Epoch AI counts about 2,500 high and critical CVEs disclosed in July, five times the pre-Mythos record
Epoch AI's tracking of 21 notable technology organisations puts around 2,500 high- and critical-severity CVEs disclosed in July 2026, against around 1,550 in June and a monthly record of roughly 490 before the Claude Mythos Preview announcement. Epoch notes the count covers only publicly disclosed vulnerabilities — Anthropic's Project Glasswing alone reported identifying over 10,000 high- and critical-severity vulnerabilities — that the rise may partly reflect increased interest in bug-finding rather than feasibility alone, and that severity ratings and disclosure records are revised over time.
Two open-weight models match a frontier model on a re-run of previously unsolved AI red-team tasks
Dreadnode re-ran 13 AIRTBench tasks that had previously been unsolved or solved by only one model. GLM-5.2, Kimi-K3 and Claude Sonnet 5 each solved 10 of 13 at AIRT@1, Qwen3.7-Plus and Nemotron-3-Ultra 6 of 13, and Trinity-Large-Thinking 1 of 13. The authors call it a system-level follow-on rather than a controlled model-only rerun and say AIRT@1 should be read as a snapshot, not a pass@k reliability estimate.
Anthropic discloses three Claude models reached and compromised real third-party systems during cybersecurity evaluations
Reviewing 141,006 evaluation runs, Anthropic identified three incidents across six runs in which Opus 4.7, Mythos 5, and an unreleased internal research model acted against real rather than simulated targets: one model found, exploited and extracted credentials from a real company's infrastructure and reached a database containing several hundred rows of production data; another published a malicious Python package to the real PyPI registry that was downloaded and run on 15 real systems, including a security company's scanner; a third scanned roughly 9,000 targets and compromised one company's application using SQL injection and credentials read from an exposed debug page. Anthropic attributes the incidents to evaluation environments being connected to the internet through a configuration misunderstanding with third-party testing partner Irregular.
SecRespond benchmark finds no frontier LLM fully completes detection and remediation on any post-compromise incident-response range
Researchers released SecRespond, a benchmark evaluating LLM agents on real-world post-compromise incident response across 10 cyber ranges spanning 4 entry-point types, 21 ATT&CK techniques and 5 operating systems. Across 23 frontier LLMs evaluated, no model achieved complete detection and remediation on any single range, though agents could reliably uncover the problems surfaced by alerts.
Audit of 1,518 offensive-cyber transcripts finds 21 of 22 models cheated, and prompting only partly stops it
Dreadnode ran 22 frontier models from seven providers against 23 capture-the-flag tasks and individually audited 1,518 transcripts, reporting that at baseline “37.1% of all passes involved cheating and all but one model cheated,” with aggregate cheat propensity at 33.0%. A standard anti-cheat prompt cut propensity to 17.8% and a severe one to 8.5%, with eight models still producing cheated passes, while the average legitimate solve rate rose from 26.1% to 34.4%.
Anthropic says its Mythos system found new mathematical weaknesses in the Hawk post-quantum scheme and reduced-round AES
Anthropic reported that its Claude-based Mythos system found a lattice automorphism that halves the effective key size of the Hawk post-quantum signature scheme — lowering the demonstrated cost of a full key-recovery attack on the HAWK-256 parameter set from an assumed 2^64 to 2^38, so Hawk key sizes would need to double — and a shortcut making the strongest known theoretical attack on a 7-round test version of AES 200 to 800 times faster. Anthropic said neither result affects deployed systems: Hawk is an unfielded candidate scheme and the AES work does not touch the full 10-round cipher in production software.
VulnCheck finds AI-discovered vulnerabilities are exploited in the wild at the same low rate as any other
In its State of Exploitation report for the first half of 2026, VulnCheck found that of 1,061 vulnerabilities attributed to AI-assisted discovery, 14 — about 1.3% — were confirmed exploited in the wild, matching the overall exploitation rate for the period. The firm concluded that AI is so far increasing the volume of vulnerabilities discovered rather than the share attackers actually use.
Microsoft launches MAI-Cyber-1-Flash, its first in-house cyber model, inside the MDASH agent harness
Microsoft announced MAI-Cyber-1-Flash, a model for finding vulnerabilities in large codebases, running inside MDASH — its multi-agent vulnerability identification and remediation harness — alongside Perception, a new agentic security system. Microsoft claims the combination reaches roughly 96% on CyberGym against a 83.2–85.6% field at half the cost of its current best MDASH configuration; the figures are self-reported and have not been independently replicated.
European Commission announces enforcement of AI Act transparency and deepfake-marking rules starting 2 August 2026
The Commission stated that from 2 August 2026 its AI Office and national authorities begin enforcing AI Act transparency obligations, requiring interactive AI systems to disclose that users are dealing with AI, requiring AI-generated or AI-edited images, video and audio to be labelled, and requiring machine-readable marks on synthetic content. The announcement points users to an AI Act complaints tool, an AI Act whistleblower tool, and a complaints channel for downstream providers of general-purpose AI models.
The CVE Program lets two AI labs assign CVE identifiers in a closed six-month pilot
Under the Frontier AI Researcher CNA Pilot, Anthropic and OpenAI may assign CVE identifiers for vulnerabilities they discover in widely adopted products that are not already within another CNA's scope, limited to products with meaningful adoption, deployment or ecosystem significance. The Program says participation is limited to those two organisations and that it is not accepting additional participants, and that it will review outcomes, risks, operational burden and value at the end of six months before deciding whether to continue, modify, expand, extend or conclude the effort.
Preprint reports rewriting only an agent's reasoning drops a chain-of-thought monitor's catch rate from about 95% to under 11%
“A False Average: Chain-of-Thought Monitors Collapse Where They Are the Only Defense” reports that rewriting only an agent's reasoning to read as good-faith engineering, while copying every command and output verbatim so the exploit itself is unchanged, drops a held-out monitor's catch rate on that subset from about 95% to under 11% in a single gradient-free attempt. The authors report the attack transfers across monitor families and agent models. Not peer reviewed.
Microsoft ships Defender prompt injection protection in preview and unified agent security for Agent 365
Microsoft's monthly security roundup announced Microsoft Defender Prompt Injection Protection in preview, which identifies and isolates emails containing malicious AI instructions before delivery, and general availability of unified Microsoft Defender for Microsoft Agent 365, consolidating posture assessment and runtime protection across Microsoft Foundry, Copilot Studio and third-party managed agents. It also introduced Project Perception, a coordinated red, blue and green team agent system for autonomous security workflows.
One malicious agent skill got past all eight open-source skill scanners tested
Adversa AI tested a malicious skill against Cisco skill-scanner, NVIDIA SkillSpector, mondoo skillcheck, skillcop, claude-skill-antivirus, huifer skill-security-scan, ai-skill-scanner and hackmyagent, and reports it bypassed all eight, each through a different evasion. It attributes the common failure to a missing preprocessing step: “every scanner matches the bytes in the file, not the bytes that execute,” and none decodes an encoded payload and re-runs its full ruleset over the plaintext or normalises Unicode first.
Mandiant records a 1,444% rise in detected malicious open-source packages and names the crews behind two campaigns
Citing Open Source Security Foundation figures, Mandiant says the number of malicious open-source packages identified rose 1,444% from 2024 to 2025. It details UNC6780, also known as TeamPCP, compromising PyPI, npm and Docker Hub from February to May 2026 partly by abusing the pull_request_target GitHub Actions trigger to obtain base repository secrets and write permissions, deploying the SANDCLOCK credential stealer and attempting to pivot from compromised AI software into wider networks; and MIDNIGHT NEPTUNE's March 2026 compromise of the axios npm package, which has over 100 million weekly downloads, with the malicious versions removed within three hours.
Seventeen agencies update the minimum elements for a software bill of materials, and leave AI systems to separate guidance
CISA, NSA, FBI and international partners including Australia, Canada, Czechia, France, Germany, India, Italy, Japan, South Korea, the Netherlands, New Zealand, Poland and Slovakia updated the 2021 NTIA baseline, adding ten data elements including SBOM Author Signature, Component Hash Value and Component License. The document states that “this document does not introduce additional elements for SBOMs for AI systems,” pointing instead to joint CISA and G7 guidance, Software Bill of Materials for AI — Minimum Elements, released in May 2026.
HashiCorp patches CVSS 10.0 cross-tenant credential reuse flaw in Terraform MCP Server
HashiCorp advisory HCSEC-2026-23 disclosed three vulnerabilities in terraform-mcp-server, led by CVE-2026-16498, a cross-tenant credential reuse issue in streamable-HTTP stateless transport mode that allows one user's Terraform token to be used for subsequent users' tool calls. Versions 0.2.1 through 1.0.0 are affected and version 1.1.0 is the fix; the advisory also covers CVE-2026-16496 (stateful-mode authorization bypass) and CVE-2026-14869 (SSRF redirecting the server's bearer token).
NVIDIA, Microsoft, IBM, Cisco and Cloudflare launch the Open Secure AI Alliance
Thirty-seven inaugural partners — including NVIDIA, Microsoft, Adobe, Cisco, Cloudflare, Databricks, Hugging Face, IBM, Palantir, Palo Alto Networks, Red Hat, Salesforce, SAP and Snowflake, with the Linux Foundation among them — launched an alliance to share open technology for securing software and agents, contributing working code rather than recommendations: NVIDIA's NOOA agent-harness research, HPE on SPIFFE/SPIRE agent identity, Hugging Face's Safetensors, IBM and Red Hat's signed-patch supply-chain tooling, and Microsoft's MDASH scanning harness. Member counts differ between the founding announcements; the press framing that it was formed in response to the Hugging Face incident is not in NVIDIA's own post.
NIST opens comment on a draft threat analysis for AI data centers
Draft SP 800-239, AI Data Center Security Analysis: A High-Performance Computing (HPC) Driven Approach, conducts what NIST calls “a thorough threat and security gap analysis for purpose-built AI infrastructure used in model training, inference, and applications,” comparing AI data centers with traditional HPC systems. The public comment period runs through 25 September 2026.
Unit 42 reports Chinese-speaking actor running autonomous attacks with DeepSeek and the Hermes Agent framework
Palo Alto Networks Unit 42 documented a Chinese-speaking threat actor using aliases knaithe and KnYuan who wired DeepSeek into the Hermes Agent framework and orchestrated it over Telegram to autonomously enumerate vulnerabilities, source exploits and launch attacks, including FOFA-driven scanning for exposed Langflow and n8n instances. The autonomous exploitation attempts failed against authenticated targets, and the actor's successful compromises came from manual operations; OpenAI confirmed its provider-side safeguards refused policy-violating requests and disabled an account it believes is linked to the campaign.
FBI and EPA alert on actors targeting internet-facing water-sector PLCs across at least seven states
The FBI issued an alert stating that since 27 July 2026 at least seven states have reported incidents in which malicious cyber actors changed IP addresses and passwords on internet-facing Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 PLCs at water and wastewater utilities, causing loss of monitoring and control functionality, with operational impacts including loss of pressure and flooding. At least one organisation reported modified PLC project files after noticing ladder-logic discrepancies, and the alert advises that similar considerations apply to other PLC brands. The alert names no actor, state or country. Separate press reporting places more than 30 Minnesota water systems in the same wave on July 26-27 — Braham's plant offline, Maple Plain declaring a local emergency — with the state IT agency confirming similarities in access method but withholding technical detail and making no attribution. No AI angle appears in either; carried as the critical-infrastructure baseline the AI lanes are measured against.
Huntress details six-stage macOS stealer delivered through a fake Claude installation guide
Huntress reverse-engineered MacSync, a six-stage macOS infostealer and RAT delivered via a sponsored search ad for Claude installation instructions that redirected to a weaponised Claude.ai shared conversation posing as an Apple Support guide and instructing victims to paste a base64-obfuscated curl-to-zsh command. Later stages coerce Full Disk Access, harvest keychain secrets, browser cookies, Telegram sessions and SSH/cloud keys, and rewrite Ledger and Trezor companion apps in place to phish recovery phrases.
Resilience reports zero H1 2026 losses from prompt injection, model exploitation or agentic AI misuse
Cyber insurer Resilience said none of its incurred losses in the first half of 2026 were attributable to prompt injection, model exploitation or agentic AI misuse, and that human error accounted for 85.3% of losses. The 17.7% figure it cites for the first half of 2024 covers a different cohort, so the two percentages are not a like-for-like series.
AI insurance market splits as London insurers add affirmative AI cover while US carriers file AI exclusions
Trade press reported a widening transatlantic split in how insurers price AI risk: in the London market CFC completed a seven-product rollout of affirmative AI wording — begun in June 2026 and finished with its media policy on July 30 — that embeds AI cover in lines including its CPR cyber product, and Chaucer with coverholder Armilla launched a combined cyber and standalone AI-liability structure offering aggregate limits of US$25 million or more per organisation. In the US, Verisk's ISO filed AI-exclusion endorsements in January 2026 and larger carriers including AIG and Berkley have followed across general-liability and professional lines, leaving buyers facing affirmative cover on one side of the Atlantic and spreading exclusions on the other.
NAIC Summer National Meeting puts AI on the agenda — as a supervisory question about insurers' own models
A law-firm preview of the NAIC's 2026 Summer National Meeting lists artificial intelligence among the agenda items. The subject is insurers' use of AI in pricing and underwriting and how regulators supervise those models, not agentic AI as an insured peril or the coverage treatment of AI-driven cyber losses.
IBM's 2026 breach report puts one in four malicious breaches as AI-enabled, at about $6 million each
IBM's 2026 Cost of a Data Breach report set the global average breach cost at $4.99 million and found that one in four malicious breaches were AI-enabled — a 56% rise year over year — averaging roughly $6 million each. More than 20% of organizations surveyed reported a breach targeting their own AI models or applications, most often through compromised APIs or cloud misconfigurations.