AI Watch: AI security moves to Washington's center stage

White House AI testing framework arrives but key details remain secret, Congress probes OpenAI incident as calls for stronger AI oversight grow, China's open AI push fuels geopolitical debate, Banks press ahead with AI agents, US eyes China data center tech ban, much more.

Share
AI Watch: AI security moves to Washington's center stage
Photo by Louis Velazquez / Unsplash
white concrete dome museum
Photo by Louis Velazquez / Unsplash

Metacurity is the cybersecurity news you'd need hours to assemble yourself.

Every weekday, we read the releases, filings, court documents, and reports that vendors and PR teams often don't want summarized — then tell you what actually changed and why it matters. Minimum vendor marketing, no outrage bait, no SEO filler.

Metacurity delivers

  • Full archive access — every newsletter and AI Watch roundup, searchable and browsable.
  • Our weekly curated long-reads roundup — the best cybersecurity writing from across the industry, filtered and vetted so you're not sorting through it yourself,
  • Periodic specialized reports and analyses — deep dives that go beyond our daily coverage
  • Support for independent, no-spin cybersecurity journalism — funded by readers, not vendors or investors.

Reader support is what keeps Metacurity independent. It allows us to focus on serving the cybersecurity community—not advertisers, vendors, or investors—and to continue delivering the thoughtful analysis you've come to rely on every weekday.

Please consider supporting us. And thank you!

A flurry of government and industry actions Monday underscored how quickly AI agent security has become a cybersecurity priority in the wake of last week's OpenAI-Hugging Face incident.

Within days, the White House finalized a voluntary testing framework for frontier AI models, Congress opened an inquiry into OpenAI, advocacy groups called for a formal investigation, and enterprises pressed ahead with plans to deploy AI agents anyway.

White House framework arrives — with key details still hidden

The White House on Monday briefed leading AI developers on a long-awaited voluntary framework for pre-deployment testing of frontier AI models, meeting an Aug. 1 deadline established under President Trump's June executive order on AI. Representatives from OpenAI, Anthropic, Google and Meta were invited to discuss the framework, which establishes procedures for companies to submit qualifying models for government evaluation before release voluntarily.

But the framework's substance remains largely opaque. Administration officials said it addresses cybersecurity protections, safeguarding proprietary information and procedures for government review — yet the capability thresholds that determine which models qualify for review, and the benchmarks used to evaluate them, remain undisclosed.

"The voluntary framework outlined in the June 2 executive order is complete. Discussions with industry about next steps are underway," a White House official told Reuters. Defending the lack of transparency, one official told Axios: "Just because things are unclassified doesn't mean we are going to broadcast them to everyone."

That opacity has prompted questions from observers about how companies will actually be evaluated and what role the framework will play in shaping AI governance going forward. Even so, its completion marks one of the administration's first major AI policy milestones since the executive order was issued.

Congress begins scrutinizing the OpenAI incident

Congress also moved quickly to examine last week's episode. A House cybersecurity panel requested a briefing from OpenAI about its AI agent, seeking details on how the evaluation escaped its intended environment and what security controls failed.

OpenAI has characterized the event as occurring during controlled testing rather than public deployment, but lawmakers appear to view it as an early warning about the risks of increasingly autonomous AI systems interacting with real-world infrastructure. The request signals that AI agent security is beginning to draw the kind of congressional attention traditionally reserved for major incidents affecting critical infrastructure or software supply chains.

Advocacy groups push for broader oversight

Public interest organizations are also using the incident to push the regulatory debate forward. A coalition led by Public Citizen called on Congress to investigate the incident and examine whether voluntary safety commitments provide adequate oversight of frontier AI development, arguing that policymakers should look beyond the model's behavior to organizational governance, evaluation practices, independent auditing and accountability.

Separately, lawmakers cited the incident while promoting legislative proposals including emergency shutdown capabilities for advanced AI systems and additional resources for federal AI safety efforts — competing approaches that show Washington still hasn't settled on a preferred regulatory model.

Open models enter the geopolitical debate

The week's developments also intensified debate over open-weight models. Hugging Face CEO Clément Delangue argued that China is gaining ground in open AI because its developers collaborate more openly than many US frontier labs, framing open-source AI as both an innovation and a geopolitical issue. The comments add another layer to the ongoing dispute over whether restricting model access improves security or instead limits independent security research and defensive innovation.

Enterprises keep deploying anyway

Despite the scrutiny, enterprises are moving ahead. National Australia Bank said it's testing AI agents internally and intends to expand into customer-facing services, becoming one of the latest major financial institutions to publicly outline an agentic AI strategy — part of a broader pattern across regulated industries of pursuing deployment while building out governance, monitoring and operational controls rather than pausing to wait.

Why it matters

The throughline: AI security discussions are expanding beyond model capabilities to how increasingly autonomous systems are evaluated, governed and deployed. As organizations give AI agents access to credentials, APIs, internal applications and sensitive data, the security challenge increasingly lies not just in the models themselves but in the controls around them — identity and authorization, monitoring, containment, incident response.

That shift, from securing model intelligence to securing the systems that let agents act, may prove to be the more consequential story to watch than any single announcement this week. (Luke Fountain and Megan Cassella / CNBC, David McCabe, Mike Isaac, Ana Swanson and Kate Conger / New York Times, Samantha Subin / CNBC, Maria Curi / Axios, Madison Alder / FedScoop, Courtney ​Rozen / Reuters, Richard Henderson and Rthvika Suvarna / Bloomberg)

Related: CNN, QuartzReutersPoliticoPunchbowl NewsDaily SabahThe Prompt, The Independent,  Business InsiderBeInCryptoBloomberg Technology, The Hill, The Verge, FortuneForbesFinancial Times9to5Mac, RuntimeWire, Business Insider, MoneycontrolThe DecoderDigital TrendsDigitThe Economic Times, MacTech.com, Politico, The Rundown AIImplicator.aiCNNThe Daily CallerCBS NewsBenzingaPunchbowl NewsDaily SabahReutersQuartzThe Independent, The Prompt, The Information, The Herald Business

The Trump administration is drafting a ban on US imports of new models of Chinese data center components, according to four people familiar with the matter, as it seeks to protect the infrastructure that undergirds the AI boom.

The Federal Communications Commission is working on the measure to bar imports of new Chinese optical transceivers, which allow data to travel over fiber-optic cables at the speed of light within data centers. Officials hope to publish it this year, when it would take effect.

The move aims to prevent Chinese firms from stealing data, installing malware or disrupting service at U.S. data centers, which house the chips to train and ​run AI models.

The FCC could still modify or shelve the restriction, the sources stressed, speaking on condition of anonymity to discuss sensitive matters. But it is ​the latest example of the Trump administration trying to limit Chinese technological incursions into cutting-edge U.S. industries before they become embedded in the ⁠supply chain.

"Transceivers definitely pose a risk," said Divyansh Kaushik, an AI policy expert at Washington, D.C., advisory firm Beacon Global Strategies. "As the data center buildout scales up, you want ​to make sure the data center supply chain is secure from the get-go," he added. (Alexandra Alper / Reuters)

Related: The Information, Bloomberg LawRobotics & Automation NewsCryptoPotato, SupplyChainBrain, r/worldnews

Apple is yet again challenging the UK government in court over its attempts to access the encrypted data of customers, including iPhone users, according to two people familiar with the matter.

The Investigatory Powers Tribunal, a UK court that scrutinizes secret surveillance activities, gave notice that Apple had filed a fresh challenge to the government’s pursuit of user data stored in the cloud, the people said, asking not to be named due to the confidentiality of the case. The court’s proceedings are generally closed to the public, and it wasn’t immediately clear what Apple wrote in the filing. A hearing on the challenge is scheduled for September.

It’s the latest development in a major privacy fight set off last year when UK authorities ordered Apple to circumvent encryption that the company uses to secure user data stored on its cloud services. The UK’s move drew criticism from privacy advocates and senior US government officials who described it as an effort to open a backdoor to users’ files, including photos and communications.

Under pressure from US President Donald Trump’s administration, the UK government agreed that it would not seek access to Americans’ data. But British authorities have continued to push the Cupertino, California-based device maker for access to UK users’ data, according to the people familiar with the matter.

On July 13, Apple brought a new legal challenge to the Investigatory Powers Tribunal, said the people. (Ryan Gallagher / Bloomberg)

Related: MacDailyNewsTech-Economic TimesSlashdot, TechCrunch

Messaging platform Telegram appears to have been removed from Apple's App Store in multiple countries, although the reason for its apparent removal remains unclear.

As of Monday evening, searches for Telegram on the iOS and iPadOS App Store were no longer returning the messaging app for some users across several regions.

At the time of writing, however, Telegram remains available through the Mac App Store. The app also appears to remain available through Google Play.

Neither Apple nor Telegram has issued statements about the situation. 9to5Mac has reached out to Apple, and we’ll update this post if we hear back or as soon as more information becomes available. (Marcus Mendes / 9to5Mac)

Related: Bloomberg, ReutersLivemintAMBCryptoAndroid AuthorityTRT WorldThe Economic TimesAppleInsiderFinancial Express, Cointelegraph, Reclaim The NetInc42, MacRumors, ForbesMediaNamaBlockonomiMashablecrypto.news

Researchers at Palo Alto Networks' Unit 42 discovered three attacks that allow malware on already-compromised Windows devices to abuse Google Password Manager's synced passkeys to take over accounts, bypass user verification, and extract passkey private keys.

A new report by Palo Alto Networks' Unit 42 demonstrates three novel attacks, collectively called "Pass-ta-key," that target Google Password Manager in Chrome on Windows devices equipped with a Trusted Platform Module (TPM).

All three attacks require malware to be already running on the victim's computer and do not break the cryptography used by passkeys. Instead, they exploit weaknesses in how Chrome and Google's cloud authenticator handle device trust, onboarding, recovery, and synced credentials.

While the researchers say passkeys remain significantly safer than traditional passwords, the attacks demonstrate that they do not eliminate the risks posed by malware already running on a compromised device.

Unit 42 recommends that websites require and properly validate user verification. Credential managers should also validate newly registered device keys, harden recovery and device re-registration processes, and prevent master keys from becoming accessible in browser memory.

The researchers disclosed the Google Password Manager attacks to Google and reported related user-verification flaws to affected services, including eBay, before publishing their findings. (Lawrence Abrams / Bleeping Computer)

Related: Unit42, DigitalTrends, Techzine, GBHackers, Cyber Security News

Pass-ta-key attack flow. Source: Unit42.

Security software provider N-Able is warning customers that hackers are exploiting an authentication bypass vulnerability (CVE-2026-18577) affecting both hosted and on-premises N-central servers.

The company on Sunday released hotfix 2026.3.1.7 to address the security issue, which affects all versions of N-central before 2026.3.

On August 1st, the vendor disclosed that it detected active exploitation and launched an investigation that uncovered additional security concerns affecting all versions of N-central, its flagship Remote Monitoring and Management (RMM) platform.

In an update the next day, the company announced the hotfix and strongly recommended all customers upgrade immediately to the new release.

Hosted deployments already received the update, while customers of on-premises instances need to install it manually. (Bill Toulas / Bleeping Computer)

Related: N-Able, Huntress, Help Net Security, eSecurity Planet, Arctic Wolf, Dark Reading, The Next Web, SC Media

Some of these apps claim to have been installed on hundreds of millions of smart TVs in people’s homes, per the app developers.

At least one of the smart TV apps was a simple Pac-Man game that Samsung had endorsed and prominently featured in its “Editor’s Choice” section on customers’ TV screens.

These apps contain software that funnels outsiders’ web traffic through ordinary home and office internet connections, known as residential proxy networks (or “resproxies”), which are increasingly being linked to cybercrime. When opened, apps with resproxy code can turn the smart TV into an always-on tunnel for outsiders to funnel their web traffic through, known as an exit node — even when the app is no longer open. 

After TechCrunch contacted Samsung with a request for comment, the electronics giant said in an emailed statement that it was banning apps that share their users’ internet connections, and will remove apps that contain the functionality. (Zack Whittaker / TechCrunch)

Related: Android PoliceMnemonicNeowinEngadgetDigital Trends, XDA Developers, r/technology, Slashdot

Samsung site recommending Pac-Man game. Source: Mnemonic.

River Financial Corporation, the bank holding company behind River Bank & Trust, said in an SEC filing it received confirmation that data stolen in a ransomware attack was deleted.

The attack occurred on June 16 and was identified three days later. River’s investigation into the incident determined that ransomware was deployed across portions of its server environment.

In response, the company took the affected systems offline and disabled administrative accounts that had been compromised.

“River, with the assistance of a third-party forensic firm, is investigating the nature and scope of the incident, including whether any personally identifiable information was subject to unauthorized access or exfiltration,” the company said.

Subsequent 8-K forms filed with the SEC revealed that hackers accessed portions of River’s network and exfiltrated certain data and that at least four lawsuits have been filed against the company.

The investigation into the nature, scope, and impact of the incident, however, continues, and it shows that River has yet to determine if the hackers stole any personal information from its systems.

The filing’s wording, however, shows that the company has engaged with the hackers to have the stolen data deleted, likely as the result of a ransom payment.

“As part of its response, River took steps to attempt to suppress the affected data, including obtaining representations from the threat actor that it deleted the data in its possession,” River said. (Ionut Arghire / Security Week)

Related: SEC, SEC, Security Affairs, SC Media, Cybersecurity Insiders

Federal employees and contractors whose sensitive personal data was stolen in the massive Office of Personnel Management breaches disclosed a decade ago would receive identity protection for the rest of their lives under new bicameral legislation.

Senate Intelligence Committee Vice Chair Mark Warner (D-VA) and Del. Eleanor Holmes Norton (D-DC) plan to introduce the RECOVER PII Act on Monday, aiming to prevent the federal government’s identity-protection program for victims from expiring Sept. 30, according to bill text.

Sens. Tim Kaine (D-VA), Angela Alsobrooks (D-MD), and Chris Van Hollen (D-MD) are also Senate cosponsors. (David DiMolfetta / NextGov/FCW)

Related: SC Media, VitalLaw, Congress.gov

According to Interpol, artificial intelligence has become a core driver of cybercrime in Africa, contributing to 55 percent of reported incidents across the continent.

The international police agency warned that the recorded frequency of AI deployment in criminal activity “represents a dramatic increase from previous years and reflects a fundamental shift in criminal methodology.” Since 2024, cybercrime-related losses have more than doubled from $192 million to $484 million, driven primarily by AI-facilitated scams, credential harvesting, and automated social engineering campaigns.

“Cybercrime has emerged as one of the most significant criminal threats to the region. AI is automating every stage of a cyberattack from reconnaissance and phishing to extortion and evasion,” said Neal Jetton, director of INTERPOL’s cybercrime unit. “AI is automating every stage of a cyberattack from reconnaissance and phishing to extortion and evasion.”

The 40-page “African Cyberthreat Assessment Report 2026” analyzed cybercrime trends between January and December 2025 based on survey data from 26 African member countries. It gathered insights from law enforcement agencies, national cybersecurity units, and judicial authorities.

The findings were cross-referenced with telemetry data from private sector
partners, including Fortinet, TrendAI, the Shadowserver Foundation, Mastercard, and S2W, to validate trends and eliminate reporting bias.

The report highlighted how online scams have transitioned from “isolated phishing incidents” into highly organized, industrialized criminal enterprises. These operations often work from centralized scam centers linked to human trafficking and transnational organized crime, similar to the massive, multi-million dollar investment fraud networks and their surrounding ecosystem of enablers exposed by OCCRP's Scam Empire investigation last year.

According to the report, 72 percent of surveyed countries confirmed the presence of scam centers within their borders, with the highest concentration found in Southern and West Africa. (OCCRP)

Related: Interpol, Infosecurity Magazine, Digwatch, Pulse, APA News, The Citizen, The Diplomatic Insight, TVC News, The Guardian Nigeria, GBC Ghana Online, Dawan

A new survey from the National Association of State Chief Information Officers and Deloitte found state CISOs are facing growing demands that are not being matched by more resources.

State CISOs say they are dealing with more work and tightening budgets, especially with the rise of artificial intelligence and the funding from COVID drying up.

Meredith Ward, the deputy executive director of the National Association of State CIOs, said before anyone jumps to the conclusion that it’s all “doom and gloom” for state CISOs, there are plenty of positive signs that demonstrate the impact these security experts are having on their states.

“CISOs are involved. They’re at the table. They are involved in policy. They’re involved in acceptable use and safe use of artificial intelligence. That’s really good,” Ward said.

“But there was really bad headlines too. CISO confidence is way down in a lot of things, in the cyber practices of local governments, the cyber practices of third parties and in being able to combat AI-enabled threats. A lot of times, I like to describe the state CISO job as almost like playing a game of whack-a-mole. If anyone else is old and remembers playing that, that it’s like what’s going to come up next. It’s just a constant level of not knowing.”

Only 22% of the respondents say they are “extremely or very confident” in their state’s ability to protect against external threats. This is down from 48% in 2022.

Additionally, CISOs say their confidence in local governments and public higher education cyber capabilities is at the lowest ever, reaching 63% of the respondents this year from 35% in 2022. (Jason Miller / Federal News Network)

Related: Deloitte.com, Ask the CISO

Zenity, which develops a platform for securing AI agents, has raised $125 million in a Series C funding round.

Norwest Venture Partners led the round with participation from new investors Qumra Capital, SoftBank Vision Fund 2, Hitachi Ventures, and LG Technology Ventures, alongside existing investors DTCP, Vertex Ventures, Third Point Ventures, and Intel Capital. (Meir Orbach / CTech)

Related: Globes, Zenity, Ventureburn, FinSMEs, Verdict, Pulse 2.0, Silicon Angle, citybiz, Ynetnews, Fortune, BusinessWire, FinTech Global

Credit-card giant Visa has agreed to buy Israeli online fraud and financial crime detection provider BioCatch for $2.4 billion.

Visa said it is acquiring BioCatch from London-based private equity firm Permira and other investors. As part of the deal, the Israeli pioneer in the field of behavioral biometrics will become part of Visa, but will continue to operate with the same team. The transaction is expected to close by the end of Visa’s fiscal second quarter of 2027, pending customary regulatory approvals and conditions. (Sharon Wrobel / The Times of Israel)

Related: BiometricUpdateBusiness Wire Technology News, Middle East Monitor, American Banker, iTnewsCNBCInc.comDisruption BankingeMarketerBarron's OnlineBenzingaDow Jones NewswiresBloombergQuartzCTechPulse 2.0ReutersCapital BriefFinancial PostSecurityWeekPYMNTS

Best Thing of the Day: Don't Blindly Copy and Paste AI Output

Niklas Gruhn coins an excellent new term - meat proxy - for people who unthinkingly copy and paste the output of AI systems to their peers.

Bonus Best Thing of the Day: College Students Want to Use Ethical AI

According to research from American University's Kogod School of Business, undergraduate and graduate business students want "more structured preparation to use AI effectively, ethically, and competitively in the workplace."

Worst Thing of the Day: Is ICE the Root of All Evil?

In recent months, ICE has deployed a round-the-clock digital dragnet to scour the public internet—from Facebook to Instagram to X—for speech that could endanger the agency’s mission.

Bonus Worst Thing of the Day: When Law Enforcement Dips Into a Crypto Criminal's Stash

FBI agent Patrick Yaroch claimed he had begun stealing $1 million in cryptocurrency in late 2024 or early 2025, and made 10 or 12 withdrawals in total, using a pass phrase to the suspect’s account that the FBI had obtained during its investigation of the individual.

Closing Thought