OpenAI loosens GPT-5.6 cyber guardrails for vetted defenders
Anthropic to watermark Claude output, Gunra ransomware targets critical infrastructure through Fortinet flaws, WormGPT creator faces trial in Portugal, Ransomware disrupts systems at Winnipeg’s largest hospital, China-linked hackers exploit N-central flaw to deploy ransomware, much more

Metacurity is the cybersecurity news you'd need hours to assemble yourself.
Every weekday, we read the releases, filings, court documents, and reports that vendors and PR teams often don't want summarized — then tell you what actually changed and why it matters. Minimum vendor marketing, no outrage bait, no SEO filler.
A paid subscription to Metacurity delivers
- Full archive access — every newsletter and AI Watch roundup, searchable and browsable.
- Our weekly curated long-reads roundup — the best cybersecurity writing from across the industry, filtered and vetted so you're not sorting through it yourself,
- Periodic specialized reports and analyses — deep dives that go beyond our daily coverage
- Support for independent, no-spin cybersecurity journalism — funded by readers, not vendors or investors.
Reader support is what keeps Metacurity independent. It allows us to focus on serving the cybersecurity community—not advertisers, vendors, or investors—and to continue delivering the thoughtful analysis you've come to rely on every weekday.
Please consider supporting us. And thank you!
OpenAI announced it is expanding OpenAI Daybreak with two access tiers designed to give approved defenders the right capabilities for their work.
The first tier is Daybreak Blue, which provides access to frontier general-purpose models, including GPT‑5.6 Sol, with safeguards tailored to authorized defensive security work. It is the recommended starting point for most defenders, supporting vulnerability discovery, secure code review, malware analysis, incident response, and patch validation.
Daybreak Blue removes the guardrails around GPT‑5.6 Sol, which OpenAI claims helps defenders get more out of the model in real-world security tasks, including incident detection and response, investigations, vulnerability management, and security assessments
The second tier is Daybreak Red, which provides access to its purpose-trained cybersecurity models for authorized vulnerability research, exploit validation, and security testing.
Even without system-level guardrails, there are still highly dual-use cybersecurity prompts (e.g., pentesting production systems) where GPT‑5.6 Sol will refuse to comply. To address this, we trained GPT‑5.6‑Cyber, available through Daybreak Red access, to further reduce refusals and improve performance on certain tasks. GPT‑5.6‑Cyber helps trusted defenders conduct legitimate security activities.
OpenAI also introduced GPT‑5.6‑Cyber, available through Daybreak Red. Built on GPT‑5.6 Sol, it is trained to improve capabilities on several specialized cybersecurity tasks (e.g., finding zero-day vulnerabilities and developing exploit chains) and to reduce refusals for certain higher-risk, dual-use cyber tasks. (OpenAI)
Related: SiliconANGLE, iThinkDifferent, Implicator.ai, SQ Magazine, Neowin, Unite.AI, The Decoder, RuntimeWire, TechCrunch, VentureBeat, CyberScoop, Axios, OpenAI, Help Net Security, The New Stack, OpenAI, CNBC, The Guardian, Security Week, Engadget, CSO Online, BeInCrypto, Bleeping Computer, The Stack
Anthropic will embed watermarks in the text and files generated by future models it launches in the EU, as part of its effort to comply with content and transparency rules in the bloc's AI Act.
"Generated text will carry embedded watermarks, and generated files will include digitally signed provenance metadata where supported," the company said in a help document.
The AI biz is also working on models it has already released to add output marking during the transition period allowed under EU law.
"Marking will apply to output from supported models wherever Claude is offered, worldwide," the company said.
The move may further amplify the appeal of open weight models and alienate Claude customers, who don't necessarily want consumers of their AI-generated content to know its provenance. In the past, Claude users have expressed frustration with pricing changes, reliability issues, and model safeguards that have hindered legitimate work in the name of safety.
Claude users appear to be skeptical that a text-based watermarking scheme will work. Researchers have already demonstrated that image-based watermarking can be undone.
Anthropic intends to apply marks to output from covered Claude models on the Claude Platform (API), Claude, Claude Code, Claude Cowork, and Claude Tag. This also includes third-party providers of Anthropic models like AWS, Google Cloud, and Microsoft Foundry.
Anthropic expects to provide details about how people can detect Claude's marks, as required under EU law, in forthcoming documentation. (Thomas Claburn / The Register)
Related: Claude, Android Authority, The Hans India, Business Insider, The Economic Times, The Decoder, Digit, Business Standard, Cyber Security News, RuntimeWire, Notebookcheck, RuntimeWire, Engadget, Hacker News, r/france, r/ClaudeAI, r/privacy, r/claudexplorers, r/singularity, r/ClaudeAI, r/accelerate
US law enforcement agencies and South Korea’s National Policy Agency issued an advisory warning that the Gunra ransomware gang is breaching critical infrastructure organizations through vulnerabilities in popular brands of firewalls.
The agencies spotlighted the ransomware operation that emerged in April 2025 and is built using source code from the Conti ransomware that was leaked in 2022.
“Gunra is another variant in the ongoing trend of ransomware attacks causing disruption and harm to US and international organizations,” said Chris Butera, acting executive assistant director for cybersecurity at the Cybersecurity and Infrastructure Security Agency (CISA).
The agencies warned that Gunra actors have been exploiting CVE-2024-55591 and CVE-2025-24472 — two vulnerabilities affecting popular firewall products from Fortinet that CISA previously warned about — to gain privileged access to organizations, allowing them to steal and encrypt data before extorting organizations.
They offered evidence gleaned from several incidents handled by the FBI and South Korea’s police agency. They found the group is targeting the healthcare, financial services, and government sectors globally. In most cases, victims were given exorbitant ransom demands that were over 10 million dollars and told they had five to seven days to pay.
Two weeks ago, researchers warned that some tools and infrastructure used by North Korea’s Lazarus Group appear to have been shared with Gunra as it targeted South Korean organizations. (Jonathan Grieg / The Record)
Related: CISA, MeriTalk, CyberScoop, Bleeping Computer, Firstpost, The Korea Times, The Chosun Daily, Digital Today, ChosunBiz, Seoul Economic Daily, RTO Insider
A young Portuguese man who started hacking at just 10 years old is set to stand trial for creating a malicious version of ChatGPT, Público reports.
WormGPT was available on the deep web without any guardrails or ethical boundaries blocking users from carrying out illegal acts, such as generating a phishing email campaign.
According to the newspaper, João (not his real name) didn’t see himself as a criminal and was motivated mostly by learning until other hackers started contacting him to create tools that would do more serious acts, like cloning credit cards. He decided to get rid of the program, sounding alarms at the FBI, which alerted the Criminal Investigation Police (PJ). They found a letter on his computer saying he’d sell it for €55,000.
Still living with his parents, he was arrested at the start of 2025 and released on bail with the condition he had no access to the internet, complicating his computer engineering studies, but the privilege was eventually restored. In court, the judge urged João, now 23, to use his brain for good, and he’s been completely cooperative with the investigation. (Jorge Branco / Portugal Weekly)
Related: Publico
A ransomware attack on Winnipeg's Health Sciences Centre has affected door access, heating, ventilation and air-conditioning at Manitoba's largest hospital.
Shared Health said it's responding to what it called "a ransomware incident affecting certain facility maintenance systems."
Patient care and clinical operations are not affected, the health authority said, urging anyone who needs to attend the hospital to do so.
"Clinical services continue uninterrupted, and based on the investigation conducted to date, there is no indication that patients have been affected," the statement, provided to CBC News by spokesperson Tara Seel, says.
Shared Health said it has launched an investigation to determine the nature and scope of the attack and is reviewing the systems affected by it. No other systems appear to be affected, the statement said.
Shared Health also said it has notified the provincial government and has sought expert advice to try to resolve the problem. (Bartley Kives / CBC News)
Related: ChrisD.ca, Winnipeg Free Press, CTV News
According to Microsoft, a financially motivated threat actor linked to China is exploiting a critical vulnerability affecting widely used cybersecurity software in a supply-chain attack that could see the hackers deploy custom ransomware across a cascading list of victims’ networks.
Microsoft warned that the Storm-1175 group began deploying a new ransomware strain on August 2 called StormEncryptor. The hackers previously used the Medusa ransomware to extort healthcare, professional services and finance organizations in Australia, Britain and the United States.
In April, the hackers were described as operating “high-velocity ransomware campaigns” exploiting both recently disclosed vulnerabilities and zero-day exploits, “in some cases a full week before public vulnerability disclosure.” Microsoft said it had seen the group move from initial access to full encryption in under 24 hours.
In this latest campaign, Microsoft said the group is likely exploiting CVE-2026-18577 — a vulnerability in N-central, a remote monitoring and management (RMM) console used by thousands of managed service providers to administer client endpoints.
Microsoft has not formally confirmed the access vector, but noted that StormEncryptor deployments began the same day the flaw was disclosed. The vulnerability gives attackers “unauthenticated, ‘god-mode’ access,” the cybersecurity firm Huntress warned. (Alexander Martin / The Record)
Related: SC Media, Microsoft, Bleeping Computer, Cyber Press, GBHackers

Researchers from the digital defense firm A Security disclosed vulnerabilities in the video conferencing platform Zoom that could have been exploited to take over targets’ devices.
Anyone on a call that involved screen sharing, whether participants or the host, would have been vulnerable to a silent attack that could be carried out with no indication and no interaction from the victim.
They say the bug was discovered in early June using publicly available AI models, and that it took fewer than 20 prompts to uncover the vulnerabilities and create a working attack. Zoom issued a security advisory, including details about fixes the company has already begun rolling out to address the flaws, which affected devices running all operating systems that Zoom supports—Windows, macOS, Linux, iOS, and Android. (Lily Hay Newman / Wired)
Related: A Security, Zoom
Delta Air Lines flight 591 from Las Vegas to Atlanta experienced a WiFi hacking scare following DEF CON, the world’s largest hacking convention.
Sunday’s flight didn’t leave Las Vegas until 8:30 a.m. Monday, 17 hours and 42 minutes late, and reached Atlanta at 3:05 p.m. Eastern time.
About an hour after takeoff, the crew used the ACARS system to ask that corporate security be alerted that a passenger had created a “scam WiFi” network called Delta WiFi Fast and said they believed the person was trying to scam other passengers.
Seventeen minutes later, the crew sent a follow-up: “NO INFO AS OF NOW.” They said several passengers had attended a cybersecurity conference in Las Vegas and “were able to jam our WiFi and broadcast their signal.” Two independent ground receivers picked up that message.
A post in a private Delta frequent flyer group filled in details, and it spread to Reddit, explaining that DEF CON attendees used a WiFi Pineapple (a pocket security testing router) and cloned Delta’s network, served a phishing page, harvested Google credentials, and the plane was met by federal agents who seized their equipment.
One Reddit commenter who says they were on the flight reports that the pilots made several announcements and shut off the passenger WiFi for part of the trip. They thought it appeared to be a fake access point and said they saw no police or federal agents at the gate. Another anonymous commenter claimed the plane was met and one person was detained. (Gary Leff / View From the Wings)
Related: r/delta

LexisNexis took its Diligence, Metabase API, and Newsdesk services offline as part of its response to unusual activity on servers hosted and managed by an unnamed third-party vendor.
The company said it is investigating the incident with assistance from a cybersecurity forensic firm and is rebuilding affected systems in a new environment before bringing the services back online.
“Earlier this week, we identified unusual activity on servers that are hosted and managed by a third-party vendor,” reads the notification sent to customers last week. (Bill Toulas / Bleeping Computer)
Related: SC Media, The Register

The European Union Agency for Cybersecurity announced that NATO's cyber defense arm and a startup that uses artificial intelligence to find software flaws can now issue the ID numbers the industry uses to track those flaws.
The NATO Cyber Security Centre, part of the NATO Communications and Information Agency, and AISLE, a cybersecurity company with offices in San Francisco and Prague, joined as CVE numbering authorities under the ENISA Root. The CVE program assigns a unique record to each publicly disclosed security flaw so that governments, vendors and researchers have a common marker when referring to particular vulnerabilities.
Twenty numbering authorities now sit under the ENISA Root, with 12 brought in by ENISA itself and eight moving over from the MITRE Root, run by the US nonprofit that has handled the program’s daily work for more than 20 years.
Hans de Vries, ENISA’s chief cybersecurity and operations officer, linked the growth to changes in how people find flaws. (Greg Otto / CyberScoop)
Related: ENISA, Industrial Cyber, eeNews Europe
According to WordPress security firm Defiant, a threat actor compromised the upstream infrastructure of BdThemes, a developer of premium WordPress web-design tools, and modified a remote JSON feed delivered to administrators’ browsers to create rogue admin accounts.
Starting Saturday, the affected BdThemes products were no longer available for download after the WordPress Plugins team closed all of them pending a full review.
BdThemes provides premium WordPress plugins, including Element Pack, Prime Slider, Ultimate Post Kit, Pixel Gallery, and Ultimate Store Kit.
Defiant's Wordfence researchers say that reports that the command-and-control (C2) infrastructure used in the observed attacks points to the same attacker behind the recent Advanced Responsive Video Embedder and OptinMonster supply-chain compromises.
After discovering the attacks, the researchers analyzed available records and determined that the earliest possible start of the campaign was June 23.
The affected plugins were pulled from the WordPress.org directory on August 8, pending investigation, while two poisoned API endpoints now return clean JSON data. (Bill Toulas / Bleeping Computer)
Related: Wordfence, GBHackers, Cyber Press, Cyber Security News
A data breach occurred at Jeju Air, South Korea’s top low-cost carrier (LCC), exposing personal information including passport numbers of over 100 customers.
Amid a series of large-scale personal information leaks at SK Telecom, Coupang, Tving, and others recently, concerns over corporate management of personal data are growing.
According to the aviation industry on August 11, a problem occurred on August 5 where some reservation information of over 100 Jeju Air customers was exposed on the Naver search engine. The exposed information included customer names, partially obscured passport numbers, and other personal data entered during the flight ticket reservation process.
Jeju Air immediately blocked the page upon identifying the issue. The airline reported the incident to the Personal Information Protection Commission and is individually contacting affected customers to inform them of the exposure and subsequent measures. Jeju Air decided to cover the costs of reissuing passports and also provide separate compensation of 100,000 Korean won. A Jeju Air representative stated, “We are currently investigating the exact circumstances of the incident.” (Han Ye-na / The Chosun Daily)
Related: KBS World
Security researcher Bill Swearingen says he can now produce patterns on demand that, when applied to clothing and objects, prevent some of the most commonly deployed license plate readers and surveillance cameras from detecting whatever the pattern covers, from people to vehicles.
His project, which he calls noRecognition, allows people to escape the automatic detection and algorithmic surveillance used across the US and beyond.
Swearingen’s computer-generated patterns do not block surveillance cameras from recording video footage. Instead, they scramble the camera’s ability to identify objects, people, or faces so that the cameras do not trigger any detection alerts. By blocking the camera’s ability to detect what the pattern covers, the person becomes a needle in a haystack again — until someone knows where to look.
In its first public test Friday at the Def Con cybersecurity conference in Las Vegas, Swearingen successfully demonstrated the pattern printed on a vehicle, proving that these patterns can be effective at defeating surveillance detection in the real world. (Zack Whittaker / TechCrunch)
Related: noRecognition, Inc, SC Media, Gadget Review

Ceva Logistics, one of the world’s largest shipping and logistics giants, has been hacked.
Several companies that rely on Ceva for shipping their products to their customers say that their personal information was also stolen in the breach.
The cyberattack on Ceva is affecting at least eight warehouses across Europe used for shipping goods across the continent.
Industry news site FreightWaves reports that the hack began on July 29 and is causing shipping delays for many of the goods in affected warehouses.
Ceva is a France-headquartered shipping and logistics giant that companies around the world rely on to deliver their goods from their assembly lines to customer homes. The company, which brought in $18.3 billion in revenue in 2025, has over a thousand warehouses across the world.
Shipping and logistics giants have become a growing target for cybercriminals in recent years for their ability to access and hijack trucks and containers to get goods into the hands of real-world gangs.
The hack at Ceva also resulted in a data breach, affecting a large amount of personal information belonging to retail customers that Ceva relies on for delivering goods to people’s home addresses. Several companies reported that hackers took their customers’ names, home addresses, phone numbers, and email addresses used to place their orders from Ceva’s systems. (Zack Whittaker / TechCrunch)
Related: Cleveland.com, Infosecurity Magazine, Freight Waves, Tech Radar, IT Pro, Help Net Security, Windows Central, Beta News, Games Industry Biz, Bleeping Computer, Startup Fortune
A new program is seeking to assist water providers around the country as multiple states grapple with possible Iran-linked cyber intrusions against water infrastructure.
The Water Watch Center provides direct cyber mitigation support to utilities serving fewer than 10,000 people, which represents most of the nation’s community water systems. Launched at this year’s DEF CON hacker convention, the initiative is a joint effort between the National Rural Water Association and DEF CON Franklin, a project of the Cyber Policy Initiative at the University of Chicago Harris School of Public Policy.
More than 30 community water systems in Minnesota were targeted late last month, according to state officials. Around 12 states have reported similar activity in recent days, though state officials said they continued operating safely and experienced no known effects on public health. The FBI and Cybersecurity and Infrastructure Security Agency are working on incident response.
An initial group of five cybersecurity firms will help deliver services to water utilities as part of the initiative.
“These leading cyber firms and NRWA are architecting a scalable cyber delivery model that has eluded water industry and national security officials to date,” Jake Braun, the co-founder of DEF CON Franklin and a former White House acting principal deputy national cyber director, said in a statement. (David DiMolfetta / NextGov/FCW)
Related: PR Newswire, The Register, Silicon Angle, The Record
Google DeepMind’s AGI Safety and Alignment Team, which seeks to mitigate the risks of advanced AI, is encouraging job candidates for its open roles to fill out a special form alongside their application to eliminate the risk it may be automatically screened out by the company’s internal AI systems, according to a document viewed by Bloomberg, which contained the disclaimer “PLEASE DO NOT SHARE THIS DOC WIDELY.”
“We have an applications system with a non-trivial probability your CV will be screened out incorrectly or take too long to reach us,” the document states. “Filling out this form makes sure that a real human on the team will get to see your application.”
A Google DeepMind spokesperson said the company aims to “recruit and hire the most qualified talent at Google DeepMind” and denied that the company's systems filter out applicants incorrectly. “This team set up a special form to go past the recruiter review, and get their resumes direct to the people on the team. But there are no shortcuts to getting hired,” the spokesperson added. (Julia Love / Bloomberg)
Related: Startup Fortune, Times of India
In an operation codenamed "Tight Net," Hong Kong police said they arrested eight people for allegedly operating compensated dating scams involving 80 cases, totaling HK$6.2 million over the past two years.
Officers said the suspects presented fake name cards on social media platforms, pretending to be lawyers and tycoons, and offered between HK$50,000 and HK$70,000 a month to become the victims' sugar daddies.
Officers said 65 percent of the victims were women, and over half of them worked in the services trade or as office workers. The biggest single case amounted to HK$480,000. Police said all transactions were conducted online and the victims had never met the scammers in person.
The victims were required to pay a so‑called legal fee before they could receive the money, officers said. (rthk.hk)
Related: China Daily
Corma, a developer of foundation models for defensive cybersecurity, has raised $60 million in a Seed round.
Sequoia Capital led the round with participation from Khosla Ventures and Coatue. (Meir Orbach / CTech)
Related: Ventureburn, Sequoia Capital, Fortune
Best Thing of the Day: Making 'No More Pervert Glasses' a Bigger Trend
Courts in England and Wales have joined a number of restaurants, theatres and pubs in banning Meta glasses, amid a mounting backlash against what has been described as "spyware."
Worst Thing of the Day: Don't Store Intimate Images on Internet-Accessible Sites
The Federal Bureau of Investigation (FBI) warns the public about sexual exploitation (SE) actors targeting adult and underage victims by illegally accessing their social media and personal accounts to steal and post their explicit content for sale on criminal marketplaces.
Bonus Worst Thing of the Day: Urge the Next Administration to Unwind This
Immigration and Customs Enforcement (ICE) plans to pay LexisNexis millions more dollars for continued access to data it can feed into a Palantir platform, according to newly published procurement records. The data is to help, among other sections, ICE’s Enforcement and Removal Operations (ERO), the part of ICE focused on deportation.
Extra Bonus Worst Thing of the Day: Love Is Love
A new Chinese regulation that went into effect in July has essentially banished AI companions, breaking the hearts of millions of Chinese users who relied on them as romantic partners to virtual recreations of deceased loved ones.
Closing Thought
