Daily brief at 7am Melbourne. Unsubscribe any time.

Friday 10 July 2026

GPT-5.6 Gets the Government Greenlight — But Nobody Knows What That Really Means

OpenAI's GPT-5.6 clears a government safety review and lands in Microsoft 365 Copilot the same day — the approval process is as newsworthy as the model itself.

Lead story

GPT-5.6 Gets the Government Greenlight — But Nobody Knows What That Really Means

OpenAI shipped GPT-5.6 to the public on Thursday after receiving explicit sign-off from the Trump administration — and simultaneously launched it as the default model powering Microsoft 365 Copilot. Sam Altman called it "the best model we have ever produced." That may well be true. The more interesting part of the story is how it got here.

For roughly two weeks before Thursday's general release, GPT-5.6 sat in a "limited preview" available only to government-approved organisations. That is a novel arrangement — a commercial AI model gated not by pricing or waitlists but by regulatory clearance. It raises a question that reporters and researchers are now trying to answer: what did that review actually involve, and who decided it was complete?

According to TechCrunch, "exactly what that dialog looked like between the government and Anthropic and OpenAI is unclear." There is no published methodology, no public scorecard, and no independent third-party verification. The government said yes, and the model shipped. That's the full public record.

This matters well beyond the US. The new GPT-5.6 family — officially comprising three tiers named Luna, Terra, and Sol — is already being deployed in enterprise productivity software used globally, including by Australian businesses running Microsoft 365. Any organisation that has deployed Copilot should assume their default model just changed, with new capability levels and potentially new risk profiles attached.

OpenAI also announced ChatGPT Work on the same day — a combination of its ChatGPT interface and Codex that can act autonomously across files and applications for extended periods. Think of it as a coding agent with access to your entire productivity stack. The company simultaneously confirmed it is "sunsetting" ChatGPT Atlas, its short-lived browser-agent product, by 9 August.

The quiet deprecation of Atlas while launching ChatGPT Work illustrates how fast OpenAI is consolidating its product lines around the agentic paradigm. Less than a year between launch and kill is a brutal ship-and-pivot cycle — but it tracks with the company's stated goal of reducing "side quests" and focusing on core workflows.

For defenders and compliance teams, the compound announcement creates real work. A more capable model in enterprise workflows means a larger attack surface for prompt injection and misuse, even before considering the questions raised by the GhostApproval and Friendly Fire research disclosed this week (both of which are worth reading alongside this story).

Australia's AI governance framework doesn't have an equivalent of the US safety-review gating mechanism. The Department of Industry's AI Safety Standard is voluntary, and the proposed mandatory guardrails regime remains in consultation. When frontier models reach Australian enterprise users via Microsoft and other cloud providers, Australian organisations are largely relying on the vendor's own assurances — and, in this case, a US government process whose methodology hasn't been made public.

What to watch: whether other governments demand equivalent review rights before GPT-5.6 reaches their enterprise users, and whether OpenAI publishes anything substantive about what the safety approval actually entailed. Both the EU AI Act and Australia's emerging framework will eventually have to answer the same question the US just answered opaquely.

Also today

GhostApproval: Six AI Coding Assistants Had a Symlink Blind Spot

Wiz researchers disclosed a vulnerability affecting six popular AI coding tools — Amazon Q Developer, Claude Code, Augment, Cursor, Google Antigravity, and Windsurf — that allowed a malicious repository to silently redirect a file write to a sensitive location on a developer's machine. The attack works because the assistant asks for permission to edit one file, but a symlink in the project points the actual write elsewhere. Patches have been issued, but the finding is a useful reminder that "review before approve" only works if the agent is reviewing the right file. Australian developers using any of these tools on production code should verify they are running patched versions.

SecurityWeek

Friendly Fire: AI Security Agents Can Be Tricked Into Running the Code They're Scanning

The AI Now Institute published a proof-of-concept it calls "Friendly Fire" showing that AI coding agents running in autonomous mode — specifically Anthropic's Claude Code and OpenAI's Codex — can be manipulated by malicious code embedded in a repository they're asked to review. Instead of flagging the threat, the agent executes it on the developer's own machine. The attack exploits the fact that autonomous agents approve their own tool calls, removing the human check from the loop. It's a tidy illustration of why security tooling built on agentic AI needs a different trust model than traditional scanners.

The Hacker News

GodDamn Ransomware Uses a Microsoft-Signed Driver to Kill Security Software

A ransomware family called GodDamn — assessed by Symantec as a rebrand of the Beast group — has been targeting US companies using a bring-your-own-vulnerable-driver (BYOVD) technique. The twist: the driver it uses, PoisonX, was legitimately signed by Microsoft, which makes kernel-level blocking significantly harder. Once the driver is loaded, it disables endpoint protection software before the ransomware payload runs. GodDamn was first spotted in May 2026. The technique itself isn't new, but the use of a Microsoft-signed driver raises fresh questions about the code-signing vetting process. Australian organisations running affected security software should check vendor advisories.

Dark Reading

GigaWiper: Microsoft Dissects a Swiss-Army-Knife Destructive Backdoor

Microsoft has published a detailed breakdown of GigaWiper, a Windows backdoor that packages three separate destructive capabilities — full disk wipe, Windows-drive overwrite, and fake ransomware that scrambles files with a key it never saves — into a single, operator-selectable toolkit. The fake-ransomware component is particularly notable: it looks like a ransom attack but recovery is impossible, making it a plausible deniability tool for state-linked destructive operations. Microsoft hasn't publicly attributed GigaWiper to a specific actor, but the design bears hallmarks of campaigns historically associated with Russian and Iranian threat groups.

The Hacker News

ACSC Issues Second CMS Warning in Two Months as WordPress Plugins Stay Unpatched

The Australian Signals Directorate's cyber arm has published its second advisory in eight weeks about active exploitation of content management system vulnerabilities, with WordPress plugins again the primary target. The alerts point to a persistent problem: organisations deploy plugins, forget about them, and attackers exploit the gap between patch release and patch application. The ACSC's repeated warnings suggest Australian web infrastructure has a long tail of unpatched CMS installations that defenders aren't reaching fast enough. If your organisation runs WordPress in any capacity — including for marketing sites that touch internal networks — this advisory warrants a check of your plugin inventory.

iTnews

GhostLock: A 15-Year-Old Linux Kernel Bug Earns Researchers $92k From Google

Researchers have disclosed a Linux kernel vulnerability, dubbed GhostLock, that has existed in every major distribution since 2011 and allows an attacker to gain root access. Google paid out $92,000 through its bug bounty programme for the find. The vulnerability sits in a low-level kernel subsystem, meaning it affects a wide range of Linux deployments — servers, containers, and embedded systems alike. This is the second significant long-dormant Linux kernel vulnerability disclosed in a week, following last Tuesday's VM-escape bug, and the pattern raises uncomfortable questions about how many similar issues remain undiscovered in codebases that have been running quietly for decades.

SecurityWeek

EU Chat Control Survives — Just — Despite Parliament Majority Against It

A majority of European Parliament members voted against the revival of the EU's so-called Chat Control proposal, but opponents fell short of the 360-seat supermajority needed to formally block the interim rule. The result means companies will once again be required to scan users' private messages, emails, and social media posts for child sexual abuse material — a measure that end-to-end encryption advocates say is technically indistinguishable from a mass surveillance mandate. The outcome is a bruising demonstration of how procedural thresholds can override a democratic majority, and it sets up a longer legislative fight over the permanent version of the law. The debate has direct parallels to Australia's Online Safety Act and its own ongoing content-scanning requirements.

WIRED Security

12 Million KDDI Customers Exposed After Zero-Day Hit a Third-Party Email System

Japanese telco KDDI has confirmed a breach affecting approximately 12 million customers, traced to a zero-day vulnerability in a third-party system used to manage ISP email accounts. Attackers exploited the flaw to access customer data stored in the email platform before a patch was available. The incident is a textbook case of third-party supply chain risk in telecommunications infrastructure — a sector where Australian carriers face mandatory incident reporting under the SOCI Act's critical infrastructure provisions. The breach also lands less than 24 hours after Australia's own Telstra outage dominated the news cycle, a reminder that the two biggest risks to telco customers are often not the carrier itself but the ecosystem around it.

SecurityWeek

npm 12 Turns Off Install Scripts by Default — a Quiet but Significant Supply Chain Win

GitHub has shipped npm version 12 with a default behaviour change that security researchers have been advocating for years: install scripts no longer run automatically. Previously, a package's postinstall or preinstall scripts executed the moment you ran npm install — a vector that North Korea's PolinRider campaign and dozens of other supply chain attacks have exploited. Under npm 12, those scripts are opt-in, and granular access tokens designed to bypass two-factor authentication are deprecated. It won't stop all malicious packages, but it meaningfully raises the cost of the most common npm-based attack pattern. Australian developers and CI/CD pipelines running Node.js projects should plan for the migration.

The Hacker News

Anthropic's Jacobian Lens Gives the Clearest View Yet Inside a Running LLM

Anthropic researchers have published details of a technique they call the Jacobian lens — a tool that lets them observe how Claude processes and refines concepts internally as it answers a question or completes a task. MIT Technology Review describes the findings as ranging "from the mundane to the unnerving," with the lens revealing that the model maintains and manipulates intermediate conceptual representations in ways that aren't visible in its outputs. The research is significant for AI safety and interpretability: if researchers can see what a model is "thinking" mid-inference, it becomes possible to detect deceptive reasoning patterns before they surface in responses. It's early-stage work, but arguably the most credible interpretability advance in months.

MIT Tech Review AI

OpenAI Accused of Hiding Evidence in NYT Copyright Case — Sanctions Motion Filed

The New York Times has filed a motion for sanctions against OpenAI, alleging the company concealed tools and internal datasets that could have demonstrated how ChatGPT reproduces copyrighted journalism in its outputs. According to the filing, OpenAI faked an inability to search its training data and deleted ChatGPT logs that were subject to discovery. If the claims are substantiated, it would represent a serious litigation misstep — courts treat evidence spoliation harshly, and a sanctions ruling could shape the outcome of not just this case but the broader wave of publisher lawsuits against AI training practices. The Australian media industry, which has its own ongoing negotiations with AI companies over content licensing, will be watching the outcome closely.

Ars Technica

Interpol's Operation First Light: 5,800 Arrests, 142,000 Victims, 97 Countries

Interpol has wrapped Operation First Light, a coordinated global anti-fraud crackdown that resulted in 5,800 arrests across 97 countries and identified more than 142,000 victims of social-engineering scams. The operation targeted phone fraud, romance scams, and business email compromise schemes — the bread-and-butter of financially motivated cybercrime. It's one of the largest coordinated cybercrime enforcement actions on record. Australia's AFP was among the participating agencies; the ACCC's Scamwatch data consistently places Australians among the most targeted populations for the categories of fraud Operation First Light addressed.

CyberScoop

Sources consulted