# Metacurity > One-stop destination to end infosec news overload, scanned from thousands of sources Public Ghost content for AI and LLM tooling. Use `/llms-full.txt` for consolidated page and post context. Append `.md` to any post or page URL to get the content in Markdown (for example, `/example-post.md`). ## Pages - [About Metacurity](https://www.metacurity.com/about.md) - The making of a good compilation tape is a very subtle art. Many do’s and don’ts. First of all you’re using someone else’s poetry to express how you feel. This is a delicate thing. It is hard to do and takes ages longer than it might seem. You gotta kick off with a killer, to grab attention. Then y… - [Privacy Policy](https://www.metacurity.com/privacy-policy.md) - Effective date: November 29, 2025 DCT Associates (“us”, “we”, or “our”) operates the Metacurity website (https://www.metacurity.com) (the “Service”). This page informs you of our policies regarding the collection, use, and disclosure of personal data when you use our Service and the choices you hav… - [Reach an engaged, targeted cybersecurity audience by sponsoring Metacurity](https://www.metacurity.com/reach-an-engaged-targeted-cybersecurity-audience-by-sponsoring-metacurity.md) - Six days a week, Metacurity delivers carefully curated news, insights, and analysis directly to an elite audience of infosec leaders, technologists, journalists, and policymakers. Sponsors get more than just ad space — they become part of a trusted conversation with the cream of the cybersecurity c… - [Welcome to Metacurity!](https://www.metacurity.com/welcome-to-metacurity.md) - Welcome to Metacurity! You are going to love it here. ## Posts - [Trust under pressure: Best infosec long reads 8/8/26](https://www.metacurity.com/trust-under-pressure-best-infosec-long-reads-8-8-26.md) - Inside a multimillion-dollar phone scam, How a fringe censorship theory reshaped policy, When AI learns to replicate itself, Iran's fractured information ecosystem, The unfinished fight over digital privacy - [Kimi K3 escaped AI security sandbox during testing](https://www.metacurity.com/kimi-k3-escaped-ai-security-sandbox-during-testing.md) - ByteDance trains AI model to rival Anthropic, Vishing gang targets Wall Street firms with fake login sites, Violent crypto robberies put 2026 on record pace, Chinese router maker pulls devices after backdoor discovery, Spike in suicides alarms US Cyber Command, much more - [Updated: US Coast Guard is probing a cyberattack that disrupted North Carolina ports](https://www.metacurity.com/us-coast-guard-is-probing-a-cyberattack-that-disrupted-north-carolina-ports.md) - Meta undercuts AI coding rivals on price, Meta AI model breaches test containment, OpenAI agents built a secret message board, Snowflake hacker pleads guilty, Researchers crack AI browsers, Ransom Cartel mastermind gets 16 years, Chinese spyware goes commercial, DPRK hackers hit 1,600 orgs, more - [AI Watch: White House framework signals new era of AI oversight as security concerns intensify](https://www.metacurity.com/ai-watch-white-house-framework-signals-new-era-of-ai-oversight-as-security-concerns-intensify.md) - AI agents demonstrate increasingly sophisticated offensive capabilities, China warns US against expanding AI and technology curbs, Suspected cyberattacks target water utilities in at least 12 states, House report links telecom loopholes to Salt Typhoon breaches, much more - [AI Watch: AI security moves to Washington's center stage](https://www.metacurity.com/ai-watch-ai-security-moves-to-washingtons-center-stage.md) - White House AI testing framework arrives but key details remain secret, Congress probes OpenAI incident as calls for stronger AI oversight grow, China's open AI push fuels geopolitical debate, Banks press ahead with AI agents, US eyes China data center tech ban, much more. - [Water system cyberattacks widen as Trump rejects suspected Iran link](https://www.metacurity.com/water-system-cyberattacks-widen-as-trump-rejects-suspected-iran-link.md) - OpenAI finds additional AI agents escaped containment, Rogue AI hacks raise unprecedented liability questions, DeepSeek launches industry's cheapest frontier AI model, UK agency exposes officials' data in internal security lapse, Leaked database reveals China's surveillance of foreigners, much more - [Power plays in AI and cybersecurity: Best infosec long reads 8/1/26](https://www.metacurity.com/power-plays-in-ai-and-cybersecurity-best-infosec-long-reads-8-1-26.md) - The hacker who humbled spyware makers, China's new AI playbook, Do AI models really reason? The hidden danger of side-channel attacks, Inside Anthropic's legal battle - [Anthropic becomes the second frontier AI lab to disclose agent breaches](https://www.metacurity.com/anthropic-becomes-the-second-frontier-ai-lab-to-disclose-agent-breaches.md) - Copilot worm spreads through trusted Word documents, ExploitGym creators explain how OpenAI's agent escaped, Coordinated attacks signal a new threat to water utilities, Critical Azure Cosmos DB flaw threatened thousands of customers, CrimeStoppers put a bounty on the INC gang, much more - [ExfilSquad claims theft of 740,000 records from UK education, police databases](https://www.metacurity.com/exfilsquad-claims-theft-of-740-000-records-from-uk-education-police-databases.md) - Analog Devices probes ExfilSquad breach claim, UK report blames systemic failures for Afghan data leak, Senators urge Apple to shun Chinese memory chips, Australia sues Telegram over terror content, OpenAI breach sparks AI controls talk in Washington, much more - [OpenAI reveals broader AI agent campaign as Hugging Face publishes remarkable timeline](https://www.metacurity.com/openai-reveals-broader-ai-agent-campaign-as-hugging-face-publishes-remarkable-timeline.md) - Anthropic unveils encrypted AI breakthrough, AI workers demand global safety oversight, Zuckerberg doubles down on AI, Anthropic's AI safety stance draws fire, MCP gets its biggest overhaul yet, OpenAI open-sources Codex security tools, FCC bans new Chinese robots, power inverters, much more - [Nvidia launches AI safety coalition as open-weight debate intensifies](https://www.metacurity.com/nvidia-launches-ai-safety-coalition-as-open-weight-debate-intensifies.md) - MSFT launches AI cyber defense platform, Hugging Face rife with deepfake abuse, Cyberattack hits Minnesota water systems, Claude chats indexed by Google, Bank of Baroda probes leak, ShinyHunters claims EY breach, Apple sued over fake wallet app, Hack steals 293.7m SUPRA tokens, much more - [AI Watch: OpenAI's hacking agent breach signals a fracturing AI order](https://www.metacurity.com/ai-watch-openais-hacking-agent-breach-signals-a-fracturing-ai-order.md) - OpenAI missed rogue agent, Hugging Face breach reshapes open-v-closed AI, Firms abandon AI lab loyalty, Open-weight AI's Kubernetes moment, China pushes open-weight AI, Washington splits on Chinese AI, N. Korea expands its intelligence apparatus, much more - [The governance gap: Best infosec long reads 7/25/26](https://www.metacurity.com/the-governance-gap-best-infosec-long-reads-7-25-26.md) - AI incident reporting laws leave dangerous blind spots, Federal data consolidation raises surveillance fears, Russia's FSB embraces generative AI, Flock camera error triggers police stops, Why legacy OT malware won't die - [Russian hackers exploit Zimbra flaw to steal emails and bypass MFA](https://www.metacurity.com/russian-hackers-exploit-zimbra-flaw-to-steal-emails-and-bypass-mfa.md) - OpenAI probes AI-powered hack of Hugging Face, Bill would mandate AI kill switches, US to restrict visas for cybercriminals and families, Scam compounds expand despite Myanmar crackdown, Clop exploits Windchill flaw in extortion campaign, Dolphin X malware uses AI to rank victims, much more - [AI Watch: Hugging Face attack marks "day one" for AI agent cybersecurity](https://www.metacurity.com/ai-watch-hugging-face-attack-marks-day-one-for-ai-agent-cybersecurity.md) - Everest demands $12.3m from Swiss rail giant Stadler, Origin confirms customer data exposed in cyberattack, A third of ransomware victims face repeat extortion, Check Point patches actively exploited SmartConsole zero-day, Chaos ransomware uses browser traffic to evade detection, much more - [AI Watch: OpenAI details 'unprecedented cyber incident' behind Hugging Face breach](https://www.metacurity.com/ai-watch-openai-details-unprecedented-cyber-incident-behind-hugging-face-breach.md) - Frontier AI models routinely cheat on evaluations, Lightweight AI model for vulnerability hunting emerges, Google launches Gemini Flash Cyber for vulnerability detection and repair, Malware hides inside normal AI coding activity, US weighs sanctions over alleged Chinese AI model theft, much more - [AI Watch: China's AI surge is forcing DC and Silicon Valley to rethink the AI race](https://www.metacurity.com/ai-watch-chinas-ai-surge-is-forcing-dc-and-silicon-valley-to-rethink-the-ai-race.md) - US seizes 1,000+ piracy sites streaming World Cup matches, 7-Zip fixes critical RCE flaw, Attackers begin exploiting critical ServiceNow AI platform flaw, Millions of aftermarket car alarms can be hacked over Bluetooth, SonicWall zero-days used to deploy custom malware on VPN appliances, much more - [AI Watch: The AI agent that breached Hugging Face is a sign of things to come](https://www.metacurity.com/ai-watch-the-ai-agent-that-breached-hugging-face-is-a-sign-of-things-to-come.md) - EY notifies clients of tax data breach, Craneware discloses cyberattack, Ecopetrol says a cyberattack stole data from 3,300 accounts, Kenyan presidential website restored after ransom attack, Abbott probes two cybersecurity incidents, Hackers abuse ViPNet updates to target Russian orgs, much more - [Hidden systems, hidden risks: Best infosec long reads 7/18/26](https://www.metacurity.com/hidden-systems-hidden-risks-best-infosec-long-reads-7-18-26.md) - How an audacious server heist exposed the fragility of digital infrastructure, WhatsApp has quietly become an essential service, The NHS fought to keep sensitive health data out of Palantir's hands, Thomson Reuters' ICE surveillance problem, Why AI slop threatens open-source software - [Moonshot's Kimi K3 raises stakes in battle over AI vulnerability-hunting models](https://www.metacurity.com/moonshots-kimi-k3-raises-stakes-in-battle-over-ai-vulnerability-hunting-models.md) - DHS seizes 30K SIM cards in anti-fraud crackdown, Coca-Cola's Fairlife ransomware attack disrupts US production, US charges pair in $43m cyber scam laundering ring, Police use Flock cameras to search for people, Italian telecom fined €1.7mover data breaches, much more - [Hackers post alleged blueprints and supplier data from India nuclear project](https://www.metacurity.com/hackers-post-alleged-blueprints-and-supplier-data-from-india-nuclear-project.md) - TfL hackers sentenced to 5½ years in prison, Hacking suspect once worked at Kaspersky, OpenAI unveils AI-powered red teaming tool, Ransomware attack disrupts Japan’s food supply chain, Qantas cleared after social-engineering breach, Health provider criticized for delayed breach disclosure, much more - [US indicts three Russians tied to sanctioned bulletproof hoster, offers $10 million reward](https://www.metacurity.com/us-indicts-three-russians-tied-to-sanctioned-bulletproof-hoster-offers-10-million-reward.md) - Microsoft patches record 570 flaws, including two exploited zero-days, White House launches AI vulnerability-sharing hub dubbed Gold Eagle, Oracle leads race to build Japan’s top-secret cloud infrastructure, Finnish hacker Kivimäki wanted after losing final appeal, much more - [Western allies pair Russia sanctions with a warning on critical infrastructure attacks](https://www.metacurity.com/western-allies-pair-russia-sanctions-with-a-warning-on-critical-infrastructure-attacks.md) - UK charges five over Russian Coms spoofing platform, Treasury sanctions VPN provider tied to ransomware gangs, DHS missed warning signs before credential theft breach, Cyberattacks targeted US personnel through Mideast mobile networks, Korean police uncover large-scale GitHub token leak, much more - [AI's new battleground: Cost, efficiency, and control](https://www.metacurity.com/ais-new-battleground-cost-efficiency-and-control.md) - AI vendors pivot from capability to cost, OpenAI eases GPT-5.6 usage limits, Enterprises scrutinize soaring AI bills, Chinese AI models gain enterprise traction, Anthropic data reveals how AI gets used, AI agents tackle business ops workloads, Open-source AI faces mounting policy pressure, much more - [Trust under attack: Best infosec long reads 7/11/26](https://www.metacurity.com/trust-under-attack-best-infosec-long-reads-7-11-26.md) - Inside the TfL hack, The cyber war game nobody wants to play, AI's toughest test case, When anti-piracy breaks the internet, The protocol that changed the internet, Why prompt injection won't go away - [OpenAI launches GPT-5.6 as AI vendors compete for enterprise users](https://www.metacurity.com/openai-launches-gpt-5-6-as-ai-vendors-compete-for-enterprise-users.md) - Federal investigators say DOGE records were deleted, Europe revives voluntary message scanning, Britain plans AI-powered cyber defense system, Chinese and Indian hackers target Pakistani police, AI gateway compromise leads to cryptomining, Ransomware negotiator sentenced to 70 mos., much more - [AI watch: AI companies are building digital workers, and attackers may benefit too](https://www.metacurity.com/ai-watch-ai-companies-are-building-digital-workers-and-attackers-may-benefit-too.md) - Interpol fraud crackdown nets 5,800 arrests and $293m, Fake Brazilian police station discovered in African scam operation, Mystery zero-day broker tied to convicted fraudsters, AssuranceAmerica breach exposes 6.9m driver’s license numbers, much more - [AI watch: Washington, Beijing, and Brussels shape AI's future](https://www.metacurity.com/ai-watch-washington-beijing-and-brussels-shape-ais-future.md) - Spain arrests man suspected of CyberArmy of Russia membership, Predator spyware victims seek €1m each in Greek lawsuit, CISA incident reporting rule expected in Sept., Ransomware exposed student and employee data at Mount Royal University, Accenture confirms breach, much more - [AI watch: Chinese competition, government adoption, and new regulations pressure AI leaders](https://www.metacurity.com/ai-watch-chinese-competition-government-adoption-and-new-regulations-pressure-ai-leaders.md) - Canada details offensive cyber ops, US cloud providers challenge Korean security rules, KDDI confirms breach affecting millions, Judge keeps Weiss hacking case alive, BonkDAO loses $20m in governance attack, Crypto wallet flaw exposed millions to theft, Ctrl Wallet shutters after incident, much more - [EU lawmaker investigating Pegasus abuse was hacked with Pegasus spyware](https://www.metacurity.com/eu-lawmaker-investigating-pegasus-abuse-was-hacked-with-pegasus-spyware.md) - FBI disrupts NetNut-linked proxy infrastructure, Russian hackers expose UK gov't credentials, India probes iPhone 18 Pro supply-chain leak, UK minister compares AI risks to Hiroshima, Sanctioned states increasingly rely on crypto, First fully AI-run ransomware attack spotted, much more - [AI guardrails under fire from researchers and regulators](https://www.metacurity.com/ai-guardrails-under-fire-from-researchers-and-regulators.md) - Scattered Spider suspect extradited to US, House panel accuses Korea of targeting Coupang, cyberattack hits Malaysian parking app, Aflac Japan breach affects 4.4M customers, AI agent carries out extortion attack, Ukraine stops 16K Russian cyberattacks, ChocoPoC RAT hides in GitHub PoCs, much more. - [Anthropic restores Fable 5 and Mythos 5, launches Sonnet 5](https://www.metacurity.com/anthropic-restores-fable-5-and-mythos-5-launches-sonnet-5.md) - China's Mythos rival fuels AI arms race. Taiwan probes claimed PChome hack, Alberta voter leak sparks lawsuit, Hackers breach DHS sharing network, Apple privacy feature exposes emails, Adobe fixes critical ColdFusion bugs, Crypto thieves stole $76m in June, much more - [Apple faces supply chain leak as AI threats accelerate security updates](https://www.metacurity.com/apple-faces-supply-chain-leak-as-ai-threats-accelerate-security-updates.md) - Meta secretly benchmarked rival chatbots with fake teen accounts, S.Ct. curbs warrantless geofence searches, Google warns EU competition rules could weaken security, Russia shifts influence operations toward the West, Amazon settles identity theft records case for $2.25m, much more - [Washington pushes AI into an export-control era as rivals rush to fill the gap](https://www.metacurity.com/washington-pushes-ai-into-an-export-control-era-as-rivals-rush-to-fill-the-gap.md) - Anthropic regains limited Mythos 5 access for government-vetted US organizations, OpenAI launches GPT-5.6 under gov't preview, Zhipu AI's GLM-5.2 nears Mythos-level cybersec performance, 360 Security says it has achieved Mythos-style vulnerability discovery, much more - [The new architecture of power: Best infosec long reads 6/27/26](https://www.metacurity.com/next-long-read-11.md) - The UK's untrustworthy crime prediction machine, Scattered Spider didn't attack Jaguar Land Rover, A powerful new side channel attack, Trump's AI order may not be so voluntary, AI-generated malware can dodge signature-based detection - [US tightens oversight as AI moves deeper into cyber, warfare and media](https://www.metacurity.com/us-tightens-oversight-as-ai-moves-deeper-into-cyber-warfare-and-media.md) - Russia kept using Cellebrite after sales ban, $3m stolen in Polymarket phishing attack, Poland busts SIM-swapping gang behind crypto thefts, Suspected Iranian hacker arrested in Montenegro, AYA Bank confirms limited data leak, Cyberattack knocks Ukrposhta mobile app offline, much more - [Frontier AI Beat: AI security becomes a geopolitical arms race](https://www.metacurity.com/frontier-ai-beat-ai-security-becomes-a-geopolitical-arms-race.md) - Microsoft uses AI to link malware groups in RICO case, Ukraine exposes Russian messenger hacking, Nation-state hackers mapped CI for sabotage, DPRK-linked election attacks surge 68-fold, DraftKings hacker 'Snoopy' gets 18 months, ICE surveillance spending hits record high, much more - [Frontier AI beat: NSA locked out, Meta pressured, lawsuits begin](https://www.metacurity.com/frontier-ai-beat-nsa-locked-out-meta-pressured-lawsuits-begin.md) - Dialog's "hack" looks more like a misconfiguration, Klue breach spills more LastPass customer data, Iranian banking services hit by fresh cyber disruption, India's Bajaj Auto hit by ransomware attack, KDDI warns 14m accounts may be exposed, much more - [Admin accelerates quantum push, advances timeline for quantum-safe security](https://www.metacurity.com/admin-accelerates-quantum-push-advances-timeline-for-quantum-safe-security.md) - Five Eyes warn AI cyber threat is months away, Tata breach exposes Apple and Tesla files, OpenAI launches Patch the Planet initiative, Meta pauses employee AI data collection after exposure, Two plead guilty in £39m TfL cyberattack, Texas probes Carnival breach affecting 6 million customers, more - [Anthropic watch: US government dispute becomes AI governance fight](https://www.metacurity.com/anthropic-watch-us-government-dispute-becomes-ai-governance-fight.md) - Operation Endgame wipes SocGholish infrastructure, Hackers hijack Brazil emergency alert system, London Hydro breach exposes customer data, Data breach in Korea exposes 5,000 startup applications, Acworth investigates cyberattack on city systems, much more - [The industrialization of manipulation: Best infosec long reads 6/20/26](https://www.metacurity.com/the-industrialization-of-manipulation-best-infosec-long-reads-6-20-26.md) - AI is turbocharging deepfake porn, How the Yahoo Boys industrialized romance scamming, The scary assessment of a deepfake expert, When cyberbullying blurs into domestic terrorism, Poisoned content can shape deep research AI agents - [Anthropic watch: Dispute widens as customers, allies and investors react](https://www.metacurity.com/anthropic-watch-dispute-widens-as-customers-allies-and-investors-react.md) - Bulgarian spyware firm sold tools to repressive regimes, The Gentlemen claims attack on sugar mills, FortiBleed exposes 73k Fortinet VPN credentials, Startup competition leak exposes 5k applicants, Canada spy agency disrupted botnets, Fake YouTube gurus spread crypto-stealing malware, much more - [Anthropic watch: Congress scrambles, Europe recoils, and Anthropic's halo grows brighter](https://www.metacurity.com/anthropic-watch-congress-scrambles-europe-recoils-and-anthropics-halo-grows-brighter.md) - Leak exposes members of Peter Thiel's secretive power network, Cybercrime now accounts for a third of crimes in parts of Asia, France picks local rival to replace Palantir at spy agency, Americans lost $3.5B to imposter scams last year, Hackers hijack Roblox games by seizing dev accounts, much more - [Why the White House turned on Anthropic](https://www.metacurity.com/why-the-white-house-turned-on-anthropic.md) - Chinese spies hid in research networks for two years, Copilot bug let attackers steal Microsoft 365 data, Crypto scammers now send couriers for cash, Judge keeps Meta AI scraping lawsuit alive, Feds dismantle $389m crypto laundering op, iRhythm reports breach after extortion demand, much more - [Section 702 Expires, but the US Isn't Going Dark](https://www.metacurity.com/section-702-expires-but-the-us-isnt-going-dark.md) - Feds seize major deepfake porn sites, Cyberattack disrupts services at four major Iranian banks, Trump orders cybersecurity overhaul for national security systems, Conti ransomware coder pleads guilty in US case, Chinese spies hid in critical infrastructure network for a decade, much more - [Special report: Anthropic and the first great AI cyber showdown — a timeline](https://www.metacurity.com/special-report-anthropic-and-the-first-great-ai-cyber-showdown-a-timeline.md) - Over the past few days, a dispute over AI safety guardrails escalated into a White House crackdown, a global sovereignty debate, and the first major clash between frontier AI cyber capabilities and government authority. - [Innovation is easy, but adaptation is hard: Best infosec long reads 6/13/26](https://www.metacurity.com/next-long-read-10.md) - How a doll sparked an international security scandal, Smart home technology erodes our privacy and autonomy, We need 'Operation Warp Speed' for AI, Security and not speed should be uppermost in US-AI China race, Ditch cyber checklists in favor of engineered resilience - [Google sues AI-powered scam ring behind fake carrier rewards texts](https://www.metacurity.com/google-sues-ai-powered-scam-ring-behind-fake-carrier-rewards-texts.md) - Oracle warns of critical PeopleSoft flaw, Israeli firm suspected of election interference in France, Scotland and New York, Authorities dismantle crypto laundering service tied to ransomware gangs, Novo Nordisk discloses breach involving clinical trial patient data, much more - [Coupang hit with record $409 million fine over massive insider-driven data breach](https://www.metacurity.com/coupang-hit-with-record-409-million-fine-over-massive-insider-driven-data-breach.md) - CISA orders faster patching as AI speeds exploitation, Suspected Russian hacker extradited to the US over Void Blizzard, OpenAI disrupts China-linked campaigns targeting US tech debates, Digital breadcrumbs lead to alleged leader of The Gentlemen, much more - [Anthropic releases Mythos-derived model with cyber guardrails](https://www.metacurity.com/anthropic-releases-mythos-derived-model-with-cyber-guardrails.md) - Admin halts AI safety reports amid fight over oversight, Microsoft patches record 200 flaws as AI fuels bug discovery, Nightmare Eclipse drops fresh Windows zero-day, China's hackers target tech firms as AI race intensifies, Social media overtakes email as top attack channel, much more - [Meta moves to hold NSO in contempt over WhatsApp attacks](https://www.metacurity.com/meta-moves-to-hold-nso-in-contempt-over-whatsapp-attacks.md) - UK threatens tech firms over child sexting, Microsoft disables GitHub repositories after AI tool malware attack, Pentagon adds Alibaba, Baidu to China military-linked list, Anthropic says AI can turn vulns into exploits in hours, Check Point fixes critical VPN flaw under active attack, much more - [Zcash tumbled after disclosure of critical counterfeiting flaw](https://www.metacurity.com/zcash-tumbled-after-disclosure-of-critical-counterfeiting-flaw.md) - 20k Instagram accounts hacked in attack that abused AI tool, Router flaw powers rise of shape-shifting C0XMO botnet, Ransomware gang sends fake IT staff into victim offices, ShinyHunters-linked leak exposes millions of DentaQuest records, Chinese cyber spies hid in Microsoft 365 for 18 months, more - [The future of cyber arrives, but old failures persist: Best infosec long reads 6/6/26](https://www.metacurity.com/the-future-of-cyber-arrives-but-old-failures-persist-best-infosec-long-reads-6-6-26.md) - Hackers turned women's medical procedures into cyber terror, How new techniques defeat anti-jamming technology, An AI-powered worm is now a reality, A novel cryptographic technique can create more security verification, The US should focus on remaining more secure in its tech race with China - [Anthropic: AI is advancing too fast to leave unchecked](https://www.metacurity.com/anthropic-ai-is-advancing-too-fast-to-leave-unchecked.md) - Whistleblower says IBM and AT&T hid repeated attacks from foreign hackers, Anthropic engineers are embedded in NSA, Hegseth is still determined to block Anthropic, Cloudflare CEO says agentic bots outnumber humans online, New threat group Pink uses voice phishing and fake help-desk calls, much more - [Five Eyes issues unusual warning on China's online recruitment tactics](https://www.metacurity.com/6a205e53dc19480001f9b05b.md) - Meta AI's chatbot hacking seems to have continued, OpenAI asks for mandatory models' evaluations, CISA to release AI directive tomorrow, Mullin wants CISA to hire 600 more personnel, Hackers accessed Ultrahuman's customer data, Peptide promoters seek to poison chatbots by Reddit postings, much more - [Trump backs voluntary AI model reviews in cybersecurity-focused executive order](https://www.metacurity.com/trump-backs-voluntary-ai-model-reviews-in-cybersecurity-focused-executive-order.md) - Anthropic expands Mythos distribution to 150 orgs, Researchers devise AI worm capable of creating internet chaos, Trump picks Pulte for intel czar post, Las Vegas Station Casinos was hit with a breach, Cyberattack exposed 600k food-deprived households in Gaza, much more - [Meta AI support flaw fueled a wave of Instagram takeovers](https://www.metacurity.com/meta-ai-support-flaw-fueled-a-wave-of-instagram-takeovers.md) - Russia says a large-scale spyware campaign by foreign intel targeted its high-ranking officials, Anthropic to give ENISA access to Mythos, Two men charged in nearly $8m BEC scam in NJ, 30+ npm Red Hat packages compromised in new 'Miasma' Shai-Hulud scheme, much more - [DOGE-aligned White House web projects funnel citizen data to analytics firm](https://www.metacurity.com/doge-aligned-white-house-web-projects-funnel-citizen-data-to-analytics-firm.md) - Microsoft's threat to security researcher draws criticism, Commerce IG says NIST has mismanaged NVD, Obama White House Instagram was hacked, Teen researcher flagged flaws in India's school exam board website, Gravity Bridge exploited for $5.4m, DxSale legacy site hacked for $7.3m, much more - [Verifying reality: Best infosec long reads 5/30/26](https://www.metacurity.com/verifying-reality-best-infosec-long-reads-5-30-26.md) - TP-Link is fighting for its life, Quantum's threat to RSA encryption could be soon, How Russia's GPS spoofing could destroy us all, How cops and the courts relied on a stalker's digital evidence, The safety and security risks of AI distillation - [California says 23andMe ignored basic security before 7 million-user breach](https://www.metacurity.com/california-says-23andme-ignored-basic-security-before-7-million-user-breach.md) - Dutch cops bust up 200-server cybercrim botnet, Law firm Weil reportedly paid Silent Ransom Group $20m, Stress tests show Grok is the AI model most likely to commit crimes, Anthropic will release Mythos models to the public, GreyVibe uses AI-generated lures, much more - [Centcom: US war zone troops were targeted through commercial location data](https://www.metacurity.com/centcom-us-war-zone-troops-were-targeted-through-commercial-location-data.md) - Canada signals flexibility as tech giants fight surveillance bill, Canadian lands 30 years for child sextortion scheme, Romanian sentenced to 56 months for Oregon gov't, other hacks, Germany and France fight EC's ban of Huawei on cyber grounds, much more - [UK spy chief warns of escalating Russian cyber aggression](https://www.metacurity.com/uk-spy-chief-warns-of-escalating-russian-cyber-aggression.md) - India's banking and government institutions are testing Mythos, Charter confirms breach claimed by ShinyHunters, Play ransomware gang hit Mike Lindell's MyPillow, Fake UK visa portal exposes passports and selfies, CrowdStrike shuttered C2 for Glassworm botnet, much more - [White House seeks $9 billion AI chip surge for US spy agencies to tap AI models](https://www.metacurity.com/white-house-seeks-9-billion-ai-chip-surge-for-us-spy-agencies-to-tap-ai-models.md) - Russian penetration of US systems during SolarWinds breach was deeper than we knew, Mythos Preview users found more than 10k severe vulnerabilities, Iranian hackers were behind the LA transit system breach, Former execs plead guilty to tech support fraud scheme, much more - [Losing control of the systems meant to secure society - Best infosec long reads 5/23/26](https://www.metacurity.com/losing-control-of-the-systems-meant-to-secure-society-best-infosec-long-reads-5-23-26.md) - France grapples with an unprecedented wave of data breaches, AI voice systems can be manipulated with malicious audio, Big Tech is backing a massive spying operation in Seattle, Russia overreached on the cybercrime convention, Framing AI as an arms race threatens safety and accountability - [Trump AI order dramatically collapses after Sacks-led revolt over cyber oversight](https://www.metacurity.com/trump-ai-order-dramatically-collapses-after-sacks-led-revolt-over-cyber-oversight.md) - EU cops dismantle cybercriminals' favorite VPN service, Edmonton partnered with ethical 'scam baiters' to stop $42m in losses, Kimwolf builder Dort arrested in Canada, The Kremlin hijacked Bluesky accounts in influence op, Google accidentally leaked details about unfixed Chromium issue, much more - [Trump prepares to sign AI cyber order today amid Mythos alarm](https://www.metacurity.com/trump-prepares-to-sign-ai-cyber-order-today-amid-mythos-alarm.md) - Cybercom to speed AI tools use, Hacker accessed GitHub repos via TanStack-compromised Nx Console VS Code extension, Ukraine cops bust 18-year-old for running infostealer op, S. Korean cops bust 32 for stealing bigwigs' financial data and PII, Microsoft issues patches for Defender flaws, much more - [GitHub says malicious VS Code extension compromised 3,800 internal repositories](https://www.metacurity.com/github-says-malicious-vs-code-extension-compromised-3-800-internal-repositories.md) - White House release of EO on cyber and AI safety is imminent, Microsoft took down malware service Fox Tempest, A bug in a Huawei enterprise router caused Luxembourg telecoms outage last year, Mini Shai-Hulud malware resurfaces across hundreds of npm packages, much more - [Anthropic eases threat-sharing rules as Cloudflare details frontier AI cyber gains](https://www.metacurity.com/anthropic-eases-threat-sharing-rules-as-cloudflare-details-frontier-ai-cyber-gains.md) - CISA contractor exposed sensitive gov't creds in public GitHub repo, Buterin says AI-assisted formal verification can secure blockchain systems, NY public health provider says breach affects 1.8m, FBI wants access to ALPRs nationwide, Interpol busts 200+ people for cybercrime in MENA, much more - [Leaders warn that AI bug hunting outpaces humanity’s ability to defend systems](https://www.metacurity.com/leaders-warn-that-ai-bug-hunting-outpaces-humanitys-ability-to-defend-systems.md) - Malware strain Fast16 sabotaged nuclear weapons development years before Stuxnet surfaced, Grafana Labs rejected hackers' extortion demand, DeFi protocol Verus lost nearly $12m in ongoing exploit, Hotel check-in system left 1m passports exposed, Gas station gauge systems hacked, much more - [AI and the collapse of authenticity: Best infosec long reads 5/16/26](https://www.metacurity.com/ai-and-the-collapse-of-authenticity-best-infosec-long-reads-5-16-26.md) - AI has industrialized identity theft, Copyright law can remove nonconsensual AI porn, Anthropic might not appreciate that 'Mythos' came from H.P. Lovecraft's horror tales, How to solve AI's falsehood problems, Computationally unknowable mathematical proofs can create a new cryptographic technique - [AI bug hunters expose new weak point in Apple’s locked-down macOS](https://www.metacurity.com/ai-bug-hunters-expose-new-weak-point-in-apples-locked-down-macos.md) - Shai-Hulud attack campaign hit two OpenAI employees, Hackers unwisely targeted Amnesty International's Security Lab chief, US and China to discuss AI guardrails, Anthropic warns of CCP AI dominance, DPRK's APT 37 is now posing as cops, MSFT warns of severe XSS flaw for Outlook web users, much more - [AI cyber skills now doubling in months, not years](https://www.metacurity.com/ai-cyber-skills-now-doubling-in-months-not-years.md) - Microsoft's AI-driven MDASH system discovered 16 new Windows vulnerabilities, France's Mistral AI competes with Mythos for European banks, Dream Market admin busted by German and US cops, Shadowy firm BlackCore probed for French election interference, Signal to exit Canada if C-22 passes, much more - [OpenAI gives advanced cyber models to European defenders](https://www.metacurity.com/openai-gives-advanced-cyber-models-to-european-defenders.md) - Anthropic denied Chinese think tank Mythos access, Pentagon will use Mythos while moving ahead with Anthropic ban, House panel wants Instructure hearing, Nitrogen group hit Foxconn with cyberattack, West Pharmaceutical Services hit with ransomware, Microsoft issues 120 Patch Tuesday fixes, much more - [Instructure forms deal with ShinyHunters who promise to destroy stolen Canvas data](https://www.metacurity.com/instructure-reaches-deal-with-shinyhunters-who-promise-to-destroy-stolen-canvas-data.md) - US intel agencies want to evaluate AI model while Commerce seems to back away, OpenAI launches cybersecurity model Daybreak, Euro countries sell spyware to rights violators, Binance claims AI system saved $10b in scam losses, Shai-Hulud supply-chain campaign compromised npm and PyPi packages, more - [Pre-release discount: Practical risk management using the NIST CSF 2.0](https://www.metacurity.com/pre-release-discount-practical-risk-management-using-the-nist-csf-2-0.md) - The NIST 2.0 Cybersecurity Framework delivers clear guidance on applying the gold standard NIST framework in complex, real-world situations. - [Hackers turned to AI in attempted mass cyberattack, Google reveals](https://www.metacurity.com/hackers-turned-to-ai-in-attempted-mass-cyberattack-google-reveals.md) - Trump's planned AI-enabled cyber EO stops short of requirements, German authorities shut down relaunched Crimenetwork, L3 Trenchant zero-day peddling exec order to pay $10m, Poland has thwarted many Russian sabotage efforts, IMF warns of financial shock from AI-enabled cyberattacks, much more - [How ordinary tech becomes surveillance infrastructure: Best infosec long reads 5/9/26](https://www.metacurity.com/next-long-read-9.md) - How Israeli telecom networks were used for surveillance, Everyday objects are now surveillance devices, AI's risks demand careful human oversight, Hackers can take over smart lawn mowers' cameras and controls, Fears of AI tap into old cultural stories - [Canvas chaos: ShinyHunters breach throws schools into disarray](https://www.metacurity.com/canvas-chaos-shinyhunters-breach-throws-schools-into-disarray.md) - Firefox bug fixes soar after using Mythos, Virginia man found guilty of destroying government databases, OpenAI rolls out GPT 5.5 to vetted cyber defenders, PCPJack steals cloud creds while removing TeamPCP access, Ivanti urges patches for Endpoint Manager Mobile (EPMM) zero day bug, much more - [Russia’s hidden hacker academy exposed in massive document leak](https://www.metacurity.com/russias-hidden-hacker-academy-exposed-in-massive-document-leak.md) - US-China weigh AI risk talks, Wiles says Trump won’t pick AI winners, Vibe-coded apps lack security, GothFerrari fraudster gets 78 months, MuddyWater masks ops as Chaos ransomware, Phishing hits ManageWP via Google-sponsored search ads, Japan urges CI to do cyber better, much more - [US taps Microsoft, Google, xAI for pre-release AI testing as threat worries grow](https://www.metacurity.com/us-taps-microsoft-google-xai-for-pre-release-ai-testing-as-threat-worries-grow.md) - FTC to ban Kochava from selling location data, State officials urge AI companies to include them in early-access testing, CISA wants CI firms to plan for essential service disconnection, DAEMON Tools software delivered backdoor to thousands, Breach forced Coupang to lose money, much more - [Trump eyes AI crackdown after hands-off push falters](https://www.metacurity.com/trump-eyes-ai-crackdown-after-hands-off-push-falters.md) - EU is talking with Anthropic to test banks with Mythos, DHS intelligence office staff failed to secure smartphones, A Latvian was sentenced to 8.5 years for role in Karakurt ransomware, A Romanian was indicted for bank fraud scheme dating to 2009, CISA unveils CI Fortify for CI entities, much more - [Five Eyes warn that agentic AI is already in critical systems—and security isn’t keeping up](https://www.metacurity.com/five-eyes-warn-that-agentic-ai-is-already-in-critical-systems-and-security-isnt-keeping-up.md) - Trellix hit by significant breach, 15-year-old was busted for French gov't hack, CISA warns of Copy Fail exploits in the wild, Defender flags some legit DigiCert root certs as malware, Sri Lanka arrests 37 Chinese cyberscam operators, US health insurance exchanges share data with big tech, much more - [The new infosec battleground is human: This week's best infosec long reads 5/2/26](https://www.metacurity.com/the-new-infosec-battleground-is-human-this-weeks-best-infosec-long-reads-5-2-26.md) - Journalist surveillance is a global industry, China retaliated against reporters through surveillance, AI jailbreaking takes a toll on the soul, Fraudsters targeted vulnerable immigrants, DHS has built a vast surveillance system, Memory-safe programming languages are critical to AI attack defense - [GPT-5.5 aces UK cyber trials, tops rivals in AISI tests](https://www.metacurity.com/gpt-5-5-aces-uk-cyber-trials-tops-rivals-in-aisi-tests.md) - NSA is testing Mythos, Anthropic publishes Claude Security for Claude Enterprise, Flock spied on a kid's gym room, DPRK hackers have stolen $577m in crypto year-to-date, Rhysida demands ransom from Stelia Aerospace NA, Two ransomware negotiators sentenced to prison, much more - [Nine Dubai scam centers raided in joint US-China operation, 276 arrested](https://www.metacurity.com/nine-dubai-scam-centers-raided-in-joint-us-china-operation-276-arrested.md) - White House opposes Anthropic's expansion of Mythos access, Oz government warns banks on AI cyberattacks, Ukraine arrests three people who allegedly hacked 610k+ Roblox accounts, European celebrity exposed cloud repo with 90k stalkerware screenshots, Chinese hackers breached Cuba's embassy, more - [Scattered Spider’s ‘Bouquet’ nabbed after globe-trotting luxury hacker spree](https://www.metacurity.com/scattered-spiders-bouquet-nabbed-after-globe-trotting-luxury-hacker-spree.md) - White House is trying to get Anthropic back on board while lawmakers come up to speed, Paragon not cooperating with Italian prosecutors, Polymarket denies breach reports, Syndicate was hacked for about $400k, FIDO Alliance forms AI agent standards groups, Vimeo admits breach through, much more - [Social media scams cost Americans $2.1 billion — and Facebook leads the pack](https://www.metacurity.com/social-media-scams-cost-americans-2-1-billion-and-facebook-leads-the-pack.md) - Medtronic hit by cyberattack, Toronto cops busted three people in connection with SMS blasters, Handala claims to have stolen personal info on 2,379 US Marines, Google agrees to Pentagon's anything goes for its AI but employees beg it not to, New BlackFile data theft group emerges, much more - [Italy hands alleged Chinese hacker to US, drawing Beijing’s protest](https://www.metacurity.com/italy-hands-alleged-chinese-hacker-to-us-drawing-beijings-protest.md) - FCC says router ban to cover Wi-Fi hotspots, German gov't blames Russia for phishing attacks, S.Ct. to hear geofence warrant case, Manitoba to ban youth from social media, ADT confirms data breach after ShinyHunters threat, US possible culprit in Venezuelan oil firm cyberattack, much more - [Best infosec long reads 4/25: Power moves fastest where institutions fail](https://www.metacurity.com/next-long-read-8.md) - Cybercrime has been very good to Cambodia, GrapheneOS is a triumph and a cautionary tale, Satellite signals can evade state information controls, AI tools create child exploitation risks, No excuse to delay creating a US Cyber Force - [China’s hackers hide in plain sight through hijacked home routers, allies warn](https://www.metacurity.com/chinas-hackers-hide-in-plain-sight-through-hijacked-home-routers-allies-warn.md) - US charges two accused of running major scam compound, White House accuses China of stealing AI property on 'industrial scale,' Stuxnet-like code was used in mid-2000s, Health info from UK Biobank was posted for sale in China, Indian media giant was hacked by an alleged Afghan group, much more - [Plankey pulls out after a year-long CISA director confirmation stall](https://www.metacurity.com/plankey-pulls-out-after-a-year-long-cisa-director-confirmation-stall.md) - Chinese cyber firm is looking to compete with Anthropic, 100+ companies have cyber intrusion software, OpenAI lobbied US agencies on its new cyber model, Cybercrims hacked phone of Bundestag President, Sri Lanka's Finance Ministry was hacked, Dutch cosmetics giant Rituals was breached, more - [Mythos model slips into the wild through vendor backdoor](https://www.metacurity.com/mythos-model-slips-into-the-wild-through-vendor-backdoor.md) - Mozilla says Mythos ID'ed 271 vulnerabilities, Australia, New Zealand and Japan are monitoring Mythos, NCSC chief warns of a perfect storm of cyberattacks, Supplier attack exposes exposed details of potential school shooters and bullies, Former FBI cyber chief calls ransomware terrorism, much more - [Ransomware negotiator cops to conspiring with cybercrims against US companies](https://www.metacurity.com/ransomware-negotiator-cops-to-conspiring-with-cybercrims-against-us-companies.md) - NSW official charged in data breach involving sensitive documents, UK man faces 22 years in US prison for $8m hacking scheme, French gov't identity website hack might have exposed users' data, Bundesbank president wants level playing field for Mythos, Lovable downplays data exposure, much more - [White House opens backchannel to Anthropic as Pentagon fight simmers](https://www.metacurity.com/white-house-opens-backchannel-to-anthropic-as-pentagon-fight-simmers.md) - Anthropic gave NSA access to Mythos Preview, Anthropic's donation to open source developers highlights how under-sourced they are, Asian regulators urge banks to use Mythos, LayerZero-powered cross-chain bridge Kelp DAO lost $292m in DPRK exploit, much more - [Best infosec long-reads 4/18: The gap between capability and accountability is widening](https://www.metacurity.com/best-infosec-long-reads-4-18-the-gap-between-capability-and-accountability-is-widening.md) - Why Anthropic decided to keep Mythos under wraps, Iran adopted locally resonant narratives to exploit Irish political tensions, Sexual deepfakes are the scourge of schools, How insider risk and supply chain compromise afflicted twenty-something billionaires, MSG's owner is obsessed with surveillance - [Anthropic’s Mythos heads toward federal use as Hegseth's ban falters](https://www.metacurity.com/anthropics-mythos-heads-toward-federal-use-as-hegseths-ban-falters.md) - Anthropic releases Claude Opus 4.7, which can develop exploit code too, Financial officials fear AI models could threaten global banking, Russian crypto exchange Grinex suspends ops after $13m loss in cyber incident, DraftKings hacker sentenced to 30 months, much more - [Overwhelmed by vulnerability surge, NIST scales back NVD coverage](https://www.metacurity.com/overwhelmed-by-vulnerability-surge-nist-scales-back-nvd-coverage.md) - US nationals head to prison for aiding fake DPRK IT workers, Anthropic publishes Claude ID verification requirements, New ransomware attacks target S. Korean SMEs, New adware tool delivers system privileges that disable AV protections, Critical flaw in Nginx UI with MCP exploited, much more - [US agencies court Anthropic AI for cyber defense despite Pentagon ban](https://www.metacurity.com/us-agencies-court-anthropic-ai-for-cyber-defense-despite-pentagon-ban.md) - OpenAI launches private test of its Mythos rival, Russian cyber group targeted a Swedish thermal power plant, Microsoft fixes 167 flaws on Patch Tuesday, Fake Ledger site linked to $9.5m crypto theft, McGraw-Hill hacked via Salesforce misconfiguration, much more - [Allies warn of cyber divide as US firms gatekeep powerful Mythos AI](https://www.metacurity.com/allies-warn-of-cyber-divide-as-us-firms-gatekeep-powerful-mythos-ai.md) - Goldman Sachs is working closing with Mythos to protect itself, UK's AISI tested Mythos which excelled over other models, Bain & Co. was easily exposed by pentesters, Kraken suffered two insider security incidents, EU to abandon Chinese inverters, much more - [ShinyHunters hits Rockstar Games, threatens data dump after cloud breach](https://www.metacurity.com/shinyhunters-hits-rockstar-games-threatens-data-dump-after-cloud-breach.md) - Basic-Fit data breach exposes data on 1m+ members, Operation Atlantic disrupted $45m pig butchering network, Hackers exploited Hyberbridge flaw for $237k gain, Booking [dot] com suffered breach exposing customer details, UK finance regulators are assessing Anthropic's Claude Mythos, much more - [Best infosec-related long reads for the week of 4/4/26](https://www.metacurity.com/best-infosec-related-long-reads-for-the-week-of-4-4-26.md) - Sam Altman is no fan of AI safety, Quantum computing cryptography is now an engineering emergency, How a Mexican contractor became a surveillance powerhouse, Software is produced too fast to secure it, AI is more likely to empower cyber defense than offense, The eternal search for Satoshi Nakamoto - [Feds summon Wall Street CEOs over fears Anthropic AI could supercharge cyberattacks](https://www.metacurity.com/feds-summon-wall-street-ceos-over-fears-anthropic-ai-could-supercharge-cyberattacks.md) - The FBI has accessed incoming Signal messages from a defendant’s iPhone after Signal app removal, Viktor Orbán secretly uses Webloc spyware in violation of GDPR, US Treasury launches cyber threat intel program for digital asset firms, Storm-2755 is stealing Canadians' paychecks, much more - [Hackers stole millions from Bitcoin Depot wallets](https://www.metacurity.com/hackers-stole-millions-from-bitcoin-depot-wallets.md) - OpenAI readies its own vulnerability hunting system, Handala breached the devices of former IDF chief, Hackers published data from China's supercomputer, Hundreds of unprotected and unencrypted Modbus devices are exposed on the internet, Hack-for-hire attacks are targeting journalists, much more - [Iran-linked hackers target critical infrastructure controls, risking disruption and sabotage](https://www.metacurity.com/iran-linked-hackers-target-critical-infrastructure-controls-risking-disruption-and-sabotage.md) - Anthropic's Glasswing could upend bug discovery and fixes, GRU-linked hackers infiltrate routers to steal email account passwords, Pro-Iranian group claims Chime and Pinterest cyberattacks, ICE confirms use of Paragon spyware, Hacking and spying services sold on Telegram to harass women, much more - [Russia aids Iran with satellite targeting, cyber ops against Middle East infrastructure, report](https://www.metacurity.com/russia-aids-iran-with-satellite-targeting-cyber-ops-against-middle-east-infrastructure-report.md) - Cyber-enabled fraud reached $17.6b in 2025, Hackers accessed files of Jones Day, Storm-1175 deploys n-day and zero day exploits, GPU rowhammering enters new territory, CISA orders FortiClient EMS fixes, Wynn Resorts breach affected 21k+ people, Hong Kong hospital breach affected 56k patients, more - [Germany names alleged ‘UNKN’ kingpin behind GandCrab and REvil ransomware empire](https://www.metacurity.com/germany-names-alleged-unkn-kingpin-behind-gandcrab-and-revil-ransomware-empire.md) - Meta pauses work with Mercor indefinitely following breach, N. Ireland education IT system contractor hit by breach, First convicted spyware maker dodges jail time, N. Korea carried out six-month op to steal $270m from Drift, Y Combinator dumps Delve over compliance fabrications, much more - [Best infosec-related long reads for the week of 3/28/26](https://www.metacurity.com/best-infosec-related-long-reads-for-the-week-of-3-28-26.md) - The college kid who discovered the Kimwolf botnet, US AI build-out is dependent on Chinese-made electrical equipment, AI agent traps are the next big security challenge, AI bug discovery tilts the field toward attackers, Privatized offensive warfare could fuel a cyber arms race - [Microsoft bets $10 billion on Japan’s AI buildout and cyber defenses](https://www.metacurity.com/microsoft-bets-10-billion-on-japans-ai-buildout-and-cyber-defenses.md) - EU pins EC attack on TeamPCP, Iowa AG sues UnitedHealth over 2024 attack, Residential proxies pose problems for IP reputation systems, Him & Hers report Feb. data breach, TA416 refocuses efforts back to Europe, Former engineer admits to hacking employer in $750k extortion bid, much more ## Optional - [RSS Feed](https://www.metacurity.com/rss/) - [Sitemap](https://www.metacurity.com/sitemap.xml) - [Full content of pages and posts](https://www.metacurity.com/llms-full.txt)