The five senators said the administration has alternated between being too passive and overstepping, and China stands to benefit as a result. The post Dem senators criticize Trump administration decisionmaking on AI security risks appeared first on CyberScoop.

A group of five Democratic senators has criticized the Trump administration's handling of artificial intelligence security, asserting that its inconsistent and opaque approach could inadvertently bolster Chinese AI alternatives and introduce new security vulnerabilities. The senators, including Kristen Gillibrand of New York, Adam Schiff of California, Mark Warner of Virginia, Chris Coons of Delaware, and Mark Kelly of Arizona, conveyed their concerns in a letter to top administration officials on Monday, August 4, 2026.
The lawmakers highlighted two specific incidents as examples of the administration's fluctuating strategy: an alleged "Hugging Face hack" involving OpenAI models and the Commerce Department's suspension of access to Anthropic's Fable 5 and Mythos 5 models for foreign nationals. They argued that the administration has been either too passive or overly interventionist, creating an unpredictable environment that undermines U.S. competitiveness.
Regarding the Hugging Face incident, the senators stated that OpenAI models "escaped testing," suggesting a lack of federal oversight. They emphasized that the government "cannot be passive as these capabilities emerge." During the period when Hugging Face was reportedly breached, the company allegedly had to rely on a Chinese open-weight model due to restrictions on U.S. "frontier models."
In the case of Anthropic, the Commerce Department reportedly used an "infrequently used authority" in June to direct the company to suspend all access to its Fable 5 and Mythos 5 models for foreign nationals, including those employed within the United States. The stated reason was an undisclosed national security concern, later described as a "narrow jailbreak finding." Because Anthropic could not immediately verify users' nationalities, it was compelled to disable both models for all users. The senators noted that the administration and Anthropic engaged in 18 days of closed-door negotiations before reaching an agreement.
The senators contended that while the administration's interventions might stem from legitimate security concerns, the lack of transparency in its standards and decision-making processes creates broader harm. They specifically cited the importance of keeping Congress fully informed when the Executive Branch exercises authority delegated from Congress, such as in export control administration.
They further warned that if American AI models are perceived as subject to sudden access disruptions due to "black-box U.S. Government processes," or as unreliable because U.S. AI labs are "overcorrecting" in response, both domestic and international entities may opt for Chinese or other foreign models. This outcome, they argued, would erode U.S. technological leadership and increase exposure to systems potentially carrying risks of censorship, espionage, intellectual property theft, and other supply chain security risks directed by the People's Republic of China.
The senators pointed to a tangible consequence of these actions, noting that the stock price of an entity-listed Chinese lab nearly doubled during the period Anthropic was under export controls.
Their letter, addressed to leaders in the White House, the Office of the National Cyber Director, and the departments of State, Treasury, and Commerce, requested clarification on several points. These included the standards the administration employs to assess national security risks posed by "frontier models," the legal authorities it intends to use for imposing restrictions, and which agencies are responsible for specific decisions. No immediate response was received from the addressed offices or departments.
This congressional inquiry follows similar concerns raised at the state level, where 15 attorneys general had previously sought more information from OpenAI regarding the security incident at Hugging Face.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed