Cyberattacks on water plants are at a larger scale than before

In an August 3 interview on CNBC’s Squawk Box, The Chertoff Group’s Head of Cybersecurity Adam Isles told host Becky Quick that while Iranian cyber trade craft is not new, the scale of the attacks on water systems in the US is bigger than we’ve seen previously. AI is lowering the knowledge gap for the […]
Inside the OpenAI–Hugging Face Agentic Breach

In mid-July 2026, Hugging Face disclosed an intrusion into part of its production infrastructure driven end-to-end by an autonomous AI agent system. Hugging Face detected and remediated largely using AI of its own. Days later, OpenAI confirmed that the “attacker” was in fact its own models. The models were GPT‑5.6 Sol and a more capable, […]
A New Taxonomy for Fighting Omnichannel Retail Fraud

Fraud carries a steep price tag for both merchants and consumers. The National Retail Federation (NRF) has updated its retail fraud taxonomy to combat it. Account takeover fraud cost consumers $15.6 billion in 2024, up from $12.7 billion the year before, according to Javelin research. The Federal Trade Commission reported at least $212 million in […]
Defensible Security in the Age of Mythos

Summary The security landscape is undergoing a fundamental recalibration with the release of Anthropic’s Mythos Preview and other Mythos-class models. As we learned during its limited release, Mythos can identify and weaponize complex software vulnerabilities at unprecedented speed. Combined with the rapid acceleration of AI-assisted coding, security leadership and practitioners are facing an “offense-defense” arms […]
Defensible Safety and Security Programs in the AI Age

Nobody knows what “good enough” looks like yet. There is no straight compliance play. That changes everything about how security leaders need to operate. Summary The Goalposts Are Murky, And That’s the Point The NIST AI Risk Management Framework and ISO 42001 are abstract by design. But the deeper problem is that no one, not […]
Mythos Implications for Cybersecurity Leaders

Summary What happened? On April 6th, Anthropic revealed Project Glasswing, Anthropic’s initiative to secure critical software against AI-enabled adversarial vulnerability identification and exploitation. It is powered by Claude Mythos, which Anthropic calls a step-change in artificial intelligence reasoning and coding. Mythos is reported to be capable of autonomously identifying and exploiting high-severity and zero-day vulnerabilities at […]
Iran Targets Western Companies with Cyber Attacks

Iran Cybersecurity Threat Update In our March 1 blog on the unfolding Iran situation, we warned that the killing of the Supreme Leader of Iran, Ali Khamenei, and significant Iran Revolutionary Guard Corps (IRGC) leadership losses increased both the motivation and the likelihood of Iranian cyber retaliation. As military operations continue, we are now seeing […]
Iran Update – 1 March 2026: What Khamenei’s Death Changes

This update supersedes our initial advisory of 28 February 2026. What Has Changed U.S. and Israeli operations have entered a second day. Iranian Supreme Leader Ayatollah Ali Khamenei has been confirmed dead. At least 40 senior Iranian military and security officials were killed in the same strike package, including the IRGC Commander, Defense Minister and […]
Emerging Legal and Regulatory Frameworks Governing AI

Summary Artificial intelligence (AI) has quickly emerged as a transformative technology, impacting nearly every aspect of society, from medicine to education to manufacturing. Governments are beginning to respond, and what they do to govern the development and deployment of novel forms of AI will be one of the major themes of the next several years. […]
Managing Software Supply Chain Risk: A Buyer’s Guide

Chertoff Group Cybersecurity leaders Adam Isles and David London, along with John Steven, senior advisor and CEO of Aedify, led a CyberSymposium learning session about how software purchasers can incorporate best practices to secure their software supply chains. The discussion offered a summary of software security frameworks and their limitations, where organizations can encounter blind […]