for more party control over A.I. and stricter government oversight. This, he said, was necessary to protect political stability at home; to defend against increasingly sophisticated cyberattacks and misinformation campaigns from “hostile forces”; and to compete militarily with countries like the United States.

AI-linked stocks tumbled on Monday after the bosses of Anthropic, OpenAI and SpaceX called for a slowdown in “reckless” development, citing fears the technology could soon run out of control.

Shares in SoftBank, a Japanese investor that is a big backer of OpenAI, slumped 13%, while the South Korean Kospi stock index, which relies heavily on chip makers that supply AI companies, dropped by 3%.

Shares in the big global microchip supplier Taiwan Semiconductor Manufacturing Company dropped 1.2%. Futures for the Nasdaq pointed to a 1.3% drop in the tech-heavy index when the US stock market opens this afternoon.

In Europe, shares in the Dutch tech manufacturer ASML, Europe’s biggest company by value and an important supplier for the semiconductor industry, slumped by as much as 5.4% in morning trading.

Despite all the turmoil, Anthropic told shareholders that its ​adjusted operating income ‌will be positive for a second straight ​quarter, the Financial ​Times reported, ⁠citing multiple people ​with knowledge of the ​matter.

Anthropic's gross margins are above 80% before accounting ​for revenue shared ​with distribution partners, including Amazon and ⁠the cost of training its model, the newspaper said. (Ben Berkowitz /Axios, Robert Booth and Julia Kollewe / The Guardian, Bloomberg News, ​and Sathvi G Bhat / Reuters)

Related: Dario Amodei, New York Times, Wall Street Journal, Associated Press, CBS NewsForbesBloombergAustralian Financial ReviewBBCThe Washington SunBarron's OnlineChicago TribuneJoe.My.God., Business Insider, David Sacks on X, New York Times, AxiosNeowinLivemintThe Free PressNewsMax.comWall Street JournalNPRHuffPostWashington Examiner, Marcus on AI, Shelly Palmer, The Stack, The Independent, NPR, CNBC, Reuters, The Washington Post, Help Net Security, China Cyberspace, Financial Times, NPR, South China Morning Post, Reuters, Associated Press, Bloomberg


Metacurity is the cybersecurity news, analysis, and insight you'd need hours and possibly days to assemble yourself.

Every weekday, we read the releases, filings, court documents, and reports that vendors and PR teams often don't want summarized — then tell you what actually changed and why it matters. Minimum vendor marketing, no outrage bait, no SEO filler.

A paid subscription to Metacurity delivers

  • Full archive access — every newsletter and AI Watch roundup, searchable and browsable.
  • Our weekly curated long-reads roundup — the best cybersecurity writing from across the industry, filtered and vetted so you're not sorting through it yourself,
  • Periodic specialized reports and analyses — deep dives that go beyond our daily coverage
  • Support for independent, no-spin cybersecurity journalism — funded by readers, not vendors or investors.

Reader support is what keeps Metacurity independent. It allows us to focus on serving the cybersecurity community—not advertisers, vendors, or investors—and to continue delivering the thoughtful analysis you've come to rely on every weekday.

Please consider supporting us. And thank you!


Anthropic, OpenAI and Google have been holding discussions about working together to create a standards body for the AI industry, people familiar with the matter said, even before Anthropic CEO Dario Amodei called on Saturday for AI companies to coordinate on testing and auditing the technology.

OpenAI CEO Sam Altman, for his part, told staff at a companywide town hall meeting earlier this week that he supported a testing and auditing organization for the AI industry but believed that major AI labs would have to create a standards body on their own without the support of the US government, a person familiar with the comments said.

Top AI CEOs back industry-led self-regulation for AI development.
Trump administration’s draft executive order for AI self-regulator stalled.

That kind of industry self-regulation was part of a broader proposal Amodei published on Saturday to slow AI development and establish independent oversight amid mounting risks posed by increasingly powerful AI. Amodei said companies could move ahead with voluntary safety standards while the government hammers out AI regulation, with the government potentially enabling or mediating industry discussions.

The idea of a self-regulatory organization for AI has been part of the public conversation for several months. In July, Hassabis published an essay laying out a proposal for a self-regulatory body modeled after the Financial Industry Regulatory Authority, which oversees US broker-dealers and securities professionals.

But the extent to which companies had already started working together on setting industry standards has not been previously reported. Since July, a working group of representatives below the CEO level from Google, Anthropic and OpenAI have been regularly meeting about the proposal for a standards body, according to people familiar with the matter.

An executive order draft circulated in the White House that would have created such an organization, but the effort stalled in the late summer after failing to garner enough support within the Trump administration, The Information previously reported. (Leo Schwartz / The Information)

Related:  Seoul Economic Daily, BIG by Matt Stoller, The Asia Business Daily

The Trump administration is grappling with how to foster AI, a technology that’s underpinned US economic growth, while also mitigating safety concerns raised by an alarming spate of hacks by rogue AI models.

It’s left administration officials struggling to balance promoting AI adoption against addressing unpredictable cybersecurity risks, according to people familiar with internal deliberations.

Trump's largely toothless June order on AI cybersecurity has come to symbolize his reluctance to impede hundreds of billions of dollars in tech investment. Administration officials are wary of undercutting the US lead over China, an advantage challenged by a new vanguard of Chinese developers, including Moonshot AI.

On Sunday, Trump played down the idea of further guardrails, reiterating his previous stance that the US needs to keep expanding AI, even in the face of growing domestic opposition to the data centers needed to power the technology.

“We’re leading China in AI. We’re the most sophisticated country in the world, and frankly, I want to keep it that way because whoever wins AI wins,” Trump told reporters on the sidelines of the Irish Open golf tournament. “And we can put guardrails. We can do this and that. But I think you have a lot of very negative forces that are bringing it up that shouldn’t be bringing it up.” (Sarah Frier and Michael Shepard / Bloomberg)

Related:  Fortune, BloombergBBCThe VergeSecurity AffairsSky NewsWashington PostTechCrunchBusiness InsiderWall Street JournalAustralian Financial ReviewNewserTürkiye TodayReutersThe Washington SunAssociated PressTelegraphReutersThe HillMediaiteNew York PostDaily SabahNew York Times, HuffPost

US House Speaker Mike Johnson (R-LA) said that Congress won't lead the charge on regulating AI safety.

Johnson was urged this week to cancel the House recess and bring representatives back to DC to pass a law on AI safeguards.

During a Sunday appearance on CNN's "State of the Union," Johnson said Congress intervening isn't the answer and that AI companies can halt their work at any time.

We have to "resist Congress jumping in and imposing some sort of emergency moratorium. It's got to be done right, safely, wisely," he said. (Donica Phifer / Axios)

Related: Politico, WinBuzzerNew York TimesThe WrapThe HillStraight ArrowNBC NewsYahoo FinanceTMZ.comNew York PostBloomberg, Associated Press

The attack overwhelmed maintainers of RubyGems and forced them to shut down new account registrations as they dealt with the chaos it had caused, operators of the service said.

A coalition of AI researchers said it had unearthed evidence that OpenAI agents were behind the May attack and shared its findings with The Wall Street Journal and OpenAI. The AI developer on Friday confirmed that its agents had been involved in an incident involving RubyGems.

“Based on our review, our agents used the RubyGems platform to access the internet to carry out benign tasks and retrieve public information. We’ll continue to investigate as part of our broader review of agent activity during training and evaluation,” an OpenAI spokeswoman said in a statement.

The OpenAI agents were asked to do things such as fill out spreadsheets and create reports. The AI agents appear to have gone to RubyGems to access publicly available information as part of a training run, using the coding service as a kind of makeshift web browser in an environment where they didn’t have full internet access, OpenAI said.

While the incident caused minor harm overall, it demonstrated the capabilities of these agents, said Sydney Von Arx, the chief executive of Nightingale Collective, a not-for-profit organization that helped uncover the attack.

“They can escape from the internet and wreak havoc,” she said. (Robert McMillan / Wall Street Journal)

Related: Infosecurity Magazine, Pasquale Pillitteri, Neowin, The Decoder

Three weeks after his arrest, the State Attorney’s Office’s Cyber Department filed a major indictment against Michael “Miki” Bar, a 43-year-old hacker from Ashkelon who served as Chief Information Security Officer for the Hamat Group.

The group itself has no connection to the charges.

According to the indictment, Bar infiltrated malware into the computer systems of 26 companies, two kibbutzim, and private individuals, allowing him to execute thousands of remote commands and collect passwords, correspondence, sensitive business information, and recordings from cameras and microphones.

The list of companies allegedly targeted by Bar, included in an appendix to the indictment, includes Sheldor, Gindi and Machpel Mishmarot. The two kibbutzim named in the indictment are Gazit and Kfar Menachem.

The case took a particularly striking turn on April 30. According to the indictment, Bar was contacted by investigators from the National Cyber Directorate, which was examining a large-scale attack on companies in the Israeli economy and suspected that the Hamat Group had also been compromised.

Because of his position as the company’s CISO, Bar was given details of the incident and a tool designed to locate the malware in Hamat’s computer systems.
But according to the indictment, the person who received the tool and was expected to help investigators find the attacker was himself the alleged attacker.

Bar allegedly concealed his involvement, continued speaking with the cyber investigators for about two weeks, and did not stop his activities. On the contrary, the prosecution alleges that after learning that his malware had been detected, he developed a new and more sophisticated program and used it to infiltrate the systems of additional companies. (Amir Kurz / CTech)

Related: Ynet News, Jerusalem Post

Researchers at Silent Push identified a North Korean fake job recruitment scam channel hosted on a Discord Server from a defender colleague, and the company engaged with the recruitment representative to ask about their offering and determine if the individual was actually a North Korean IT worker.

After connecting via Telegram, the researchers asked the suspect NK persona “Tec Guru” about virtual private networks (VPNs); they advised Silent Push to use Astrill VPN, a VPN often used by North Korean IT workers.

Silent Push identified the threat actor’s primary tactic as identity and proxy theft, under the guise of a front/facilitator recruitment scheme.

Based on technical reference indicators pointing to the persona being a North Korean IT worker, and on their speech patterns, among other flags, Silent Push believes they are North Korean.

Organizations engaging with North Korean IT workers face severe sanctions risks and are advised to verify applicants' physical locations during job interviews. Silent Push developed a detection method for these operations. (Silent Push)

The National Security Agency is set to undergo its most extensive internal restructuring in at least a decade, according to current and former officials briefed on the emerging plan.

The new design for one of the most powerful US intelligence agencies, which was announced to senior NSA leaders last week, is the brainchild of Army Gen. Joshua M. Rudd, the NSA director, these officials said.

Rudd’s initiative calls for the creation at NSA’s Fort Meade, Maryland, headquarters of five new organizations inside the agency, in artificial intelligence, China, cybersecurity, combat support or warfighting, and global intelligence. Each will be led by a newly elevated “mission director,” according to former officials.

This new organizational configuration will better reflect NSA’s current and future priorities, Rudd believes, according to current and former officials. NSA, the US intelligence community’s premier global eavesdropping arm, specializes in digital espionage.

The mission heads will have the “effective” authorities of an NSA deputy director, according to one former official familiar with the plan. This former official, like others in this article, spoke on the condition of anonymity to discuss sensitive information about the agency, whose operations are highly classified. (Zach Dorfman, Warren P. Strobel and Noah Robertson / Washington Post)

Related: The Record, SpyTalk

British fintech Revolut confirmed that it disclosed sensitive customer information to an unauthorized third party after receiving fraudulent requests sent from a legitimate government agency email domain.

The exposed data included customers’ identity and contact details, including their birth date, postal and email addresses, and phone numbers, as well as copies of their identity documents including passports and driver’s licenses, according to a notification emailed to affected customers and reviewed by TechCrunch. The data may have also included verification selfies, account statements, and transaction histories, the firm said in its notification.

A Revolut spokesperson confirmed to TechCrunch that a “limited” number of customers were impacted and said the company had contacted those customers directly. Revolut, however, did not disclose the exact number of impacted individuals. It also did not answer whether the incident was limited to a specific market and declined to disclose the government agency involved.

“Revolut recently identified a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information,” the spokesperson said.

Revolut told TechCrunch that it blocked the email address after discovering the scam from the unauthorized third party and alerted the relevant government agency, law enforcement, and relevant regulators, adding, “Revolut systems and customer funds are unaffected.” (Jagmeet Singh / TechCrunch)

Related: City AM, Reuters, Pasquale Pillitteri, Yellow, Irish Times, CoinMarketCap, Help Net Security, AML Intelligence, Cyber Daily

GitLab released emergency patches for two high-severity flaws in its software development platform, one of them holding the highest possible severity score, while a security firm reports that it has already seen attackers probing the internet for the flaws.

The company patched the issues in new versions of both its Community Edition and Enterprise Edition, and urged those that use self-managed installations to upgrade as soon as possible. GitLab said its own hosted service already runs the fixed code, and that customers of its single-tenant Dedicated offering are not impacted.

The more serious of the two flaws, tracked as CVE-2026-85706, sits in the interface that handles repository commits. GitLab said that under certain conditions, an attacker could read any file on the server because the code failed to confine file paths properly and did not enforce authentication. An attacker does not need an account or credentials to take advantage of the flaw.

The vulnerability affects every release from 18.7 up to 19.1.8, along with the 19.2 and 19.3 lines before this week’s patches. GitLab assigned it a CVSS score of 10.0, the top of the scale used across the industry.

The second flaw, CVE-2026-87719, affects only GitLab’s Enterprise Edition. The company says a logged-in user with Duo Chat access could hide a command inside an ordinary request, prompting the server to look up its own settings for the software’s Advanced Search feature, which would return the settings and passwords being held. It affects releases from 18.3 onward and carries a CVSS score of 9.9.

WatchTowr Labs wrote in a LinkedIn post Friday that it was already watching probes against the path traversal flaw, which it said an attacker can trigger in one HTTP request. The firm said organizations running self-hosted GitLab servers reachable from the open internet face the greatest risk, and pointed defenders toward their logs, suggesting they look for POST requests to addresses under /api/v4/projects/{id}/repository/commits/ that carry a file.path parameter. (Greg Otto / CyberScoop)

Related: GitLab, Bleeping Computer, SC Media, Security Affairs, Infosecurity Magazine, DevOps, Cyber Daily, watchTowr on LinkedIn

Researchers at Gen Digital report that threat actors linked to a China-aligned espionage group are exploiting a critical vulnerability (CVE-2026-51990) in Tencent’s Sogou Input Method for Windows to deploy the GrayRabbit backdoor.

They warn that the security issue is a one-click remote code execution (RCE) flaw.

"We observed this vulnerability actively exploited in the wild by the UNC3569 threat group to deploy the GRAYRABBIT backdoor through a crafted link," Gen Threat Labs says.

Sogou Input Method is a popular Windows application that lets users type Chinese characters using a standard keyboard and also offers a custom link handler and a built-in web browser using an outdated Chromium engine.

Developed by Chinese tech giant Tencent, Sogou Input Method reportedly has hundreds of millions of installations in China. (Bill Toulas / Bleeping Computer)

Related: Gen Threat Labs, Security Week

The UNC3569 attack chain. Source: Gen Threat Labs

Researchers at Wiz report that threat actors are exploiting critical and high-severity vulnerabilities in JFrog Artifactory to bypass authentication, gain administrative privileges, and deploy a Rust backdoor on vulnerable self-hosted servers.

Wiz confirmed exploitation across multiple environments, including an exploit chain that combines CVE-2026-42018 and CVE-2026-42016.

The third vulnerability is CVE-2026-82329, a critical authentication bypass that offensive security company watchTowr observed being exploited earlier this month to mint administrator tokens.

According to Wiz, attackers exploit CVE-2026-42018 to obtain a JSON Web Token (JWT) belonging to an internal Artifactory anonymous user, even when anonymous access is disabled, with low privileges.

Then they increase permissions to admin level by exploiting CVE-2026-42016, caused by insufficient token validation.

Between August 15 and September 8, multiple threat actors exploited the two vulnerabilities to obtain a JWT for the internal anonymous user and then exchange it for an admin-scoped token.

The researchers note that in some cases the attacker took less than five minutes to create an administrator account.

After creating admin accounts and generating long-lived access tokens, the attackers installed malicious Groovy plugins to execute arbitrary commands and established persistence by deploying a Rust-based backdoor.

“Between August 15 and September 8, 2026, we observed multiple actors chain CVE-2026-42018 and CVE-2026-42016 against self-hosted Artifactory instances,” Wiz says.

“Across multiple cases, we observed a custom Rust backdoor with C2 capabilities being dropped.”

In the next stage, the threat actor downloaded additional payloads into /dev/shm, /tmp, and /var/tmp, uploaded webshells, stole Artifactory configuration data and cluster join keys, enumerated repositories, tokens, and users, and added their SSH keys to newly created accounts.

Wiz warns that between 49% and 62% of reachable Artifactory instances are vulnerable to at least one of the three flaws. (Bill Toulas / Bleeping Computer)

Related: Wiz, Security Week, Cyber Security News, Cyber Press

Source: Wiz.

Dutch startup Fortaegis has raised $50 million to commercialize a security architecture that uses the physical properties of silicon chips to protect AI infrastructure, autonomous systems and connected machines.

Singapore-based Serendipity Capital led the oversubscribed Series A round and was joined by TEL Venture Capital, the corporate venture arm of chip-equipment maker Tokyo Electron, as well as TNO, Prodrive Technologies, NP-Hard Ventures, NovaCapital, Access Ventures and Coalition Capital. (Matt Swayne / AI Insider)

Related: Financial Times, Techzine, The Quantum Insider, Dealroom

Best Thing of the Day: Documenting the Rise of Enemy Surveillance in America

Artist Cara Esten Hurtle bought a used DJI drone off of Facebook Marketplace to spy on Flock cameras to record the rise of enemy surveillance in America.

Worst Thing of the Day: Extending Online Hate to European Women Politicians

Almost 150 politicians across Europe have been included on harmful deepfake pornography websites over the last few years, most of whom were women members of parliament (MPs) from 22 European Union countries, according to researcher Benjamin Shultz.

Closing Thought