The Register-Security

"Anthropic's super bug-hunting model Mythos is hardcore good at math, as latest vuln under attack shows."

Views expressed in this cybersecurity, cybercrime update are those of the reporters and correspondents.  Accessed on 05 October 2026, 1249 UTC.

Content and Source:  "The Register-Security" via email subscription from https://feedly.com.

https://feedly.com/i/subscription/content/feed%2Fhttp%3A%2F%2Fwww.theregister.co.uk%2Fsecurity%2Fheadlines.atom

Please check subscription link or scroll down to read your selections.  Thanks for joining us today.

Russ Roberts (https://hawaiicybersecurityjournal.net).

229K followers31 articles per week

Oct 3, 2026

The second Anthropic-linked vulnerability known to have been exploited in the wild saw initial activity from an IP address in China targeting vulnerable hosts in the US and Japan. The vuln is a critical authentication-bypass bug in Rejetto HTTP File Server (HFS) that can lead to full admin access and remote code execution. HFS is an open source web file server that previously appeared on the US Cy
OpenAI's agents have repeatedly strayed beyond their intended scope. Two separate reports detail the activity, including one from Sam Altman’s company saying it has notified more than 100 organizations about potentially problematic model activity. OpenAI, in a late Wednesday update to its ongoing Hugging Face investigation, said it has notified more than 100 organizations that “misaligned models”
A California business owner was arrested on Thursday after being charged with allegedly smuggling Nvidia hardware to China without the proper export licenses. Keeping the highest-end GPUs out of Chinese hands has been a priority for the US government. Greg Lui, 38, allegedly tried to export around $300 million worth of Nvidia kit - typically used for artificial intelligence (AI) development - via
California's attorney general has subpoenaed OpenAI as the state investigates what happens when the AI lab's models escape their testing environments and start meddling with systems on the open internet. Attorney General Rob Bonta said his office served OpenAI with an investigative subpoena this week as part of a broader California Department of Justice probe into cybersecurity incidents and risks
Fortinet is warning customers to lock down FortiMail after attackers started exploiting a critical bug that lets them write files to vulnerable systems without logging in. The flaw, tracked as CVE-2026-104286, carries a CVSS score of 9.8 and affects multiple versions of Fortinet's email security platform. Fortinet describes the vulnerability as a combination of path traversal and improper handling
AI agents hacked the hackers - the Dutch Institute for Vulnerability Disclosure (DIVD) - via two zero-day bugs in its Zammad support platform, abusing the flaws to hijack sessions, run code remotely as the local zammad user, and escalate privileges to root. The chained exploits took just seconds to move from session hijacking to root access, and on Thursday, the nonprofit bug hunting organization
Depending on Chinese technology for European infrastructure poses risks that not every country takes seriously. So says the Royal United Services Institute (RUSI), which suggests that the EU needs to do better in helping members assess the risk and take appropriate action to safeguard the entire bloc. The UK-based think tank said in a report today that the EU should develop a new risk assessment f
A suspected Chinese espionage group impersonated AI policy figures, including a senior Anthropic employee and a former White House official, in phishing campaigns targeting AI policy experts at US universities, think tanks, and law firms, security researchers say. The bulk of these campaigns occurred in July, according to Proofpoint, which discovered the espionage attempts and attributed them to a
Attackers were poking at a critical Zimbra mail server bug weeks before it was publicly disclosed, and then moved on to steal credentials, raid mailboxes, and take deeper control of compromised systems. Microsoft Threat Intelligence said it tracked exploitation of CVE-2026-73570, an unauthenticated command injection vulnerability in Zimbra Collaboration Suite that gives attackers a potentially eas
MI5 has warned that more than 100 UK-linked academics contributed to research projects allegedly funded to improve China's spying capabilities. The Security Service issued an unusually public espionage alert this week naming the China General Technology Research Institute (CGTRI), also translated as the China Academy of General Technology (CAGT). MI5 says the organization has "very strong ties" to
Welcome back to PWNED, the weekly column where we warn you about weak security practices. This week’s terrifying tale involves a lack of important patching and a humorously bad password belonging to the person in charge of tech security at a law firm. Have a story about someone leaving a gaping hole in their network? Share it with us at pwned@sitpub.com. Anonymity is available upon request. Our st
England's secondary schools are reporting slightly fewer cybersecurity incidents and faster recovery when disaster strikes, according to a survey by exams regulator Ofqual. Twenty-seven percent of schools reported an incident during the 2025/26 academic year, down from 29 percent a year earlier and 34 percent in 2023/24. Ofqual surveyed 3,775 secondary teachers in England in July. For questions co

Oct 1, 2026

Britain's data protection watchdog has acquired a new legal identity and governance structure, although the familiar ICO initials are staying put. On September 30, the Information Commission replaced the Information Commissioner as the statutory regulator. The organization itself will be known as the Information Commission's Office and will continue using the ICO name. The change is more than a bu

Sep 30, 2026

The proportion of workers in the UK cybersecurity industry identifying as women has dropped to 16 percent, the lowest level since 2021. Gender diversity has long been an issue pervading the STEM fields, although in cybersecurity this is especially pronounced, both at senior leadership and education levels. This is despite evidence that girls regularly outperform boys in STEM subjects at UK schools
OpenAI, which hoovered up vast amounts of internet content amid copyright fights, has accused individuals associated with China’s Moonshot AI of being involved in a "distillation attack" that began July 1. The house of Altman warns that extracting its models’ reasoning at scale could help rivals train capable models without preserving the same guardrails. Model distillation is a machine learning t
A 16-year-old security researcher named Faav found an authentication flaw in Microsoft’s Titan analytics service that allowed him to gain administrator access, submit unauthorized SQL queries with no valid credentials, and potentially reach analytics databases containing an estimated 17.3 trillion stored rows. Titan is an internal analytics platform, and Redmond restricts access via its web interf

Comments

Popular posts from this blog

The Hacker News

SecurityWeek Briefing

PCMag SecurityWatch