An internal cybersecurity evaluation to evaluate Hugging Face's offensive cyber capabilities allowed two of the company's advanced A...
Canada's federal banking regulator has privately warned financial institutions that advances in frontier artificial intelligence are shrinking the time available to detect and contain software vulnerabilities, according to an internal email that specifically identified Anthropic's Claude Mythos, an uncommon move for a regulator that typically avoids naming individual technologies.
The email, sent on April 29 by the Office of the Superintendent of Financial Institutions (OSFI), was addressed to chief technology officers, chief information security officers and chief risk officers at federally regulated banks and insurance companies. Obtained by Reuters through Canada's Access to Information Act, the communication described advanced AI models such as Anthropic's Claude Mythos as accelerating the pace at which cyber risks can emerge, prompting institutions to strengthen the speed of risk identification, mitigation and incident response.
Unlike most regulatory guidance, which generally refers to broad categories such as generative AI or emerging technologies, the OSFI email explicitly referenced Claude Mythos by name. Financial regulators typically adopt technology-neutral language to ensure guidance remains applicable as technologies evolve, making the direct reference to a specific frontier AI model particularly notable.
According to the released correspondence, OSFI warned that advanced AI systems are compressing the timeframe available for organizations to respond to newly identified vulnerabilities before they can be exploited. The regulator indicated that the bulletin accompanying the email outlined sound practices that federally regulated financial institutions could adopt to improve the speed and effectiveness of identifying, mitigating and responding to cyber risks.
However, portions of the document released under Canada's Access to Information Act were redacted, leaving many of the regulator's recommended practices undisclosed. While the details of the guidance remain partially withheld, the available sections reveal OSFI's assessment that rapidly advancing AI capabilities are challenging long-standing assumptions underpinning vulnerability management.
For decades, many cybersecurity programs have operated on the expectation that defenders would have days or even weeks to evaluate newly disclosed vulnerabilities, test patches and deploy mitigations before attackers developed reliable exploits. Frontier AI models capable of rapidly analyzing software code and identifying exploitable weaknesses could substantially reduce that window, increasing pressure on organizations to accelerate patch management and defensive operations.
The concern is particularly relevant for financial institutions, many of which continue to operate complex legacy infrastructure supporting critical banking services. Core banking platforms often consist of decades-old software integrated with newer digital systems, making security updates and vulnerability remediation significantly more complex than in less regulated technology environments. A shorter interval between vulnerability discovery and exploitation therefore presents operational challenges for institutions responsible for maintaining highly available financial services.
Claude Mythos has drawn attention within the cybersecurity community for its reported ability to assist with sophisticated vulnerability research and exploit development in controlled environments. Anthropic introduced the model through Project Glasswing, a restricted-access initiative designed to provide selected organizations with advanced cybersecurity capabilities for defensive research rather than broad public deployment. Access to the model remains limited and subject to eligibility requirements established by Anthropic.
The timing of OSFI's communication coincided with a series of regulatory discussions surrounding frontier AI models. Earlier in April, senior executives from Canadian banks reportedly met with regulators to discuss the implications of Claude Mythos. Around the same period, U.S. Treasury Secretary Scott Bessent and then-Federal Reserve Chair Jerome Powell also convened bank chief executives to examine the potential cybersecurity implications associated with increasingly capable AI systems.
International regulators have since demonstrated similar interest. Authorities at the European Central Bank and the Bank of England have reportedly discussed the implications of frontier AI for financial sector resilience, while Australia's corporate regulator, the Australian Securities and Investments Commission (ASIC), has confirmed that it is monitoring developments related to the technology.
Following questions from Reuters regarding the internal email, OSFI subsequently published a public bulletin addressing the governance of generative and agentic artificial intelligence. The regulator reiterated that its supervisory approach focuses on how federally regulated financial institutions identify, govern and manage risks arising from AI adoption rather than regulating individual AI models themselves.
"Our focus is not the technology itself, but how federally regulated financial institutions govern and manage the risks associated with its use," OSFI said in its public statement.
Nevertheless, the regulator's internal correspondence referred to Anthropic's Claude Mythos by name on multiple occasions, distinguishing it from the more general language typically used in regulatory communications concerning emerging technologies.
OSFI oversees Canada's federally regulated banks, insurance companies and pension plans, with responsibilities that include monitoring financial stability risks arising from cybersecurity, foreign interference, geopolitical developments and technological change. The emergence of highly capable AI models has increasingly placed these categories of risk in closer alignment as governments evaluate both the opportunities and security implications associated with frontier AI.
While the Canadian government has confirmed that it has access to Claude Mythos, it remains unclear whether any of Canada's major financial institutions currently participate in Anthropic's controlled-access Project Glasswing program. Several banks declined to comment publicly on whether they have access to the model, referring questions instead to the Canadian Bankers Association.
In response, the Canadian Bankers Association said member institutions have invested substantially in protecting Canada's financial system and continue to comply with OSFI's cybersecurity risk management and incident reporting requirements, without addressing whether banks currently have access to the frontier AI model.
At the same time, Canada's largest banks continue expanding their AI strategies across customer services, internal operations and software development. Royal Bank of Canada, TD Bank and Bank of Montreal have outlined initiatives aimed at integrating AI into business operations while reducing reliance on external technology vendors. Scotiabank, CIBC and National Bank have also disclosed AI-related programs intended to improve operational efficiency and customer services.
Bruce Ross, Royal Bank of Canada's Group Head of Artificial Intelligence, said in June that models such as Claude Mythos are changing the cyber threat environment by enabling exploit code to emerge much sooner after vulnerabilities are discovered. He said the bank's response has focused on strengthening AI-powered defensive capabilities to counter increasingly sophisticated attacks.
Anthropic has also expanded Project Glasswing in recent months, reporting that participating organizations have collectively identified more than 10,000 high- and critical-severity software vulnerabilities using the platform's advanced cybersecurity capabilities. The company has positioned the initiative as a defensive research program intended to improve software security while maintaining controlled access to highly capable AI systems.
A former ransomware negotiator who was hired to help organizations respond to cyber extortion incidents has been sentenced to 70 months in federal prison after admitting he secretly worked with BlackCat ransomware affiliates, using confidential client information to increase ransom payments while participating in additional ransomware attacks.
The U.S. Department of Justice said Angelo Martino, 41, abused his position at incident response firm DigitalMint by sharing privileged information obtained during ransomware negotiations with BlackCat, also tracked as ALPHV. Prosecutors said the information allowed the ransomware group to negotiate from a stronger position while victims remained unaware that details intended to protect them had been disclosed to the attackers.
As part of his role, Martino managed active ransomware cases for organizations seeking assistance after cyberattacks. His work gave him access to confidential information that companies typically share only with trusted negotiators, including cyber insurance policy limits, internal assessments of how much they were prepared to pay, and negotiation strategies developed during incident response.
According to court documents, Martino began providing that information to BlackCat operators in April 2023. Prosecutors said he communicated with the group through multiple channels connected to BlackCat's extortion platform. While one conversation took place through the standard negotiation interface used during ransomware incidents, he also relied on an intermediary chat feature within the group's panel and the encrypted messaging application Tox to exchange information directly with the attackers outside the victims' view.
Federal prosecutors said those private communications were intended to help BlackCat maximize ransom demands. In exchange for sharing confidential information, including insurance coverage limits and the negotiating positions of victim organizations, Martino received a portion of the cryptocurrency paid by ransomware victims.
The Justice Department said five organizations whose cases were handled by Martino collectively paid more than $75 million to BlackCat affiliates between April and September 2023. Prosecutors argued that access to confidential negotiation data enabled the attackers to demand higher payments than they otherwise might have secured. The affected organizations operated in the financial services, healthcare, retail, hospitality, and nonprofit sectors, with several experiencing operational disruption alongside the financial losses associated with the attacks.
Investigators also determined that Martino later became an active participant in BlackCat's ransomware operation. In May 2023, he obtained affiliate access to the ransomware-as-a-service platform, permissions generally granted to trusted partners responsible for compromising victim networks and deploying the malware.
Court filings state that Martino shared those affiliate credentials with Kevin Martin and Ryan Goldberg, both cybersecurity professionals. The three men subsequently carried out additional ransomware attacks and agreed to divide ransom proceeds among themselves while paying 20% of each payment to BlackCat's administrators in exchange for continued access to the group's malware and extortion infrastructure.
One attack targeted a medical device manufacturer that ultimately paid approximately $1.2 million in ransom. Other organizations refused to pay but still incurred costs associated with business interruption, system recovery, and incident response following the attacks.
Prosecutors said Martino received millions of dollars in cryptocurrency through the conspiracy. Federal investigators recovered and seized more than $10 million in assets connected to the case, although authorities said some proceeds had already been used to purchase residential properties, vehicles, and a boat. As part of his sentence, Martino must forfeit assets linked to the criminal activity and pay 10% of his future income following his release from prison.
Before sentencing, Martino requested a reduced 24-month prison term, citing his cooperation with investigators during the prosecution of his co-conspirators. Martin and Goldberg were each sentenced to four years in prison earlier this year after pleading guilty for their involvement in the BlackCat attacks.
"Angelo Martino sold out the very victims he was hired to represent, handing their confidential negotiating positions to BlackCat actors to drive up ransoms and enrich himself," FBI Cyber Division Assistant Director Brett Leatherman said following the sentencing.
BlackCat operates as a ransomware-as-a-service platform, providing malware and extortion infrastructure to affiliates that compromise organizations and share a percentage of ransom payments with the group's administrators. The FBI has linked the operation to more than 1,000 victims and at least $300 million in ransom payments through September 2023. Although law enforcement disrupted parts of the group's infrastructure and previously released a decryptor for some victims, affiliates continued launching attacks after those actions.
DigitalMint said it was unaware of Martino's conduct until it was contacted by the Department of Justice and described itself as another victim of the scheme. The company said the employees involved were terminated immediately after the allegations came to light and that it fully cooperated with investigators throughout the criminal investigation.
The company also said Martino deliberately bypassed internal safeguards by communicating with threat actors through unauthorized channels that were not visible within its monitoring systems. According to DigitalMint, its security controls aligned with industry practices, but the unauthorized communications were intentionally concealed from the company's oversight mechanisms.