Strategy


Report: Over Half of Cybersecurity Professionals Have Been Asked to Conceal Security Incidents
Bitdefender's annual report reveals that 55% of cybersecurity professionals have been asked to conceal security incidents, a proportion that rose during 2024-2025 and then stabilized; meanwhile, over half of respondents believe AI favors attackers. The report also highlights issues such as shadow AI and the confidence gap between management and frontline staff.

Anthropic Resumes Fable and Mythos Models After Government Approval
Anthropic reopened access to its advanced AI models Fable and Mythos on Wednesday, following the Trump administration's lifting of export control restrictions. Fable 5 is available to general users, while the more powerful Mythos 5 is restricted to a trusted partner consortium. The company stated it has improved safety classifiers and is working with government and industry partners to establish more formal review standards.

DHS Proposes New Framework to Strengthen Public-Private Collaboration on Critical Infrastructure Security
The U.S. Department of Homeland Security (DHS) on Tuesday proposed a new public-private collaborative framework for critical infrastructure to replace the previous framework abolished shortly after President Trump returned to the White House. The new framework, named the "Alliance for National Community Harmony and Operational Resilience - Critical Infrastructure National Council" (ANCHOR-CI), will serve as an umbrella structure for multiple advisory committees, designed to foster cooperation between the government and the private sector on cybersecurity and critical infrastructure resilience. It encompasses four types of committees—sector-specific, cross-sector, industry, and regional—managed by the Cybersecurity and Infrastructure Security Agency (CISA) with an initial term of two years. However, the new framework does not include the liability protections under the former CIPAC framework, raising concerns within the industry.

OpenAI proactively restricts release of new AI models at government's request
OpenAI announced on Friday that, at the request of the Trump administration, it will restrict the public release of its new GPT-5.6 series models (Sol, Terra, Luna), offering limited previews to a small number of trusted partners first. The company stated it will temporarily comply with the government's request and plans a broader release within weeks. Previously, the government had imposed export controls on Anthropic's models, and this incident highlights a shift in AI regulatory policy.

From Myth to Reality: 2026 Penetration Testing Report Reveals the Urgency of Programmatic Defense
Anthropic's Claude Mythos model autonomously discovered thousands of zero-day vulnerabilities within weeks, including a 27-year-old OpenBSD flaw. The 2026 penetration testing report notes that the speed at which enterprises fix critical vulnerabilities varies by up to 25 times, with the slowest group taking 249 days, and the perception gap between C-suite executives and frontline staff regarding SLA compliance reaching as high as 42 percentage points. The report recommends shifting to a programmatic offensive security model, adopting virtual patching, real-time risk registries, and AI-driven defenses to counter machine-speed threats.

Tech and AI Companies Unite to Combat Open Source Software Security Vulnerabilities
Several tech companies, including Anthropic, AWS, IBM, and Microsoft, have announced a joint initiative to discover, disclose, and fix security vulnerabilities in open source software. The alliance, named Akrites, will establish shared security incident response teams and coordinated vulnerability disclosure processes. Led by the Linux Foundation, founding members have committed resources such as funding, engineers, and cybersecurity experts. This move is primarily driven by the emergence of frontier AI models, which have greatly accelerated vulnerability discovery capabilities, while the existing open source ecosystem struggles to respond quickly.

FCC mandates cybersecurity measures for U.S. emergency alert distributors
The U.S. Federal Communications Commission (FCC) on Thursday approved a set of basic cybersecurity rules for companies that issue emergency alerts. The order, adopted unanimously by three commissioners, mandates that Emergency Alerting System (EAS) operators—such as radio stations, broadcast TV networks, and cable systems—use strong passwords, deploy network firewalls, and promptly apply security patches. The FCC stated the requirements aim to protect EAS from hijacking and preserve public trust. The move follows past incidents, including a 2013 zombie-apocalypse hoax and a 2022 critical vulnerability warning. The FCC also plans further security rules for EAS and Wireless Emergency Alerts (WEA) systems.

AWS Releases New Tools for Agent Security and Data Access
At the New York Summit on June 17, AWS released AWS Continuum (security risk identification and remediation) and AWS Context (enterprise data search layer), and upgraded tools such as Kiro, AWS DevOps Agent, AWS Transform, Amazon Bedrock AgentCore, and Amazon Quick Suite to address the growing security and data integration needs of AI agents in enterprise operations.