After weeks of exclusion, the EU now gains access to Anthropic’s Mythos hacking AI model, while the Commission works on a formal action plan for such systems.
Lapsus$ stole source code from Vodafone and published it, demonstrating the gang’s operationalization and highlighting the critical need to secure source code and developer assets within zero-trust infrastructure.
An npm package disguised as an OpenAI Codex interface with 29,000 weekly downloads steals authentication tokens and enables attackers to abuse APIs under stolen identities.
A China-aligned group distributes targeted phishing emails with malicious ZIP attachments in Czechia and Taiwan to gain access to government, research institutions, and financial sector organizations.
Barely perceptible acoustic signals embedded in audio files can covertly manipulate AI speech models into data exfiltration or network access, while conventional security mechanisms fail to detect 70–93 percent of attacks.
Vodafone refused to pay Lapsus$ extortionists, prompting the group to publish source code and infrastructure documentation—confirming security leadership’s stance against ransom payments.
Microsoft authentication services have experienced a global outage, preventing MFA configuration and access to the central portal for sign-in activity management.
European regulation through the EU AI Act and NIS2 Directive shapes digital sovereignty requirements and demands new governance and security structures from CDOs.