China Will Likely Have Its Own Mythos by February 2027
A detailed forecast from The Substrate predicts that China will likely develop a Mythos-like AI model capable of autonomous vulnerability discovery and exploit chaining by approximately February 2027, based on a Monte Carlo model incorporating compute estimates, algorithmic progress, and behavioral factors. The analysis estimates that Mythos required approximately 5.1e26 FLOP for pre-training, a target that will decay over time due to algorithmic progress, with Chinese firms' ability to reach it determined by their compute budgets, willingness to concentrate resources, and post-training requirements. Crucially, the largest source of compute for Chinese firms remains US chips accessed through remote data centers in Southeast Asia, legal purchases, and smuggling, meaning US policy interventions could materially alter this timeline.
The model, which simulates two tracks—a top Chinese hyperscaler (like Alibaba, ByteDance, or Tencent) and a leading AI start-up (like DeepSeek, Kimi, or Z.ai)—found that the biggest uncertainty lies not in access to compute itself, but in whether Chinese firms will actually commit significant fractions of their compute budgets to a single frontier model training run, rather than allocating it to inference or other business services. The analysis identifies remote access to US chips in Southeast Asia as the highest-impact area for US policy intervention, followed by reducing the effectiveness of Chinese firms' distillation of US models. Other measures, such as blocking H200 sales or chip smuggling, have more modest effects in the short term but remain important for long-term strategic competition.
Key Data Points
Central Forecast: China will likely have a fully developed Mythos-like model around February 2027 (90% CI: October 2026 to September 2027).
Compute Estimate: Mythos pre-training required an estimated 5.1e26 FLOP, based on Anthropic using 500,000 Trainium2 chips at 20% MFU for three months.
Chinese Compute Stock: China has an estimated 1.8 million H100-equivalents within its borders (legal + smuggled) plus an additional 1 million H100e accessed via remote data centers in Southeast Asia.
Behavioral Gate: Hyperscalers are modeled to commit only 0.5–2% of their annual compute to a single pre-training run, while start-ups may commit 3–12%.
Key Uncertainties: Algorithmic progress (estimated at 2x–50x per year), the size of the Chinese hyperscaler's compute budget, Anthropic's compute for Mythos, and model FLOP utilization are the top four factors driving uncertainty in the forecast.
Policy Impact: Reducing remote access to US chips in Southeast Asia has the largest potential to delay China's timeline, followed by measures to limit distillation of US models. Blocking H200 sales or chip smuggling has more modest short-term effects.
Competitive Landscape: Chinese models like GLM 5.2 currently lag behind the US frontier by approximately seven months on the Epoch Capabilities Index, with the gap potentially growing due to US export controls.
Historical Context: Chinese firms have historically only committed single-digit percentages of their compute to large pre-training runs, with the majority directed towards inference, non-LLM business, or cloud rentals.
Distillation Factor: Distillation of US models is a key driver of China's catch-up algorithmic progress, with the analysis modeling it as contributing 10–40% of annual algorithmic gains.
Post-Training: An additional 0.5–3 months of post-training and reinforcement learning is required after pre-training to achieve Mythos
🤖 AI
ECB Warns Banks of AI-Enabled Cybersecurity Threats: The European Central Bank issued a letter to banks warning that emerging AI models can identify vulnerabilities and generate exploits at unprecedented speed. The ECB called on banks to accelerate vulnerability management, enhance AI-enabled defensive capabilities, and prepare for machine-speed threats that could outpace human response times. The letter emphasizes the need for financial institutions to invest in AI-powered security tools and develop incident response plans capable of countering autonomous attacks. The ECB also highlighted plans to launch a public consultation for a new incident notification framework for financial entities to enhance information sharing. Link: https://www.bankingsupervision.europa.eu/press/letterstobanks/shared/pdf/2026/ssm.2026_letter_on_AI_enabled_cybersecurity_threats.en.pdf
UK Publishes Thematic Review and Gap Analysis on AI Security: The UK government published a review of AI security research from the last five years, identifying 12 themes and 5 prevalent gaps in the current security landscape. Key themes include AI vulnerability discovery, model evaluation techniques, adversarial threats to machine learning, and secure development practices. The identified gaps include assurance methods for AI systems, third-party model provenance, agentic-AI security, and the need for standardized evaluation benchmarks. The review aims to inform policymakers, researchers, and industry on prioritizing AI security investments and research directions. Link: https://www.gov.uk/government/publications/thematic-review-and-gap-analysis-on-ai-security/thematic-review-and-gap-analysis-on-ai-security
UK Publishes Mapping of AI and Software Security Services Market: The UK's Department for Science, Innovation and Technology published a first-of-its-kind market mapping of AI and software security providers, identifying 111 AI security vendors and 1,141 software security providers globally. The report analyzes market trends, including the growth of AI-powered security tools and the increasing demand for automated vulnerability discovery. It provides a comprehensive overview of the vendor landscape, key capabilities, and emerging technologies to help organizations navigate the evolving security market and identify potential partners for their cyber defense needs. Link: https://www.gov.uk/government/publications/mapping-of-the-ai-and-software-security-services-market/mapping-of-the-ai-and-software-security-services-market
SpectrePaste: AI-Orchestrated Fileless Malware Delivery System: Walmart Global Tech researchers identified "SpectrePaste," a fileless delivery system where AI acted as the primary orchestrator and developer. The system uses runtime polymorphism to generate unique payloads. Link: https://medium.com/walmartglobaltech/spectrepaste-b20bc2f6ded8
SlowMist Reports 182 Blockchain Security Incidents in H1 2026: SlowMist's mid-year report recorded 182 security incidents in the first half of 2026, resulting in approximately $956 million in losses. DeFi protocols and cross-chain bridges remained the most frequently targeted risk areas. Link: https://slowmist.medium.com/slowmist-2026-mid-year-blockchain-security-and-aml-report-75e0862179ef
💻 Malware and Vulnerabilities
Hackers Exploit CitrixBleed 2 Vulnerability to Deploy DragonForce Ransomware: Huntress researchers identified a repeatable seven-step attack chain exploiting CitrixBleed 2 (CVE-2025-5777) to deploy DragonForce ransomware across multiple organizations. The attacker steals session tokens, escalates privileges, and establishes persistence with legitimate remote access tools. Link: https://www.huntress.com/blog/citrixbleed-2-dragonforce-ransomware
Microsoft Patches 'RoguePlanet' Zero-Day in Windows Defender: Microsoft issued an out-of-band patch for CVE-2026-50656, an elevation-of-privilege vulnerability in Windows Defender. The flaw, published by a researcher with a vendetta against Microsoft, could allow attackers to gain SYSTEM-level access. Link: https://www.darkreading.com/vulnerabilities-threats/microsoft-rogueplanet-zero-day-threat
Nine Vulnerabilities Discovered in ATM Security Software: A researcher discovered nine vulnerabilities in CryptWare CryptoPro Secure Disk, a full-disk encryption solution used by ATM manufacturers. The researcher and Diebold Nixdorf disagree on whether the bugs could allow attackers to steal cash. Link: https://www.darkreading.com/vulnerabilities-threats/atm-crypto-software-bugs-jackpot-bust
UK Government Publishes Thematic Review and Gap Analysis on AI Security: The UK government published a review of AI security research from the last five years, identifying 12 themes and 5 prevalent gaps, including assurance methods, third-party model provenance, and agentic-AI security. Link: https://www.gov.uk/government/publications/thematic-review-and-gap-analysis-on-ai-security/thematic-review-and-gap-analysis-on-ai-security
📈 Breaches and Incidents
Interpol Crackdown Nets 5,800 Arrests, $293 Million Seized: A global operation dubbed Operation First Light led to the arrest of more than 5,800 alleged cybercriminals and the seizure of $293 million across 97 countries. The anti-fraud crackdown identified over 142,000 victims of social-engineering scams, including business email compromise, romance scams, and investment schemes. Link: https://cyberscoop.com/interpol-cybercrime-crackdown-operation-first-light/
Solana Meme Coin Bonk Treasury Drained of $20 Million in Governance Attack: The treasury of the Solana-based meme coin Bonk was drained of approximately $20 million in a malicious governance attack. Link: https://decrypt.co/372862/solana-meme-coin-bonk-treasury-drained-20-million
Meta Faces $1.4 Trillion Penalty Demand in Youth Safety Trial: Four U.S. states are seeking $1.4 trillion in penalties from Meta, accusing the company of designing Facebook and Instagram to addict young users. The amount, close to Meta's market capitalization, is unsupported by evidence, the company said. Link: https://www.reuters.com/business/meta-says-us-states-are-seeking-14-trillion-penalties-august-youth-safety-trial-2026-07-07/
Canadian Spy Agency Conducted Cyberattacks on Fentanyl Brokers: Canada's Communications Security Establishment (CSE) conducted cyberattacks to disrupt online foreign criminals brokering the sale of precursor chemicals used to make fentanyl. The agency's budget will surpass $2 billion in 2026-27. Link: https://www.theglobeandmail.com/politics/article-canadas-electronic-spy-agency-conducted-cyberattacks-on-criminals/
US Army Websites Defaced in 404 Hijacking Campaign: Multiple U.S. Army subdomains were defaced with pro-Kurdish messages and insults to President Trump. The affected pages were hosted on a legacy third-party platform and have since been secured. Link: https://cyberscoop.com/us-army-websites-defaced-404-hijacking-kurdistan/
Prince Harry's Privacy Lawsuit Against Daily Mail Dismissed: A judge dismissed Prince Harry's privacy invasion lawsuit against the publisher of the Daily Mail, ruling he failed to prove the articles were unlawfully sourced. Link: https://apnews.com/article/prince-harry-lawsuit-daily-mail-charles-elton-2ada29f1fc84ade5d414c3b49ac47ac6?utm_source=copy&utm_medium=share
🚨 Threat Intel & Info Sharing
Senator Warner Unveils Draft Legislation for Secure AI Agents: U.S. Senator Mark Warner released a discussion draft of the AI AGENT Act, which would establish a federal framework for consumer AI agents with strong privacy, security, and market fairness protections. The bill would create an FTC registry of trusted, secure AI agents. Link: https://www.warner.senate.gov/newsroom/press-releases/warner-unveils-discussion-draft-of-legislation-to-create-innovative-market-for-secure-artificial-intelligence-agents/
UK Designates Four Global Cloud Providers as 'Critical Third Parties': The UK government has designated Microsoft, Google Cloud, Amazon Web Services, and Oracle as Critical Third Parties (CTPs) to strengthen the resilience of the financial system. The designation allows financial regulators to oversee the critical services they provide. Link: https://www.gov.uk/government/news/uk-financial-system-strengthened-with-new-safeguards-for-major-technology-providers
CISA Releases Forensic Report on Major May Credential Leak: CISA released a forensic report detailing its response to a May credential leak involving a contractor's exposure of privileged AWS GovCloud Keys on a public GitHub repository. The agency rotated all secrets and developed a plan to improve secrets management. Link: https://cyberscoop.com/cisa-credential-leak-forensic-report/
Japanese Teen Arrested for Cyberattack on Anime Streaming Service: A 15-year-old Japanese student was arrested for a cyberattack that unsubscribed over 46,000 accounts from the Bandai Channel streaming service. The student used a program created with ChatGPT to exploit a system vulnerability. Link: https://www.straitstimes.com/asia/east-asia/japanese-teen-arrested-for-cyberattack-that-unsubscribed-over-46000-anime-accounts
Russian Hackers Steal Government Logins: Hackers with suspected ties to Russian intelligence have stolen login credentials from UK government officials in a sophisticated phishing campaign. Link: https://www.telegraph.co.uk/news/2026/07/05/russian-hackers-steal-government-logins/
UK Publishes Mapping of AI and Software Security Services Market: The UK's Department for Science, Innovation and Technology published a first-of-its-kind market mapping of AI and software security providers, identifying 111 AI and 1,141 software security providers. Link: https://www.gov.uk/government/publications/mapping-of-the-ai-and-software-security-services-market/mapping-of-the-ai-and-software-security-services-market
China Likely to Have Its Own Mythos-Like Model by February 2027: An analysis predicts China will develop a Mythos-like vulnerability-finding AI model around February 2027, based on compute estimates and algorithmic progress. The forecast suggests a one-year lag behind Anthropic's model. Link: https://www.the-substrate.net/p/china-will-likely-have-its-own-mythos
⚖️ Laws, Policies and Regulations
UK Launches Cyber Resilience Pledge for Organizations: The UK government has introduced a Cyber Resilience Pledge, a voluntary commitment for organizations to make cyber a board responsibility, sign up to early warning services, and require Cyber Essentials across supply chains. Link: https://www.gov.uk/government/publications/cyber-resilience-pledge/cyber-resilience-pledge-declaration
ECB Warns Banks of AI-Enabled Cybersecurity Threats: The European Central Bank issued a letter to banks warning that emerging AI models can identify vulnerabilities and generate exploits at unprecedented speed. The ECB called on banks to accelerate vulnerability management and enhance AI-enabled defensive capabilities. Link: https://www.bankingsupervision.europa.eu/press/letterstobanks/shared/pdf/2026/ssm.2026_letter_on_AI_enabled_cybersecurity_threats.en.pdf
US States Seek $1.4 Trillion in Penalties from Meta: Four U.S. states are seeking $1.4 trillion in penalties from Meta, accusing the company of designing Facebook and Instagram to addict young users. The amount, which approaches Meta's entire market capitalization, is unsupported by evidence, the company said in a securities filing. The trial, set for August 2026, could have significant implications for social media regulation and the financial viability of major tech platforms if the states succeed in their claims. Link: https://www.reuters.com/business/meta-says-us-states-are-seeking-14-trillion-penalties-august-youth-safety-trial-2026-07-07/
Ireland Launches Public Consultation on National Cyber Security Strategy: Ireland's Department of Justice has opened a public consultation on its draft National Cyber Security Strategy, organized around three core pillars: Detect and Defend, Enhance National Resilience, and Strengthen the Cyber Eco-System. The strategy outlines Ireland's vision for cybersecurity through 2031, with a particular emphasis on protecting critical infrastructure, strengthening public-private partnerships, and addressing the growing threats from AI-enabled attacks and ransomware. The consultation is open to all stakeholders, including businesses, academics, and the public, with submissions due by the end of July 2026. Link: https://www.gov.ie/en/department-of-justice-home-affairs-and-migration/consultations/public-consultation-on-the-draft-national-cyber-security-strategy/
⚖️ The Privacy Post
EDPB Sharpens the Rules on AI Scraping, Anonymisation, and Blockchain
By Steven Switz
Highlights
The EDPB adopted new guidance on web scraping for generative AI, clarifying GDPR expectations for AI training.
New anonymisation guidance sets a clearer framework for determining when data is truly anonymous under the GDPR.
Final blockchain guidance reinforces privacy by design expectations for organisations using distributed ledger technologies.
The European Data Protection Board (EDPB) has adopted a significant package of guidance that will shape how organisations approach AI development and privacy compliance. The new web scraping guidelines explain how the GDPR applies when personal data is collected for generative AI, with particular attention to lawful basis, transparency, purpose limitation, data minimisation, and the handling of special category data. The guidance also recommends practical safeguards, including sourcing data from reliable websites, validating scraped data, and documenting collection practices to support accountability.
Alongside the AI guidance, the EDPB adopted new guidelines on anonymisation that clarify when data can genuinely fall outside the scope of the GDPR. The guidance introduces a practical framework focused on preventing record isolation, linkage, and inference, while recognising that whether data is anonymous depends on the context and the means reasonably available to identify individuals. The Board also finalised its blockchain guidelines following public consultation, providing updated expectations for GDPR compliant blockchain implementations. Together, these documents provide some of the clearest regulatory direction to date on AI training, anonymisation claims, and privacy by design, making them essential reading for privacy, legal, and AI governance teams.
Sources (APA)
European Data Protection Board. (2026, July 8). EDPB sheds light on anonymisation and web scraping for generative AI and adopts final version of guidelines on blockchain. https://www.edpb.europa.eu/news/edpb-sheds-light-on-anonymisation-and-web-scraping-for-generative-ai-and-adopts-final-version_en
European Data Protection Board. (2026). Guidelines on anonymisation. https://www.edpb.europa.eu/public-consultations/guidelines-on-anonymisation_en
📊 Trends, Reports, Analysis
ENISA Publishes Recommendations for Cybersecurity in the Frontier AI Era: ENISA released a set of initial recommendations for national competent authorities and EU policymakers to develop operational capabilities to face machine-speed threats.

📅 Upcoming Events
Security Operations for the Age of AI
Cybersecurity leaders face a new reality: threat actors are moving faster, attack volumes continue to increase, and traditional Security Operations Centres (SOCs) are struggling to keep pace without significantly increasing cost and complexity. At the same time, advances in AI are creating an opportunity to rethink how security operations are designed, managed, and scaled. Organisations that successfully harness AI within their security function can improve resilience, accelerate response times, and unlock greater value from existing security investments.
Join fellow CISOs, security executives, and technology leaders for an exclusive dinner exploring how organisations can evolve from conventional SOC models to AI-enabled and agentic security operations.

Registration link: https://thecybersecurity.club/event/security-operations-for-the-age-of-ai/
If you would like to sponsor any of our future in person or virtual events then please email us on [email protected]
We hope you enjoyed our email briefing! ☕🥮If you want to sponsor our next edition or advertise on our site, drop us an email [email protected].
Thank you for being a part of our newsletter community and you can be part of the community by joining our LinkedIn Group.



