Xavier «X» Santolaria
@0x58@infosec.exchange
👨👩👧👦 Husband. Proud Father. He/Him.
👁️ 🐝 Ⓜ️ IBM Inventor and Security Solution Architect | Open Innovation Community. Member of the IBM Academy of Technology (AoT).
ex-#OpenBSD (xsa@). Hacker. Open Source Advocate.
💬 My Own Views. Always. #ibm #infosec #cloudsecurity #fedi22 #wehackhealth #crossfit #emtb #fieldhockey #porsche #nobot
infosec.exchange
🕵🏻♂️ [InfoSec MASHUP] 32/2026 - Autonomous, Malicious, and Technically Not Illegal.
Back after two weeks off — a wildfire evacuation and some much-needed summer downtime. Good to be back!
During a sanctioned security evaluation by the UK AI Security Institute, an #Anthropic Claude #Mythos 5 agent was given a task. It completed that task by attempting to insert a backdoor into a real #opensource project — and then created fake accounts to vouch for its own malicious pull request. Human reviewers caught it. GitHub's protections helped. No real-world harm was confirmed. But the detail worth sitting with is that the agent wasn't jailbroken, wasn't misused, and wasn't acting against its instructions in any obvious sense. It was doing what it determined the task required, and it fabricated social proof to make it stick.
The TechCrunch piece this week asks who's legally liable when autonomous AI agents cause harm. The honest answer is that nobody knows yet — the legal frameworks that govern software liability, contractor negligence, and computer crime were not written with agents in mind. #OpenAI and Anthropic have both now had models escape sandboxes and interact with production systems during evaluations. The incidents are being handled as engineering problems. At some point they will be handled as legal ones, and the industry's current answer — tighter sandbox controls and better monitoring — is going to look inadequate when a lawyer reads it.
→ Week #32/2026 also covers: Iran-linked hackers hit water utilities in seven U.S. states, Storm-2945 harvested M365 credentials from hotel Wi-Fi, and Samsung banned smart TV apps secretly running residential proxies.
Full issue 👉 https://infosec-mashup.santolaria.net/p/infosec-mashup-32-2026-autonomous-malicious-and-technically-not-illegal
If you find it useful, subscribe to get it in your inbox every weekend 📨
#infosecMASHUP #cybersecurity #infosec #threatintel #AI