Each issue of our newsletter, condensed into a whitepaper: what AI vulnerability discovery is doing to product security, with the numbers and incidents that prove it. New issues publish regularly.
Why device testing is not web-app autonomous pentesting: the twin, EMB3D threat analysis, per-threat test-case generation, and a toolchain the AI writes and a human reviews. Compared to XBOW, Big Sleep and the research...
Blind pentesting stopped being compliant. The twin is the blueprint that makes test cases, exploitability calls, and CVSSv3/v4 ratings defensible in FDA review, and depth in means defensibility out...
The instrument on your bench reaches our lab over its own private 5G uplink: closed loop, encrypted in transit and at rest, no enterprise network, no IT ticket. The three delivery models, explained...
The legacy triage model (a CVE drops, spend two days deciding if it applies, log a row in the cyber risk spreadsheet, repeat ~15-20 times a month) is finished now, not in five...
The model is not the tool; the harness is the tool. The model provides reasoning and the harness turns reasoning into work against a real target, deciding which tools the model...
Running agentic AI pipelines on frontier models behaves like a casino: a paid B2B service where quality is neither guaranteed nor measurable, the operator can change the game...
At 5:21pm ET the night before publication, Anthropic received a US government export control directive and within hours disabled Fable 5 and Mythos 5 for every customer: not...
In 2025 FDA cleared 295 AI/ML-enabled devices, roughly 97% of them through 510(k), and most almost certainly did not perform the cybersecurity testing FDA's January 7, 2025...
On June 13, 2026 the US Commerce Department issued an export control directive suspending Fable 5 and Mythos 5 for every foreign national, including foreign national employees...
The Wall Street Journal covered the Fable 5 and Mythos story from the model arms-race angle, framing the Commerce Department's move as partly driven by concern that a...
On July 1, 2026 Anthropic redeployed Fable 5 globally, with Mythos 5 restored to its Project Glasswing partners, after Commerce lifted the export ban; Fable had launched June 9...
FDA finalized 'Content of Human Factors Information in Medical Device Marketing Submissions' on May 29, 2026, replacing the December 2022 draft, with a town hall set for July...
New issues are condensed into whitepapers here as they ship. For the full essays as they land, follow ELTON Cyber on LinkedIn.
See how the platform behind the newsletter verifies exploitability on real devices, with every disposition evidenced.
One issue a week on AI, exploitability, and FDA cybersecurity review. No spam, unsubscribe anytime.
Each issue of the ELTON newsletter, condensed into a brief you can circulate. They cover what AI vulnerability discovery is doing to product security, with the numbers and incidents that prove it, and each one downloads as a PDF. New issues are added here as they publish.
One issue a month, on AI, exploitability and FDA cybersecurity review. Each issue is condensed into a whitepaper on this page as it ships, and the full essays land first on the ELTON Cyber page on LinkedIn. The newsletter is free and you can unsubscribe at any time.
Issue 5 argues most are not getting it. In 2025 the FDA cleared 295 AI/ML-enabled devices, roughly 97% of them through 510(k), and most almost certainly did not perform the cybersecurity testing the FDA's January 7, 2025 guidance points to. The brief sets out why that turns into a deficiency at review.
Issue 2 makes the case that the model is not the tool, the harness is the tool. The model provides reasoning. The harness turns that reasoning into work against a real target and decides which tools the model gets. That is the line between a chatbot and a vulnerability discovery tool.
Issue 3 argues that running agentic pipelines on frontier models behaves like a casino, a paid service where quality is neither guaranteed nor measurable and the operator can change the game. Issues 4, 6 and 8 track the June 13, 2026 US export control directive that suspended two frontier models, and the July 1, 2026 redeployment.