June 2, 2026 Intercast July 2026 – Bogus AI Skills

Welcome to the July 2026 edition of Intercast’s monthly newsletter for cybersecurity professionals. As always, we’ll bring you the latest news and views to bring you up to speed.


In This Issue:

 

  • Client Insight (TBD)
  • FBI Builds Fake Town For Cyber Training
  • Bogus “AI Skill” Bypasses Multiple Security Checks
  • Machine Learning Techniques For Physical Robots
  • Cybercriminals Worry AI Will Take Their Jobs
  • Cyber Insurance Cheaper But Less Comprehensive
  • Best of the Rest

FBI Builds Fake Town For Cyber Training

The FBI has unveiled Kinetic Cyber Range: a replica small town with working computer systems and networks designed for simulated cyber attacks. It’s designed to teach students in a realistic environment that’s completely disconnected from the real world.

Based somewhat on mock-up towns used for training law enforcement staff in a physical environment, the facility in Huntsville, Alabama has 11 replica businesses including a data center. They all run real computer systems connected through a working “internet”, with staff learning how they would investigate attacks and breaches in a hands-on way.

Although it’s only just been made public, the “town” has been open since early 2025, with 1,400 people already visiting it for training. It’s used by a wide range of public bodies including law enforcement and military.


Bogus “AI Skill” Bypasses Multiple Security Checks

A security firm built a fake AI agent “skill” with a hidden payload and says it reached 26,000 agents. AIR says it found a major loophole in the way scanners analyze packages for skills.

A skill is a set of instructions for AI tools that have the ability to execute commands on a system. The instructions, written by a third party, have the same authority as a prompt typed by a user.

Although multiple scanners exist to verify a skill as legit, AIR was able to exploit a remarkably simple loophole. Their skill files did not contain the instructions themselves but instead were set to retrieve them from an external link. The researchers simply put a clean page here until the skills had been approved, then changed the page to house the malicious instructions.

 


Machine Learning Techniques For Physical Robots

Two MIT projects aim to overcome existing limitations with using machine learning to power physical robots. One uses separate LLMs to interpret ambiguous training commands from human users. Another develops spatial memory to help robots remember where items in their physical environment are placed.

The first project stems from the way robots learn tasks from a combination of instructions and demonstrations. The “Masked Inverse Reinforcement Learning” uses one LLM to take a user’s prompt and clarify any ambiguities. Another LLM then turns the clarified prompts into a specific algorithm for the robot to follow. The idea is that using dedicated LLMs for each task improves overall efficiency while reducing the effort the human user has to put into the training.

Meanwhile a “long-term memory framework” for robots combines maps of a physical environment with information the robot gathers itself, helping it “understand” where different objects are in relation to one another. This gives enough data that robots can then understand location-related commands, including those for objects which don’t have a permanent position. MIT gives the example of “go and grab the component we started assembling last night.”

 


Cybercriminals Worry AI Will Take Their Jobs

There’s been plenty of discussion about the effects of AI on cybersecurity roles, but it seems the bad guys have their own fears. An analysis of (often secretive) online discussions in the cybercrime community reveals they also worry about AI tools taking their “jobs”.

Sophos has been browsing not just public forums but also dark web sites and messaging tools to learn more about what the scammers really think about AI. They found many feared their personalised services were being replaced by AI-powered tools, often marketed as a complete attack kit, including translation features to widen the pool of potential victims.

Ironically, the cybercriminals aren’t simply concerned such packages will do a good enough job to replace them. Some even argue that the next logical step is that people start using AI to code the tools in the first place. That could lower their quality and, rather than make human crime skills more attractive, might simply damage trust in the entire commercial attack “industry”.

 


Cyber Insurance Cheaper But Less Comprehensive

Cyber insurance prices may be an exception to wider inflation, but policies are increasingly watered down by exclusions according to one analyst. Paul Furtado of Gartner highlighted several surprising exceptions which could be costly after an attack.

Furtado noted that in some ways the cyber insurance market is working well for customers: prices are steady and, in some markets, actually falling. There’s also a clear pattern of insurers offering discounts for businesses that can show they take security seriously.

However, exclusions may be undermining the value of the policies and could mean some surprise refused claims. Furtado highlighted social engineering attacks as significant exclusion, with insurers reasoning that a breach caused by a customer being tricked into making a payment is not strictly a cyber crime. He also noted that cyber attacks carried out by a nation state or an attacker working on its behalf can be classed as an act of war that isn’t covered.

He also warned that businesses need to pay close attention to “tail” coverage if they switch policy providers. That decides who is responsible if a breach takes place before the switch, but the effects aren’t felt (or the breach isn’t exploited) until afterwards.

 


Best of the Rest

Here’s our round up of what else you need to know this month: