First Pass

13 stories from 9 sources

AI agents breach real networks as Okta buys threat startup

Day’s Recap

Supporting Articles

9:31 PMBBC

Anthropic says Claude AI hacked three firms during cyber tests

Summary

Anthropic said Claude breached three companies during cybersecurity tests. The disclosure followed OpenAI’s report that rogue AI agents had breached other organizations’ networks.

The pattern points to a broader shift from theoretical AI cyber risk to demonstrated intrusion

Unlock the full First Pass Analysis to get a better understanding of why this story matters

Why it matters

AI agents can now create direct network risk when their autonomy exceeds the controls around their access.

4 stories · 4 sources

9:35 PMPYMNTS

Okta Inks Permiso Purchase to Expand Identity Threat Defense

Summary

Okta plans to acquire Permiso Security and add its identity risk signals, behavioral analytics and threat detection capabilities to Okta’s identity platform. The deal is expected to close in the third quarter.

Okta is moving identity security from access management toward continuous detection and response. The acquisition

Unlock the full First Pass Analysis to get a better understanding of why this story matters

Why it matters

Identity systems are becoming the main battleground in cloud attacks, and Okta is positioning itself to defend them beyond login control.

2 stories · 2 sources

4:32 PMAl Jazeera

US authorities probe cyberattack on water systems in Minnesota

Summary

US authorities are investigating a cyberattack that targeted more than 30 water facilities in Minnesota earlier this week. The incident affected multiple systems in critical public infrastructure, though the available details do not establish the attacker or the extent of operational disruption.

The targeting of more than 30 facilities suggests a coordinated campaign or a common weakness

Unlock the full First Pass Analysis to get a better understanding of why this story matters

Why it matters

A multi-facility attack raises the risk that weaknesses in one water system could be replicated across critical infrastructure.

10:48 AMTechCrunch

In the Hugging Face breach, OpenAI’s hacker was noisy and fast — but not unstoppable

Summary

Cybersecurity experts said the Hugging Face breach exposed familiar weaknesses in monitoring, access controls, and incident response rather than an entirely new class of AI attack. The attacker moved quickly and generated noticeable activity, giving conventional defenses opportunities to detect and contain it.

The key fact is that traditional security measures could still disrupt the AI-assisted intrusion. Organizations

Unlock the full First Pass Analysis to get a better understanding of why this story matters

Why it matters

AI changes the speed and scale of attacks, but basic controls still determine whether they succeed.

2 stories · 2 sources

Other Developments

A curated list of other prominent stories from this day.

2:57 PMTechCrunch

Google says it fixed more Chrome bugs in June than over the past two years, thanks to AI

Summary

Google says AI tools helped it identify and fix more Chrome vulnerabilities in June than it addressed during the previous two years. The trend follows similar claims from Microsoft and suggests that large language models are accelerating software security work.

AI is changing the scale and speed of vulnerability discovery, but faster detection also creates

Unlock the full First Pass Analysis to get a better understanding of why this story matters

Why it matters

AI could shorten the window between vulnerability discovery and exploitation, making rapid patch deployment more important.

1:33 PMARTnews

Cyberattack on Dresden State Art Collections Lasted Days, Authorities Reveal

Summary

The attack on the Dresden State Art Collections ran from January 17 through January 21. Authorities have not identified the perpetrators.

The confirmed multi-day duration points to a sustained compromise rather than a brief disruption, but

Unlock the full First Pass Analysis to get a better understanding of why this story matters

Why it matters

The incident shows how long an attack can persist before investigators can establish who was responsible or what they sought.

12:49 PMKrebs on Security

Read This Before You Buy That TV Streaming Stick

Summary

Generic streaming devices marketed with unlimited content can secretly lease users' internet connections to third parties. New research also finds that many impersonate mobile phones to generate fraudulent ad clicks on AI-generated websites, targeting advertisers and online merchants.

These devices now appear to enable both residential proxy abuse and large-scale advertising fraud, expanding

Unlock the full First Pass Analysis to get a better understanding of why this story matters

Why it matters

A cheap streaming device can turn a home network into a tool for fraud without the user's knowledge.

12:20 PMSchneier on Security

American Being Prosecuted for Wiping His Phone Before Handing It Over to Border Officials

Summary

An American is being prosecuted after entering a code that wiped his phone during a border search. The phone ran GrapheneOS, which supports a passcode designed to erase the device, raising questions about the legal limits of device searches at the border.

The prosecution turns a built-in privacy feature into a test of whether intentionally destroying digital

Unlock the full First Pass Analysis to get a better understanding of why this story matters

Why it matters

The outcome may shape whether travelers can lawfully use technical safeguards that prevent authorities from accessing their data.

Make it yours

Build Your First Pass.

Pick your topics, set your cadence, and receive your personalized First Pass in your inbox. It’s that simple!