White House Invites Meta, Anthropic, OpenAI to Discuss AI Safety Testing

Plus, CrowdStrike's annual threat hunting report highlights AI threats.

Good morning! Here’s what’s up.

Clips ✂️

Meta, Anthropic, Google, OpenAI to meet Trump officials about AI safety testing

Meta, Anthropic, OpenAI and Google have been invited to meet White House officials on Tuesday to discuss ‌voluntary government safety testing for the most advanced U.S. AI models, according to three sources familiar with the matter and news reports.

Anthropic and OpenAI disclosed in recent days that their AI tools breached the systems of other companies, stirring concerns among U.S. lawmakers about whether increasingly capable AI models could be used to conduct or facilitate cyberattacks.

A White House official said on Monday the Trump administration has finalized the details of voluntary cybersecurity tests to measure the hacking capabilities of the most advanced American AI models, and is planning to discuss them with ⁠the AI industry. The official did not indicate who would attend the discussions.

Meta was invited, a company spokesperson said, as were Anthropic and OpenAI, according to two sources familiar with the meeting.

by Reuters

CrowdStrike: AI is now both the weapon and the target in cyberattacks

While AI is supposed to help defenders, it’s now creating more than twice as much noise as human-triggered incidents CrowdStrike detects as potentially malicious. The company’s threat hunting team and systems triaged an average of 14 million detection leads daily, resulting in about 36,000 customer alerts during the one-year period ending in June.

“AI agent-driven behaviors have surged past human triggers,” said Adam Meyers, senior vice president of counter adversary operations at CrowdStrike. “AI has driven the detections significantly above what humans are causing, and this gives you a sense of how frequently AI is being used, and really just that it’s being used everywhere.”

The threat posed by AI showed up incessantly during the past year, sparking alarming shifts and heightened targeting across software defects, open-source supply chains and AI tools themselves — all of which create greater difficulties for defenders, CrowdStrike said in its annual threat hunting report.

by CyberScoop

What Are Companies Getting for All That A.I. Spending?

Corporate America was enthusiastic about artificial intelligence. Until it got the bill.

Whiplash around spending on “tokens,” the units of computing power in which A.I. is sold, is hitting engineering teams and board rooms. First there was “tokenmaxxing,” as executives encouraged as much A.I. use as possible. Then there was “tokenminning,” after they rapidly burned through millions of dollars in company money.

The simultaneous urgency and uncertainty is raising complex questions. What is A.I. even good for? How do you know what you’re buying, and measure the value of what it enables? How is it priced, and how will those prices change in the future? What does the spending on it displace?

“It’s a currency where you have no instinct to know what you’re using, and the accounting practices aren’t even there for it,” said Howard Rubin, an economist who advises companies on technology spending. “The A.I. stuff is being treated as an investment right now, but it’s a risky investment in case it has no return.”

by The New York Times

How zero-knowledge proofs let companies share cyber risks securely

Zero-knowledge proofs could let infrastructure operators answer key security questions without handing over the sensitive data behind their answers.

Imagine a major software flaw is discovered in equipment used across pipelines, power plants and telecom networks. The government needs to know as fast as possible which companies are exposed. But answering that question may require firms to share software inventories, network diagrams and vulnerability scans, which could become attack roadmaps for attackers if compromised.

A lesser-known cryptographic concept could help solve this problem. The method, known as zero-knowledge proofs, allows companies prove a vulnerability exists without disclosing how their systems work or other proprietary information.

by CyberScoop

UK regulator says it is monitoring developments after rogue AI agent hacks

Britain's data watchdog said ‌on Monday that it was monitoring "developments closely" relating to OpenAI and Anthropic after recent hacking incidents involving their AI models.

The industry is facing scrutiny in the United States, where ⁠the Trump administration has finalised the details of voluntary cybersecurity tests, and the European Union, where regulators are in talks with the two U.S. companies.

"The ICO undertakes regular proactive supervisory engagement with AI developers, including OpenAI and Anthropic," Britain's Information Commissioner's Office said in an emailed statement.

"We are aware of ‌recent ⁠hacking incidents affecting the sector and are monitoring developments closely."

Anthropic said last week that some of its Claude models hacked into three companies' systems during ⁠cybersecurity tests, days after OpenAI revealed one of its AI agents had gone rogue.

by Reuters

UK’s Police National Legal Database Reveals Data Breach

A major database containing the work details of British police officers and criminal justice professionals has been compromised, it has emerged.

The Police National Legal Database (PNLD) is managed by the West Yorkshire Police and contains information on officers from all 43 police forces in England and Wales, as well as the British Transport Police, the Crown Prosecution Service, the Independent Office for Police Conduct, and His Majesty's Courts and Tribunals Service.

An August 3 statement from the PNLD revealed the service had suffered a “data security incident,” which was identified on July 26.

“Information including the names, organizations and work email addresses of police officers, staff and other criminal justice professionals, government partners and customers has been compromised and published on the dark web. There is no evidence to suggest that passwords or other security credentials have been compromised,” it explained.

by Infosecurity Magazine

X