AI Risk Monitoring Failed. Claude Explained The Evidence Away.

Document lit on a dark surface casting a shadow that does not match its shape, illustrating AI risk monitoring failing when a model explained away the evidence

“If you are providing an AI-driven tool or service like Replit, would your network security liability policy cover customer lawsuits claiming that your AI agents conducted unauthorized access, data destruction, or transmission of malicious code?” Erin Kenneally asked that question in her September 29, 2025 guest essay for CINI. Nearly a year later, Anthropic has … Read more

AXA XL S-RM Acquisition Adds Forensics And Incident Data To Risk Advisory

AXA XL announced Thursday it will acquire the remaining shares of S-RM. The specialty insurer already held roughly 49% of the London-based consultancy. AXA XL did not disclose financial terms. The deal needs regulatory approvals and should close by the end of September 2026. S-RM opened its doors in 2005 and now serves clients in … Read more

Hackers Silenced The Water Alarms. Insurers Are Being Asked To Fix It.

Attackers did not just lock operators out. Federal guidance says they learned to disable the alarms that warn something is wrong. A proposal wants underwriters to enforce a standard of care that courts already struck down once. Attackers spent late July inside the control systems of American water utilities. They changed IP addresses. They set … Read more

The AI Agents Got Out. The Bill Has No Name On It.

Somewhere in mid-July, two OpenAI models decided the sandbox was optional. Reporting indicates they exploited a previously unknown flaw, walked out onto the open internet, and broke into the production systems of Hugging Face, the AI model-hosting platform. OpenAI called it an “unprecedented cyber incident, involving state-of-the-art cyber capabilities.” Some might translate that as: our … Read more

Dangling DNS Takeover Risk: Inside Silent Push’s “Danglegeddon” Study

There are billions of subdomains on the internet pointing to nothing. Silent Push calls them “billions of forgotten, abandoned, and misconfigured subdomains.” Most sit quietly. None of them look dangerous. Silent Push just proved how wrong that assumption is. The threat intelligence firm ran a simulation across four sectors: government, banking, automotive manufacturing, and pharmaceuticals. … Read more

×