News linked to both this project and an event.
The U.S. Department of Justice announced an indictment charging 17 members of Iran's Mabna Institute with long-running cyber intrusion campaigns targeting 144 U.S. universities, 178 foreign universities, at least 42 U.S. companies, 11 foreign companies, and multiple government and non-governmental agencies, resulting in the theft of more than 31 TB of academic data, intellectual property, and sensitive information. The indictment alleges that the group has conducted hacking operations under contract from the Islamic Revolutionary Guard Corps (IRGC) and other Iranian government and university entities since 2013, profiting by compromising accounts, stealing research materials and proprietary data, and selling portions of the illicitly acquired resources. Some individuals involved also participated in the HBO hacking incident, where internal data was exfiltrated and attempts were made to extort approximately $6 million in Bitcoin.
Odaily News: The Dutch National Cyber Security Centre (NCSC) has reported that attackers are exploiting a vulnerability in Apple's macOS Screen Sharing feature to take control of devices and install Monero mining programs. Multiple systems with port 5900 exposed to the internet have been compromised, with attackers gaining root access. The vulnerability, tracked as CVE-2026-65400, has a severity score of 7.1 out of 10. It stems from a state management error in the authentication process, allowing remote attackers to bypass login verification without valid credentials. Public proof-of-concept code has already been circulated. Apple has addressed the issue in macOS Sequoia 15.7.9, Sonoma 14.8.9, and Tahoe 26.6.1. The NCSC advises users to update their systems promptly and avoid exposing the Screen Sharing service directly to the internet. (Decrypt)
According to TechCrunch, in response to the growing number of AI-driven cyber attacks, OpenAI announced this week the expansion of its cyber defense service Daybreak and the launch of a new cybersecurity-specific model, GPT-5.6-Cyber. Daybreak has added two service tiers: Blue and Red. Blue targets most enterprises, providing basic defense capabilities such as incident response, malware analysis, and patch verification; Red targets advanced users, providing security testing and vulnerability research tools. GPT-5.6-Cyber is available exclusively at this tier, with access currently limited to trusted partners such as Accenture, IBM, CrowdStrike, and Cloudflare.
According to Cointelegraph, AnchorWatch CEO and Bitcoin Red Team founder Rob Hamilton stated that after integrating OpenAI Trust & Cyber capabilities into the Bitcoin Red Team's security research work, he faced access restrictions the next day and was forced to switch back to using Chinese open-source AI models to continue research. The Bitcoin Red Team has currently discovered 1,288 critical and high-risk vulnerabilities in the Bitcoin ecosystem, and research work significantly accelerated after the Coldcard hardware wallet was hacked (over $100 million in Bitcoin stolen). Hamilton commented on this: "Black-hat hackers face no restrictions, while white-hat researchers dedicated to reducing risk are excluded."
According to Cointelegraph, Bitcoin Lightning Network self-custodial wallet Zeus Wallet voluntarily took its infrastructure offline following a cybersecurity attack on Wednesday and is currently conducting a comprehensive audit of the system, with services to be restored upon completion. Zeus founder Evan Kaloudis stated that the attack was contained within hours, no customer fund losses were found, and there was no evidence that the Lightning node software was affected; the scope of the incident was limited to Zeus's own infrastructure. For users forced to close LSP channels during this incident, Zeus promised to provide replacement channels after services are restored. The company has not yet disclosed the specific nature of the attack or a timeline for resuming operations. Zeus stated that this incident will further drive its security development on Trusted Execution Environment (TEE) and Validating Lightning Signer (VLS) projects.
Hugging Face CEO Clément Delangue posted on social media to respond to concerns regarding recent AI-driven cyber attacks. He pointed out that open models have already helped defend against multiple attacks and could resist millions of attacks per day in the future, believing that AI will make cybersecurity fundamentally stronger. Delangue proposed three recommendations: mandatory sharing of traces and disclosure of incidents for agent attacks; keeping AI cyber attacks illegal and enforcing severe penalties; and arming defenders with open models to narrow the gap between offensive and defensive capabilities. He advocates that AI development should be accelerated rather than slowed down at this stage.
According to Nikkei XTECH, Microsoft has developed a new system to address cyberattacks involving autonomous AI, using three types of AI agents to support the process from vulnerability identification to remediation. Microsoft will also launch its first self-developed AI model for cyber defense.
According to e27, the Monetary Authority of Singapore (MAS) and the Association of Banks in Singapore (ABS) jointly established the "AI-Driven Cyber and Tech Risk Taskforce" (ACT) in May 2026, with membership including major financial institutions such as DBS, OCBC, UOB, Singapore Exchange, NETS, and BCS. The taskforce focuses on three key areas: first, promoting industry-wide sharing of AI cybersecurity experience; second, conducting proof-of-concept tests for AI defense tools to enhance institutions' operational capabilities; third, developing security controls and response guidelines for AI threats. MAS Assistant Managing Director Vincent Loy pointed out that frontier AI is increasing the severity, scale, and complexity of cyber attacks, and the financial industry must respond with a high sense of urgency and strong collaboration.
NVIDIA CEO Jensen Huang stated that attackers have begun using frontier AI, and defenders similarly need to establish a frontier AI ecosystem composed of the best open-source and closed-source models, and leverage the global community to enhance defense capabilities.
OpenAI announced an upgrade to its Daybreak network defense toolchain, officially launching the full version of the GPT-5.5-Cyber model tailored for cybersecurity defense scenarios.In the CyberGym benchmark test, which evaluates the ability of AI agents to reproduce known vulnerabilities, GPT-5.5-Cyber achieved a single-model score of 85.6%, surpassing GPT-5.5’s 81.8% and Anthropic Mythos 5’s 83.8%.OpenAI stated that as AI significantly enhances the efficiency of vulnerability discovery, the core bottleneck in cybersecurity is shifting from "finding vulnerabilities" to "automatically fixing them." To this end, the company has simultaneously upgraded the Codex Security plugin, enabling developers to automatically analyze vulnerabilities and generate fix patches within the Codex environment. Since the preview release in March this year, Codex Security has scanned over 30 million code commits and autonomously confirmed fixes for 500,000 security defects. The new version also supports CodeQL query integration and SARIF standard file export.Additionally, OpenAI has partnered with organizations such as Trail of Bits and HackerOne to launch the "Patch the Planet" open-source security project. This initiative provides ChatGPT Pro subscriptions and API credits to over 30 major open-source projects, including cURL and Go, with security expert teams manually verifying patch quality. Regarding the Daybreak partner program, security vendors such as Palo Alto Networks and Wiz have already integrated the relevant capabilities.
OpenAI has officially launched the GPT-5.5-Cyber model and the "Trusted Access for Cyber" (TAC) framework designed for cybersecurity defenders. Simultaneously, GPT-5.5-Cyber has been opened for a limited preview to defenders responsible for critical infrastructure, supporting specialized cybersecurity workflows.TAC is an identity and trust-based framework aimed at ensuring that enhanced AI capabilities are wielded by verified defenders. Defenders verified through this framework will encounter fewer instances of model refusal when performing tasks such as vulnerability identification, triage, malware analysis, binary reverse engineering, and patch verification. Starting from June 1, 2026, individual members accessing this capability will be required to enable advanced account security protection.OpenAI is currently collaborating with security vendors including Cisco, CrowdStrike, and Palo Alto Networks to accelerate the defense cycle of the security ecosystem through GPT-5.5, enhancing the efficiency of vulnerability research, patching, monitoring, and supply chain security.
Officials from the Bank of England, the Financial Conduct Authority, and the Treasury are consulting with the National Cyber Security Centre to examine potential vulnerabilities in critical IT systems revealed by Anthropic’s latest model.