This week’s defence and security AI stories converge on a single theme: the dual-use nature of AI has become impossible to ignore. From Anthropic’s cyber-capable model being frozen by US export controls, to Russian actors running billion-credential campaigns against NATO-adjacent infrastructure, to the IDF expanding AI-assisted weapons to allied militaries, the line between AI as shield and AI as weapon is dissolving in real time. European and UK institutions are scrambling to govern and react — with the UK AI Safety Institute, EU’s ENISA, and NATO all drawn into new AI security frameworks this week.
Top story: US government freezes Anthropic’s Fable 5 and Mythos 5 for foreign nationals over fears their autonomous hacking capabilities exceed existing regulatory boundaries.
US Freezes Anthropic’s Mythos Model Over Uncontrolled Hacking Fears
Cybersecurity Magazine · Risk
The US government abruptly froze access to Anthropic’s Claude Fable 5 and Mythos 5 for foreign nationals on 12 June, citing fears that their automated hacking capabilities were escaping regulatory boundaries. The UK AI Safety Institute had already found the model could exploit defences 73% of the time in controlled evaluations. Because US export control rules applied to Anthropic’s own international staff, the company was forced to cut off all global customers at short notice — a sign that frontier AI cybersecurity models are now being treated as strategic weapons exports.
https://cybermagazine.com/news/why-the-us-is-freezing-anthropics-new-claude-models
FortiBleed: Russian Actors Compromise 86,000 Firewalls Across 194 Countries
Bleeping Computer · Risk
CISA issued an emergency advisory on 18 June after a Russian-speaking threat group executed approximately 1.16 billion credential attempts against over 320,000 FortiGate firewall and VPN targets, compromising nearly 87,000 devices across government, critical infrastructure, and multinational corporations in 194 countries. The UK’s NCSC joined CISA in warning organisations, and Recorded Future confirmed a NATO defence contractor was among those targeted — raising the spectre of espionage objectives alongside opportunistic access. The campaign, codenamed FortiBleed, underscores how AI-assisted credential automation is enabling attacks at scales previously impossible.
UK AI Safety Institute Confirms Mythos Executes Multi-Stage Attacks Autonomously
UK AI Safety Institute (AISI) · Regulation
The UK government’s AI Safety Institute published its evaluation of Anthropic’s Claude Mythos Preview, confirming that in controlled conditions where the model was given network access, it could execute multi-stage attacks on vulnerable networks and discover and exploit vulnerabilities autonomously — tasks that would take human professionals days to complete. The AISI, working alongside NCSC, noted that just two years ago the best models could barely complete beginner-level cyber tasks, making this a step-change in offensive capability. The evaluation is being used to inform UK and allied policy on how to govern frontier AI cyber models before their capabilities become widely accessible.
https://www.aisi.gov.uk/blog/our-evaluation-of-claude-mythos-previews-cyber-capabilities
Infosecurity Europe Survey: AI Attacks Now the Top Threat, Trust in AI Low
Infosecurity Magazine · Risk
A survey of 168 cybersecurity leaders conducted at Infosecurity Europe 2026 found that AI-powered attacks at scale are now the single biggest security concern — cited by 41% of respondents, double the proportion citing supply chain risk. Despite this, only 8% of professionals said they would trust AI to make security decisions without human approval, and just 19% completely trust threat intelligence systems. The findings — coming from Europe’s largest security conference — reveal a critical paradox for defence-sector practitioners: adversaries are deploying AI at speed while defenders remain cautious about delegating authority to their own AI tools.
https://www.infosecurity-magazine.com/news/ai-threats-alert-fatigue-challenge/
