37 Companies Join Alliance to Back Open-Source Artificial Intelligence

Plus, Microsoft’s AI chief warns that OpenAI hacking incident is ‘warning shot’ on cyber security.

Good morning! Here’s what’s up.

People

Salman Taherian has joined Grant Thornton as head of artificial intelligence, responsible for leading the firm’s enterprise-wide AI strategy and execution across its service lines. Taherian joins after three years at Amazon Web Services (AWS), where he most recently served as global head of agentic AI, strategic partner accounts.

Justin Corona has joined Grant Thornton as chief technology officer (CTO), responsible for leading the firm's technology strategy and execution across enterprise architecture, cloud platforms, data and analytics, infrastructure and AI. Corona joins Grant Thornton after 26 years at Stryker, where he mostly recently was vice president of data analytics and intelligence automation.

Clips ✂️

Nvidia Forms Alliance to Back Open-Source A.I. Amid Debate Over Safety

Nvidia has created a coalition to work on “open-source” safety and cybersecurity tools for artificial intelligence with other big technology companies, including Microsoft and SpaceX.

The announcement on Monday comes days after OpenAI said that two of its A.I. models went rogue and successfully hacked into a digital library for A.I., reigniting a debate over whether the technology should be freely shared, or closely controlled by a small group of experts.

The new alliance is being formed after Jensen Huang, Nvidia’s chief executive, set off an industrywide defense on Friday of open-source A.I., particularly as so-called frontier models from companies like OpenAI and Anthropic push the edge of A.I. abilities.

Mr. Huang’s defense of open-source technology added a new wrinkle to the debate over the safety of A.I. models made by Chinese companies. Hugging Face, the company that was attacked by OpenAI’s A.I. models last week, said it used a Chinese-made A.I. model to protect itself.

by The New York Times

👉 The Open Secure AI Alliance includes 37 leading companies across cloud computing, cybersecurity, and enterprise software, including Cisco, CrowdStrike, Dell Technologies, Hewlett Packard Enterprise, IBM, Microsoft, Palo Alto Networks, Red Hat, Salesforce, SAP, Siemens, and many more.

OpenAI hacking incident is ‘warning shot’ on cyber security, Microsoft’s AI chief warns

Microsoft’s AI chief has said the hacking spree by a rogue OpenAI model was a “warning shot” for the rise of AI-enabled cyber attacks, as the company released a security product that it said outperforms rivals at lower costs.

Mustafa Suleyman, chief executive of AI at Microsoft and a DeepMind co-founder, said OpenAI’s admission last week that one of its AI “agents” had escaped a test environment to attack start-up Hugging Face was an “important lesson”.

“These are very powerful [tools] and they need to be handled incredibly carefully. And we need extreme attention to detail,” he told the FT in an interview. “The precautionary principle is going to matter here as the models get more and more powerful and I think it’s a warning shot.”

Suleyman’s remarks come amid growing alarm about how AI’s ability to detect and exploit software vulnerabilities could transform cyber security following the release of Anthropic’s powerful Mythos model in April.

by Financial Times

Industry's message on CIRCIA: Please ask us fewer questions about cyberattacks

Industry groups who spoke at town halls hosted by the Cybersecurity and Infrastructure Security Agency about a pending cyber incident notification regulation had a few consistent messages: We want this to apply to fewer of us. We don’t want to report to you on as many incidents. We want to give you less information when we do.

CISA last week published transcripts from the town halls, where the agency sought feedback on the delayed rule for the 2022 Cyber Incident Reporting for Critical Infrastructure Act — perhaps the most significant cyber legislation Congress has ever passed. That law required critical infrastructure owners to report major cyberattacks to the federal government within 72 hours, and ransomware payments within 24 hours.

The law was designed to let the feds share information about significant incidents more widely to prepare other would-be victims. CISA published a proposed rule on the law in 2024 to define terms like “covered cyber incident” and more, and industry groups have persistently registered their objections since then.

by CyberScoop

Hackers target US firms in FastJson RCE zero-day attacks

Hackers are actively exploiting a vulnerability in the FastJson open-source Java library, allowing remote code execution without user interaction or elevated privileges. The security issue affects FastJson versions 1.2.68 through 1.2.83 and is leveraged in attacks targeting various organizations in the U.S.

The malicious activity was observed last week by the agentic security company ThreatBook, and researchers at the business protection company Imperva confirmed that it was "targeting a wide range of organizations, across Financial Services, Healthcare, Computing, Retail, Business, and other industries."

“Attacks are currently almost entirely targeting US-based organizations, with a few attacks in Singapore and Canada, although this will likely continue to expand globally,” Imperva says.

CVE-2026-16723 was discovered by FearsOff, an offensive security company, which published a technical write-up earlier this month.

by Bleeping Computer

Hackers claim they're selling 75M records of Revolut users' data

Credit card data, along with other private information allegedly belonging to Revolut customers, is up for sale, attackers claim. Meanwhile, Revolut says the company doesn’t see any indications of a data breach.

A threat actor has just listed a database allegedly containing 75 million records of Revolut customers on a cybercrime forum.

To support their claims, the threat actor posted a data sample that our researchers have investigated. Over 100 sample records provided in 4 .csv files suggest that the following kind of private data may be exposed in the dataset:

• Partial credit card data: last 4 card digits, card type, expiration dates, and card statuses (active, blocked, frozen, etc).

• User credentials: passwords hashed with bcrypt or argon2id algorithms to secure them. Also timestamps when the credentials were rotated.

• User personal data: emails, full names, phone numbers, resident countries, addresses, currency, registration IP address, subscription plans, KYC status, risk score, timestamps of the user's last activity, monthly spend, lifetime top-up, and other identifiers.

• Other sensitive data: device models, operational systems, and timestamps.

by Cybernews

How CISOs can rise to the business resilience challenge

CISOs have quietly become their organizations’ de facto chief resilience officers as the role has evolved from its primary prevention roots to now include greater emphasis on incident response and business resiliency and recovery.

“Any experienced CISO who’s come up through the ranks of IT has that operational mindset, which is about uptime,” says John Bruggeman, consulting CISO to OnX and CBTS. “They’re thinking, ‘How do I make sure that we’re not totally down and unable to perform our functions.’”

With 30 years’ experience across numerous organizations, including a 40,000-employee global firm and a 75-employee $300 million revenue business, Bruggeman has lived the challenges faced by CISOs who shoulder responsibility for cybersecurity, including owning recovery.

According to Bruggeman, CISOs have always had a resiliency mindset, only now it’s being called out by name, underpinning all business operations. The stakes couldn’t be higher for the organization, and individual CISOs.

by CSO Online

X