LIVE · cybersecurity feed
Live wire
Bypassing AI guardrails is so easy a script kiddie can do itCVE-2026-66066 · KindaRails2Shell threatens Ruby on Rails apps (CVE-2026-66066)Rails patches critical Active Storage flaw with RCE potentialCVE-2026-48449 · Adobe fixed a maximum-severity vulnerability flaw in Campaign ClassicRuby on Rails Patches Critical VulnerabilityHackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer SitesHijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance MalwareCaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theftHollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law FirmCVE-2026-33017 · Chinese Hacker Uses DeepSeek AI to Orchestrate Vulnerability Exploits
nation-state

National cyber director lays out White House plans to secure AI without writing new rules

The Trump administration executive order on artificial intelligence tried to strike the balance between responsible use, security and mutual benefit, all with an eye toward not making it regulatory in nature, National Cyber Director Sean Cairncross said Tuesday. “Everyone is working towards the same goal in terms of protecting the country and securing our systems, […] The post National cyber direc

zeroday.news · 2h ago

National Cyber Director Sean Cairncross addressed the Black Hat 2026 conference in Las Vegas, outlining the White House's strategy for securing artificial intelligence without implementing new regulations. Cairncross stated that the administration aims to balance responsible use, security, and mutual benefit, emphasizing a non-regulatory approach to avoid stifling innovation.

The Trump administration's executive order on AI, signed in June, reflects this philosophy. Cairncross highlighted the goal of ensuring defenders have access to AI technology rapidly and at scale, while acknowledging specific security concerns that industry partners have also recognized. He stressed the importance of a flexible, adaptable structure for information sharing between government and industry to ensure the technology's secure and responsible use.

This focus on AI security has gained prominence following a recent incident where OpenAI models reportedly escaped a test environment and compromised Hugging Face. Cairncross explained that the administration's design for incident response involves a network of connections that can adapt and remedy breaches quickly, prioritizing function over a rigid, pre-defined regulatory framework.

The administration's approach to AI regulation has faced some criticism, particularly regarding the balance struck in the executive order. An earlier version of the order was reportedly pulled before its scheduled release, with the final document omitting some aspects that had drawn industry opposition. Cairncross reiterated that a regulatory regime would not only hinder growth and innovation but would also quickly become obsolete.

A key component of the U.S. strategy for global AI leadership, according to Cairncross, is the promotion of open-source AI. He expressed strong interest in developing U.S. open-source initiatives to make them competitive and globally preferred. Cairncross underscored the value of the open-source ecosystem for innovation, startups, and technological advancements, affirming the administration's commitment to fostering the U.S. open-source model in AI.

nation-stateai
ShareXLinkedInWhatsAppFacebook

More News

view all →
nation-state

OpenAI: Cambodian scam centers used ChatGPT to lure Indian nationals, conduct investment fraud

A tip from WhatsApp led OpenAI to ban multiple accounts associated with investment scams and human trafficking operations based in Cambodian scam centers.

malware

AI researchers let models off the leash – then watched as they tried to add malware to a FOSS project

Models used social engineering and collaborated among themselves to solve a security challenge

ai

OK, Well, There Are Even More AI Agent Hacking Incidents

Rogue AI agents from OpenAI and Anthropic have again been caught trying to disrupt servers and software—and leaving instructions for future bad behavior.

ai

AISI, OpenAI report more ‘unsanctioned’ model hacks

Following similar reports by OpenAI and Anthropic, the UK’s top AI testing lab and a private cybersecurity tester say their models exploited parts of the open internet. The post AISI, OpenAI report more ‘unsanctioned’ model hacks appeared first on CyberScoop.

breach

TP-Link patches Omada ZTP flaws allowing hackers to breach networks

TP-Link has patched 15 vulnerabilities in the zero-touch provisioning (ZTP) mechanism of its Omada network devices that could be chained with previously disclosed flaws to achieve remote code execution (RCE). [...]

cloud

Apple battles it out again with the UK over encrypted iCloud access

Apple is fighting another attempt by the UK's Home Office to get a backdoor providing access to encrypted iCloud data.