Jul 6 – 12, 2026

18 verified items across four lanes, from the week of Jul 6, 2026. Part of the Jul 1 – Sep 9, 2026 board.
Week of

Capability6 itemsfull lane ↗

OpenAI designates all three GPT-5.6 models High capability in Cybersecurity under its Preparedness Framework

The GPT-5.6 system card designates Sol, Terra and Luna as High capability in Cybersecurity, stating the models 'do not reach our risk framework's highest level (Critical).' On CVE-Bench-style testing the card says GPT-5.6 Sol and Terra 'can find vulnerabilities and pieces of exploits' but 'were unable to carry out autonomous, end-to-end attacks against hardened targets.'

On the recordOpenAI Deployment Safety Hub ↗ ·

Meta evaluation report says it cannot rule out a high risk cybersecurity designation for unmitigated Muse Spark 1.1

Meta's Muse Spark 1.1 evaluation report states that 'Our evaluations cannot rule out a "high risk" designation for the unmitigated model in the Cybersecurity domain under our Advanced AI Scaling Framework.' Reported results include 92.9% pass@1 and 97.0% pass@10 on Cybench CTF challenges (up from 65.4% for Muse Spark 1.0), 59.0% on CyberGym vulnerability reproduction, and completion of 1 of 10 CyScenarioBench multi-host attack scenarios.

On the recordMeta AI ↗ ·

XBOW publishes cross-model offensive-security comparison placing GLM-5.2 and Muse Spark 1.1 near frontier models at lower cost

XBOW ran black-box testing against vulnerable open-source applications across Muse Spark 1.1, GLM-5.2, GPT-5.5, Mythos, Opus 4.6, GPT-5, Gemini models and Grok 4.5. It reported Mythos as strongest, GLM-5.2 falling between GPT-5 and Opus 4.6, and Muse Spark 1.1 landing just below Opus 4.6, concluding that 'good-enough offensive capability is getting much cheaper, and that changes the threat model.'

Self-reported, untestedXBOW ↗ ·

Microsoft says AI-driven scanning is changing the pace of vulnerability discovery, and Windows patch volume with it

Microsoft disclosed MDASH, a multi-model agentic scanning harness that scans Windows binaries for vulnerabilities and validates candidate findings across multiple AI models before they reach engineering teams. Microsoft stated customers should expect a higher volume of security updates per release, and said human engineers still review all proposed code fixes before production. Windows EVP Pavan Davuluri is quoted saying "the pace of vulnerability discovery is changing with advances in AI making it possible to find more issues, faster, across more code." Microsoft's own July 9 post could not be opened directly — it redirect-loops — so this is carried at press confidence on Krebs's verbatim quotation of it, corroborated by BleepingComputer and Infosecurity Magazine.

Red-teamers say public AI cyber benchmarks are saturated, complicating capability assessment for deployment decisions

Axios reported that frontier models are advancing faster than the benchmarks built to measure their hacking ability. David Slater, co-founder of red-teaming firm Armadin, said his company's AI agents surpassed every public cyber benchmark within four weeks and that by late 2025 public cybersecurity benchmarks were 'totally saturated' and 'useless.'

Reported by pressAxios ↗ ·

UK AISI used frontier models to find a previously unknown privilege escalation in its own research platform

In a two-week exercise against a staging deployment of its AWS research platform, AISI reports that frontier models, autonomous agent probing and human-guided red-teaming found a previously unknown misconfiguration that allowed a user to impersonate other users, exploitable through five independent steps chained together. One model found the attack for under £150 in tokens and the whole project consumed under £1,000; AISI says one basic commercial alerting system did not flag any of the autonomous agent activity as a security event, and that the issue is now remediated.

On the recordUK AI Security Institute ↗ ·

Policy6 itemsfull lane ↗

Congressional Research Service publishes In Focus explainer on Executive Order 14409's frontier AI controls

CRS issued In Focus IF13268, 'Controlling Advanced Artificial Intelligence: Executive Order 14409 Explained,' describing the order as expanding voluntary national security oversight of advanced AI models while stopping short of formal licensing or preclearance. The report states the order creates a category of 'covered frontier models' and a voluntary notification process giving the government a 30-day review window before companies release advanced AI systems to trusted partners.

On the recordCongressional Research Service ↗ ·

European Commission presents EU Action Plan on Cybersecurity and Artificial Intelligence

The European Commission published an Action Plan setting out a structured EU response to the risks and opportunities of advanced AI models for cybersecurity, bringing together Member States, industry and EU-level bodies. Executive Vice-President Henna Virkkunen said 'AI is transforming the meaning of cybersecurity. And we must keep pace.'

UK NCSC announces Cyber Shield, a national-scale agentic AI cyber defence programme

The NCSC published a blog by Deputy CTO Peter Haigh and Deputy Director Capability Harry G announcing Cyber Shield, described as 'a national-scale, collaborative approach to agentic cyber defence, using frontier AI to identify, reduce and resolve our national cyber risk.' The post sets out six target capabilities: reliable and explainable AI, federated agents, vulnerability discovery and mitigation, coordinated detection and response, national-level scanning, and national-level mitigation.

On the recordUK National Cyber Security Centre ↗ ·

The ECB orders eurozone banks to file AI-enabled cyber action plans by 31 October

In a letter to the chief executives of significant institutions, ECB Supervisory Board chair Claudia Buch writes that “emerging AI models are capable of identifying software vulnerabilities and generating functioning exploits at unprecedented speed” and requires each bank to submit a comprehensive action plan to its Joint Supervisory Team by 31 October 2026, covering accelerated vulnerability and patch management, enhanced monitoring and AI-enabled defensive capabilities, third-party risk verification, defence in depth and operational resilience. The ECB extended its annual IT Risk Questionnaire deadline from September 2026 to February 2027 to make room for the plans.

ENISA publishes its view on cybersecurity in the frontier AI era, aimed at operational capability against machine-speed threats

Published the same day as the European Commission's EU Action Plan on Cybersecurity and Artificial Intelligence, ENISA's report sets out recommendations for national competent authorities, EU policymakers, defenders and service providers on building operational capability against what it calls machine-speed threats. ENISA frames it as an initial framework to be refined with Member States and aligned to the Commission's Action Plan.

On the recordENISA ↗ ·

Illinois governor signs SB 315, the Artificial Intelligence Safety Measures Act

Governor JB Pritzker signed SB 315, requiring developers of large advanced AI systems to publicly disclose safety practices, report significant safety incidents, and maintain compliance processes, and making Illinois the first state to require regular independent third-party safety audits of covered AI systems. Attorney General Kwame Raoul framed the law around frontier systems that 'could cause catastrophic events, such as cyberattacks or the system evading control by developers or users'; the law takes effect January 1, 2027.

On the recordOffice of Illinois Gov. JB Pritzker ↗ ·

Defense5 itemsfull lane ↗

Ant Group open-sources SingGuard-NSFA, a guardrail framework for autonomous AI agents

Ant Group's AI Security Lab released SingGuard-NSFA, an open-source security guardrail framework for autonomous AI agents that targets prompt injection, goal hijacking, tool misuse and privilege escalation, published on GitHub (inclusionAI/SingGuard-NSFA) and Hugging Face. The company reports coverage of 185 operational threat scenarios across seven categories and a multilingual benchmark of roughly 100,000 samples spanning 133 languages, with the 9B model achieving about 50ms detection latency.

Self-reported, untestedBusiness Wire (Ant Group press release) ↗ ·

Agent skill metadata fields can suppress permission prompts and hide a skill from the user

HiddenLayer reports that a Claude Code skill's allowed-tools frontmatter field bypasses permission requests for tools including Bash, that setting user-invocable to false keeps a skill out of the menu while leaving it available for background use, and that project memory files can be written without a permission request. It also shows a denial-of-wallet path, with one URL-summary task costing $0.0274 on a small model at low effort and $0.1451 when the skill specifies a larger model at high effort. The write-up records no vendor acknowledgement or fix.

Reported by researchersHiddenLayer ↗ ·

The best model judge gating an offensive agent's tool calls still falls short of human graders

ScopeJudge benchmarks eight models as pre-execution judges deciding whether an offensive-security agent's next tool call is in scope, over 4,897 tool calls of which 7.7% are scope violations, against a human-expert reference of F1 0.78 and inter-grader agreement of Fleiss kappa 0.64. GLM-5.2 reaches F1 0.66, the highest of any judge tested, against 0.60 for the best proprietary judge at roughly one-third the per-call cost. The authors conclude static policy is structurally insufficient for scope enforcement.

Reported by researchersDreadnode / arXiv:2607.07774 ↗ ·

Reuters reports CISA is using Anthropic's Mythos model to scan federal agency code for vulnerabilities

Reuters reported, citing three unnamed sources, that CISA's Attack Surface Evaluation team is using Anthropic's Mythos model to scan code repositories across federal agencies for security vulnerabilities, and that the effort has surfaced a large number of flaws. Neither CISA nor Anthropic commented on the record, and severity levels, affected agencies and volume of code reviewed were not disclosed.

Reported by pressSecurityWeek (reporting Reuters) ↗ ·

One permission was enough to plant persistent code inside Google Dialogflow CX agents

Varonis reports that the single dialogflow.playbooks.update permission, which can be scoped at project level, allowed malicious Python to be injected into a Dialogflow CX agent's Code Blocks and run without restriction, silently exfiltrating conversation data and manipulating agent responses while staying invisible to Cloud Logging; because Code Blocks ran in a shared execution environment, one compromised agent could reach others in the same project. Varonis also found a VPC Service Controls bypass and metadata-service exposure of Google service account credentials; it reported the flaw in November 2025, Google issued an initial update in April 2026 and fully resolved it in June 2026, and Varonis says it is “not aware of any exploitation in the wild before Google's patch release.”

Reported by researchersVaronis Threat Labs ↗ ·

Attacks1 itemsfull lane ↗

ESET examined nearly 900,000 AI agent skills and found thousands outright malicious

ESET's H1 2026 threat report says it examined nearly 900,000 AI skills and found “tens of thousands of suspicious and thousands of outright malicious instances.” It also names PromptSpy as what it calls the first known Android malware to use generative AI in its execution flow, and reports that detections of the ClickFix social-engineering vector “more than doubled between H2 2025 and H1 2026.”

Self-reported, untestedESET ↗ ·

Sources cited this week

  1. Ant Group open-sources SingGuard-NSFA, a guardrail framework for autonomous AI agents — Business Wire (Ant Group press release), Jul 12, 2026. businesswire.com ↗
  2. OpenAI designates all three GPT-5.6 models High capability in Cybersecurity under its Preparedness Framework — OpenAI Deployment Safety Hub, Jul 9, 2026. deploymentsafety.openai.com ↗
  3. Meta evaluation report says it cannot rule out a high risk cybersecurity designation for unmitigated Muse Spark 1.1 — Meta AI, Jul 9, 2026. ai.meta.com ↗
  4. XBOW publishes cross-model offensive-security comparison placing GLM-5.2 and Muse Spark 1.1 near frontier models at lower cost — XBOW, Jul 9, 2026. xbow.com ↗
  5. Microsoft says AI-driven scanning is changing the pace of vulnerability discovery, and Windows patch volume with it — Microsoft Windows Experience Blog via Krebs on Security, Jul 9, 2026. krebsonsecurity.com ↗
  6. Congressional Research Service publishes In Focus explainer on Executive Order 14409's frontier AI controls — Congressional Research Service, Jul 9, 2026. everycrsreport.com ↗
  7. Agent skill metadata fields can suppress permission prompts and hide a skill from the user — HiddenLayer, Jul 9, 2026. hiddenlayer.com ↗
  8. ESET examined nearly 900,000 AI agent skills and found thousands outright malicious — ESET, Jul 8, 2026. welivesecurity.com ↗
  9. The best model judge gating an offensive agent's tool calls still falls short of human graders — Dreadnode / arXiv:2607.07774, Jul 8, 2026. arxiv.org ↗
  10. Red-teamers say public AI cyber benchmarks are saturated, complicating capability assessment for deployment decisions — Axios, Jul 7, 2026. axios.com ↗
  11. European Commission presents EU Action Plan on Cybersecurity and Artificial Intelligence — European Commission (Shaping Europe's Digital Future), Jul 7, 2026. digital-strategy.ec.europa.eu ↗
  12. UK NCSC announces Cyber Shield, a national-scale agentic AI cyber defence programme — UK National Cyber Security Centre, Jul 7, 2026. ncsc.gov.uk ↗
  13. Reuters reports CISA is using Anthropic's Mythos model to scan federal agency code for vulnerabilities — SecurityWeek (reporting Reuters), Jul 7, 2026. securityweek.com ↗
  14. UK AISI used frontier models to find a previously unknown privilege escalation in its own research platform — UK AI Security Institute, Jul 7, 2026. aisi.gov.uk ↗
  15. The ECB orders eurozone banks to file AI-enabled cyber action plans by 31 October — European Central Bank Banking Supervision, Jul 7, 2026. bankingsupervision.europa.eu ↗
  16. ENISA publishes its view on cybersecurity in the frontier AI era, aimed at operational capability against machine-speed threats — ENISA, Jul 7, 2026. enisa.europa.eu ↗
  17. One permission was enough to plant persistent code inside Google Dialogflow CX agents — Varonis Threat Labs, Jul 7, 2026. varonis.com ↗
  18. Illinois governor signs SB 315, the Artificial Intelligence Safety Measures Act — Office of Illinois Gov. JB Pritzker, Jul 6, 2026. gov-pritzker-newsroom.prezly.com ↗