There was a lot of news stories this week, as you can see below, but I think it is fair to say the fact that Mythos was breached by China is the major story. Let’s dig into what happened…
The U.S. government recently made history by ordering the immediate, worldwide recall of a highly advanced artificial intelligence model developed by Anthropic. The AI, known as “Mythos,” possessed an unprecedented ability to analyze computer code and discover software vulnerabilities (or “bugs”). Fearing that a “jailbreak”, a trick prompt used to bypass safety guardrails, could allow malicious actors or foreign intelligence groups to weaponize the AI to scan critical infrastructure for security holes, the White House stepped in. Anthropic complied by pulling the model entirely offline within 90 minutes, marking a massive shift in how world governments view the intersection of AI technology and national security.
For anyone beginning their cybersecurity learning journey, this event proves that advanced AI is now officially classified as a dual-use cyberweapon. In cybersecurity, there is a constant race between defenders patching software holes and attackers exploiting them. Tools like Mythos can act as “offensive AI” to find hidden vulnerabilities at humanly impossible speeds, or as “defensive AI” to help engineers fix those gaps first. As a future cybersecurity professional, your role will increasingly focus on this “shot clock”, using defensive AI to secure systems before an adversary’s malicious AI can break them.
Furthermore, this situation highlights that AI safety and prompt injection are no longer just tech theories; they are critical frontline cybersecurity domains. Hackers don’t always need to steal source code to compromise an AI; they can use a process called “distillation” to drain a model’s knowledge simply by querying it and copying its capabilities. As you continue your security education, remember that the future of cyber defense is expanding beyond traditional firewalls and passwords. Protecting tomorrow’s digital world will require building stronger AI guardrails and mastering the tools needed to defend against automated, weaponized code.
Projects
- TryHackMe – Prompt Engineering – In Progress
- SANS SEC401 – In Progress
Articles
- China may have accessed Mythos – The White House reportedly has suspicions that a China-linked group had access to Anthropic’s powerful AI.
- The FBI built its own replica small town to simulate real-world cyberattacks – The Federal Bureau of Investigation is pulling back the curtain on a 22,000 square-foot replica town on its Huntsville, Alabama campus that it built to train law enforcement in simulating and investigating real-world cyberattacks.
- FBI takes down massive China-based cybercrime network that caused $1.9B in losses – Outsider provided phishing kits and infrastructure for cybercriminals to scam victims with lures claiming they missed packages, had unpaid tolls or parking violations.
- Chinese hackers hijack auth flow, spy on isolated network for a decade – Chinese hackers took control of a target organization’s authentication stack and maintained persistence for 10 years, with full visibility into the administrative activity.
- Ex-school district employee jailed for hacks on former employer – A former IT employee at an Iowa school district was sentenced to 21 months in prison for conducting a prolonged cyberattack against the former employer that disrupted classroom operations, deleted accounts, and caused tens of thousands of dollars in damages.
- FBI disrupts massive AI-powered phishing service using a million URLs – In a coordinated effort, the FBI, working with Google and Black Lotus Labs, has dismantled a massive Chinese phishing-as-a-service operation called Outsider Enterprise with thousands of phishing websites used to steal credit card data and passwords.
- Chinese Hackers Target Medical, Military, and AI Research in North America – Google’s Threat Intelligence Group has been tracking the cyberespionage group as UNC6508 since early 2025.
- Chinese Hackers Abused Google Workspace Rules to Steal Research and Defense Emails – A China-linked espionage group hid inside North American medical, academic, and military research networks for more than a year, quietly stealing sensitive research and defense email.
- FTC warns of record $3.5 billion losses to imposter scams in 2025 – The U.S. Federal Trade Commission (FTC) warned that Americans lost $3.5 billion to imposter scams in 2025, with reported losses nearly tripling since 2020.
- Cal Water Investigating Iranian Hackers’ Claims – California Water Service says there is no indication of operational disruptions to its water and wastewater systems.
- Fake Microsoft Alerts Used to Deploy North Korean NarwhalRAT Malware – The North Korean state-sponsored hacking group known as ScarCruft (aka APT37) has been observed using spear-phishing messages impersonating Microsoft Account security notifications to deliver malware called NarwhalRAT.
- Kodak confirms data breach claimed by ShinyHunters extortion gang – Kodak has confirmed that it’s working with external cybersecurity experts to investigate a security breach after hackers gained access to some of the company’s data.
- Junior Hacker Used Tailscale and OpenSSH to Keep Access After His C2 Went Offline – A French-speaking attacker broke into a small French automotive business, planted a keylogger, and stole banking and email credentials.
- Telegram admits it couldn’t police exam-leak channels, India tells court – India’s government has told the Delhi High Court that Telegram was warned about two weeks before it was blocked, and that the platform conceded it could not proactively detect the channels selling leaked exam papers.
- Apple fixes Beats Studio Buds flaw that let hackers spy on conversations – Apple has released security updates to patch a high-severity flaw affecting the Beats Studio Buds wireless earbuds that could allow attackers in Bluetooth range to spy on users’ conversations.
- Splunk Enterprise Vulnerability Exploited in Attacks Days After Disclosure – CISA has given federal agencies only three days to patch CVE-2026-20253, which can be exploited for unauthenticated remote code execution.

