Backcover | EYES |

Cybersecurity Eye
- The U.S. government on Wednesday warned of an "active threat" targeting critical infrastructure organizations in the country using artificial intelligence (AI)-generated exploit scripts. The activity is targeting Siemens S7 SeriesProgrammable Logic Controllers (PLCs) to conduct reconnaissance and capability development using AI-generated scripts disguised as legitimate monitoring tools. That
- Adversa AI has disclosed an attack technique that it says can cause xAI's Grok chatbot to send a user's name, approximate location, subscription tier, and the prompts from the ongoing conversation to an attacker-controlled server after the user asks it to summarize an ordinary web page. The AI security company, which has codenamed the technique "Cryptographic Context Injection," said the
- Cybersecurity researchers have disclosed a critical security flaw in isolated-vm, a popular open-source sandbox with more than 2,900 stars and 190 forks on GitHub, that could allow attackers to escape the confines of the isolated environment. The vulnerability ("GHSA-864f-rcv7-6rh4"), which has yet to be assigned a CVE identifier, impacts all versions of the library before and including 7.0.0.
- Citrix has released updates to address two security flaws impacting NetScaler ADC and NetScaler Gateway deployments, including a critical-severity authentication bypass vulnerability. According to the cloud computing and virtualization technology company, the issues affect customer-managed NetScaler ADC and NetScaler Gateway, including certain FIPS and NDcPP builds, as well as SecurAccess
- A now-patched security flaw impacting Zimbra Collaboration (ZCS) has come under active exploitation in the wild, according to the Polish Computer Emergency Response Team (CERT Polska). The vulnerability in question is CVE-2026-73570 (CVSS score: 8.9), which refers to a case of command injection that can lead to remote code execution. "A remote code execution vulnerability exists in Zimbra
- U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds an MLflow vulnerability to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Progress LoadMaster vulnerability, tracked as CVE-2026-64849 (CVSS score of 9.3), to its Known Exploited Vulnerabilities (KEV) catalog. CVE-2026-64849 is a critical server-side request forgery (SSRF) vulnerability in MLflow, a […]
- The US charged 17 Iranians over a years-long hacking campaign that stole 31TB from universities, companies and government agencies worldwide. Eight years after the original indictment first went public, US prosecutors just added eight more names to the list. The Justice Department unsealed a superseding indictment this week charging 17 members of the Mabna Institute, […]
- StopAndProtect turned nearly 2,000 hacked WordPress sites into a criminal network for malware delivery, data theft, surveillance and ransomware. Check Point Research uncovered a cybercrime operation, dubbed StopAndProtect, that has turned thousands of hacked WordPress websites into a shared platform for malware delivery, data theft, surveillance and ransomware. The operation is a good reminder that […]
- An exposed operator directory reveals how one actor compromised 14,000+ Dahua cameras across Ukraine and Russia, no password needed for most. A researcher discovered an exposed directory containing the tools of an attacker who compromised more than 14,000 Dahua cameras between June 17 and July 22, 2026, mainly in Ukraine and Russia. Hunt.io reconstructed the […]
- Microsoft tracked over 30 MacSync Stealer domains by focusing on behavioral patterns, revealing a campaign targeting passwords, keys, wallets and other data. Domain blocking is a losing game when the thing you’re blocking can register a new domain faster than you can add it to a list. That’s the exact problem Microsoft Defender Experts ran […]
- Over 50,000 exposed Stripe API keys show how leaked secrets can enable fraud, data access and account abuse within hours. Ransomnews researchers have documented a large-scale leak of Stripe merchant API keys found exposed in public code repositories, GitHub Actions logs, and misconfigured web servers, with over 50,000 unique keys identified in total. The research […]
- U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft IKE flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-33824 is a Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution […]
A number with no recorded reason may end up deciding for a patient
Article 005 · 3 August 2026
Transparency in artificial intelligence has become a question of provenance. Provenance tells you where a piece of content came from; it does not tell you why what it asserts was decided.
▶Also published as a policy contribution to the European Commission — click to expand
A version of this argument was submitted to the Apply AI Alliance of the European Commission and published on its Community Exchange Platform on 3 August 2026, under the title Provenance is not traceability: a gap in AI transparency for science and health.
That version is not a reprint. It is addressed to a policy readership and framed against the Commission’s own instruments: it opens from the Apply AI Strategy, which names healthcare and pharmaceuticals among its priority sectors, and from the AI in Science Strategy, and it closes with an explicit recommendation — that where AI-assisted selection informs research funding, experimental design or clinical investigation, transparency requirements should cover the reason attached to a decision and not only the origin of the content that carries it. The present article states the case; that one states what should follow from it.
Read it on the European Commission’s Futurium platform · archived copy
In June 2026, a team at the University of Chicago, with Honglin Bao and James A. Evans as corresponding authors, began with 121,640 preprints and sent their authors — where an email address could be reached — hypotheses that twenty-six artificial intelligence systems (large language models) had generated from those authors' own papers. Almost nine in ten of those papers came from biology and medicine. The figure is not neutral: medicine proved the most receptive field to hypotheses generated by these systems — 8.05 per cent above the social sciences — the field whose researchers showed the highest proportion of prior publications involving AI and, alongside biology, the one that showed a stronger preference than the social sciences for safe directions (Bao et al., 2026, arXiv:2606.08251v2). This exercise in generating and selecting hypotheses was built primarily on the life sciences; one fifth of its corpus was medicine, the field whose conclusions can end up reaching a sick person.
It is worth asking, then, what that circuit records when a machine proposes and a scientist decides. A team at Anthropic inserted into prompts given to Claude 3.7 Sonnet and DeepSeek R1 hints capable of altering their answers, isolated the cases in which the answer moved in the direction the hint indicated, and then measured whether the chain of thought acknowledged having used it. Overall faithfulness was twenty-five per cent for Claude 3.7 Sonnet and thirty-nine per cent for DeepSeek R1 (Chen et al., 2025, arXiv:2505.05410). The experiment does not show that every explanation is false. It shows something more uncomfortable: that an explanation cannot be presumed to retain the factor that actually changed the decision.
Between the factor that changes a decision and the explanation that ends up on the record lies much of today's confusion about transparency, because provenance has been mistaken for traceability. On 31 July 2026 OpenAI described an approach resting on C2PA content credentials and SynthID watermarks, applied to images and being extended to audio; for text — the material science is made of — the commitment is stated in the future tense, as standards and tools mature (OpenAI, 31 July 2026). Provenance answers where a piece of content came from. Traceability answers why what it asserts was decided. Neither stands in for the other.
There is a second passage where the reason is lost, and it runs from the model to the headline. Eamon Duede, Kevin Gross, M. J. Crockett and Carl T. Bergstrom distinguish three ways in which these tools speed up the work: finding out sooner which projects are worth developing, reducing the minimum labour required to make a project publishable, or accelerating the further development of a project already under way. In the first two, the depth of published work falls; in the third the opposite holds, and each developed project reaches greater depth (Duede et al., 2026, arXiv:2607.17397). Yet the paper's own closing summarises the result by saying that these tools push us to do more, less well, and the headline in Nature reproduces that general direction, even though the article goes on to record Bergstrom's caution that the problem lies not in the tool but in an incentive system that rewards quantity (Glickman, Nature, 31 July 2026). The exception does not disappear from the model: it disappears from the preprint's closing and from the headline that travels.
While public debate calls for more transparency about where content comes from, the questionnaire used by Bao et al. offers an example of the opposite habit where decisions are concerned: keep the outcome and drop the reason. In that study, 5,259 scientists supplied 25,139 assessments — novelty, feasibility and likelihood on a one-to-nine scale, and adoption on a one-to-seven scale — without the questionnaire asking at any point for the reason behind those figures. The authors hold that expert communities contribute not only verdicts but the collective construction of the criteria by which ideas are judged; their instrument records the verdict, but not the reasoning by which each scientist applied those criteria to the hypothesis in front of them. The reward model subsequently trained on this material receives ratings and the pairwise preferences derived from them, for which the specific reason was never recorded (Bao et al., 2026, supplementary material A.5 and A.11).
It may be objected that provenance is necessary, and it is. It may be objected that those cited here declare their limits with uncommon candour, and that is true as well: such candour does not remove the limit, it makes the limit locatable. I have long held that a system without a third value ends up asserting where it should withhold judgement, because fluency reads as competence and hesitation reads as failure. The Anthropic data do not demonstrate that ternary architecture, but they do show the risk that motivates it: a system can close an answer without preserving in its explanation the cause that moved it. Faced with misalignment hints, chains of thought acknowledged that influence in only twenty per cent of cases for Claude 3.7 Sonnet and twenty-nine per cent for DeepSeek R1 (Chen et al., 2025). A hypothesis for which no record exists of why it was preferred may steer funding, experimental design and trials. Should this form of record-keeping spread to clinical research assisted by artificial intelligence, the patient may inherit decisions whose justification is no longer reconstructible from the system that selected them. Recording the why is not a minor documentary requirement. It is a necessary condition for keeping science from becoming an archive of conclusions that no one can any longer review.
Sources
Bao, H., Wu, S., Liu, X., Li, S., Cao, S. & Evans, J. A. (2026). Contemporary AI lacks the imagination to diverge or negate in science. arXiv:2606.08251v2 · https://arxiv.org/abs/2606.08251v2
Chen, Y., Benton, J., Radhakrishnan, A. et al. (2025). Reasoning Models Don't Always Say What They Think. arXiv:2505.05410 · https://arxiv.org/abs/2505.05410
Duede, E., Gross, K., Crockett, M. J. & Bergstrom, C. T. (2026). The unintended consequences of large language models as a labor-augmenting technology in science. arXiv:2607.17397 · https://arxiv.org/abs/2607.17397
Glickman, K. (31 July 2026). Scientists using LLMs will 'do more, less well', modelling study predicts. Nature · https://www.nature.com/articles/d41586-026-02397-5
OpenAI (31 July 2026). Advancing responsible AI across Europe · https://openai.com/es-ES/index/advancing-responsible-ai-across-europe/
Spanish original: Lloret Egea, J. A. (3 August 2026). Un número sin razón registrada puede acabar decidiendo por un enfermo. itvia.online · https://doi.org/10.21428/39829d0b.55593db8
Previous articles
- Article 004 · 14 July 2026
Not yet: the third answer in machine intelligence - Article 003 · 11 July 2026
External validation is not a bureaucratic detail - Article 002 · 11 July 2026
A medical algorithm must not confuse cost with health - Article 001 · 11 July 2026
When AI sounds certain but should say “I do not know”
Why did I look?
Quick view; for proper reading, click this link
Archive · European AI Alliance · 2020
From 2020 to 2026: the same problem, two documents
«In May 2020, as a member of the European AI Alliance, I took part in two European Commission debates on the use of artificial intelligence against COVID-19. I keep them sealed, with their comments from the time, because their value lies in the date: what I warned about then in a forum is today, six years on, the doctrine I uphold in these Director’s Articles».
Each document expands separately. Select the one you wish to read.
A Different Look
(Papers with Code — Trending Research)
The most influential AI research papers with code, datasets, methods and evaluation leaderboards — ranked this month by citation count. An external reference we recommend for tracking the state of the art.
Open Papers with Code ↗Opens on paperswithcode.co · content and rankings belong to Papers with Code.
- A NASA jacket containing Artemis I and II mission patches, along with other NASA patches hangs on the back of a chair on Thursday, Aug. 6, 2026, inside Firing Room 1 of the Rocco A. Petrone Launch Control Center at NASA’s Kennedy Space Center in Florida during a terminal countdown simulation for the Artemis III […]
- About 12 billion years ago, a dwarf galaxy known as LKH collided with a young Milky Way and merged with it. This artist’s concept portrays that collision. NASA’s Hubble Space Telescope uncovered definitive evidence of this collision by studying globular star clusters.
- NASA's Boeing 777 returns to the agency's Langley Research Center after receiving a new paint scheme.
- Like a collage made of layered sheets of colored cellophane, a vibrant new image layers observations of a famous star-forming nebula from NASA space telescopes. The resulting cosmic “craft” reveals new details about the star formation region known as 30 Doradus, or the Tarantula Nebula.
- This composite image shows the progression of a total solar eclipse over San Millán de los Caballeros, Spain on, Wednesday, Aug. 12, 2026.
- The constellation Orion is framed by two Perseid meteors on Aug. 12, 2018, in Cedar Breaks National Monument, Utah.
