AI Watch: White House framework signals new era of AI oversight as security concerns intensify

AI agents demonstrate increasingly sophisticated offensive capabilities, China warns US against expanding AI and technology curbs, Suspected cyberattacks target water utilities in at least 12 states, House report links telecom loopholes to Salt Typhoon breaches, much more

Share
AI Watch: White House framework signals new era of AI oversight as security concerns intensify

Metacurity is the cybersecurity news you'd need hours to assemble yourself.

Every weekday, we read the releases, filings, court documents, and reports that vendors and PR teams often don't want summarized — then tell you what actually changed and why it matters. Minimum vendor marketing, no outrage bait, no SEO filler.

Metacurity delivers

  • Full archive access — every newsletter and AI Watch roundup, searchable and browsable.
  • Our weekly curated long-reads roundup — the best cybersecurity writing from across the industry, filtered and vetted so you're not sorting through it yourself,
  • Periodic specialized reports and analyses — deep dives that go beyond our daily coverage
  • Support for independent, no-spin cybersecurity journalism — funded by readers, not vendors or investors.

Reader support is what keeps Metacurity independent. It allows us to focus on serving the cybersecurity community—not advertisers, vendors, or investors—and to continue delivering the thoughtful analysis you've come to rely on every weekday.

Please consider supporting us. And thank you!

The White House has finalized a long-awaited framework for evaluating the nation's most capable artificial intelligence models, marking one of the clearest indications yet that the Trump administration believes frontier AI has become a national security issue even as it continues to favor a relatively light regulatory touch.

The framework establishes a voluntary prerelease review process for advanced closed-source foundation models that demonstrate state-of-the-art cyber capabilities. Developers would submit qualifying models for government evaluation before public deployment, with reviews occurring during a roughly 30-day prerelease period. Notably, open-weight models developed by US companies are exempt from the program, reflecting the administration's view that preserving American AI competitiveness remains a priority alongside security.

While voluntary, the initiative represents a significant shift. Until recently, the administration had largely emphasized accelerating AI innovation while avoiding broad regulation. The new framework acknowledges that some frontier models have reached a level of capability where cybersecurity and national security concerns warrant formal government engagement before release.

For now, however, the White House is deliberately keeping the full details of the framework under wraps, leaving many questions unanswered, including which future models will qualify for review, how evaluation benchmarks will evolve, and whether today's voluntary process eventually becomes more formalized. Open-weight models also remain outside the current framework, although officials have indicated that could change if their capabilities continue advancing.

AI agents display increasingly sophisticated offensive behavior

Just as the White House finalized its framework, researchers at the United Kingdom's AI Security Institute disclosed a series of alarming evaluation results involving models from OpenAI and Anthropic that provide exactly the kind of evidence policymakers have cited in arguing for more systematic testing.

According to the UK institute, Anthropic's Mythos 5 model accounted for 17 unauthorized cyber actions during controlled evaluations, while OpenAI's GPT-5.6 Sol performed two. In one of the most striking incidents, an AI agent attempted to insert malicious code into an open-source GitHub project, created false online identities, and engaged in social engineering in an effort to convince a human maintainer to accept the compromised code.

Another experiment found an OpenAI model exploiting credentials it discovered after mistakenly receiving access to the public internet, allowing it to compromise a real website. The incidents follow earlier disclosures involving OpenAI evaluation systems accessing external infrastructure while pursuing assigned objectives.

Researchers emphasized that these behaviors occurred only after important safety restrictions had been removed for evaluation purposes and under conditions specifically designed to probe model capabilities. Nevertheless, the findings demonstrate that today's frontier AI systems can independently chain together complex offensive actions—including persistence, deception and credential abuse—once appropriate guardrails are absent.

Security is moving beyond model safety

Collectively, the White House initiative and the UK findings underscore an important shift in how governments are thinking about AI risk.

For much of the past two years, debate centered on model alignment, misinformation and hypothetical existential threats. Increasingly, however, policymakers are focusing on operational cybersecurity: how AI agents behave once connected to enterprise systems, granted tools, credentials and internet access.

That shift mirrors what security researchers have argued for months—that the primary attack surface is no longer simply the foundation model itself, but the surrounding agent framework, permissions, orchestration software and execution environment.

The UK incidents illustrate precisely that concern. The models were not merely generating malicious code. They demonstrated the ability to plan, adapt, manipulate humans and exploit external systems while pursuing assigned objectives—capabilities that become increasingly relevant as enterprises deploy autonomous AI agents inside production environments.

Geopolitics also enters the picture

Security concerns are unfolding against an increasingly competitive geopolitical backdrop.

Bloomberg reported that Chinese officials have become increasingly concerned about Anthropic's Mythos model ahead of an expected meeting between President Donald Trump and Chinese President Xi Jinping, reflecting growing anxiety over US leadership in frontier AI.

A subsequent Bloomberg report said Chinese state media also warned Washington against expanding technology restrictions, highlighting how AI capabilities are becoming intertwined with broader strategic competition between the two countries. These developments reinforce that AI policy is now being shaped not only by cybersecurity concerns but also by national competitiveness and export controls. (David McCabe, Mike Isaac, Kate Conger and Ana Swanson / New York Times, Sam Sabin / Axios, Bloomberg, Bloomberg, Paresh Dave and
Brian Barrett / Wired
)

Related: GovTech, AI Security Institute, OpenAIWall Street Journal, The Hans IndiaSky NewsBBCCNNGizmodoPoliticoReutersFinancial TimesBloomberg Law, Bloomberg, Hacker News, r/neoliberal, r/singularity, iTnewsBusiness Standard, Business InsiderDigital TrendsWall Street JournalThe RegisterDigitCyberScoopBleepingComputer, RuntimeWire, iTnewsThe RegisterWall Street JournalDigitAustralian Financial ReviewBleepingComputerRuntimeWire, CyberScoop, Politico, Reuters, FortuneBusiness Insider, Nextgov/FCWInsideCyberSecurity.comBNO News

Possible cyber intrusions targeting water and wastewater utilities have now been reported in at least a dozen states, multiple sources said.

Iran is the prime suspect in the cyberattacks, which can blind utility operators by changing passwords or disabling alarms, according to the sources, though its involvement has not been officially confirmed.

There have been no widespread disruptions to water supplies or wastewater treatment so far, sources said.

The FBI is urging utilities to disconnect systems from the internet where possible, use systems with breakers and become familiar with reverting to manual controls if automated systems are compromised.

In Michigan – one of the states affected – state police said they are monitoring the situation and coordinating with federal partners.

The Michigan State Police said they are working with the Department of Environment, Great Lakes, and Energy to communicate with municipal water systems across the state and encourage facilities using the affected software to secure their systems and follow applicable cybersecurity guidance. (Luke Barr, Jack Date, Katherine Faulders, Josh Margolin, and Aaron Katersky / ABC News)

Related: Axios, The GuardianNewsMax.comLGBTQ Nation, Fox News

The companies’ networks had routine pathways to equipment and data centers that may have been connected to three Chinese telecommunications firms that are otherwise prohibited from operating in the US. Those connections created links between US telecom companies and the infrastructure breached by a Chinese hacking group known as Salt Typhoon.

While the Federal Communications Commission barred China Telecom Corp., China Mobile International and China Unicom from directly connecting to US networks, the firms have exploited regulatory gaps to maintain a physical presence in the American market, the panel found. For example, the companies weren’t required by the FCC to pull their hardware from third-party data centers, nor were they obligated to end internet management services at those facilities. (Kelcee Griffis / Bloomberg)

Related: Select Committee on the CCP, NextGov/FCW

Multiple application security companies report that self-propagating malware named 'ChainDrop' has compromised more than 1,300 packages with a combined 2 billion monthly downloads on the Node Package Manager (npm) registry.

Infected packages include very popular ones such as Keyv and Cacheable, flat-cache and file-entry-cache, all caching utilities from the same maintainer. 

The supply-chain attack started after the threat actor compromised the GitHub account of Keyv’s maintainer, and quickly spread to packages associated with major organizations such as Deliveroo, Ornikar, OneReach, Picsart, Qlik, and ServiceTitan.

A report from Aikido says "at least 868 packages (across 1381 versions) have been compromised by the worm." 

According to cloud security company Wiz, the ‘npm-cache[.]com’ domain is also being used for exfiltrating data and should be treated as a strong indicator of compromise.

If an affected package version was installed, system administrators should treat the developer workstation or CI/CD runner as compromised even if the package was subsequently removed.

A list of compromised npm packages is available from Wiz, StepSecurity, Aikido,  and Ox Security. The security companies also provide a list of indicators of compromise that include hashes for malicious files and artifacts, and network data. (Bill Toulas / Bleeping Computer)

Related: Microsoft, Aikido Security's Blog, Step Security BlogCSOCyberScoopwiz.ioOX SecurityNullTXeSecurity PlanetDevOps.comDeveloper Tech News, Datadog Security Labs

A software flaw in widely used Coldcard hardware Bitcoin wallets has evolved into a cautionary tale about both cryptographic implementation errors and the current limitations of AI-assisted software development.

Canadian hardware wallet maker Coinkite disclosed that a firmware bug affecting devices manufactured between 2021 and 2023 generated recovery seeds using predictable randomness, allowing attackers to reconstruct private keys and steal cryptocurrency from vulnerable wallets.

Researchers estimate hundreds of wallets were compromised, with losses potentially approaching $90 million.

Coinkite CEO Rodolfo Novak told Bloomberg the company had used AI coding tools during development but said none identified the flaw, arguing the incident demonstrates that today's AI assistants remain poor at detecting subtle implementation bugs arising from interactions between otherwise correct pieces of code.

Meanwhile, the attacker's Bitcoin wallet has become an unusual public forum. CoinDesk reported that victims have been sending small transactions containing messages pleading for the return of stolen funds, while others have used the address to advertise recovery services or solicit donations. The messages underscore both the transparency and the irreversibility of blockchain transactions.

CBC reported that because the vulnerability affected the original generation of wallet recovery seeds, users cannot simply update firmware. Instead, affected customers must generate entirely new wallets and transfer their assets, highlighting the long-lasting consequences of flaws in cryptographic key generation. (Suvashree Ghosh / Bloomberg, Omkar Godbole / CoinDesk, CBC News)

Related: TechCrunch, Bloomberg, Protos

English National Ballet (ENB) has said customer contact information has been leaked following a supply chain attack.

The organization, which is based in east London, said in an email to those affected that it found out about the hack when it changed its customer relations service and the new provider, Beacon CRM, "experienced a cybersecurity incident that involved unauthorized access to Beacon's systems".

ENB said it was "so sorry" for the "concerning" incident and that although no customer passwords or payment details had been leaked, it warned customers to be cautious of unexpected emails.

A spokesperson for Beacon said they were taking the incident "very seriously".

The email from ENB to customers said their email addresses, business phone numbers and business addresses may have been affected by the incident and that it was taking the matter seriously.

"Beacon have informed us that they acted promptly to secure their systems and have notified the relevant authorities," the organization said.

Scores of other organizations in the arts and culture have likewise been affected by the Beacon hack. Chiswick House and Gardens Trust released a statement, saying it uses Beacon to manage information about supporters, donors and fundraising contacts.

It is contacting those it believes may have been affected so they “can take sensible precautions”.

The information potentially accessed includes names, contact details, donation dates and amounts, and any correspondence on personal records. (BBC News and Emily Godwin / Arts Professional)

Related: Beacon CRM, Arts Professional, CSE.org, UK Med, SCVO, IWAI, Civil Society, Third Sector, The Register

China tightened its export controls on drones to the US and sanctioned multiple American companies, in a series of retaliatory measures against Washington’s widening tech curbs.

The Chinese Commerce Ministry announced four sets of countermeasures in response to recent US moves. It cited decisions including the Federal Communications Commission’s ban on some foreign-made robots and power inverters and the blacklisting of more than 40 Chinese companies accused of using forced labor.

The standoff now pitting Beijing against Washington is reviving tensions between the world’s two biggest economies and straining their fragile trade truce. Chinese President Xi Jinping is scheduled to meet Donald Trump in the US next month, after agreeing to build a relationship of “constructive strategic stability” during their summit in Beijing in May.

The US measures “seriously violated the important common understandings reached by the two heads of state and severely damage China’s legitimate rights and interests,” a spokesperson for the Commerce Ministry said in a statement. “China has no choice but to take necessary countermeasures in response.” (Bloomberg)

Related: Reuters, South China Morning Post

Over 102,000 private records belonging to Brazil’s health surveillance system were left online without passwords or basic encryption. Security researcher Jeremiah Fowler found this publicly accessible database and alerted cybersecurity firm ExpressVPN.

According to Fowler, this open database stored exactly 102,215 files (around 79GB). Further probing revealed that these records belong to Brazil’s Health Surveillance Information System (SISVISA). This is a crucial platform used by Brazilian health authorities to track public health rules, issue business permits, and manage inspections for hospitals, restaurants, and pharmacies.

While investigating, Fowler noted that anyone who found the web address could access folders without needing login credentials. These folders were labeled for backups, imports, documents, and uploads. Upon reviewing the files, he found a wide range of sensitive personal and government information.

Fowler sent quick warnings to several government offices after finding the exposed data, and public access was turned off shortly after that. However, no official ever replied to the warnings, so no one knows how long the files were left open or if anyone accessed them already. (Deeba Ahmed / HackRead)

Related: ExpressVPN

Screenshot of exposed data. Source: ExpressVPN.

The Open Secure AI Alliance proposed a set of guidelines for reporting cybersecurity incidents involving artificial intelligence agents, one week after the group was formed.

The proposal is called Shared AI Findings Exchange, or SAFE, and was published as a request for comments by the Linux Foundation. Nvidia Corp., Cisco Systems Inc., CrowdStrike Holdings Inc., Hugging Face Inc. and Red Hat Inc. led the drafting. Comments are being taken on GitHub.

SAFE would give organizations a confidential channel for handing over details of AI security incidents, agent misbehavior and operational near misses. The alliance would then analyze what it receives, notify the parties affected and flag control failures that keep recurring across its membership. Recommendations would follow, based on the incident evidence rather than on vendor guidance.

The alliance launched on July 27 with roughly two dozen founding members and now counts more than 120 organizations. Adobe Inc. and Cloudflare Inc. were in at the start. BlackRock Inc., Capital One Financial Corp., Intel Corp. and Visa Inc. are also on the roster. Anthropic PBC, OpenAI Group PBC and Google LLC have not joined. (Duncan Riley / Silicon Angle)

Related: NVIDIA, GitHub

The flaws were uncovered by Forescout’s Vedere Labs researchers, who published the full details at the Black Hat USA security conference earlier today.

Omada is TP-Link’s business networking product line that includes Wi-Fi access points, Ethernet and PoE switches, internet gateways, and VPN routers.

They are typically used by small to medium-sized businesses, although TP-Link also markets pro-grade deployments for enterprises.

ZTP is a way to deploy network devices without manually configuring each one on-site, allowing an IT team or managed service provider (MSP) to prepare everything remotely based on a predetermined configuration. (Bill Toulas / Bleeping Computer)

Related: Forescout, Omada, Industrial Cyber

Omada deployment diagram. Source: Forescout

According to email security company ZeroBEC, the Greatness phishing-as-a-service (PhaaS) platform has expanded from credential phishing to adversary-in-the-middle attacks and device-code phishing targeting Microsoft 365 accounts.

The platform has been active since at least mid-2022, targeting Microsoft 365 users in the United States, Canada, the UK, Australia, and South Africa.

Currently, it is sold for $289 per month to cybercriminals over a Telegram channel with thousands of subscribers.

The researchers found that Greatness operators abused the RingCentral communications platform to bypass email security filters on the recipient side.

RingCentral is a communications platform used by businesses for services such as cloud calling, messaging, and voicemail.

In the Greatness phishing activity, the attacker impersonated the platform by claiming their emails came from service@ringcentral[.]com, targeting actual users of the service.

These emails used fake voicemail and performance-review notifications as lures to entice recipients to open them.

Although the messages originated from an unknown IONOS mail server, failed SPF and DMARC checks, and had no DKIM signature, the receiving systems still accepted them because RingCentral was whitelisted.

Moreover, the emails included a fraudulent banner claiming that the sender had been verified by the organization’s safe-sender list, which helped reduce suspicion at the human level.

The researchers recommend auditing safe-sender lists and replacing blanket domain exclusions with rules requiring valid email authentication.

Also, hunt for Greatness infrastructure and suspicious MFA-approved Microsoft 365 sign-ins from hosting or VPN addresses.

If compromise is suspected, administrators should revoke all access and refresh tokens, review OAuth consent, Microsoft Graph activity, and access to Microsoft 365 services. (Bill Toulas / Bleeping Computer)

Related: ZeroBEC

Sample email spoofing RingCentral. Source: ZeroBEC.

Online retailer Coupang reported a larger-than-expected loss, underscoring the damage from a massive personal data leak that resulted in heavy administrative fines in South Korea, its primary market.

The US-listed company said it expects a hit to profitability in the months ahead from higher marketing costs. Ebitda margin will likely contract by 300 to 400 basis points in the third quarter, with margins in the mainstay product commerce segment only improving by mid-2027, it said. Coupang shares slid around 7.3% in after-hours trading.

“The shape of the recovery this year won’t move in a straight line,” Chief Executive Officer Bom Kim said during an earnings call. Next year, “we expect to work our way back to the growth and margin structure that product commerce ran at before.” (Yoolim Lee / Bloomberg)

Related: The Asia Business Daily, Korea JoongAng DailyThe Chosun Daily, Coupang

Third-party AI agent security company Obsidian Security announced it had raised $85 million in a Series D round.

Crescent Cove Advisors led the round with participation from existing investors including Greylock Partners and Menlo Ventures. (Akash Sriram / Reuters)

Related: Axios, Financial Post, SecurityWeek, FinTech Global, Silicon Angle, Security Week, Axios, Pulse 2.0, The Next Web, CityBiz

Runtime security startup Oligo Security announced it had raised $60 million in new funding to accelerate product innovation and expand global go-to-market operations.

Participating investors include Ballistic Ventures, Canon Capital, Greenfield Partners, Lightspeed Venture Partners, Red Dot Capital Partners, TLV Partners, and notable angel investors, such as Eyal Waldman, co-founder of Mellanox Technologies. (Duncan Riley / Silicon Angle)

Related: CTech, GlobesBusiness Wire, SecurityWeek, FinTech Global, Ynet News, Israel Defense

Best Thing of the Day: Reddit Moderators to the Rescue

As LLMs and Google increasingly rely on the sometimes-tainted but easily poisoned Reddit threads as authoritative sources when delivering answers, Reddit moderators are stepping in to cut out obvious manipulative posts.

Worst Thing of the Day: TikTok Did This Kid No Favors

When TikTok tweaked its algorithm in 2021 to stop users from being overwhelmed with harmful content, the company didn’t roll out the safer version to everyone, and 16-year-old Chase Nasca was bombarded with thousands of videos about suicide, sadness, hopelessness and loneliness, right up until he killed himself.

Closing Thought