This week

- Mozilla says Mythos is more capable, but tooling, orchestration are needed to capitalise
- ClaudeBleed: Poor authorisation in Anthropic’s Chrome extension
- CISA says US CNI should plan to operate in an isolated environment
Interesting stats
1/8 of professionals admit to selling company login details for money, according to UK fraud prevention outfit Cifas (report)
32% of 1,000 children surveyed by UK digital safety group Internet Matters say they have bypassed age checks introduced by the Online Safety Act, including by *ahem* _drawing a moustache on their faces LINK See also: Meta is seeking a judicial review in the UK over how Ofcom determines “qualifying worldwide revenue”.
£102 million ($138M) lost by Brits to romance scams last year, around £9,500 ($12,866) on average per scam, according to the City of London Police
Five Three things
-
Mozilla’s Mythos Musings: The Mozilla Foundation published a post about their experiences using Anthropic’s Mythos model to go bug hunting in Firefox’s source code. The TL;DR: ”Suddenly, the bugs are very good,” and while the model got a lot more capable, this is also attribute to how they “dramatically improved out technical for harnessing these models”. The result is that AI slop bugs are out, and reports from Mythos are of a much higher quality, and easier to remediate, with “almost no false positives”. Some of the issues Mozilla found had been undetected for a decade. Still, the underlying story here is one of orchestration and coverage. Mozilla spent time observing and iterating from some pretty basic prompts, but admits they have built “a lot of orchestration and tooling” to optimise and scale their process. AI gave them a thousand interns, and those thousand interns are also super expensive. Zooming out, bad actors are almost certainly using (less capable) models to perform similar analysis of popular open source software and libraries. Particularly those used in edge networking devices (firewalls, VPNs, etc) that are attractive entry points for espionage-focused adversaries. My gut feel is that most criminals won’t currently be engaging in such speculative testing, but will instead deploy AI to enhance their social engineering, where the near-term ROI is likely to be higher. It will push a premium on proprietary vendor source code, though. Stepping back again, as Bruce Schneier points out for The Guardian, finding loopholes isn’t just something limited to computer code and there are far-reaching societal impacts, for example, how many investment banks are already ‘red teaming’ tax codes for loopholes?
-
ClaudeBleed: At the same time as Anthropic’s PR machine has been riding high, there have been a series of vulnerabilities and security incidents affecting its products. This week, LayerX researchers found that any other extension can hijack Claude’s Chrome extension because it trusts
*.claude.ai/*as an origin, without distinguishing who is telling it to do something. The researchers found they could exfiltrate data from Google Drive, send emails, steal source code (see above!), and more. Whatever Claude could do on your behalf, any other extension could also trigger, silently, without your knowledge. LayerX say Anthropic has issued a partial fix, which has not addressed the root cause of the vulnerability. -
CI Fortify: CISA has launched an initiative called CI Fortify, encouraging US critical infrastructure operators to be ready to deliver essential services for “weeks to months” while isolated from, for example, IT networks or the Internet. The aim is for resilience that would allow vital services in the United States to sustain essential operations during a geopolitical conflict. While this is sensible — these are critical services after all — the overt references to geopolitical conflict and isolation are striking. It’s an acknowledgement that the availability or trustworthiness of ‘cyberspace’ (aka the Internet or other networks) may be ceded, like physical territory, to an adversary and may take time to reclaim. Once such an example, linked from the announcement, was the China-linked Volt Typhoon campaign. The American ambition there was eviction and eradication, but if you think that’s not achievable near-term, then having a backup plan to isolate and restore isn’t a bad idea.
In brief
-
⚠️ Incidents: Commercial retail management firm Cushman & Wakefield says it has suffered a vishing attack, with both ShinyHunters and Qilin cybercrime groups claiming to have stolen “over 500,000” Salesforce records. Kaspersky has attributed a Chinese group to the month-long backdoor of popular Windows disc imaging tool Daemon Tools (v12.5.0.2421—12.5.0.2434). Thousands of infected machines reported back system information, with twelve of them receiving a targeted second-stage malware payload. Braintrust, an AI evaluation startup, has confirmed “unauthorised access” to one of its AWS accounts and has asked all of its customers to rotate their API keys used with the service. Cyber company Trellix has confirmed unauthorised access to its source code, claimed by the RansomHouse group, while the company says it has not seen evidence of tampering with its release or distribution process.
-
🏴☠️ Ransomware: Kaspersky say that Amazon’s Simple Email Service (SES) is being increasingly abused to send phishing emails because of the large number of legitimate credentials exposed via GitHub repos, .env files, and other means.
-
🕵️ Threat Intel: Rapid7 say with “medium confidence” that they believe intelligence agents from Iran are behind the Chaos ransomware gang.SentinelOne researchers say they have discovered a worm that eradicates TeamPCP infections, so it can take its place.
-
🪲 Vulnerabilities: Palo Alto Networks has warned customers of a zero-day vulnerability in PAN-OS’ User-ID Authentication Portal that can lead to arbitrary code execution (CVE-2026-0300; 9.3/10; advisory). Dirty Frag: An exploit for another Copy Fail (vol. 9, iss. 18) style vulnerability has been disclosed, affecting all major Linux distributions after an embargo was breached (no CVE or patches, yet). Ivanti’s Endpoint Manager Mobile (EPMM) has a high-severity, zero-day vulnerability that leads to remote code execution (CVE-2026-6973; 7.2/10; advisory).
-
🛠️ Security engineering: A Hugging Face repo spoofing OpenAI’s Privacy Filter project contained malicious code; it was downloaded 244,000 times before being removed.
-
🏭 Operational technology: A Taiwanese university student halted four trains for 48 minutes in April by using software-defined radio to transmit a “General Alarm” signal over the TETRA communication system used by the country’s railway network. Poland’s intelligence agency says it’s aware of five incidents on water treatment plants where attackers could have tampered with the safety of the water supply.
-
🧿 Privacy: General Motors will pay $12.75 million as part of a settlement under the California Consumer Privacy Act (CCPA) for collecting and storing driving data without consent, and then selling it to data brokers.
-
👮 Law Enforcement: Former L3Harris exec Peter Williams has been ordered to pay $10 million restitution to the firm for stealing and selling trade secrets to a Russian exploit broker.
-
💰 Investments, mergers and acquisitions: Autonomous offensive testing firm XBOW has announced a $35 million extension to its $120 million Series C funding round. Herd Security has announced a $3 million Seed round for its platform that uses AI to generate test, image, and video training packages based on company policies and security events.
-
🗞️ Industry news: SOC vendor Arctic Wolf has laid off 250 employees (approx. 10%) to “better align the company’s structure” with its investments in AI and Agentic SOC.
And finally
- My pals Mariana and Ed are starting a new AI Security Community in London to, in their words, “create space for thoughtful, honest conversations between the people actually building and securing these systems.” The first meetup is on 28th May, and they’re taking over Hijingo Bingo. RSVP if you’re interested.