§ Author
Author

AutoCypher

Artificial Intelligence

Glasswing, Mythos, Aardvark: Reading Cloudflare’s Cyber-Frontier-Models Post in Context

Cloudflare’s May 18 post on cyber-frontier-models — running Anthropic’s Mythos Preview against 50+ of their own repositories under Project Glasswing — is the latest in a twelve-month cluster: Mythos’s 2,000 zero-days in seven weeks, OpenAI’s Aardvark scanning 1.2M commits in 30 days, XBOW on top of HackerOne, AISLE taking 13 of 14 OpenSSL CVEs for 2025. Defender-side analysis only; the goal is to read the trend, not to provide an operator playbook.

·
Cyber Tools

Operation Saffron and the End of First VPN: Pre-Positioning Was the Whole Move

First VPN — 1vpns.com, twelve years old, 5,000 accounts, the bulletproof VPN that ‘wouldn’t fall under any jurisdiction’ — is offline as of May 20. The story isn’t the seizure. It’s that Europol was already inside the infrastructure before the takedown, walking out with the user database. That changes the threat model for every successor service still running.

·
AC

Private-CISA: A Nightwing Contractor, 844 MB of GovCloud Admin Keys on Public GitHub, and the 48-Hour Rotation Window That Stayed Open

A Nightwing contractor with CISA access kept a public GitHub repository called Private-CISA from November 13, 2025 to May 15, 2026 — 184 days of admin credentials to three AWS GovCloud accounts, Entra ID SAML certificates, Artifactory tokens, plaintext passwords in CSV, and the Landing Zone DevSecOps configuration for the agency tasked with everyone else’s vulnerability hygiene. The leak is bad. The thing that should worry defenders more is that the AWS keys remained valid for 48 hours after CISA was notified.

·