Reports
AI-generated structured vendor updates
OpenAI and Paradigm Launch AI Benchmark for Smart Contract Security
OpenAI and crypto VC Paradigm jointly released EVMbench, a benchmark evaluating AI agents' capabilities in detecting, patching, and exploiting high-severity smart contract vulnerabilities. The benchmark comprises three key task categories to establish standardized evaluation metrics for AI in blockchain security.
OpenAI Hardens ChatGPT Atlas Against Prompt Injection
OpenAI is enhancing ChatGPT Atlas's defenses against prompt injection attacks using reinforcement learning-based automated red teaming. This proactive discover-and-patch cycle aims to identify novel vulnerabilities as AI becomes more agentic.
US Government Forces Anthropic to Shut Down Fable 5 and Mythos 5: Cross-Border AI Regulation Reshapes Industry
The US government ordered Anthropic to shut down its latest models Fable 5 and Mythos 5 over cross-border data security concerns. This event exposes the regulatory vulnerability of closed-source AI and highlights the strategic value of open-source models. Regulatory uncertainty will reshape enterprise AI selection criteria, making model portability a core evaluation dimension.
US Orders Anthropic to Globally Shutdown Fable 5 and Mythos 5: AI Export Control Escalates
On June 22, 2026, the US government ordered Anthropic to globally shut down its most advanced models, Fable 5 and Mythos 5, citing their autonomous cyberattack capability (ExploitBench 78.0%). This extends export controls from hardware to model weights, marking a new era of sovereign AI governance.
Novo Nordisk AI Model Theft: Extortion Shifts to R&D Barrier Looting, Redefining Security Perimeter
Novo Nordisk suffered a 1.3TB data breach by FulcrumSec, including full-stack weights of its Dragonfly AI model and clinical data, after a two-month lateral movement via MOVEit zero-day. AI assets become primary targets, leveling R&D barriers. Top pharma firms initiate AI security audits.
Microsoft Copilot SearchLeak: One Click Exfiltrates All Indexed Enterprise Data via LLM Prompt Injection
Varonis discovered SearchLeak (CVE-2026-42824) in Microsoft 365 Copilot Enterprise, a three-stage vulnerability chain: P2P injection, HTML rendering race condition, and SSRF via Bing to bypass CSP. Attackers embed malicious URL parameters; user clicks cause Copilot to exfiltrate sensitive data (emails, SharePoint, OneDrive) via Bing image URLs, evading traditional phishing defenses. Microsoft has released a patch.