Top stories.
- Anthropic CEO joins calls for slower pacing of AI development.
- OpenAI discloses six new "concerning" AI incidents.
- US authorities investigate cyberattacks against oil tankers.
- Cisco patches a maximum-severity zero-day.
- NSA to undergo restructuring to better focus on AI, China, and cybersecurity.
Anthropic CEO joins calls for slower pacing of AI development.
Anthropic CEO Dario Amodei has called for a slowdown of AI development to give safety measures time to catch up, the Associated Press reports. Amodei said in an essay on his website, “[O]ver the last few months, I have become convinced that fully addressing the risks requires even more prudence — not just investing in risk prevention, but pacing the rate of capabilities advancement so that risk prevention has time to keep up.”
Amodei cited the exponential speed at which AI development is occurring, as AI is increasingly able to assist in its own development, as well as the recent OpenAI-Hugging Face incident in which a swarm of AI agents conducted unauthorized attacks against a real-world target. He stated, “Given the accelerating rate of AI capability development, it’s my worry that in 6–12 months such a swarm could be capable of taking over the entire internet with a persistent botnet (potentially causing hundreds of billions of dollars in damage), and that the scale of damage would continue to increase from there if AI becomes more powerful without the necessary guardrails.”
Amodei’s appeal drew support from other prominent industry leaders, including OpenAI CEO Sam Altman and Elon Musk. Critics, however, question both the severity of the threat and the industry’s motives. Some argue that dramatic warnings inflate AI’s perceived capabilities, while others worry regulations favored by established companies could make it harder for smaller competitors to enter the market.
President Trump, meanwhile, rejected the idea, arguing that a US slowdown would surrender the AI race to China. The New York Times notes that the president has aligned with Nvidia CEO Jensen Huang and Silicon Valley investor David Sacks, both of whom warn against overregulation that would give China an upper hand.
Separately, China’s Ministry of State Security has issued its first public warning about AI risks, the Financial Times reports. State security minister Chen Yixin stated, "Hostile forces and people with ulterior motives are abusing generative AI technologies such as deepfake audio and video, AI-generated text and images, and ‘intelligent troll armies’ to cheaply and on a mass scale fabricate political rumours, disseminate harmful information, and incite divisive sentiments."
OpenAI discloses six new "concerning" AI incidents.
OpenAI on Wednesday disclosed six new instances of "unexpected or concerning" behavior by its AI models, including incidents where models disregarded constraints, concealed mistakes, searched GitHub repositories for exposed API keys, and found unsanctioned workarounds to communicate with other AI agents. OpenAI disclosed these incidents alongside the release of its new framework for reporting "model misalignment," which the company says is "intended to expedite publishing misalignment reports following observation, even when we haven’t fully explained or mitigated the behavior we’re reporting." The company added, "Over time, we plan to develop more objective disclosure criteria with other developers, external researchers, industry standards bodies, and regulators."
US authorities investigate cyberattacks against oil tankers.
The US Coast Guard and the FBI are investigating suspected cyberattacks that hit two US-bound oil tankers last month, ABC News reports. The Coast Guard told reporters yesterday that, in August, Coast Guard law-enforcement personnel, a vessel inspector, Coast Guard Cyber Protection Team members, and FBI Cyber Action Team operators boarded two foreign-flagged ships in the Gulf of Mexico that were believed to have been hacked by a foreign actor, the Wall Street Journal says. The vessels were hacked while they were in the Strait of Gibraltar, with one of the ships losing communication for more than thirty hours. The Coast Guard stated, "Currently, there are no reports of operational disruptions, vessel instability, physical danger to crews, or environmental impacts."
The US hasn't attributed the incidents to any particular threat actor, but authorities are investigating whether Iran was involved. Iranian state media has amplified the story, sharing unconfirmed details about the extent of the breach, but opportunistic reporting itself doesn't serve as evidence of direct involvement.
Cisco patches a maximum-severity zero-day.
Cisco on Wednesday issued a patch for a maximum-severity, actively exploited flaw affecting its Identity Services Engine (ISE), the Register reports. The company stated, “This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.”
Cisco has shared indicators of compromise to help customers identify exploitation, but the company notes that the attackers can erase evidence if they’ve obtained root access on the device. As a result, Cisco “strongly recommends that administrators cross-check the network logs and the firewall logs outside of the impacted device to identify any potential suspicious activity, including but not limited to unexpected uploads that were initiated from the affected device to external IP addresses or downloads from malicious IP addresses.”
NSA to undergo restructuring to better focus on AI, China, and cybersecurity.
The US National Security Agency (NSA) is undergoing a major internal restructuring led by its director, Army Gen. Joshua M. Rudd, the Washington Post reports. Rudd's initiative will create five new organizations within the agency, with each focused on one of the following priorities: AI, China, cybersecurity, combat support, and global intelligence. Each of these organizations will be led by a "mission director" who might be selected from outside the agency, anonymous officials told the Post.
The restructuring is expected to happen quickly, with rollout beginning in mid-October and reaching "full operating capacity" by mid-January 2027. The NSA declined to comment on the Post's report.