This week

- UK Government open letter to companies on AI cyber threats
- Mythos performs, though AISI range lacks real-world cyber defences
- OpenAI expands Trusted Access for Cyber Programme
Interesting stats
2.3 billion tokens, costing $2,283 in API costs, required to get Claude’s current Opus model to create a working exploit.
Five Three things
All AI-focused this week, hopefully grounded in what you need to know, rather than hype dominating lots of discussion last week.
-
The UK government sent an open letter to businesses on AI cyber threats, partly in response to Anthropic’s Mythos announcement. The TL;DR is that AI is advancing more rapidly than envisaged - doubling in capability every 4 months, instead of 8 months as previously thought - however, the fix is simple: top management must take cyber seriously, and get the basics (Cyber Essentials) right.
-
The AI Security Institute (AISI) evaluation goes into detail about the performance and relative token cost of models released since November 2022. As well as overall capability, the report focuses on efficiency — the number of tokens needed to achieve a result. The most complex test, dubbed The Last Ones, is a 32-step simulated corporate network attack intended to be the sort of chained attack that might take a human 20 hours to complete in a CTF setting. Mythos Preview, Opus 4.6, and GPT-4.5 all used 10x100M tokens to achieve an average of 22, 16, and 13 steps, respectively. Mythos Preview completed the 32-step course in 3 out of 10 attempts. However, as AISI notes, their range “lack[s] security features that are often present, such as active defenders and defensive tooling. There are also no penalties for the model for undertaking actions that would trigger security alerts.” AISI concludes that it’s not clear if Mythos would actually perform in real-world, well-defended systems.

- Bruce Schneier’s post, co-written with David Lie, is a well-balanced account that cuts through the hype to point out the success rate of Mythos is unknown, that smaller, cheaper models have had similar successes, and the need for greater transparency, rather than private companies chasing which parts of global infrastructure get defended first. With OpenAI claiming their next cyber model needs “strong” Know-Your-Customer (KYC) rules to restrict access (more), I wonder if governments will consider ramping up regulation (and if this might curtail this sort of announcement)?
In brief
-
⚠️ Incidents: Booking.com says ‘unauthorised parties’ gained access to guests’ booking information of an undisclosed number of its customers. The compromised booking information may include booking references, names, email and physical addresses, phone numbers, and “anything that you may have shared with the accommodation”. American fashion retailer Express left customer order information accessible to the Internet. Cryptocurrency exchange Grinex says $13.7 million funds have been stolen from its accounts. The Kyrgyzstan-based company is blaming ‘Western intelligence’ for the incident, which may seem far-fetched as a target ’til you learn that Grinex is believed to be a rebrand of Garantax, a Russian exchange sanctioned for laundering over $100 million in illicit funds. CodeWall gained access to one of Bain & Co’s AI tools using a username and password it found in public code. Bain’s Pyxis platform is used by its private equity practice in due diligence engagements, and the compromise gave access to around 10,000 conversations.
-
🏴☠️ Ransomware: ShinyHunters are trying to extort Grand Theft Auto developer Rockstar Games, though the games company says the information stolen is “non-material company information” via a third party. The third-party route matches typical TTPs for ShinyHunters, who have been targeting customer support partners and data platforms used by large enterprises. Education publisher McGraw Hill has also suffered at the hand of ShinyHunters, apparently losing ‘over 40 million’ records from their company’s Salesforce environment. McGraw Hill’s response attempts to distance itself from the breach, and draw attention to multiple Salesforce customers being impacted. UK automotive services company Autovista says it has suffered a ransomware attack, causing disruption to their data and analytics services in Europe and Australia.
-
🕵️ Threat Intel: A critical vulnerability in Nginx UI’s Model Context Protocol support is being exploited, allowing unauthenticated users to invoke the
/msp_messageendpoint and invoke privileged actions. Chinese media have been reporting on a successful trial of new undersea cable capability that could be used to sever undersea telecommunications cables. DarkTrace says it’s seen ZionSiphon malware targeting Israeli water and desalination plants and raise chlorine levels to unsafe levels, though the IP targeting routine fails and self-destructs. -
🪲 Vulnerabilities: Adobe has released an emergency fix for Acrobat Reader to mitigate a bug that can lead to arbitrary code execution; the vulnerability has been exploited in ‘zero-day’ attacks since at least December 2025 (CVE-2026-34621; 8.6/10; advisory). Fortinet has patched command injection and path traversal vulnerabilities in FortiSandbox that could lead to authentication bypass (CVE-2026-39808 & -39813; both 9.1/10; advisory: cmd injection, path traversal). Users of Cisco Webex Services platform need to patch an issue in the system’s SSO Layer that allows impersonation of any user (CVE-2026-20184; 9.8/10; advisory).
-
🧰 Guidance and tools: Microsoft’s write-up of the tactics used by threat actors to run cross-tenant Helpdesk impersonation and data exfiltration attacks.
-
🛠️ Security engineering: NIST says that it will reduce the scope of its enrichment work on the National Vulnerability Database to only focus on those that appear on CISA’s KEV list and ‘critical software’ from Executive Order 14028. NIST (and CISA) have been facing funding challenges at the same time as the number of vulnerabilities has exploded.
-
🏭 Operational technology: WolfSSL, a lightweight SSL/TLS library for embedded and IoT systems, has a critical vulnerability whereby it may accept forged certificates. While the wolfSSL project has released an update, it’s typically bundled as part of the software of an individual device, and you may need to check individual vendor updates (CVE-2026-5194; 9.1; advisory). Swedish authorities say that a pro-Russian group attempted to disrupt a thermal power plant in 2025, with the group’s tactics shifting from denial of service to more disruptive attacks.
-
🧿 Privacy: The US state of Virginia banned the sale of precise geolocation data. The law, which will come into force on 1st July, prohibits the sale of citizen locations more granular than a 1,750-foot radius.
-
📜 Policy & Regulation: The Open Rights Group has released a report saying the UK has become [over-reliant on US tech companies] and needs its own sovereignty strategy](https://www.openrightsgroup.org/press-releases/new-report-uk-needs-digital-sovereignty-strategy-to-address-threats-from-reliance-on-big-tech/). The US FCC has picked non-profit ioXt Alliance to lead their Cyber Trust Mark Programme, the label scheme to improve understanding of IoT device security.
-
👮 Law Enforcement: A Northern Ireland teenager has been arrested for suspected Computer Misuse offences following an attack against the C2K schools system earlier this year. Two New Jersey residents have been sentenced to prison time for operating ‘laptop farms’ used in fraudulent North Korean IT worker schemes. Europol says it’s arrested four people and taken down 53 domains associated with distributed denial-of-service (DDOS) attacks used by more than 75,000 attackers, as part of Operation PowerOFF. A 25-year-old US man avoided prison time for digital break-ins to US Supreme Court and Veterans Health Administration systems. Nicholas Moore entered a guilty plea, and told the judge “I made a mistake” when stealing login credentials and posting personal information to his Instagram account @ihackedthegovernment.
And finally
- No honour amongst thieves: the 0APT ransomware group is threatening to expose the identities of fellow criminals Krybit. What stands out here is that it’s a ransomware group attempting to extort another, running the same playbook as they would against typical victims. On their leak site, 0APT said Krybit poses ‘significant risks’ and that “If the group does not make the payment or contact us, we will reveal their identity, photos, names, location, and other.” 0APT added, “And if you are one of their victims, contact us to get your data unlocked.”