Searchable transcript of OpenAI’s Daybreak and Mistral’s Mythos competitor — IBM Technology (30:03). Search for a phrase, then click its timestamp to jump straight to that moment in the video.
Captions sourced from the original video on YouTube, published by IBM Technology. The video, its captions and all related intellectual property remain the property of their respective owners; AINotes claims no ownership. Provided for research, accessibility and search — see the Transcript Notice and Copyright Policy.
00:00 Move over Project Glasswing. OpenAI has its own codenamed project now, Daybreak. Let's get some tweet-length responses from our panel today. Nick, I'll start with you. What are you thinking about? Good. More competition. That's what it needs. Also more help for us to identify vulnerabilities in code. More models, more vulnerabilities. Let's see what happens, I guess.
00:26 Hello and welcome to Security Intelligence, IBM's weekly cybersecurity podcast, where our expert panelists turn the biggest industry news stories into practical takeaways you can use. I'm your host, Matt Kosinski. And joining me this week. You know him. You love him. Nick Bradley, manager, X-Force Threat Intelligence and one of the hosts of the Not the Situation Room podcast.
00:41 We've also got two new faces joining us today Diego Matos Martins, Latin America Incident Response Leader and Nikki Robinson, STSM, AI and Platform Development. Thank you for being here, folks. We're going to be talking about some of the latest developments in the Shai-Hulud technology. But first, there's a lot going on in the world of AI vulnerability hunting, and we've got to talk about it.
01:07 So to open this up today, I want to talk about OpenAI's Daybreak, Microsoft's MDASH and Mistral's Mythos competitor. Last week was a really big one for AI-powered vulnerability scanning and patching tools. First up, OpenAI announced Daybreak. This is a frontier AI for Cyber Defenders program, which gives users access to three models depending on their needs.
01:30 First up, you got GPT-5.5 for general purpose work. Then you got GPT-5.5 with Trusted Cyber Access for the more precisely tuned defensive work. And then you've got GPT-5.5 cyber, which is the most permissive model meant for specialized workflows like offensive security research. Then we had news that French AI startup Mistral is reportedly working on its own cybersecurity-focused model, spurred mainly by the fact that a lot of European institutions cannot use Mythos yet, or maybe ever.
01:58 So Mistral wants to kind of step in and fill that void. And finally, Microsoft revealed MDASH, which will enter private preview for enterprise customers in June. MDASH orchestrates a number of specialized agents powered by various models, with each agent dedicated to a different stage of the vulnerability hunting pipeline. So I want to start by taking a look at some of the architectural differences in these models.
02:20 And Nikki, I want to ask you first for your thoughts on Daybreak's approach here with the three models based on which workflow you're doing and any thoughts on that approach to AI defensive tools? Yeah, I do think the more specialized that you get, the more honed in that you get, models are used for different purposes. They're also good at some things and not, you know, they have pros and cons.
02:45 Right. So I think the more that you can kind of hone in and specialize, which model you need for which action, the better it could possibly work. So I think it's definitely an interesting approach. Absolutely. And on the other hand, with something like MDASH, you orchestrate a bunch of different agents for, for different stages of vulnerability management.
02:55 So it's, it's similar to this different model thing, but it's with like an agent approach instead. Diego any thoughts on that. Like going okay it's not just multiple models. It's multiple agents with different focuses. What are your thoughts there? MDASH has a specific focus, which is around identifying vulnerabilities on Windows and Windows systems so far and the way that they're focusing that is on, as I said, including considering 100 agents basically working together in order for them to identify with context,
03:32 identify a number of vulnerabilities and, on Windows applications or Windows systems. And for that they have identified a number of vulnerabilities already. Which part of the number of of the 16 that they have identified, the 16 CVEs, four were remote code executions. So to me, it brings us to the to the conclusion that if you have context, if you have an understanding of and focus on what you are analyzing in terms of the vulnerabilities, you can go there and identify critical stuff, which is what they're doing.
04:10 Absolutely. Nick, I want to bring you in here now. You know, looking at, you know, we've got, on the one hand the three models of Daybreak, on the other, the maybe hundreds of agents that MDASH is orchestrating. What do you think about this approach where it's like we're giving people a whole suite of models or tools instead of just one thing now. What do you what do you think?
04:26 I think more is better, right? Like I said before, I think the competition is an important thing. And I think this, this deluge of models or people trying to get to the table really quick was a, it was a given. We should have seen it coming. Mythos wasn't going to hold all the cards. It was just, I guess first to the table. Right. And what we're going to see is this continued focus on it.
04:49 And it's not just in cybersecurity for vulnerability detection and finding the exploits before the bad guys do, it's going to be the focus of AI across the board. We're going to see more focused models on specific subject matter, right. To bring it back a little bit. Like certain models are really good at technical writing. Certain models are really good at answering questions to people who are lower skilled in certain fields so they can understand, and it's not writing, you know, at the higher, you know, education
05:16 levels for people that may not be as skilled in certain things. Right. And then like you're going to see it in the medical field, you're going to see certain models that are going to get right down dirty into the tech jargon that the doctors and surgeons are going to understand, and then you're going to want the higher level where it's, you know, hey, AI, tell me why I feel this way.
05:34 You know, you're going to see the shades of all different colors when it comes to these models and what they're doing. But Patchpocalypse will continue, but I will stick with my original assessment in that it can only continue so far. The well isn't bottomless. Eventually all of the the old vulnerabilities will, for the most part, you know they'll they'll get pulled out.
05:56 I just want to add on the Patchpocalypse that you said. Right. So that's that's my biggest concern. I believe that's the biggest concern of several companies and corporations, which is that we are training AI models here to identify vulnerabilities. And and do we have the same speed for us to patch and to work on the access controls in order for us to fix that, fix everything that now the AIs are going there and identifying?
06:20 So that's a real concern that I got in there. Yeah, absolutely. Yeah. You know, I think Patchpocalypse is a phrase that's come up a few times on the show already. I think it's IBM's Ch0mpie who coined it, but it's got a lot of people thinking about it and wondering, you know, what this means for how we keep up with vulnerability hunting. I want to step back, though, to something else that you had mentioned there, Nick, which is this idea of like, competition, right?
06:45 Mythos wasn't going to hold the cards forever. People were going to step in and fill that void. And what's particularly interesting to me, though, is that from the moment that Mythos dropped, we've seen like competing views of like how we should approach access to these models. Right. And OpenAI has taken some not so thinly veiled, call them potshots, right?
07:06 Here's a quote from OpenAI's blog post. Not the one announcing Daybreak, but another recent related one. Quote: "We don't think it's practical or appropriate to centrally decide who gets to defend themselves. Instead, we aim to enable as many legitimate defenders as possible with access grounded in verification, trust signals and accountability." Nikki, I want to bring you in here not to necessarily comment on who's better Mythos or Daybreak or anything like that, but just your thoughts on like, how do we handle this
07:30 question of, these or very powerful AI tools we're putting out there, who should have access to them? Any thoughts there? Yeah, I think in a just in a general broad context, right. If we're talking about just access to information. I think it's great if we can give it to just like we have vulnerability disclosure programs, right? If we can follow vulnerability disclosure programs, give people the information that they need as quickly as possible so that they can have time to resolve issues or take a look and see if
07:59 they are, you know, true findings. So I think following a responsible disclosure of vulnerabilities should be a practice, you know, regardless of whether we have the latest AI models or not. Diego, anything to add there in terms of how we approach access to these models, who gets them, how we share the information, what are your takes? Yeah. So, I saw some companies establishing some partnerships, right, with vendors and that's one, one way for us to do that.
08:28 But I also know that it's not going to be forever, right? So, at certain points, everyone will have access and will gain access to those models. And with that, then, you know, the threat actors as well will gain access to that and will start to identify vulnerabilities as quickly as possible. So to me, you know, apart from thinking on how people are, when people are going to get access to that, is also for me to, to think of.
08:54 Okay, so how can we contain what those AI solutions or tools, the AI itself are going to identify in terms of new vulnerabilities? Right. And then to me that, you know, my take on that is, we need to think on. Okay. So they're going to basically exploit a vulnerability, find a zero day exploit of the vulnerabilities and getting into an environment. And with that, do the whole process of, possibly exfiltrate information, escalating privileges and then doing the whole post exploitation procedure.
09:31 Right. And then I would focus as well on that in terms of improving the post exploitation containment. Right. The capability of protecting a company against that. Absolutely. Nick, to kind of close this out today, I want to give you a quote from Jared Atkinson of SpecterOps as quoted by CyberScoop. He says, quote: "AI will accelerate portions of offensive security operations, but it does not fundamentally change the underlying problem defenders face.
09:54 Most organizations still struggle to see and manage the attack paths that connect initial access to critical systems and data." Now, given that you were talking before about how you think there's a bottom, how do you feel about this idea that like it's going to change some things, but it's not going to change the underlying problems defenders face? Agree?
10:13 Disagree? I actually agree completely. My my point at hitting you know, hitting the bottom, or so you might say, the the vein of vulnerabilities petering out, it's it doesn't mean that it will be gone completely. It just means this specific focus will eventually be under control. How long before that happens? I don't know. But it will eventually happen.
10:35 And we're going to be back to where it, I won't say was in the past, because we'll never be back to where we were. But it's it's not going to be Patchpocalypse forever. It just can't last. And if I'm wrong, well, I guess I'll come back and admit I'm wrong. But I hope that I'm not. And. And on the the other, the other quote that you gave that, that one I actually do disagree with.
11:00 I am all about providing tools needed to defend one's self, but we don't provide everyone a Death Star either. I think that's a really good kind of point to close out this particular segment on. Before I move along, I just want to open it up to the viewers on YouTube. If you're watching, if you have thoughts on Daybreak, MDASH, Mistral's Mythos competitor, anything we talked about here, drop them in the comments.
11:20 I do read them, I do respond. But let's move on to our next story. Curl dev tries Mythos. Now, earlier this year, and we covered this story on this podcast, the open source data transfer CLI tool curl ended its bug bounty program because of an influx of AI slop reports. Last week, curl developer Daniel Stenberg had the chance to test Anthropic's Mythos on the curl source code, and he came away a little less than impressed, shall we say, but not entirely opposed to AI vulnerability scanning.
11:57 As Stenberg writes in a blog on his website, he didn't have access to Mythos directly, but someone who did have access ran a scan on curl for him. It surfaced what it claimed were five vulnerabilities, but after human testing by the curl security team, they found that only one was an actual vulnerability, and it was a very low severity vulnerability at that.
12:13 "My personal conclusion," Stenberg writes, "cannot end up with anything else than that the big hype around this model so far was primarily marketing. I see no evidence that this setup finds issues to any particularly higher or more advanced degree than the other tools have done before Mythos." And what's interesting to me here, though, is that Stenberg doesn't say, you know, and for that reason, we shouldn't use AI.
12:38 In fact, he says, look, I use a bunch of AI tools to scan curl. They're really, really super helpful. I think everybody should do it. I just think Mythos was a little bit of marketing hype. Diego, any initial reactions to this story of Stenberg using Mythos, of where he came away? What do you think? Yeah. So to me. Again, it again helps us on reaching the conclusion that, you know, AIs are just a force multiplier, right?
12:59 So they are going to, they're basically a very strong big gun that you can use for you to identify vulnerabilities. But also you need to provide some context, you need to provide to use on a specific domain. And also you have to have the human factor in there. You have to have someone that is going there and validating the results and making sure that they they make sense.
13:23 And that you know, what the AIs have identified is something that is really exploitable or not. Yeah, I really like that you focused on that human factor there. Because again, I think a lot of the conversation, especially when Mythos hit was like, this is going to completely automate all this vulnerability hunting. It's going to completely automate hackers' jobs.
13:44 And as you point out, as Stenberg points out: No, the people still need to be there wielding these things. It's a tool, ultimately. Nikki, I want to ask you about something that's very interesting to me here in this story, which is that, like for a guy who had the who's whose tool had to shut down its bug bounty programs because of AI slop, he's like pretty pro AI.
14:02 And that was a little confusing to me. Was that, you know, do you find any contradictions there, or does that make perfect sense to you? How do you feel about that? I think what we're seeing in the, so if I'm talking about the industry at large, right, and how we utilize AI and the different ways that we utilize it, I think what we're seeing is the pendulum has swung, right.
14:19 We've seen a bunch of different AI tools come out for productivity reasons, for hunting reasons for all kinds of of use cases. But I think we're seeing the pendulum come down a little bit. Where we're seeing people are using AI where it makes the most sense. There's still, to Diego's point, there's still this human factor. There's still this human in the loop that is required to sort of go through whatever the findings might be, whatever reporting and analysis that you might get to make sure that what you're getting is
14:46 actually accurate. So I think what we're seeing is balance. We're starting to see balance between utilizing AI for certain reasons and then maintaining the human in the loop to continue with summarization and analysis of whatever those findings are. But I think what AI really does for us is it reduces the amount of time that is required to gather data, to analyze data quickly, so we can pull all of that together so we can make a very informed decision.
15:12 So I think it helps us in a decision making area, which is maybe maybe what he was hinting at. I'm not sure. But that's from my perspective. Absolutely. I like that you bring that, that word balance in here, because I do think that that's kind of the key to this. Right. And it's part of what was so interesting about Stenberg's article to me was, was it was very balanced.
15:31 He said, look. Mythos wasn't as amazing as I thought maybe it could be. But like, I see the value of AI use it all the time. And it felt like a very sober, levelheaded look at this stuff rather than some of those extremes we get both ways, right? Like you said, the pendulum maybe is finally hitting that center. Nick, I want to bring you in here. You know, especially because, as you talked about earlier, the increasing specialization of models, and Nikki's comments on focus reminded me about that, using models for more
15:54 focused purposes. Any thoughts reactions to this story from Stenberg and his use of Mythos on curl? This story actually illustrates something that it may or may not have intended to, whereas the wonders of AI in this case were also the fly in the ointment. And what I mean by that is, it's the reason the bug bounties and the AI slop kind of brought that to an end, because the very issue is that AI makes it, like we said, it's a force multiplier.
16:25 It makes us able to do things faster. But what it also did was enable people to turn in a bunch more garbage to these, you know, AI bug bounty programs. And then there wasn't enough of the human in the middle to be able to go through all of them. Because if you're going to do your due diligence, if you get 1000 submissions a day, it's your responsibility to review those thousands of submissions a day.
16:48 So at this point now, the human in the middle becomes the weak point because you have to do that. And so the AI kind of doubled back on itself and caused its own problem, which is now why we're seeing the bug bounties getting shut down. So a lot of good points here. I don't really have an argument. It was more of a point to be made. I'm glad that you highlighted that, because I do think that that is, in a lot of ways, the core takeaway from this.
17:15 You know, like Nikki said, it's about balance. And that balance is about finding where the human fits into the loop. And like, who is the kind of quality control, right? Like who is sorting through the garbage, basically. That's not easy. And I don't know that one human can do it alone. But I do think that it's almost like that's the next step we're at, right?
17:34 Like we've figured out what these things are good at, and then we can figure out how we apply them strategically, tactically. Diego, let me ask you about a quote that comes up in Stenberg's post. He writes, "It should be noted that the AI tools find the usual and established kind of errors we already know about. It just finds new instances of them. We have not seen any AI so far report a vulnerability that would somehow be of a novel kind, or somehow totally new."
18:00 Do you agree that that the AI tool is largely just find stuff we already knew about, that just find new instances of it? Do you think that will ever change? How do you feel about that take, Diego? AIs, they're, they are learning, right? So they are evolving with the time, with the amount of data that they are processing. And, you know, they are just getting more and more context for, for what, you know, with what we want them to execute for us.
18:22 So to me, there are other examples here. So he did test one, but there are other examples. For example as MDASH, that has identified critical vulnerabilities. Right. And I think that's it depends on the on the context at the end. It depends on how much trained is the AI. So to me, AI will, definitely already helps us on identifying, is already helping people identify vulnerabilities, and to me it is just going to improve.
18:53 And it's up to us to understand how we are going to work with that in terms of how we are going to fix everything that is identified and how we are going to, you know, keep the same pace of things being identified, either by us or by threat actors, and then us going and fixing everything. Right. There is one aspect that we need to make sure we don't glaze over when it comes to talking about AI being, you know, used to detect vulnerabilities.
19:22 AI. The part about this that might be a little may not be completely novel, but it it is something that we don't do as humans as well as AI does. And AI isn't just finding the vulnerabilities. Right? That's, that's that's not novel. But AI is finding vulnerabilities going, I found this vulnerability, I found this vulnerability, and I found this vulnerability.
19:40 And okay, but wait, if I put this one with this one and couple it with this one and then this vulnerability here and now, I've achieved something novel, right? Because it can look at things with that multifaceted lens that we aren't always capable of doing on that same level. And maybe we are, but we can't do it nearly as fast as AI can. So we need to make sure we don't forget about that part.
20:06 It's not just finding vulnerabilities, it's it's the finding them and learning how to chain them together to exploit and achieve the goal. I think that's a really important point. You're right, you know, because you could say, yeah, it can't find new kinds of vulnerabilities that we weren't aware of before. It just finds new instances. But it can combine those things in ways we wouldn't have combined them before.
20:24 Right? So it's like, it's not that it's a new kind of vulnerability. It might be just a new way of chaining these things together. And I do think it's worth thinking about it on that level. And that's really the key of when we talk about like how it will lower the bar to entry for cyber criminals, for example. Because if you don't need to figure out how to chain vulnerabilities together anymore, your AI can do that for you, that's really dangerous.
20:44 On the plus side, it's good for defenders because it can help point out things you may have missed that you need to plug in your own attack surface. Let's move on then, to our final story for the week, folks. Shai-Hulud goes open source. Now Team PCP, the hackers behind the notorious Shai-Hulud worm, have released the code to the public. And not just that, they are actively encouraging people to use it, even hosting a contest on BreachForums encouraging people to participate in the, quote, "Supply Chain Challenge," The
21:18 most cursed TikTok challenge I've ever heard of, for monetary rewards. To recap, the Shai-Hulud worm moves through npm packages, stealing credentials, exfiltrating data and propagating through compromised versions of packages. Nick, I know you folks talked about this on the most recent episode of Not The Situation Room, so what can you tell us about what you're thinking about the open sourcing of Shai-Hulud and what it means for defenders?
21:37 The only thing that comes to mind immediately, not the only thing. The most important thing is this is some type of chaos bomb that they're throwing into into the environment. Because the question is, is why? Right. Because if you're if you're selling, you know, this as a service. And we see a lot of bad actors selling, you know, using their product to sell it as a service, just like we do software as a service, malware as a service, ransomware as a service, all of these things.
22:05 What are they doing? So are they taking a page out of the out of the open source model where they're hoping to crowdsource additional development to make it better? Or is their intent, or is their intention to just have everyone going everywhere, a bunch of script kiddies running their stuff everywhere? So they're like, wait, here's TeamPCP, PCP over here.
22:28 No, wait, there they are. Over here. There they are, over here! There. They're over here. Where are they really? And you know, like I said earlier on my on the other podcast, will the real TeamPCP please stand up? So somewhere in there, they're executing their dastardly plan behind the smokescreen of everyone else. But then maybe they just don't care, and they're just going to do what they want to do.
22:50 And that's where I said, I think they're throwing the chaos bomb out there. Yeah, chaos bomb, I think is a really good way to encapsulate it. And you hit like two of the big kind of interpretations I've seen about this. On the one hand, there are people saying like, look, basically it's one big free hackathon for them. It's people developing new strains of their code that they can use.
23:06 And on the other hand, it's like you said, it's a smokescreen. Like which one of you is actually TeamPCP? Do we know? Does it matter? And, Diego, I saw you kind of nodding along when Nick was talking. Do you have anything to add? Any any any initial responses there from you in terms of the open sourcing of Shai-Hulud? So I was wondering the same, right.
23:24 So why they are going, they are leaking their source code now. And I was basically comparing the evolution of the Shai-Hulud campaign. Right. So if you if you go back to September 2025, they infected about 500 packages, more or less. Right. npm packages. And then after that it was like 700 packages in November, more or less 25,000 repos. And then that number started to reduce until the Mini Shai-Hulud campaign.
23:55 So I don't know if it's because, you know, GitHub is, GitHub along with npm, are including some controls in place or putting some controls in place, which are reducing the amounts of impacts that Shai-Hulud and TeamPCP is able to generate. And for that they said, okay, screw it, let's just share our source code so people can use it the way they want.
24:20 And for that, people can just go modify that and just or let's enable, let's weaponize the whole threat actor ecosystem and let's basically let people use our source code the way they want. I don't know that that's that's one of the conclusions. One really quick detail that I would like to point out, and I have to give credit to Sophie Cunningham for pointing this out to me because I glazed over it completely is this is actually Mini Shai-Hulud.
24:50 It's not the original Shai-Hulud. And she threw that out. I was like, wait, I haven't heard anything about that. What are you talking about? And so Mini Shai-Hulud is the latest iteration of the software and it is different. And so I'm not sure if that really means anything, or if it's just letting us see the constant evolution of their software, which might also be a hint as to where they intend to go with this and what they're trying to do with the crowdsourcing.
25:13 No, I'm glad you point that out. Right, because we do need to be cognizant of exactly what strain we're talking about here, right? And like you said, it could point towards where this thing is going to evolve. Diego, I know that you had mentioned that you responded to a Shai-Hulud 2.0 incident. Is there anything you could tell us about your experience there that might shed some light for us on this, or on just Shai-Hulud in general?
25:33 By that time, I thought, okay, so, a lot of companies are putting controls in place, are basically containing the whole situation, are changing secrets, are basically enabling additional security features. And GitHub along with, you know, npm was also controlling the, the repository, the packages that were infected. Right. So with that I thought, okay, so that's probably the end of the campaign.
26:05 But it wasn't, and they, they keep evolving. Right? And they evolved to the 3.0. And now there is the Mini Shai-Hulud campaign and also the source code got leaked. So I wonder what's what's the next step of these guys? So one thing as well that I thought is so they are stealing a lot of secrets, right? And at the beginning they were basically leaking that in base64, double base64.
26:30 Right. And then on the 3.0, you would see that they not leaking that encrypted anymore. So you wouldn't be able to see who was infected or you wouldn't be able to see what secrets they stolen. Right. And I wonder if they are just sending that to brokers. So other threat groups can go there and execute attacks with that, but, yeah, I wonder what's what's the next step of this, this threat group specific.
27:02 Well, just to add a little bit more chaos to this. I don't know if this has been mentioned yet, but it and it seems like this is clearly done out of spite. But there's also a built-in dead man switch. Has anybody talked about that yet? This. That's interesting. That's. What can you tell us about the dead man switch. So. So like I said, this built-in dead man switch seems to be completely just out of digital spite.
27:24 Because what it does is if it detects that the stolen tokens have been revoked, it triggers an RMRF on the infected system. Yeah. Oh, really? Let's. Not just that. There is also a statistic elements which is that some researchers identified, which is that the source code identifies, if, you know, based on geolocation, if the infected host is based in a specific two countries, Iran or Israel, and on one in six chances of this malware being run on the endpoint, they are going to just go and wipe the whole filesystem of
28:11 those endpoints. So there is that as well. It really is like a maximum chaos, maximum pain-inflicting kind of campaign. And it really does make you wonder if the whole point is just let's evolve as many strains as we possibly can because like Diego, as you said, you know, this is a thing that we've seen evolving constantly since it first came out. Like we, we're already on like the fourth or fifth iteration of this thing.
28:34 And so it's just, I don't know, they're just sowing discord, trying to get as many new strains of it as they can. Given that though, like, you know, Nick, any thoughts on what the smart moves are in terms of securing yourself against the proliferating strains of Shai-Hulud? The best thing is, is just exercise as many controls as you possibly can using these type of environments.
28:54 Absolutely. And Nikki, I would just be remiss. Is there anything you wanted to add to this segment before we close it out? Yeah, I would just on the topic of security controls, anything defense in depth that you can do is absolutely the best. You know, some call it zero trust architecture but defense in depth in any way network segmentation, identity and access management controls, any of those things are going to be super helpful.
29:19 Absolutely. And I think that's a really nice point to kind of tie it all up on is that, especially for an episode where we talked so much about AI vulnerability scanning tools, this is a reminder that you can't just rely on one single tool, one single control on anything. It's about that defense in depth. It's about that network. It's about that strategic arrangement of your controls that does it.
29:36 For this episode, I want to thank our panelists, Nikki and Diego and Nick. Thank you to the viewers and the listeners and our producers. Subscribe to Security Intelligence wherever podcasts are found, so that you never miss an episode. Stay safe out there and don't feed the TeamPCP.
We don't think it's practical or appropriate to centrally decide who gets to defend themselves.
The big hype around this model so far was primarily marketing.
We don't provide everyone a Death Star either.
This is some type of chaos bomb that they're throwing into the environment.
Manager of X-Force Threat Intelligence and host of the Not the Situation Room podcast.
00:37Source of a quoted observation about AI and offensive security operations, affiliated with SpecterOps.
15:47Researcher credited with pointing out that the publicly released code was Mini Shai-Hulud.
24:45French AI startup reportedly developing a cybersecurity-focused model to address limited access to Mythos for European institutions.
01:54Platform mentioned as applying controls alongside npm to infected repositories and packages.
23:53