Whitepapers

Proof Over Probability, as briefs you can circulate.

Each issue of our newsletter, condensed into a whitepaper: what AI vulnerability discovery is doing to product security, with the numbers and incidents that prove it. New issues publish regularly.

Explainer · Threat-Led AI Pentesting

How the ELTON AI pipeline tests a medical device

Why device testing is not web-app autonomous pentesting: the twin, EMB3D threat analysis, per-threat test-case generation, and a toolchain the AI writes and a human reviews. Compared to XBOW, Big Sleep and the research...

Technical whitepaper · PDF download
Explainer · Digital Twin

Why ELTON uses a digital twin

Blind pentesting stopped being compliant. The twin is the blueprint that makes test cases, exploitability calls, and CVSSv3/v4 ratings defensible in FDA review, and depth in means defensibility out...

Technical whitepaper · PDF download
Explainer · ELTON TestLink™

How TestLink™ works, and why it never touches your network

The instrument on your bench reaches our lab over its own private 5G uplink: closed loop, encrypted in transit and at rest, no enterprise network, no IT ticket. The three delivery models, explained...

Technical whitepaper · PDF download
Issue 1 · AI vuln discovery in medtech

Myth about Mythos

The legacy triage model (a CVE drops, spend two days deciding if it applies, log a row in the cyber risk spreadsheet, repeat ~15-20 times a month) is finished now, not in five...

Newsletter brief · PDF download
Issue 2 · AI vuln discovery harness architecture

Chatbot or Vulnerability Discovery Tool?

The model is not the tool; the harness is the tool. The model provides reasoning and the harness turns reasoning into work against a real target, deciding which tools the model...

Newsletter brief · PDF download
Issue 3 · Agentic AI cost and quality variance

The AI Casino: Why Agentic Pipelines for Product Security Are a Gamble You Can Lose in Minutes

Running agentic AI pipelines on frontier models behaves like a casino: a paid B2B service where quality is neither guaranteed nor measurable, the operator can change the game...

2026-05-30 · PDF download
Issue 4 · Export control and model dependency

The day the frontier went dark

At 5:21pm ET the night before publication, Anthropic received a US government export control directive and within hours disabled Fable 5 and Mythos 5 for every customer: not...

2026-06-13 · PDF download
Issue 5 · FDA AI-enabled device cyber testing

Your AI-enabled medical device is about to get a deficiency for cyber testing

In 2025 FDA cleared 295 AI/ML-enabled devices, roughly 97% of them through 510(k), and most almost certainly did not perform the cybersecurity testing FDA's January 7, 2025...

2026-06-26 · PDF download
Issue 6 · AI export ban and dual-use defense

Technical breakdown of the export ban on cybersecurity testing

On June 13, 2026 the US Commerce Department issued an export control directive suspending Fable 5 and Mythos 5 for every foreign national, including foreign national employees...

Newsletter brief · PDF download
Issue 7 · AI model choice as supply-chain risk

Cybersecurity Testing AI Model Arms Race Heats Up

The Wall Street Journal covered the Fable 5 and Mythos story from the model arms-race angle, framing the Commerce Department's move as partly driven by concern that a...

Newsletter brief · PDF download
Issue 8 · AI guardrails as a blocklist

Guarding the guardrails: AI reached for a 2005 idea

On July 1, 2026 Anthropic redeployed Fable 5 globally, with Mythos 5 restored to its Project Glasswing partners, after Commerce lifted the export ban; Fable had launched June 9...

Newsletter brief · PDF download
Issue 9 · FDA human factors vs cyber gap

FDA's cyber guidance keeps pointing at human factors. Human factors never points back.

FDA finalized 'Content of Human Factors Information in Medical Device Marketing Submissions' on May 29, 2026, replacing the December 2022 draft, with a town hall set for July...

Newsletter brief · PDF download
Follow along

The newsletter keeps publishing.

New issues are condensed into whitepapers here as they ship. For the full essays as they land, follow ELTON Cyber on LinkedIn.

Get started

Reading is good. Evidence is better.

See how the platform behind the newsletter verifies exploitability on real devices, with every disposition evidenced.

Proof Over Probability

Proof Over Probability, weekly.

One issue a week on AI, exploitability, and FDA cybersecurity review. No spam, unsubscribe anytime.

Questions

Common questions about the ELTON whitepapers.

What are the ELTON whitepapers?

Each issue of the ELTON newsletter, condensed into a brief you can circulate. They cover what AI vulnerability discovery is doing to product security, with the numbers and incidents that prove it, and each one downloads as a PDF. New issues are added here as they publish.

How often does ELTON publish a new issue?

One issue a month, on AI, exploitability and FDA cybersecurity review. Each issue is condensed into a whitepaper on this page as it ships, and the full essays land first on the ELTON Cyber page on LinkedIn. The newsletter is free and you can unsubscribe at any time.

Do AI-enabled medical devices need cybersecurity testing?

Issue 5 argues most are not getting it. In 2025 the FDA cleared 295 AI/ML-enabled devices, roughly 97% of them through 510(k), and most almost certainly did not perform the cybersecurity testing the FDA's January 7, 2025 guidance points to. The brief sets out why that turns into a deficiency at review.

Is an AI model a vulnerability discovery tool?

Issue 2 makes the case that the model is not the tool, the harness is the tool. The model provides reasoning. The harness turns that reasoning into work against a real target and decides which tools the model gets. That is the line between a chatbot and a vulnerability discovery tool.

Why is the AI model behind a testing pipeline a supply chain risk?

Issue 3 argues that running agentic pipelines on frontier models behaves like a casino, a paid service where quality is neither guaranteed nor measurable and the operator can change the game. Issues 4, 6 and 8 track the June 13, 2026 US export control directive that suspended two frontier models, and the July 1, 2026 redeployment.

Exploitability management for medical devices. FDA §524B methodologyExploitability proven at runtime95% faster than legacy testing Book a Demo
Platform
OverviewAvoid FDA DeficienciesAvoid Consulting FeesDigital Twin TraceabilityAI PentestingExploitability VerificationVulnerability ChainingRemediation OptimizationRemote TestLink™Incident ResponseAutomated VEX & MetricsCVSSv4 Migration
Solutions
Postmarket SurveillanceIncident ResponseSecurity EngineeringRegulatory AffairsFDA §524BEU MDR/CRAEU REDNIS2IMDRF N60 / N73Japan MHLW
Why ELTON
Subscription TestingAI-NativeFDA ComplianceVerified ExploitabilityELTON vs. Legacy TestingThreat-Led AI PentestingMDDT MethodologyCredentialsDevice ModalitiesPricing
Resources
FDA Deficiency ListFDA Testing RequirementsFDA Cyber SOPs & TemplatesRemediation LibraryRegulatory GuidesWebinarsAI NewsletterThe End of Legacy TestingThe AI Vulnerability ExplosionSecurity AdvisoriesWhitepapersIntelligence & Blog
Company
AboutLeadershipCareersPartnershipsContact Meet ELTON