Subscribe to Running With Scissors

Hacking, policy, advocacy, and the sharp end of security research. Delivered to your inbox.

Free. No spam. Unsubscribe anytime.

Check your inbox

A confirmation link has been sent to your email.

Policy Pulse - Issue #27 | Week of August 1, 2026

Anthropic discloses three Claude models breached three real organizations during cyber evals, days after OpenAI breached Hugging Face the same way. Congress pushes the FRONTIER Act as CISA's 2015 sharing law nears sunset.

Policy Pulse - Issue #27 | Week of August 1, 2026

Policy Pulse - Issue #27 | Week of August 1, 2026

Your weekly briefing on cybersecurity policy affecting vulnerability disclosure and security research.


Top Story

Anthropic discloses that three Claude models breached three real organizations during cyber evaluations, days after OpenAI's own breach of Hugging Face: the reporting channels exist, the norms and the legal frame do not

On July 30, Anthropic's Frontier Red Team disclosed that a review of 141,006 evaluation runs found three incidents, across six runs, in which Claude models reached the open internet from inside a third-party evaluation environment and gained unauthorized access to real systems at three separate organizations. The models involved were Claude Opus 4.7, Claude Mythos 5, and an internal research model. The root cause was a misconfiguration with evaluation partner Irregular that left eval machines internet-reachable, combined with prompts that asserted "no internet access" without actually enforcing a boundary. (Anthropic, TechCrunch)

The most consequential incident: Mythos 5 noticed that a fictional company's setup instructions in the eval scenario referenced a nonexistent PyPI package. It registered the package name itself, worked through an email-then-phone-number account creation chain after paid phone verification services failed, and uploaded malware that executed on 15 real systems during roughly one hour of availability, including one belonging to a security company whose scanner routinely installs newly published Python packages. Anthropic suspended all cybersecurity evaluations on July 23, identified all three incidents the following day, and notified Irregular and the affected organizations on July 27. METR is now running an independent third-party review with access to all transcripts. At the time of the disclosure, one affected organization had still not been reached. (Help Net Security, The Record)

Why it matters for VDP: Start with the legal exposure, because it is the part nobody has answered. On Anthropic's own account of the facts, its models reached systems at organizations that had not authorized the access, and in one incident uploaded code that ran on 15 machines belonging to others. Those are the two things 18 U.S.C. 1030 is built around: accessing a computer "without authorization or exceed[ing] authorized access" under (a)(2), and knowingly transmitting code that "intentionally causes damage without authorization, to a protected computer" under (a)(5). The UK's Computer Misuse Act splits the same way, section 1 for unauthorised access and section 3 for unauthorised acts impairing operation, and EU member states have their own analogs. None of them contains a good-faith research exemption. DOJ's May 2022 charging policy says good-faith security research "should not be charged," but that is a charging policy: prosecutorial discretion, revocable by memo, no defence a defendant can raise, no bar to a civil claim, and no constraint at all on a prosecutor outside the US. It also defines the protected activity as work "carried out in a manner designed to avoid any harm to individuals or the public," which raises a real question about an evaluation that put running code on other people's machines. Nobody has said whether any of this will be tested, and that uncertainty is itself the finding.

And the channel is not what is missing, which is precisely what makes this a norms problem rather than an intake one. Hugging Face, the organization OpenAI's model reached last month, publishes a security.txt with a live security address, unexpired and RFC 9116 clean. The mailbox works. What the mailbox cannot tell you is what to do with what arrives in it. Disclosure policies are drafted with a researcher in mind: they set scope, they offer safe harbor, and they trade terms for good-faith behaviour. Nobody drafted one imagining the reporter would be a frontier lab writing to say its own model broke in during a capability evaluation, that the access ran for an hour before anyone noticed, and that the report itself catalogues conduct with live legal exposure attached. So the gap is not the channel. It is that the industry has no settled answer to what a lab may do to real infrastructure in the name of capability testing, no convention for how fast it must tell you when an evaluation escapes, and no clarity on who carries the liability when it does. Neither Anthropic nor Irregular has said whether the affected organizations are weighing legal action.

Throwback: Issue #26 led with OpenAI's GPT-5.6 Sol chaining a zero-day in Artifactory to breach Hugging Face's production database during its own internal benchmarking. Two frontier labs disclosing self-caused breaches nine days apart, both originating inside cyber-capability evaluation environments, is no longer an incident. It's a pattern: the evaluation environment itself is now the attack surface.


Upcoming Deadlines & Events

Date Agency Event/Deadline Action Required Link
Aug 14, 2026 NIST Comment period closes on SP 800-219r2 (automated macOS Security Compliance Project guidance) Submit comments csrc.nist.gov
Aug 24, 2026 US Copyright Office DMCA Section 1201 petitions due (renew or lose the good-faith security research exemption) File a renewal or new-exemption petition copyright.gov
Aug 24, 2026 NIST Comment period closes on SP 800-213r1 (IoT product cybersecurity guidelines for the federal government) Submit comments csrc.nist.gov
Aug 31, 2026 Council of Europe Registration closes for Octopus Conference 2026 (25th anniversary of the Budapest Convention; Second Additional Protocol signing ceremony) Register (in-person only) coe.int
Sept 8, 2026 NIST Comment period closes on SP 800-209r1 (storage infrastructure security guidelines) Submit comments csrc.nist.gov
Sept 11, 2026 EU / ENISA Cyber Resilience Act Article 14 reporting obligations go live: 24-hour early warning, 72-hour notification, 14-day final report on actively exploited vulnerabilities Confirm Single Reporting Platform registration; build the intake-to-regulator pathway now digital-strategy.ec.europa.eu
Sept 25, 2026 NIST Comment period closes on SP 800-239 (AI data center security analysis, HPC-driven approach) Submit comments csrc.nist.gov
Sept 30, 2026 US Congress Cybersecurity Information Sharing Act of 2015 sunsets (reauthorized through this date in the Feb 3, 2026 funding bill); S.1337 would extend it ten years but has not moved Track S.1337; the sunset lands the same day as the federal funding deadline insideprivacy.com

Prioritized nearest-first. The DMCA 1201 and CISA 2015 deadlines above are the two where community inaction directly costs the community a protection it currently has.


This Week in Policy

Federal Strategy & Regulation

  • CISA publishes a revised SBOM baseline and new open source software security guidance. On July 29, CISA and partners released the 2026 Minimum Elements for SBOM, the first substantial revision of NTIA's 2021 baseline, incorporating feedback from more than 90 public comments and explicitly extending scope to open source, AI software, and SaaS. The next day, CISA published Open Source Software: Security Principles and Practices, covering how federal agencies use, assess, contribute to, and produce OSS, and how they evaluate open source AI models, citing Log4Shell and the xz utils backdoor as the motivating incidents. (CISA - SBOM, CISA - OSS guidance)
    Why it matters for VDP: SBOM is the substrate that turns "this library is vulnerable" into "these products are affected and here is who owns them," the exact attribution problem coordinated disclosure exists to solve. Agencies now formally producing and contributing OSS also become inbound targets for researcher reports, raising the question of who triages them.

  • CISA's 2015 information-sharing liability shield is under two months from expiry, with no reauthorization vehicle moving. The Cybersecurity Information Sharing Act of 2015 sunsets September 30, the same day as the federal funding deadline. A ten-year reauthorization (S. 1337) has been introduced but has not moved. (ITI)
    Why it matters for VDP: CISA 2015 supplies the liability protection that lets companies share vulnerability and threat information without fear of antitrust or disclosure liability. A lapse chills exactly the disclosure-adjacent information sharing this community depends on, and it collides with the CRA's new mandatory reporting regime taking effect nineteen days earlier (see International, below).

CVE & Vulnerability Programs

  • The House passed its FY2027 defense bill without the amendment that would have put CVE into statute. Amendment 812 to H.R. 8800 would have codified CVE program authority under CISA in statute, created a 15-member CVE Board, made vulnerability enrichment part of CVE's formal mission, and directed a joint CISA/NIST ten-year modernization plan with indefinite appropriated funding. The House Rules Committee cleared it for consideration on June 29, but the House then rejected the rule governing NDAA consideration on June 30, so members never voted on the amendments at all. H.R. 8800 passed the House 216-212 on July 22 without it; the Senate version carries no CVE language and remains stalled. (RunZero, roll call)
    Why it matters for VDP: CVE's funding remains a renewable contract, not a statutory line item. That's the same structural fragility that produced the April 2025 near-lapse, unresolved heading into FY2027.

  • NIST's OIG-ordered corrective action plan for the NVD backlog fell due inside the window, with no public confirmation it was submitted. A Commerce Office of Inspector General review found the NVD backlog stood at roughly 13,000 unprocessed vulnerabilities by the time a replacement enrichment contract was in place, grew to more than 27,000 by the end of 2025, and projected that reported vulnerabilities would surpass 60,000 in 2026. The OIG gave NIST until July 25 to submit a formal action plan against six recommendations: a strategic plan, a backlog plan with milestones, reduced duplicative severity scoring, coordination with CISA, a better external contribution process, and a stakeholder communication strategy. That deadline has passed; NIST's NVD news page still shows no update since June 17. (Help Net Security)
    Why it matters for VDP: Since April 15, every CVE published before March 1, 2026 that's still backlogged sits in "Not Scheduled" and won't be enriched. A CVE ID no longer implies a CVSS vector or CWE mapping will ever follow it.

  • Adobe and Cisco both restructured disclosure cadence this month, citing AI-accelerated vulnerability discovery. Adobe moved from monthly to twice-monthly bulletins (second and fourth Tuesday) effective July 14. Cisco shifted to a twice-monthly, risk-based model, consolidating related findings into "umbrella" CVEs and deprioritizing individual advisories for low-risk issues. (Adobe, Cisco)
    Why it matters for VDP: Cisco's umbrella-CVE consolidation changes the unit of account. If several related findings collapse into one CVE, that has direct downstream consequences for researcher credit, bounty payout structure, and any customer SLA written against per-CVE remediation timelines.

  • GitHub's restructured bug bounty program took effect July 27, cutting public-tier payouts roughly in half. The new public tier pays fixed amounts (Low $250 / Medium $2,000 / High $5,000 / Critical $10,000); a permanent, invite-only VIP tier pays substantially more (Low $1,000 / Medium $7,500 / High $20,000 / Critical $30,000+). GitHub cited AI-generated report volume as the driver; a HackerOne signal requirement effectively gates VIP-tier access behind established reputation, with four initial submissions to establish signal for newcomers. (GitHub)
    Why it matters for VDP: One of the highest-profile public programs just repriced its economics around report volume rather than report quality, and is using reputation as the gate. Programs weighing an AI-submission problem now have a live, large-scale worked example to study, both for what it fixes and for who it locks out.

AI & Emerging Tech Security

  • Congress reacts within 24 hours: Rep. Trahan calls for hearings and pushes the FRONTIER Act. Citing both the Anthropic and OpenAI disclosures, Rep. Lori Trahan (D-MA), House Energy and Commerce, said: "We can't run AI safety on the honor system. When Congress returns, we must hold hearings and move the FRONTIER Act." The bipartisan bill (H.R. 9925, Reps. Obernolte and Trahan) would authorize the Commerce Department to suspend or restrict development or deployment of an advanced AI model on a written finding that it presents an "imminent catastrophic risk," and imposes tiered requirements on developers by size, including model cards, risk-management frameworks, independent audits and incident reporting. (CFO Dive, Rep. Obernolte's office)
    Why it matters for VDP: This is the clearest sign yet that the two eval-environment breaches are being read in Washington as a systemic gap, not an isolated mishap. A mandatory third-party verification regime for the largest developers would, if enacted, directly shape how future capability evaluations are structured and disclosed.

  • A separate EO 14409 deadline (classified benchmarking process, voluntary pre-release access framework) fell due August 1, with no public deliverable found. Executive Order 14409 required, within 60 days of its June 2 signing, a classified process (NSA, CISA, NIST, Treasury) to designate "covered frontier models" with advanced cyber capabilities, and a voluntary framework granting the federal government up to 30 days of pre-release access. We independently checked the Federal Register (zero documents matching in the relevant window) and CISA's own newsroom (nothing published after July 30) and found no public artifact. Because the benchmarking process is classified by design, its absence from public channels is not proof nothing happened inside government; it is proof nothing has been said publicly. (White House - EO text, reporting)
    Why it matters for VDP: The UK AI Security Institute and NIST's CAISI have been jointly publishing cyber-capability assessments of foreign open-weight models on a weeks-long public cadence. The domestic framework that would give CISA equivalent structured visibility into US frontier models, the ones that just breached three real organizations from inside test harnesses, has no public status as of this writing.

  • The five-agency coordinated disclosure guide's safe-harbor clause, in the agencies' own words. Issue #25 covered the July 15 joint CISA/NSA/JPCERT-CC/NCSC-NL/NCSC-UK guidance. Worth quoting the model clause directly, since it's the most citable government-endorsed safe-harbor language to date: "If you make a good-faith effort to comply with this policy during your security research, [SUPPLIER NAME] will consider your research to be authorized, work with you to understand and resolve the issue quickly, and will not recommend or pursue legal action related to your research. Should legal action be initiated by a third party against you for activities that were conducted in accordance with this policy, we will make this authorization known." (CISA guide PDF)
    Why it matters for VDP: Five governments now endorse specific third-party-defense language going beyond DOJ's charging-policy-only posture. If your VDP still lacks this clause, this is the sentence to copy.

  • The DMCA Section 1201 renewal deadline is now three weeks out, and the good-faith research exemption does not renew itself. Petitions for the Tenth Triennial rulemaking, both renewals and new exemptions, are due August 24, 2026. Comments opposing renewals are due September 28. The good-faith security research exemption must be affirmatively re-petitioned this cycle or it lapses in October 2027. (Copyright Office)
    Why it matters for VDP: This is the one item in this issue where a specific reader action, filing or supporting a renewal petition, changes the outcome. The deadline is August 24.

  • Canada quietly signed the UN Cybercrime Convention, without public explanation or consultation. Law professor Michael Geist documents that Canada, which opposed the treaty's negotiation in 2019 and skipped the October 2025 Hanoi signing ceremony, signed in mid-July 2026 with no announcement. Geist notes that "over 120 security researchers cautioned that its offences threaten to criminalize good-faith security research." (Michael Geist)
    Why it matters for VDP: This is the treaty's researcher-criminalization problem arriving in a Five Eyes jurisdiction. Signature is not ratification, but a quiet signature with no domestic consultation means the researcher-protection objection has had no forum at the national level so far.

International Developments

  • The European Commission published its first official Cyber Resilience Act guidance. Communication C(2026) 5252 runs to more than 80 pages of worked examples, flowcharts and interpretive analysis, clarifying scope, open-source treatment, substantial modification, support periods, and the reporting obligations starting September 11. (European Commission, guidance documents, Lewis Silkin)
    Why it matters for VDP: Issue #26 flagged that the CRA's 24-hour reporting mandate arrives without an operational platform. There's now at least an official interpretive text manufacturers can build a compliance process against, six weeks ahead of the deadline. ENISA's Single Reporting Platform itself is still in its testing period ahead of the mandatory go-live, per ENISA's own SRP page. Once live, it also opens as a voluntary intake channel for independent researchers reporting into the EU, a genuinely new coordination surface for this community. (ENISA)

  • Australia's SOCI Act 2.0 consultation closed July 31, and the proposals include an AI-scoped incident definition. The 21-measure tranche-2 consultation, responding to an independent review of the SOCI Act whose six recommendations the government accepted in principle, would shift the higher-education asset class from a university-based test to a research-function-based one, bringing non-university research bodies into scope, and would modernize the "cyber security incident" definition (Measure 5) to operate where automation, software agents or AI-enabled tools affect the mechanism, attribution or operation of an incident. (Home Affairs, Allens)
    Why it matters for VDP: An incident definition that explicitly names AI-enabled tools and software agents is a template other Five Eyes nations are likely to borrow, and it directly affects what an Australian critical-infrastructure operator must report when an autonomous testing agent (yours or someone else's) touches their systems.

  • The Pall Mall Process opens its industry-facing negotiation window this month. 27 governments have signed the voluntary Code of Practice for States, which already recognizes penetration testing, red teaming, coordinated vulnerability disclosure, and bug bounty programs as "lawful and beneficial." Organizers have just released a consultation toward a Code of Practice for the cybersecurity industry, inviting input from companies, investors, researchers and civil society on due diligence, accountability, vendor vetting and redress. Its outcome will inform the drafting of Industry Guidelines in 2026. (Center for Cybersecurity Policy)
    Why it matters for VDP: This is the intervention point, not November. Analysts flag that current draft language around "researcher controls" could enable restrictive licensing frameworks that squeeze independent research, and that the Code doesn't require governments to notify vendors when they buy or exploit zero-days. If disclose.io or the wider research community wants the dual-use carve-out preserved, input needs to land in the next eight weeks.


Worth Reading


Friends of disclose.io

Stingrai: A census of how 53 VDP and bounty policies actually treat AI-generated reports

Stingrai retrieved and coded 53 disclosure policies on July 28, spanning four coordination platforms (HackerOne, Bugcrowd, Intigriti, YesWeHack), 20 vendor programs, and 29 open source projects, to answer a question this community keeps arguing about from anecdote: do policies actually ban AI-assisted vulnerability reports? The dataset is released under CC BY 4.0.

Key findings:

  • Zero of 53 policies ban AI-assisted submissions outright.
  • 36 of 53 (67.9%) say nothing about AI-assisted research at all.
  • Of the 16 that address it, 13 permit AI use with conditions, almost universally a human-in-the-loop or working-reproduction requirement.
  • Named programs span Apple, GitLab, Cloudflare, Google VRP, Django, FFmpeg, the Linux kernel, Wireshark, llama.cpp, Nextcloud, and curl, alongside the four platforms above.
  • The 2026 program attrition that's been read as an "AI slop" backlash (curl closing its bounty in January, Nextcloud suspending paid bounties in April, the Internet Bug Bounty pausing submissions) tracks to economic and capacity adjustments in the underlying policy text, not to bans.

📄 Full census and dataset

Stingrai's methodology, coding 53 live policy texts rather than surveying maintainer sentiment, is exactly the kind of primary-source work this community needs more of before the "AI report volume" debate hardens into policy on vibes.


Policy Pulse is a weekly bulletin from disclose.io. Keeping the security research community informed on policy that affects our work.

Have a tip or want to contribute? Reply to this email, reach out on Twitter/X, or drop a comment here!