Claude Broke Into Real Systems During Cybersecurity Tests. The Real Failure Was Control.
Claude compromised three organizations after a test environment was mistakenly left online. The lesson for CISOs: an AI agent needs no malicious intent to cause harm—only an objective, excessive reach, and weak controls.
The EU-US Data Transfer Framework Did Not Collapse. But Your Risk Model May Have.
The EU-US Data Privacy Framework is still in force. But the Supreme Court’s FTC ruling exposes a deeper problem: legal transfer mechanisms are not a substitute for sovereignty, resilience, or control. What CISOs should do now.