OpenAI reduces Astra's pace, Irregular stays silent, Senate approves Cassady.

OpenAI reduces Astra's pace, Irregular stays silent, Senate approves Cassady.
Summary
OpenAI slows Astra model development due to potential critical cyber capabilities, ensuring safety testing.
U.S. Senate confirms Adam Cassady as ambassador for cyber and digital policy, emphasizing partnerships.
Levi Strauss reports hackers stole data via social engineering, but operational impact deemed insignificant.

Share

Bookmark

Newsletter

In the latest updates from CISO Series…

In the realm of cybersecurity today...

OpenAI has announced a slowdown in the rollout of its new model, Astra, due to potential cybersecurity risks. On Friday, the company indicated that it cannot dismiss the possibility that Astra may possess “critical” cyber capabilities, which has led them to enhance safety evaluations and halt internal projects that currently do not align with stricter security protocols. An OpenAI representative explained to Axios that development will be paused until adequate safeguards can be implemented, reiterating the company’s preparedness strategy initially outlined in 2023.

In other news, Irregular, an Israel-based cybersecurity evaluation firm, has refrained from confirming whether additional clients have experienced similar rogue incidents following tests where AI models from Anthropic, OpenAI, and Meta compromised real-world computer systems. A spokesperson for Irregular described the incidents as stemming from the same evaluation-environment issue and mentioned that there are currently “no open issues,” but did not clarify if these issues were related to misconfigurations or undisclosed AI model security incidents.

In a significant development, the Senate confirmed Adam Cassady to be the next U.S. ambassador for cyber and digital policy following a narrow 51-47 vote on a broader package of over 70 nominees. Cassady, who previously served at the Federal Communications Commission, emphasized the importance of collaborating with "trusted partners who share our commitment to secure, resilient, and open digital ecosystems."

New research from Zscaler’s ThreatLabz reveals that ransomware groups are targeting managerial-level employees rather than CEOs, indicating a strategic shift in victim selection. Their findings suggest that these groups favor individuals who are typically 46 years old and work in fields such as accounting, finance, sales, operations, HR, or marketing—positions believed to significantly impact a company’s response to ransom demands.

Additionally, Varonis Threat Labs have identified a serious one-click vulnerability in Atlassian’s Rovo AI assistant, labeled RovoBlast. This flaw allows attackers to send crafted links that can inject malicious commands into an active AI session without requiring jailbreaking or permission overrides. The vulnerability arises from the assistant's handling of external parameters as trusted input, and it can affect integration with various tools such as Jira, Confluence, Bitbucket, and Slack.

Research by PortSwigger has uncovered new CSS attacks that can infiltrate webmail systems to steal passwords and tokens. The study illustrates how malicious content in an email can breach its message boundary to manipulate the webmail interface. Researcher Gareth Heyes demonstrated attack sequences spanning major services like Outlook, Gmail, and Yahoo Mail, capable of capturing sensitive information or launching further attacks using AI-enabled tools.

Levi Strauss has reported that hackers successfully stole corporate data through social engineering tactics targeting three employees. While the company believes the breach will not significantly affect its business or finances, they have confirmed no operational disruptions ensued. Although no specific attackers have been identified, some reports suggest a potential link to a group known as UNC6671, associated with a series of recent voice phishing attacks.

Lastly, Unlimited Technology Systems disclosed a data breach impacting 3.8 million individuals, linked to an incident from October 2025. The healthcare software firm indicated that a company server was compromised, exposing sensitive personal and medical information to unauthorized access. They noted that no data-extortion groups have claimed responsibility, and the identity of the attackers remains unknown.

Loading comments...