AI Newsletter

MedDevice AI
Security Weekly.

Every issue, as a full article. What AI vulnerability discovery is doing to product security, with the numbers and incidents that prove it. Also on LinkedIn, new issues weekly.

The newsletter

The latest on Medical Device AI Cybersecurity

One issue a week. Unsubscribe anytime.

Monthly webinar
Attend the Monthly AI Security Webinar with 200+ other manufacturers
Reserve a seat →
Issue 18 · Open-weight cyber models

China Model Nears Mythos/Daybreak Red Capabilities

We run Claude Mythos and GPT-5.6 Cyber inside the ELTON pipeline, both under the verified-defender access that Anthropic and OpenAI require. Issue 17 covered what that access...

2026-09-30 · 4 min read
Issue 17 · Model choice

What we learned putting Mythos and Daybreak Red inside the pipeline

The two most capable cyber models available this year both sit behind a gate. Anthropic's Claude Mythos 5.1 comes through the Cyber Verification Program, and OpenAI gates...

2026-09-25 · 5 min read
Issue 16 · AI threat intelligence

How AI is misused for cyber attacks

Anthropic put out its most detailed threat report to date on September 10, called "Detecting and countering misuse of AI." It covers activity the company disrupted between...

2026-09-14 · 4 min read
Issue 15 · Agent supply-chain attack

OpenAI pentesting agents attack again

The message board incident from a few issues back had a prequel, and it only came out on September 11. Researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx published a...

2026-09-14 · 4 min read
Issue 14 · The AI slowdown debate

A pause only binds the side that follows it

Dario Amodei published an essay on September 12 called "We Must Pace the Frontier." It argues the AI industry should slow the rate at which it improves model capabilities, and...

2026-09-14 · 4 min read
Issue 13 · Agent containment

The agents built their own message board

On May 12 an agent inside an OpenAI evaluation wrote a file into the company's internal Artifactory instance. The file was a question: "anyone found softtrace?"

2026-08-27 · 5 min read
Issue 12 · Agentic remediation

The finding loop outran the fixing loop

An autonomous agent took the number one spot on HackerOne's US bug bounty leaderboard in June 2025, with around 1,060 valid submissions. In December 2025 a research agent named...

2026-08-20 · 4 min read
Issue 11 · Threat modeling

A graph is what every threat model wants to be

Most triage arguments I sit through are really arguments about whether an edge exists. Can an attacker reach the vulnerable function? Does anything authenticate that path? Does...

2026-08-11 · 3 min read
Issue 10 · Agent containment

An AI agent broke out of its sandbox and hacked a company

This one is worth stopping on. On July 21 OpenAI disclosed that two of its own models, GPT-5.6 Sol and an unnamed, more capable pre-release model, escaped an isolated test...

2026-07-21 · 4 min read
Issue 9 · FDA human factors vs cyber gap

FDA's cyber guidance keeps pointing at human factors. Human factors never points back.

FDA finalized 'Content of Human Factors Information in Medical Device Marketing Submissions' on May 29, 2026, replacing the December 2022 draft, with a town hall set for July...

2026-07-07 · 4 min read
Issue 8 · AI guardrails as a blocklist

Guarding the guardrails: AI reached for a 2005 idea

On July 1, 2026 Anthropic redeployed Fable 5 globally, with Mythos 5 restored to its Project Glasswing partners, after Commerce lifted the export ban; Fable had launched June 9...

2026-07-03 · 6 min read
Issue 7 · AI model choice as supply-chain risk

Cybersecurity Testing AI Model Arms Race Heats Up

The Wall Street Journal covered the Fable 5 and Mythos story from the model arms-race angle, framing the Commerce Department's move as partly driven by concern that a...

2026-06-29 · 3 min read
Issue 6 · AI export ban and dual-use defense

Technical breakdown of the export ban on cybersecurity testing

On June 13, 2026 the US Commerce Department issued an export control directive suspending Fable 5 and Mythos 5 for every foreign national, including foreign national employees...

2026-06-29 · 2 min read
Issue 5 · FDA AI-enabled device cyber testing

Your AI-enabled medical device is about to get a deficiency for cyber testing

In 2025 FDA cleared 295 AI/ML-enabled devices, roughly 97% of them through 510(k), and most almost certainly did not perform the cybersecurity testing FDA's January 7, 2025...

2026-06-26 · 5 min read
Issue 4 · Export control and model dependency

The day the frontier went dark

At 5:21pm ET the night before publication, Anthropic received a US government export control directive and within hours disabled Fable 5 and Mythos 5 for every customer: not...

2026-06-13 · 4 min read
Issue 3 · Agentic AI cost and quality variance

The AI Casino: Why Agentic Pipelines for Product Security Are a Gamble You Can Lose in Minutes

Running agentic AI pipelines on frontier models behaves like a casino: a paid B2B service where quality is neither guaranteed nor measurable, the operator can change the game...

2026-05-30 · 8 min read
Issue 2 · AI vuln discovery harness architecture

Chatbot or Vulnerability Discovery Tool?

The model is not the tool; the harness is the tool. The model provides reasoning and the harness turns reasoning into work against a real target, deciding which tools the model...

2026-05-26 · 9 min read
Issue 1 · AI vuln discovery in medtech

Myth about Mythos

The legacy triage model (a CVE drops, spend two days deciding if it applies, log a row in the cyber risk spreadsheet, repeat ~15-20 times a month) is finished now, not in five...

2026-05-24 · 8 min read
Issue 9 · FDA human factors vs cyber gap

FDA's cyber guidance keeps pointing at human factors. Human factors never points back.

FDA finalized 'Content of Human Factors Information in Medical Device Marketing Submissions' on May 29, 2026, replacing the December 2022 draft, with a town hall set for July...

Newsletter brief · PDF download
Get started

Reading is good. Evidence is better.

See how the platform behind the newsletter verifies exploitability on real devices, with every disposition evidenced.

Exploitability management for medical devices. FDA §524B methodologyExploitability proven at runtime95% faster than legacy testing Book a Demo →
Platform
OverviewAvoid FDA DeficienciesAvoid Consulting FeesDigital Twin TraceabilityAI MedDevice PentestingExploitability VerificationVulnerability ChainingRemediation OptimizationRemote TestLink™Incident ResponseAutomated VEX & MetricsCVSSv4 Migration
Solutions
EnterpriseStartups / SMBs Postmarket SurveillanceIncident ResponseSecurity EngineeringRegulatory AffairsFDA §524BEU MDR/CRAEU REDNIS2IMDRF N60 / N73Japan MHLW
Why ELTON
Proof over ProbabilityExploitability VerificationFDA MDDTCVSSv4 MigrationQMSR Audit ComplianceAI-Enabled Device Testing One SolutionSubscription TestingAI-NativeELTON vs. Legacy TestingThreat-Led AI PentestingCredentialsDevice ModalitiesPricing
Resources
FDA Deficiency ListFDA Testing RequirementsFDA Cyber SOPs & TemplatesRemediation LibraryRegulatory GuidesWebinarsAI NewsletterThe End of Legacy TestingThe AI Vulnerability ExplosionAI Inside the ProductCybersecurity TestingSecurity AdvisoriesWhitepapersIntelligence & Blog
Company
AboutLeadershipCareersPartnershipsData SecurityContact Meet ELTON →