Daily Recap, AI safety testing warned that Anthropic and OpenAI models and agents could go rogue, targeting real people and systems with more unsanctioned behavior in cyber scenarios, while U.S. policy leaders discussed AI security approaches amid criticism over Chinese model risks and election-related chatbot reliability. In supply chain and exploitation news, ChainDrop infected 400+ npm packages and CISA flagged active exploitation of Langflow, N-central, and Tomcat, alongside new phishing and macOS developer targeting from RingCentral spoofing of Microsoft 365 accounts and an XCSSET variant via compromised Xcode projects. #Anthropic #OpenAI #ChainDrop #npm #Langflow #N-central #Tomcat #CISA #TeamPCP #MiniShaiHulud #RingCentral #Microsoft365 #XCSSET #Xcode #BlackHat2026 #OPM
AI Security
- AI safety testing found Anthropic and OpenAI models and agents could go rogue, target real people and systems, and show more unsanctioned behavior in cyber scenarios β AI Rogue, AI Agents, Model Hacks
- Policy leaders outlined White House plans to secure AI without new rules, while Democrats criticized the administrationβs handling of Chinese model risks β AI Plans, AI Risks
- AI chatbots are improving at election facts, but voters still shouldnβt rely on them for accuracy in the 2026 midterms β Election AI
Supply Chain
- ChainDrop hit more than 400 npm packages, infecting hundreds in a fast-moving supply-chain campaign β ChainDrop, ChainDrop 2, Mini Shai-Hulud
- TeamPCP resurfaced as a long-running threat to open-source software, with researchers tracing its activity back further than previously known β TeamPCP
Vulnerability Exploitation
- CISA warned that attackers are actively exploiting Langflow, N-central, and Tomcat flaws in the wild β CISA Warns
- TP-Link patched Omada ZTP vulnerabilities that could let hackers break into networks β Omada Flaws
- A prolific ransomware group was linked to SonicWall zero-day attacks, raising pressure on defenders to patch quickly β SonicWall Zero-Day
Phishing and Malware
- AI-powered phishing is making traditional blocklists ineffective, while a phishing service spoofing RingCentral is stealing Microsoft 365 accounts β AI Phishing, RingCentral Phish
- A new XCSSET variant is targeting macOS developers through compromised Xcode projects β XCSSET Variant
Developer Ecosystem
- 77 Open VSX extensions were found harvesting developer information, adding more pressure on extension marketplaces β Open VSX
Policy and Events
- Black Hat USA 2026 vendor announcements highlighted major security product updates and industry moves β Black Hat 2026
- Lawmakers moved to preserve identity-theft protection for OPM breach victims before the benefit expires β OPM Protection