First Pass

6 stories from 5 sources

AI's cyber reach expands, exposing new security and governance risks

Day’s Recap

Supporting Articles

10:44 AMTechCrunch

Anthropic scales Claude Mythos to critical infrastructure in 15+ countries

Summary

Anthropic is expanding Project Glasswing to provide Claude Mythos and a security vulnerability workflow to 150 organizations across more than 15 countries. The program targets critical infrastructure operators in power, water, healthcare, and communications where disruptions could impact up to 100 million people.

Why it matters

If AI meaningfully accelerates vuln discovery and triage in critical infrastructure, it can reduce systemic cyber risk, but it also raises new governance and security requirements for high-consequence environments.

7:40 AMBBC

Instagram AI chatbot tricked by hackers to give access to others' accounts

Summary

Hackers reportedly manipulated an Instagram AI support chatbot into handing over information or access that enabled takeovers of other users' accounts. The incident has been linked to a cluster of recent hijackings of high-profile Instagram accounts.

Why it matters

If AI support tools can be socially engineered into granting access, account security becomes a platform-wide systemic risk rather than an individual user problem.

7:00 AMSchneier on Security

Microsoft Threatening Security Researcher

Summary

An anonymous researcher publishing as “Nightmare Eclipse” has released a series of Windows exploits, including a method that defeats default Windows 11 BitLocker protections. Microsoft has responded by threatening legal action, triggering a public dispute over vulnerability disclosure norms and responsibility.

Why it matters

How Microsoft handles this case will shape whether researchers cooperate on coordinated disclosure or treat Windows vulnerabilities as publish first, lawyer later.

Other Developments

A curated list of other prominent stories from this day.

6:58 PMWWD

Camilla Involved in Cyber Incident Affecting Customer Data in Australia

Summary

Camilla disclosed a cyber incident affecting customer data tied to its Australian operations. The company said payment card data and banking information were not compromised.

Why it matters

Even without card or bank data, exposed customer information can drive targeted fraud and impose legal and reputational costs.

6:50 PMTechCrunch

Cyera eyes $12B valuation at 80x ARR multiple despite operating losses

Summary

Cyera is nearing a roughly $300 million financing round led by Evolution Equity Partners that would value the data security startup around $12 billion. The deal implies an estimated 80x ARR multiple even as the company is still operating at a loss.

Why it matters

An 80x ARR, loss making round signals risk appetite returning to growth security and resets private market comps for the sector.

6:44 AMBloomberg Markets

AI Fuels $280 Billion Cybersecurity Rally as Earnings Test Looms

Summary

Upcoming earnings from Palo Alto Networks and CrowdStrike are set to test whether the sharp year-to-date rally in cybersecurity stocks is supported by durable demand and guidance. Investors are looking for confirmation that growth, margins, and bookings justify current valuations.

Why it matters

These prints can either validate cyber as a resilient growth trade or trigger a broad valuation reset across the sector.

Make it yours

Build Your First Pass.

Pick your topics, set your cadence, and receive your personalized First Pass in your inbox. It’s that simple!