RSS Amplifier

Lukasz Olejnik on Cyber, Privacy and Tech Policy Critique · Jul 6, 2026

TechLetters ☕️ Cybercriminals are plagued with AI hallucination. CIA reorganises for offensive cyber. Mythos/Fable return with limits. China tightens open-source AI rules.

0
Sign in to vote or save

Lukasz Olejnik on Cyber, Privacy and Tech Policy Critique · Lukasz Olejnik on Cyber, Privacy and Tech Policy Critique

Cyberattack on NAIC, the U.S. state insurance regulators’ coordinating body. PeopleSoft zero-day was exploited - an unauthenticated SSRF-to-RCE chain. Apparently they had a working exploit before Oracle’s public advisory and patch. Attackers published stolen data and claim 3.1 TB was stolen, but NAIC hasn’t confirmed that scope. They also amended earlier dump claims blaming an “AI-generated misinterpretation.” These days, even cybercriminal activities are affected by AI hallucinations? https://content.naic.org/about/security-update

The C.I.A. is reorganising to put greater priority on cyberoperations, especially offensive cyber capabilities. It wants officers to become more skilled at using digital tools, data, and code for intelligence collection. A major focus is using AI, understood as "digital nuclear weapons" aggressively but keeping humans in control of final decisions. The agency is strengthening its ability to hack computer networks, communications systems where intelligence can be gathered. https://www.nytimes.com/2026/06/30/us/politics/cia-reorganization-cyber-ai.html?smid=tw-share

Anthropic is brinding back Mythos/Fable access. With cybersecurity uses disabled, or limited. They also confirm that GPT-5.5 nd Kimi K2.7 models were able to find the same security vulnerability which caused enacting export controls. The US Government will now get a pre‑release access and evaluation of new powerful AI models. https://www.anthropic.com/news/redeploying-fable-5

China is tightening enforcement around AI services and applications, including open-source AI models. In a 2026 campaign targeting “AI application chaos" the Cyberspace Administration of China identified inadequate safety management of open-source models as a concern. The notice says open-source communities lack identity-verification and safety-management systems, and have not established effective review or emergency-response mechanisms for datasets, model code, and other materials uploaded by users. It also criticizes the failure to promptly remove datasets or open-source models that present serious risk. This is not a ban on releasing open models. China is bringing open-source AI developers and cmmunities into its broader regulatory goals. They also have a reporting website for AI use violations, including for whistleblowers. The Cyberspace Administration of China’s reporting form accepts reports of: violations by AI application services and "disorderly AI-generated information", failures to complete required model registration, weak platform safety controls and review filters, unsafe training datasets, AI data poisoning, inadequate labeling of synthetic content, illegal misuse of AI technology, inadequate safety management of open-source models, AI-generated distortions of cultural classics, false or misleading information, impersonation, violent or vulgar material, harms to minors, using AI automation to run coordinated fake-engagement operations https://www.cac.gov.cn/2026-04/30/c_1779289298718765.htm

Bank of England deputy governor wants to have kill switches for AI trading systems before they explode the market. This is unlikely to work because is not one faulty model, but the concept of feedback loop between many systems that are each behaving “correctly” on their own. Switching them off at once could make buyers disappear and panic worse. Regulators should focus less on magical thinking. https://www.bankofengland.co.uk/speech/2026/june/sarah-breeden-panel-at-the-european-central-bank-forum-on-central-banking-2026

In case you feel it's worth it to forward this content further:

Subscribed

If you’d like to share:

Share

No posts

Read the original on techletters.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.