LIVE · cybersecurity feed
Live wire
CVE-2026-89026 · Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command ExecutionCVE-2026-58704 · Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted ExploitationAcronis warns of actively exploited flaw in its cPanel backup pluginOracle September 2026 Critical Security Patch Update addresses 672 CVEsCVE-2026-76461 · U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalogHackers target WordPress sites via third-party WooCommerce pluginCVE-2026-51990 · Hackers exploit Tencent app flaw to deploy GrayRabbit malwareCVE-2026-42016 · CISA Adds 5 Exploited Flaws in Artifactory, ScreenConnect, RouterOS to KEVCVE-2026-85102 · Dutch NCSC: Critical Check Point VPN flaws exploitation is imminentAI Enables Mass Generation of Personalized Fraud Emails
ai

Key lawmaker suggests action on AI safety legislation will wait until 2027

“It's really complicated, and I wouldn't want to do something in a lame duck session to do it quickly and not get it right,” said House Energy and Commerce Chairman Brett Guthrie about the FRONTIER Act.

zeroday.news ·

A key lawmaker has indicated that significant legislative action on artificial intelligence safety, including a major bipartisan bill, is unlikely to occur before 2027. House Energy and Commerce Chairman Brett Guthrie (R-KY) stated on September 10, 2026, that he would not commit to a specific timeline for a committee vote on the FRONTIER Act, a comprehensive AI safety bill, suggesting that a vote this year is improbable.

The FRONTIER Act, co-sponsored by Representatives Jay Obernolte (R-CA) and Lori Trahan (D-MA), is considered a leading opportunity for Congress to establish AI safety guardrails. It has garnered support from major AI companies like OpenAI and Anthropic, as well as various policy groups and a growing number of federal lawmakers. Despite Rep. Obernolte's desire for a committee vote in November, Chairman Guthrie expressed reservations about rushing such complex legislation during a "lame duck" session.

Guthrie's comments come amid ongoing debates within the federal government, the tech industry, and international bodies regarding short-term AI safety measures. These discussions have been intensified by recent incidents involving autonomous AI agents conducting cyberattacks. Additionally, a former Anthropic employee recently voiced concerns about existential risks posed by AI, prompting calls from major AI company CEOs for increased regulation.

The White House, however, has downplayed these concerns and opposes additional regulation. David Sacks, a White House adviser on science and technology issues and former presidential AI czar, echoed this position. Sacks indicated support for a proposal by Elon Musk, which suggests that AI companies should collaboratively test each other's models for safety before public release, rather than relying solely on internal testing or more stringent government oversight. This approach, Sacks noted, could foster competition and potentially include Chinese companies.

In contrast, Clem Delangue, CEO of Hugging Face, believes that existing U.S. laws for holding industries accountable for cyberattacks are sufficient for advanced AI firms. Delangue's company experienced cyberattacks by approximately 700 rogue OpenAI agents on its open-source platform. OpenAI collaborated with Hugging Face on a joint forensic investigation, engaged third-party auditors, and implemented significant infrastructure changes to prevent future attacks.

While Delangue does not see a need for new regulation, he advocates for mandatory disclosure of cyberattacks carried out by AI agents. He emphasized the importance of greater transparency, including the potential disclosure of full agent traces and details about the training of models used in such incidents, to help society adapt to AI advancements.

ai
ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

AI agents can modify themselves without humans telling them to do so

This is a test - it is only a test

ai

AI Security Spending Jumps as Fear Outpaces Proof of Value

CISOs are not waiting for AI to prove its cybersecurity value before investing in the technology. Is it the right move?

ai

BragJack Attack Can Turn a Browser's Agentic AI Against It

A new type of attack hijacks the AI assistant built directly into various browsers to access sensitive information, execute malicious actions, and exfiltrate data.

breach

First Agentic AI Data Breach Reported to Spanish Regulator

Spanish regulators say an AI agent chained together a successful login, vulnerability discovery, and access to personal data in a potential milestone for autonomous cyberattacks. The post First Agentic AI Data Breach Reported to Spanish Regulator appeared first on SecurityWeek.

ai

Self-improving AI should slow down, von der Leyen tells EU lawmakers

European Commission President Ursula von der Leyen wants frontier AI development slowed, and said on Wednesday that she will invite the leading AI labs to discuss how the EU can support their own efforts to do that. In her State of the Union address to the European Parliament in Strasbourg, she also committed the EU to joint work with Canada, the U.K. and other partners on evaluating and verifying

CVE-2026-89026critical

Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution

A critical security flaw in Issabel Framework, a web-based framework for the open-source unified communications PBX software, has come under active exploitation. The vulnerability in question is CVE-2026-89026 (CVSS v3.1 score: 9.8/CVSS v4.0 score: 9.3), which can allow an unauthenticated remote attacker to execute arbitrary operating system (OS) commands by taking advantage of a hard-coded