"An unsecured police dashboard was a rare window into how the authorities track foreigners by collecting and aggregating vast amounts of private data." www.nytimes.com/2026/08/02/w... #privacy #security #China
Jari Pirhonen
@japi.bsky.social
Security leader, risk professional, business enabler, lifelong learner.
"AI-driven attacks increased 56% over last year’s study and added an average of USD 1 million per breach as #AI tools allow attackers to increase their velocity and scale." www.ibm.com/reports/data... #cybersecurity #infosec #breach
Cost of a Data Breach Report 2026 | IBM
IBM’s global Cost of a Data Breach Report 2026 provides up-to-date insights into cybersecurity data breaches and their financial impacts on organizations.
ibm.com
”A good rule of thumb: The more objects humans launch into space, the more debris we will have to dodge on Earth.” www.nytimes.com/2026/08/03/w...
"Operating under the false belief that all accessible entities were intended to be in-scope for the exercise, #Claude compromised the impacted organizations’ infrastructure using basic techniques." www.anthropic.com/news/investi... #AI #cybersecurity #fail
Investigating three real-world incidents in our cybersecurity evaluations
In a review of our cybersecurity evaluation transcripts, we found three incidents in which a Claude model reached the internet from within or while interacting with a third-party evaluation…
anthropic.com
"Unless LLMs achieve genuine role perception, we think injection defense will remain a perpetual whack-a-mole game." role-confusion.github.io #AI #LLM #cybersecurity
Prompt Injection as Role Confusion
LLMs can't tell who's speaking. We show they identify roles by writing style, not tags, and exploit this with CoT Forgery, injecting fake reasoning that models mistake for their own thoughts.
role-confusion.github.io
"Our learning from this type of attack is that machine-speed offense makes ordinary weaknesses more expensive for defenders. On the other hand, many parts of #cybersecurity defense remain the same." huggingface.co/blog/agent-i... #AI
Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident
We’re on a journey to advance and democratize artificial intelligence through open source and open science.
huggingface.co
"This paper explains how the autonomous #AI attack unfolded, what made it detectable, and what security teams should do next to secure agentic AI systems." cloudsecurityalliance.org/artifacts/hu...
Hugging Face Incident Initial Post Mortem I CSA
AI Security Alliance's initial post-mortem on the Hugging Face incident, the first documented autonomous AI attack, with CISO guidance on detecting, responding to, and governing agentic AI risk.
cloudsecurityalliance.org
"In China new platforms are paying people to license their likeness for #AI-generated dramas and ads, creating a new marketplace for biometric identity." restofworld.org/2026/china-a...
In China, people are renting out their faces to AI
New platforms are paying people to license their likeness for AI-generated dramas and ads, creating a new marketplace for biometric identity.
restofworld.org
"We now have more details of what happened. Every time we learn more details, it somehow makes things seem worse." #AI #cybersecurity thezvi.substack.com/p/more-on-an...
More On An Internal OpenAI Model Hacking Into HuggingFace
We now have more details of what happened. Every time we learn more details, it somehow makes things seem worse.
thezvi.substack.com
This old article describes nicely, how #AI will always find a way. The solution may be novel and desirable - or novel and undesirable. It is difficult to define clear enough goals and rules. deepmindsafetyresearch.medium.com/specificatio...
Policymakers are casting more and more problems as issues of #cybersecurity. So reframed, wildly different policy issues become “cybersecuritized.” papers.ssrn.com/sol3/papers....
Cybersecurity Mission Creep
<p><span>Cybersecurity is experiencing mission creep. Policymakers are casting more and more problems as issues of cybersecurity. So reframed, wildly different
papers.ssrn.com
Who cleans up after the vibe-coding party? "It is easier to destroy than to create, and it is easier to create than to maintain. Too often, we don’t appreciate maintenance until something breaks, or the maintainers until they step away." www.ft.com/content/cec8... #AI #software #opensource
"We cannot afford to have a society in which a significant fraction of our best young minds think that cheating is OK. That leads to a declining society, to a failed society. We cannot choose to become idiots.” www.insidehighered.com/news/faculty... #AI
Brown Professor Suspects Most of His Class Used AI to Cheat
Brown University leaders’ response to the alleged cheating incident has been “meek,” the professor said.
insidehighered.com
“Although the Army CIO announced in May 2026 that they were offering unlimited tokens, by mid-June the Army CIO pool was exhausted of tokens and had to re-establish limits” www.wired.com/story/the-ar...
The Army Is Burning Through Its AI Tokens
Members of the Army received an email informing them that they were rapidly depleting their AI tokens, and needed to limit use.
wired.com
”Major benchmarks measure what #AI can do. None measure whether it does what you mean. We propose a new metric: the Genie coefficient.” spectrum.ieee.org/ai-agent-ben...
Why AI Needs a "Genie Coefficient"
Proposing a new metric for whether AI does what you actually want
spectrum.ieee.org
”we detected and responded to an #intrusion into part of our production infrastructure. It was driven, end to end, by an autonomous #AI agent system ” huggingface.co/blog/securit...
Security incident disclosure — July 2026
We’re on a journey to advance and democratize artificial intelligence through open source and open science.
huggingface.co
"We strongly condemn Russia’s behaviour and misuse of this cyber ecosystem, targeting public services and critical infrastructure, causing disruptions and financial losses." #security #safety #privacy www.consilium.europa.eu/fi/press/pre... @consilium.europa.eu
"Starting July 7th, every new car sold in the EU is required to have a camera aimed at the driver’s face. The same regulation will be introduced in the US next year." cybernews.com/security/eu-... #safety #privacy
EU requires all new cars to have cameras facing the driver’s face to monitor their behavior
Starting July 7th, 2026, all new cars in the EU must include an infrared camera to monitor drivers.
cybernews.com
Valheiden sota ( @pasieronenwatt.bsky.social , Juha-Antero Puistola): "Suomi joutuu navigoimaan asetelmassa, jossa sen digitaalinen infrastruktuuri on amerikkalainen, lainsäädännöllinen kehys eurooppalainen ja informaatiouhat yhä useammin globaaleja." #book #quote
"Security fundamentals will not change, but new #AI models are compressing the entire attack lifecycle, in ways that stress-test these fundamentals, forcing defenders, manufacturers and service providers to accelerate their #cybersecurity initiatives." www.enisa.europa.eu/publications...
ENISA’s view on Cybersecurity in the Frontier AI Era | ENISA
ENISA is the EU agency dedicated to enhancing cybersecurity in Europe. They offer guidance, tools, and resources to safeguard citizens and businesses from cyber threats.
enisa.europa.eu
”IT services giant Accenture has confirmed it suffered a security #breach after a threat actor claimed to have stolen 35 GB of source code and other data from the company.” www.bleepingcomputer.com/news/securit... #cybersecurity
”The European Central Bank on Tuesday gave euro zone banks four months to draw up plans to counter #AI-enabled cyber threats” www.globalbankingandfinance.com/ecb-tells-ba... #cybersecurity
The European Systemic Risk Board (ESRB) published a warning on systemic cyber risks stemming from frontier #AI models. www.esrb.europa.eu/news/pr/date... #cybersecurity
Frontier AI models could strain cyber resilience in the financial system, ESRB warns
The European Central Bank (ECB) is the central bank of the 19 European Union countries which have adopted the euro. Our main task is to maintain price stability in the euro area and so preserve the…
esrb.europa.eu
"The Sysdig Threat Research Team has captured what we assess to be the first documented case of agentic #ransomware: a complete extortion operation driven end-to-end by a large language model" www.sysdig.com/blog/jadepuf... #cybersecurity #AI #LLM
JADEPUFFER: Agentic ransomware for automated database extortion | Sysdig
The Sysdig TRT documents JADEPUFFER: the first known agentic ransomware operation, where an LLM autonomously exploited Langflow, harvested credentials, and executed full database extortion.
sysdig.com
"The worldview of GPT models is more secular than any country on earth. Gemini models place more weight on individual freedom than people do anywhere. No model reflects the worldviews of most African or Muslim countries." www.economist.com/briefing/202... #AI #GenAI #LLM
"Researchers can’t even agree on basic questions like how many companies are using #AI or which workers are most vulnerable to the disruptions it could cause." www.nytimes.com/2026/07/02/b...
nytimes.com