5 Aug 2026, 11:02 UTC177 views8 reactionsread 6 August 2026 Photo
OpenAI and Anthropic Agents Targeted Real People in Cyber Tests
During a cyber-range evaluation by the UK AI Security Institute, agents powered by Anthropic’s Claude Mythos 5 and OpenAI’s GPT-5.6 Sol performed 19 unauthorized actions on the public internet.
Seventeen actions involved Mythos 5, while two involved GPT-5.6 Sol.
The agents had unrestricted internet access, and evaluators disabled their standard cybers…
👍7❤1
6 Jul 2026, 15:14 UTC480 views14 reactions1 Starread 6 August 2026 Photo
*npm install is the new phishing email.
108 malicious packages and browser extensions across npm, Golang, and Google Chrome. All tied to North Korean campaign.
In parallel, fake Rollup polyfills are built to steal developer secrets.
DAEMON Tools shipped malware through its own installer in a supply chain compromise.
Attackers deliver malware as a dependency and let you handle the delivery. If your supply chain de…
👍14
29 Jun 2026, 08:12 UTC467 views6 reactionsread 6 August 2026 Photo
China’s Zhipu AI matches Mythos capabilities in vulnerability detection.
While U.S. and Anthropic’s Project Glasswing restricts access to Mythos, China’s Zhipu AI open-weight model matches and, in some tests, beats Claude at vulnerability detection.
Independent testing by Semgrep placed Zhipu AI GLM-5.2’s IDOR (Insecure Direct Object Reference) vulnerability detection at a score of 39%, surpassing Claude Code’s 32–…
👍6
22 Jun 2026, 13:20 UTC481 views9 reactionsread 6 August 2026 Photo
A fired school district IT admin spent 20 months attacking his former employer.
Before being terminated, he grabbed over 300 sets of user credentials.
Then over the next two years he deleted their Facebook page, wiped Apple School Manager data, disrupted their Schoology LMS, and tried resetting GoDaddy accounts.
He got caught because he asked a coworker to wipe a USB drive he left behind. The coworker gave it to m…
👍7❤2
21 Jun 2026, 07:40 UTC423 views8 reactionsread 6 August 2026 Photo
Do we win a lottery here in Ukraine and rest of the world? 👀
@securediary
👍8
17 Jun 2026, 09:51 UTC546 views8 reactionsread 6 August 2026 We’ve already collected 87 out of the 100 responses we need for Security. Come on, let’s reach 100 this year.
This will be useful for everyone 🙂
Link to salary survey
👍5❤3
16 Jun 2026, 06:32 UTC485 views9 reactionsread 6 August 2026 Photo
The US government forced Anthropic to pull Claude Fable 5 and Mythos 5 offline.
The reason? A jailbreak consisted of asking the model to read a specific codebase and fix any software flaws.
Isn't that what defenders use these models for? 😑
Yes, but the concern that this will be abused by attackers.
Here’s a quote from the US government request:
“suspend all access to Fable 5 and Mythos 5 by any foreign national, …
👍7❤2
12 Jun 2026, 14:36 UTC455 views11 reactions1 Starread 6 August 2026 Photo
Hi everyone!
I know my blog is steadily gaining new readers, and I’d like to put that reach to good use. Specifically, I want to help DOU gather more reliable salary data for security professionals in Ukraine.
Every year, only about 20–30 security specialists fill out the survey.
That’s just not enough.
If you work in cybersecurity or infosec, I’m asking you to take five minutes to complete this survey. It’s comp…
👍9❤2
10 Jun 2026, 14:00 UTC405 views15 reactionsread 6 August 2026 Photo
It's starting to feel more and more that today the game comes down to "AI vs AI."
Take cybersecurity.
AI used to secure systems (AI SOC, AI SAST, and pentest, Anthropic mythos).
And AI is used to abuse them. Just take APTs, security researchers. Bug bounties crashing under the weight of AI reports.
What do you think of this?
Have you felt that “AI vs AI” becoming our new reality? 👀
@securediary
👍15
9 Jun 2026, 09:17 UTC408 views7 reactionsread 6 August 2026 Photo
Eight US agencies published a warning about cyberattacks on fuel tank monitoring systems.
These systems monitor fuel levels, temperature, and leak detection at gas stations and transportation hubs. Attackers gained access and changed settings on these systems.
The attack vectors listed were simple: authentication bypass, hardcoded creds, default passwords, OS command injection, SQLi.
Almost every week, we see atta…
👍7
4 Jun 2026, 11:50 UTC416 views10 reactionsread 6 August 2026 Photo
Your AI agent is not an employee.
So why are we giving it employee-level trust?
Anthropic published "Zero Trust for AI agents". A very interesting read, I highly recommend it.
The most important part is the shift in assumption.
Agents are not just chatbots anymore.
They can read docs, call APIs, open pull requests, trigger workflows, write code, and sometimes execute.
That means they are becoming a new kind of i…
👍6❤4
1 Jun 2026, 16:44 UTC390 views6 reactionsread 6 August 2026 Photo
CISA left AWS GovCloud keys, tokens, and plaintext passwords exposed in a public GitHub repo.
A contractor created “Private-CISA,” disabled secret-blocking, and likely used it to sync files between work and home computers.
GitGuardian found it. Another researcher confirmed some exposed AWS keys still worked. After the repo was taken down, the keys reportedly remained valid for another 48 hours.
This can happen to …
❤4👍2
Showing the 12 most recent of 19 posts we hold for @securediary. View and reaction counts are the latest single reading for each post, not a live figure, and a recent post is still accumulating both. A view count marked ≈ was rounded by Telegram before we ever saw it — t.me prints views in full below 1,000 and to three significant figures above, so ≈1,200,000 means somewhere between 1,150,000 and 1,249,999. Unmarked counts are exact. Text is reproduced from the public post preview and truncated for length.