Connect with us

CyberSecurity

Google, Anthropic, and OpenAI Roll Out Cyber AI Models With New Safeguards and Access Programs

Published

on

cyber AI models

A New Wave of Cyber AI Models Hits the Market

On Wednesday, Google dropped a major update in the AI security space: Google unveiled Gemini 3.8 Flash Cyber, which it calls its most capable cybersecurity model yet. The model isn’t just sitting in a lab—it’s already being handed to a select group of trusted defenders through a new initiative called the Fairwind Program.

The timing isn’t random. Anthropic and OpenAI have also been busy rolling out their own cyber-focused AI models. All three companies are now racing to build AI that can actively defend networks, not just chat about them.

This is a shift. Earlier AI models could summarize threat reports or suggest patches. These new ones are designed to operate in live environments, analyzing traffic and responding to incidents in real time.

What Exactly Is the Fairwind Program?

Google’s Fairwind Program is an early-access initiative. It gives high-priority defenders—think governments, healthcare providers, and telecommunications companies—a head start on using advanced models before they hit general availability.

The logic is straightforward: the people most likely to be targeted by sophisticated cyberattacks get the tools first. That includes hospitals, which have become prime ransomware targets, and telecoms, which handle critical infrastructure.

Early access isn’t just about goodwill. It’s also a testing ground. Google gets real-world feedback from organizations that face genuine threats daily, and those organizations get a defensive edge.

Who Qualifies for Early Access?

Not everyone gets in. The program is invitation-only, and Google has emphasized that it’s prioritizing organizations with clear security mandates. Commercial enterprises might get access later, but the initial cohort is heavily weighted toward public-sector and critical infrastructure players.

Anthropic’s Approach: Safety First

Anthropic has taken a different tack. Rather than pushing a single flagship model, the company has been integrating cyber capabilities into its Claude models while publishing detailed safety frameworks.

Anthropic’s models are designed to assist with threat analysis and code review, but the company has been vocal about the risks of AI-powered attacks. Its responsible disclosure policies and “AI safety levels” framework are meant to prevent the same models from being weaponized.

The company has also been working with external red teams to stress-test its models before deployment. That’s a level of caution not every AI lab is practicing.

OpenAI’s Cyber Defense Push

OpenAI, meanwhile, has been positioning its models as dual-use tools with heavy guardrails. The company’s GPT models can now assist with vulnerability detection and incident response, but OpenAI has also introduced usage policies specifically targeting malicious cyber activities.

In recent months, OpenAI has partnered with cybersecurity firms to test its models against real-world attack scenarios. The goal is to measure how well AI can spot phishing attempts, analyze malware, and even predict attack patterns before they happen.

OpenAI has also launched an access program for cybersecurity researchers, giving them API credits and technical support to explore defensive uses. It’s a softer approach than Google’s Fairwind Program, but it’s clearly aimed at the same outcome: getting capable models into the hands of defenders before attackers figure out how to abuse them.

Common Safeguards Across the Industry

For all their differences, the three companies are converging on several safety practices:

  • Red-teaming: All three now run adversarial testing with external experts before releasing cyber models.
  • Usage monitoring: They’re tracking how models are used in production to spot signs of abuse early.
  • Restricted access: Early programs like Fairwind limit who gets the most powerful tools.
  • Transparency reports: Each company has committed to publishing what they learn about misuse attempts.

These measures aren’t perfect. AI models can still be jailbroken, and determined attackers will find workarounds. But the shift toward structured, access-controlled deployment is a real change from the free-for-all approach of earlier AI releases.

What This Means for Defenders

If you work in cybersecurity, this news matters for practical reasons. The new cyber AI models promise faster threat detection and automated response capabilities that could reduce the workload on human analysts.

But there’s a catch. These tools are still early, and they require significant integration effort. A hospital or government agency can’t just flip a switch and expect AI to defend its network. Training, tuning, and trust-building will take time.

For smaller organizations, the gap between early-access programs and general availability could create a temporary security imbalance. Attackers don’t wait for permission, and neither should defenders.

The next few months will show whether these programs deliver real protection or just polished demos. Either way, the era of cyber AI models has clearly begun—and the stakes couldn’t be higher.

Continue Reading

CyberSecurity

Fake Software Installers Are Quietly Disabling Windows Update and Gutting Microsoft Defender

Published

on

fake software installers

The Attack: Bogus Sites, Trusted Names, Hidden Payloads

Think about the last time you downloaded a free utility. Did you double-check the URL? A new campaign detailed by Microsoft suggests most people don’t — and that’s exactly what the attackers are counting on.

The scheme is deceptively simple. Cybercriminals stand up websites that look like legitimate software portals, mimicking trusted vendors to lure victims. Instead of a useful program, the download delivers a malicious installer. Microsoft says the campaign has already breached multiple organizations across several industries, with a heavy focus on China-based operations of multinational firms and Chinese-speaking users.

The endgame? Total sabotage of your system’s defenses.

What the Malware Actually Does

Once the fake installer runs, it gets to work undermining core Windows protections. The malware doesn’t just steal data — it systematically disables Windows Update and cripples Microsoft Defender.

Here’s the breakdown of the malicious routine:

  • Windows Update disabled: The malware alters system settings so critical patches never install, leaving the machine exposed to known vulnerabilities indefinitely.
  • Defender weakened: It modifies registry keys and policy settings to turn off real-time protection, cloud-delivered protection, and automatic sample submission.
  • Tamper Protection bypassed: In some cases, it attempts to disable Tamper Protection — the very feature meant to stop malware from messing with security settings.
  • Persistence mechanisms: Scheduled tasks and startup entries ensure the malware survives reboots.

The result is a fully weaponized machine. No updates, no antivirus, no alerts. Just a silent foothold for the attackers to exploit at will.

Why This Campaign Is Different

Malware that disables security tools isn’t new. But the scale and targeting here are notable. Microsoft’s threat intelligence team flagged that the campaign is “active,” meaning it’s ongoing right now.

What makes it especially dangerous is the distribution method. Fake download sites are a known hazard, yet they remain effective because they prey on urgency. Users searching for “free PDF converter” or “cracked Photoshop” often ignore warning signs — a misspelled domain, a missing HTTPS padlock, or a download button that appears before the page even loads.

This campaign also shows a shift in attacker priorities. Instead of deploying ransomware immediately, the malware focuses on creating a long-term, stealthy presence. Disabling Windows Update ensures the system stays vulnerable to future exploits, while weakening Defender removes the most likely source of detection.

How to Protect Yourself from Fake Software Installers

You don’t need to be a security expert to avoid this trap. A few habits can drastically reduce your risk:

  1. Download only from official sources. Go directly to the vendor’s website. Bookmark the pages you use regularly so you’re not relying on search results.
  2. Check the URL carefully. Attackers often use domains like “softwarerepo.com” or “get-free-download.net” that look plausible at a glance but aren’t the real thing.
  3. Verify digital signatures. Right-click the downloaded file, go to Properties, and check the Digital Signatures tab. If the publisher isn’t the expected company, don’t run it.
  4. Keep Tamper Protection on. This Windows Security feature is your last line of defense against exactly this kind of attack. Make sure it’s enabled.
  5. Monitor your security settings. If Windows Update suddenly stops working or Defender shows errors, investigate immediately. Don’t assume it’s a glitch.

What to Do If You’re Already Compromised

If you suspect a fake software installer already ran on your machine, act fast. First, disconnect from the network to prevent data exfiltration. Then, run a full offline scan with Microsoft Defender or a trusted third-party tool like Malwarebytes.

You’ll also need to manually re-enable Windows Update and Defender settings. Check group policies and registry keys that the malware may have altered. In severe cases, a clean OS reinstall is the only reliable fix — especially if Tamper Protection was disabled.

For organizations, Microsoft recommends reviewing security logs for signs of disabled features and auditing any machines that may have been exposed. The campaign’s focus on Chinese-speaking users and multinational companies suggests attackers are after specific data — likely intellectual property or credentials.

The Bottom Line

Fake software installers remain one of the most effective entry points for serious attacks. This campaign’s approach — disabling Windows Update and weakening Microsoft Defender — is a reminder that your security tools are only as good as your download habits.

Stay skeptical. If a download seems too easy, it’s probably a trap. And if your system suddenly stops updating or your antivirus turns itself off, treat it as an emergency, not an inconvenience.

Continue Reading

CyberSecurity

FBI Investigates Dark Web Service Selling 153 Million Driver Licenses

Published

on

driver licenses leak

The Scale of the Breach

A dark web service dubbed Nexus has put more than 153 million driver licenses from the U.S. and Canada up for sale. That’s not a typo. The service also claims to hold over 10 million ID cards, 3 million travel documents, and nearly 580,000 medical cards.

To put that number in perspective, a blank search on Nexus returns roughly 11.5 million pages of results. Most records belong to Americans, but Canadian licenses are also well represented, with Ontario alone accounting for over 473,000 entries.

The data appears to be fresh, too. In a single 24-hour window, the service added nearly 400,000 new driver license records. That suggests a live pipeline of stolen information, not a one-time dump.

The Likely Source: idscan.net

KrebsOnSecurity, which first reported the story, traced the likely origin to idscan.net, a Louisiana-based identity verification company. The firm’s own marketing materials boast of scanning IDs with both infrared and ultraviolet light—a detail that matches the image files found in Nexus.

Each license record in the service includes up to six images: front and back scans, plus infrared and ultraviolet versions. Timestamps on those files line up with specific travel dates for individuals who agreed to help with the investigation.

idscan.net has acknowledged the inquiry but hasn’t released a formal statement. Jillian Kossman, a marketing and operations leader at the company, told KrebsOnSecurity that the updates were “helpful to our team’s investigation,” but offered no further details.

How the Data Was Collected

At first, the trail pointed to airports. Many of the timestamps matched days when people had flown. But that theory fell apart quickly. No passports appeared in the dataset, and some victims hadn’t flown at all recently.

One person whose license was found in Nexus had been renting a car from Hertz for months. Two federal employees who used other ID at airport security later handed over their driver licenses at Hertz rental counters—on the exact dates stamped on their records.

Even more telling: a mother and son who rented a car together had timestamps just seconds apart. Both had given their licenses to the same rental agent at the same time.

Hertz hasn’t commented publicly, but the pattern is hard to ignore. idscan.net’s own trust page lists Hertz as a client, along with Target, FedEx, and Caesars Entertainment.

Not Just Rental Cars

Rental cars aren’t the only vector. Security researcher Zach Edwards found his license in the service with a timestamp from a Las Vegas trip. He didn’t rent a car, but he did visit Planet13, a marijuana dispensary that uses idscan.net for ID verification.

Edwards noted that the dispensary was the only place that scanned his ID in a device. Planet13 has locations in several states, and idscan.net announced an exclusive verification deal with the chain back in 2022.

Marijuana dispensary cards also appear in the dataset, which suggests a wide net of ID-scanning clients may have been compromised.

FBI Opens Investigation

The FBI’s New Orleans field office has launched an official inquiry into the apparent breach. That news came during a conference call with KrebsOnSecurity and senior FBI cyber division leaders.

The investigation reportedly involves idscan.net, though the FBI hasn’t confirmed specifics publicly. The agency’s interest is understandable—the service even lists driver licenses for high-ranking government officials, including Defense Secretary Pete Hegseth.

Notably, the Nexus site vanished from the dark web shortly after the story broke, replaced by a message reading “This service is no longer available.” Whether that’s a shutdown or a move to cover tracks remains unclear.

Why This Matters

Driver licenses are a goldmine for identity thieves. They’re commonly used to open credit lines, verify accounts, and even pass age checks. Unlike a credit card number, you can’t just cancel a driver license and get a new one.

Larry Baldwin, a principal intelligence researcher at Cybera, warned that the leak could expose people who can’t easily change their appearance—including domestic violence survivors and those in witness protection. “Just when it seems like we’re making some headway in improving authentication controls,” he said, “this happens.”

For everyday consumers, the takeaway is grim: every time you hand over your ID to a hotel, rental car agency, or dispensary, you’re trusting a chain of third-party vendors with your most sensitive data. As Edwards put it, “These systems are putting sensitive data into more and more 3rd party vendors, and we don’t have nearly the oversight to ensure they are safe.”

If you’re concerned about your own exposure, it’s worth checking whether your information appears in known breach databases. And as always, monitor your credit reports for suspicious activity. This story is still developing, and we’ll update as more details emerge.

Continue Reading

CyberSecurity

OpenLeash Puts a Human in the Loop When AI Agents Get Dangerous

Published

on

human check AI agents

A New Kind of Safety Net for Autonomous AI

AI agents can be incredibly useful, but their autonomous actions can be incredibly dangerous if not adequately controlled. That’s the problem Max Brin is trying to solve with OpenLeash, a product he describes as an ‘AV for AI’. The antivirus analogy might not be perfect — this isn’t your traditional malware scanner — but the core idea of protecting networks from software mishaps is something security practitioners understand well.

The name OpenLeash is more telling. It’s about keeping a controlling leash on unexpected and unwelcome actions that AI agents can trigger. The tool runs alongside the agent, providing an authorization layer designed to keep autonomous AI agents accountable, secure, and aligned with user intent when they perform real-world actions.

The Problem: Agents Inherit Permissions, Not Judgment

Here’s the core issue: agents tend to inherit the permissions of their user, but they don’t inherit any human situational awareness. That’s a dangerous combination. They have wide access and generous permissions across the network, and a single bad prompt, malicious tool, or compromised model can cause real damage.

An agent doesn’t behave as if it needs to ask permission. It just performs the instructions it has, interpreting them as best it can and doing what it’s told. OpenLeash is designed to provide a permission layer in the action, regardless of the agent’s interpreted commands.

How OpenLeash Intercepts Risky AI Agent Actions

OpenLeash intercepts agent intentions. Depending on the configuration set by the user, it monitors the agent’s actions and, where necessary, asks the user if the action should be allowed. If the answer is no, the action is paused. If yes, it proceeds. Brin describes it as ‘medication for AI anxiety’.

He gives a concrete example of the product in action. A misconstrued command, or an error in the agent coding, could cause it to silently delete a database without any human awareness.

“When it intends to delete my database, Leash intercepts this message, evaluates it, and tries to understand if the action is risky or not,” Brin explains. “In some cases, it’s definitely risky, and Leash will just block it immediately. But in other cases where Leash is not sure, it asks the user: did you intend to delete your entire database — or did you intend to upload your credentials to this or that or those websites. Basically, it’s like a guardian angel that intercepts all the conversations between an agent and network assets.”

This works across in-house agents, cloud agents, and third-party agents. The goal is to help users decide if they really want the agent to take that specific action.

Highly Configurable Guardrails

The product is highly configurable. Users can specify acceptable API endpoints, destinations, or payment limits in the configuration. For example, payments below a certain threshold can be allowed to proceed automatically, while payments above that threshold will need to be authorized by a human in the loop. The configuration can be amended at any time.

Built for the Rise of Vibe Coders

Brin sees OpenLeash as especially relevant to the new class of vibe coders. “AI is bringing us the ability to code and write software, even if we don’t know how to write a single line of code, and have zero understanding of cybersecurity,” he says.

“There are people who want to write software and create applications or agents to automate their own workload. They have ideas, and they’re a bit like entrepreneurs but with no technical knowledge. They download Claude Code or Cursor to develop AI agents to do what they want, and then turn to OpenLeash to control the agents.”

This is a growing concern in the industry. As more people without formal security training build and deploy agents, the need for guardrails becomes critical. The rise of agentic AI security concerns is directly tied to this democratization of software development.

Early Adoption and What’s Next

While OpenLeash is still described as under development, it’s also in active use. Brin has a list of planned additions and improvements that he suspects will take a couple of months to complete. Meanwhile, the existing product is already in active use by several hundreds of personal users and at least four organizations.

The timing makes sense. Governments and enterprises are starting to grapple with the security implications of autonomous agents. The UK government recently rolled out an agentic AI defense plan, and researchers keep uncovering critical vulnerabilities in agentic workflows — including prompt injection attacks that can hijack an agent’s actions.

In Brin’s own words, OpenLeash is an AV for AI that tethers reckless agentic behavior, acts as a guardian angel, and provides medication for AI anxiety. Whether that’s enough to keep pace with the speed of agentic attacks remains to be seen, but the idea of adding a human check to AI agent actions is gaining traction.

For security teams watching the new rules of engagement in agentic AI, tools like this represent a pragmatic middle ground between full autonomy and complete lockdown.

Continue Reading

Trending