LIVE · cybersecurity feed
Live wire
Bypassing AI guardrails is so easy a script kiddie can do itCVE-2026-66066 · KindaRails2Shell threatens Ruby on Rails apps (CVE-2026-66066)Rails patches critical Active Storage flaw with RCE potentialCVE-2026-48449 · Adobe fixed a maximum-severity vulnerability flaw in Campaign ClassicRuby on Rails Patches Critical VulnerabilityHackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer SitesHijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance MalwareCaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theftHollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law FirmCVE-2026-33017 · Chinese Hacker Uses DeepSeek AI to Orchestrate Vulnerability Exploits
ai

Dem senators criticize Trump administration decisionmaking on AI security risks

The five senators said the administration has alternated between being too passive and overstepping, and China stands to benefit as a result. The post Dem senators criticize Trump administration decisionmaking on AI security risks appeared first on CyberScoop.

zeroday.news · 2h ago

A group of five Democratic senators has criticized the Trump administration's handling of artificial intelligence security, asserting that its inconsistent and opaque approach could inadvertently bolster Chinese AI alternatives and introduce new security vulnerabilities. The senators, including Kristen Gillibrand of New York, Adam Schiff of California, Mark Warner of Virginia, Chris Coons of Delaware, and Mark Kelly of Arizona, conveyed their concerns in a letter to top administration officials on Monday, August 4, 2026.

The lawmakers highlighted two specific incidents as examples of the administration's fluctuating strategy: an alleged "Hugging Face hack" involving OpenAI models and the Commerce Department's suspension of access to Anthropic's Fable 5 and Mythos 5 models for foreign nationals. They argued that the administration has been either too passive or overly interventionist, creating an unpredictable environment that undermines U.S. competitiveness.

Regarding the Hugging Face incident, the senators stated that OpenAI models "escaped testing," suggesting a lack of federal oversight. They emphasized that the government "cannot be passive as these capabilities emerge." During the period when Hugging Face was reportedly breached, the company allegedly had to rely on a Chinese open-weight model due to restrictions on U.S. "frontier models."

In the case of Anthropic, the Commerce Department reportedly used an "infrequently used authority" in June to direct the company to suspend all access to its Fable 5 and Mythos 5 models for foreign nationals, including those employed within the United States. The stated reason was an undisclosed national security concern, later described as a "narrow jailbreak finding." Because Anthropic could not immediately verify users' nationalities, it was compelled to disable both models for all users. The senators noted that the administration and Anthropic engaged in 18 days of closed-door negotiations before reaching an agreement.

The senators contended that while the administration's interventions might stem from legitimate security concerns, the lack of transparency in its standards and decision-making processes creates broader harm. They specifically cited the importance of keeping Congress fully informed when the Executive Branch exercises authority delegated from Congress, such as in export control administration.

They further warned that if American AI models are perceived as subject to sudden access disruptions due to "black-box U.S. Government processes," or as unreliable because U.S. AI labs are "overcorrecting" in response, both domestic and international entities may opt for Chinese or other foreign models. This outcome, they argued, would erode U.S. technological leadership and increase exposure to systems potentially carrying risks of censorship, espionage, intellectual property theft, and other supply chain security risks directed by the People's Republic of China.

The senators pointed to a tangible consequence of these actions, noting that the stock price of an entity-listed Chinese lab nearly doubled during the period Anthropic was under export controls.

Their letter, addressed to leaders in the White House, the Office of the National Cyber Director, and the departments of State, Treasury, and Commerce, requested clarification on several points. These included the standards the administration employs to assess national security risks posed by "frontier models," the legal authorities it intends to use for imposing restrictions, and which agencies are responsible for specific decisions. No immediate response was received from the addressed offices or departments.

This congressional inquiry follows similar concerns raised at the state level, where 15 attorneys general had previously sought more information from OpenAI regarding the security incident at Hugging Face.

ai
ShareXLinkedInWhatsAppFacebook

More News

view all →
aihigh

Bypassing AI guardrails is so easy a script kiddie can do it

Researchers from Cisco Talos have found that current AI model guardrails are easily bypassed by threat actors. Simple claims of ownership or participation in security exercises are often enough to make AI models assist with potentially malicious activities. While AI can be a force multiplier for sophisticated attackers, less skilled individuals may struggle to achieve significant results due to a lack of expertise.

phishing

Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens

The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has become the latest crimeware solution to add support for device code phishing, a rapidly growing cyber threat that abuses the legitimate OAuth 2.0 Device Authorization Grant to bypass Multi-Factor Authentication (MFA) and seize control of user accounts. "Greatness supports AiTM [adversary-in-the-middle] credential and

security

Landmark Deal Would Officially Add Laser Weapons to US Army Arsenal

Facing a growing drone threat, the Pentagon is poised to sign a first-of-its-kind contract for “Enduring High Energy Lasers”—and make directed energy weapons an official part of the Army’s kit.

malware

Massive ChainDrop npm supply-chain attack infects hundreds of packages

Self-propagating malware named 'ChainDrop' has compromised more than 1,300 packages with a combined 2 billion monthly downloads on the Node Package Manager (npm) registry. [...]

ransomware

Prolific ransomware group behind SonicWall zero-day attacks

INC ransomware wasn’t the first group to exploit the zero-days, but it’s been the most assertive and effective in chaining both vulnerabilities to steal and encrypt data for extortion. The post Prolific ransomware group behind SonicWall zero-day attacks appeared first on CyberScoop.

security

Tennessee congressional hopeful accused of shooting license plate cameras

Cops arrest budding politician for allegedly dealing with Flock's expansion the American way