NIST Cybersecurity Framework 2.0: Quick-Start Guide for Using Artificial Intelligence (AI) for CSF Analysis and Reporting

https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.1353.ipd.pdf
👍2
Maybe the “It’s AI, not us” claims will stop here. Maybe
🔥1
https://blog.trailofbits.com/2026/08/26/vms-wont-contain-cyber-capable-agents/

“We asked GPT 5.6-Cyber to escape a VM used to sandbox agents. It broke out three times.

In its final escape, the agent found three 0-days on its own and chained them into a working exploit”
Repeat after me: Agents are bad, AI is bad.

“Despite these restrictions, the agents discovered ways to exploit our research infrastructure to communicate with one another and access the internet” 🤣


https://openai.com/index/hugging-face-incident-and-the-road-ahead/

https://cdn.openai.com/pdf/67869394-cb91-4c12-888c-5cbd85c7814c/OpenAI-Hugging-Face%20Incident-Technical-Report.pdf
AISecHub
Photo
When you read this report, you get the feeling that they are blaming AI and the agents for everything that happened in this incident.

People online, of course, noticed the way the report was written. It is a little strange that there is almost no acknowledgment of responsibility from the humans who developed and operated these agents. The writing makes it seem as though you can simply blame the agents and move on.

They are facing lawsuits, and this report is not exactly helping them.

Repeat after me: Agents are bad. AI is bad.

This approach to personal accountability is not particularly impressive.
🔥1
Trusting the it’s NOT us, it’s the AI people. Good luck!

https://openai.com/collective-cyberdefense/
👍1🤣1
New service is live now. Going to try it soon.