ScrutinEyes · verified-only analysis
Independent AI & security analysis from ScrutinEyes, the InitialEyes family's publication — every claim verified against primary sources before it ships, and syndicated here in full. Subscribe on Substack to get each issue by email.
A first-party autonomous-agent breach lands on a regulator's desk, the AI coding tools themselves get a zero-click RCE, Cisco's email gateway hands out root — and a threat actor's record count outruns what any company has confirmed.
A record Patch Tuesday nobody counts the same way, one exploit kit behind both Chrome zero-days, Anthropic names the crews weaponizing its models — and Revolut hands passports to a fake government request.
Ransomware gangs exploiting AI infrastructure, a git config that turns coding agents against their users, the full post-mortem of the 700-agent Hugging Face swarm — and three frontier labs shipping models built to hack.
A "denial-of-service" bug that was really remote code execution, a print-server zero-day the vendor didn't find, 284 million "records" that aren't 284 million people — and OpenAI's models breaking out of their own exam.
A perfect-10 bug in the identity plane, two poisoned package registries, 9,000 live cloud keys — and the week's quiet lesson about verifying what vendors tell you.
This week's four KEV flaws all shipped with patches already — the story is the gap between “fixed” and “safe,” plus the agentic-AI version of the same problem.
The EU AI Act's transparency rules apply as of August 2, 2026 — what they require, what they don't, who they bind, and what ignoring them costs.
A red-team result became a national-security incident, then a three-week policy whipsaw. The gap between how the event was described and what was actually confirmed is the whole story.
Ten failure modes, one afternoon, zero feelings. Score what you can prove.
Most enterprise MFA deployments look secure on the surface.
Analysis, not advice: nothing here is legal, regulatory, or professional advice, and a readiness assessment is not a certification. When you need a lawyer or a formal assessor, we say so plainly.