Anthropic to Release Mythos-class Models to the Public

Anthropic plans to publicly release its Mythos-class AI models, known for their exceptional ability to find security vulnerabilities in code, once stronger safeguards against misuse are developed. Currently, Mythos is available only to select partners, including governments, as unrestricted access could enable cybercriminals to exploit software flaws rapidly, and the company acknowledges that no existing safeguards fully prevent potential harm from these models.

https://www.theregister.com/security/2026/05/25/anthropic-to-release-mythos-class-models-to-the-public/5245596

GitHub Says Internal Repos Exfiltrated After Poisoned VS Code Extension Attack

GitHub suffered a security breach caused by a malicious Visual Studio Code extension that led to the exfiltration of about 3,800 internal repositories, though customer data reportedly remains safe. The attacker group TeamPCP claimed to have access to the internal source code and offered it for sale, raising concerns about potential leakage of private repositories and credentials. GitHub is continuing its investigation and monitoring for further activity while promising a more detailed report once complete.

https://www.theregister.com/devops/2026/05/20/github-says-internal-repos-exfiltrated-after-poisoned-vs-code-extension-attack/5243206

GitHub Confirms Breach, 4K Internal Repos Stolen

GitHub confirmed a breach involving the theft of approximately 4,000 internal repositories by the threat actor TeamPCP, who claimed responsibility and offered the stolen data for sale. The breach occurred through a compromised Visual Studio Code extension on an employee's device, and GitHub responded by removing the malicious extension, isolating the endpoint, rotating critical secrets, and continuing incident response investigations.

https://www.darkreading.com/application-security/github-confirms-breach-4k-internal-repos-stolen

Google’s AI Is Being Manipulated. The Search Giant Is Quietly Fighting Back

A BBC investigation revealed that AI chatbots like Google's AI and ChatGPT can be easily manipulated by publishing targeted content online, causing them to spread misinformation on critical topics such as health and finance. In response, Google has updated its spam policies to combat such manipulation, signaling increased efforts by AI companies to prevent abuse, though experts warn that manipulators often stay ahead and users should remain cautious about AI-generated answers.

https://www.bbc.com/future/article/20260519-google-tackles-attempts-to-hack-its-ai-results

Project Glasswing: What Mythos Showed Us

Project Glasswing involved testing Anthropic's Mythos Preview, a security-focused large language model (LLM), on Cloudflare's code repositories to identify vulnerabilities. Mythos Preview demonstrated advanced capabilities in chaining multiple low-severity bugs into exploitable chains and generating working proof-of-concept exploits, significantly improving the quality and actionability of vulnerability findings compared to previous models. Cloudflare noted the importance of using a tailored harness for narrow, parallel tasks and additional safeguards, as well as rethinking security workflows to handle faster detection while managing the complexity of patching and defense.

https://blog.cloudflare.com/cyber-frontier-models/

New Linux PamDOORa Backdoor Uses PAM Modules to Steal SSH Credentials

Cybersecurity researchers have revealed a new Linux backdoor called PamDOORa, sold on a Russian cybercrime forum, which exploits Pluggable Authentication Modules (PAM) to steal SSH credentials and enable persistent access through a magic password and specific TCP port. Designed as a sophisticated post-exploitation tool with anti-forensic features, PamDOORa runs with root privileges to capture user credentials and tamper with authentication logs, representing an evolution in Linux PAM-based backdoors.

https://thehackernews.com/2026/05/new-linux-pamdoora-backdoor-uses-pam.html

OpenAI’s GPT-5.5 Is as Good as Mythos at Finding Security Vulnerabilities – Schneier on Security

The UK’s AI Security Institute evaluated OpenAI’s GPT-5.5 and found that its capability to identify security vulnerabilities is comparable to Anthropic’s Claude Mythos model, with GPT-5.5 being generally available. This evaluation highlights the advancing role of large language models in cybersecurity, although discussions note limitations in reasoning and the potential plateau in detecting new attack classes without human input.

https://www.schneier.com/blog/archives/2026/05/openais-gpt-5-5-is-as-good-as-mythos-at-finding-security-vulnerabilities.html

Frontier AI Models Reap Rapid Discovery of Security Vulnerabilities

Frontier AI models, such as those tested by Palo Alto Networks under Project Glasswing, are accelerating the discovery of software security vulnerabilities, with 26 new common vulnerabilities recently disclosed compared to the usual five. While these AI tools offer potential for integrating security into the software development lifecycle, experts warn organizations have a limited three- to five-month window to leverage AI defensively before AI-driven exploitation becomes widespread.

https://www.cybersecuritydive.com/news/frontier-ai-rapid-discovery-security-vulnerabilities/820258/

Critical 18-Year-Old NGINX Vulnerability Enables Remote Code Execution Attacks

A critical 18-year-old heap buffer overflow vulnerability (CVE-2026-42945) has been discovered in NGINX's ngx_http_rewrite_module, enabling unauthenticated remote code execution (RCE) attacks. The flaw, present since 2008 and affecting numerous NGINX products, arises from a mismatch in URL rewriting logic and has a CVSS score of 9.2; security updates have been released and urgent patching is recommended.

https://cybersecuritynews.com/18-year-old-nginx-rce-vulnerability/

Microsoft’s MDASH AI System Finds 16 Windows Flaws Fixed in Patch Tuesday

Microsoft has introduced MDASH, a multi-model AI-driven system designed to autonomously discover, validate, and prove exploitable vulnerabilities in complex codebases like Windows. Tested in a private preview, MDASH identified 16 flaws fixed in the latest Patch Tuesday, including critical remote code execution vulnerabilities in Windows networking and authentication components. This system represents a production-grade advancement in AI vulnerability discovery by orchestrating over 100 specialized AI agents to enhance security at enterprise scale.

https://thehackernews.com/2026/05/microsofts-mdash-ai-system-finds-16.html

Microsoft Patches 138 Vulnerabilities, Including DNS and Netlogon RCE Flaws

Microsoft released patches addressing 138 security vulnerabilities across its product portfolio, including critical remote code execution flaws in Windows DNS and Netlogon components. These fixes, part of the May 2026 Patch Tuesday, also involve privilege escalation, information disclosure, and spoofing issues, with several vulnerabilities identified through Microsoft's new AI-driven discovery system, highlighting the growing role of AI in vulnerability detection.

https://thehackernews.com/2026/05/microsoft-patches-138-vulnerabilities.html

Mystery Microsoft Bug Leaker Keeps the Zero-Days Coming

An anonymous researcher known as Nightmare-Eclipse has released two new Microsoft Windows zero-day vulnerabilities—YellowKey, a BitLocker bypass allowing unrestricted access to encrypted machines via USB, and GreenPlasma, a privilege escalation flaw granting SYSTEM access. Security experts warn these exploits pose serious risks, especially for stolen devices and post-compromise attacks, with no known mitigation currently available for GreenPlasma; this continues an ongoing series of damaging disclosures by the researcher following a claimed breach of trust with Microsoft.

https://www.theregister.com/security/2026/05/13/disgruntled-researcher-releases-two-more-microsoft-zero-days/5239758

Thousands of Facebook Accounts Stolen by Phishing Emails Sent Through Google

Researchers have uncovered a phishing operation using Google’s AppSheet platform to send deceptive emails that have compromised around 30,000 Facebook business and advertiser accounts, primarily targeting pages with financial value. This campaign abuses trusted Google services to bypass email filters, tricking users into providing Facebook credentials and 2FA codes, enabling attackers to monetize hijacked accounts by running scams or selling access.

https://www.malwarebytes.com/blog/news/2026/05/thousands-of-facebook-accounts-stolen-by-phishing-emails-sent-through-google

Microsoft Teams Vulnerability Allows Hackers to Perform Spoofing Attacks

A newly disclosed vulnerability (CVE-2026-32185) in Microsoft Teams for Android allows local attackers to perform spoofing attacks by exploiting improper file and directory access controls, potentially deceiving users into trusting malicious content. Although exploitation requires user interaction and is limited to local environments, the flaw poses a high impact on data confidentiality; Microsoft has released a patch urging users to update immediately to mitigate risks.

https://cybersecuritynews.com/microsoft-teams-vulnerability-spoofing/

Copy.Fail Linux Vulnerability – Schneier on Security

The Copy.Fail vulnerability is a significant local privilege escalation flaw in the Linux kernel disclosed in April 2026, allowing attackers with limited access to escalate privileges to root by exploiting the kernel crypto API and splice() without modifying files on disk, thus evading detection. Affecting major distributions and shared infrastructure environments like Kubernetes, this vulnerability undermines isolation between users and containers, prompting urgent patch rollouts and discussions about new mitigation strategies such as emergency kernel “killswitches.”

https://www.schneier.com/blog/archives/2026/05/copy-fail-linux-vulnerability.html

Scroll to Top