NYTIMES (Dustin Volz) - A.I. Models Built a Computer Worm That Could Rapidly Hack WeChat Accounts
The attack, discovered by A.I. researchers, could have compromised hundreds of millions of devices within hours, experts said.
The attack, discovered by A.I. researchers, could have compromised hundreds of millions of devices within hours, experts said.
Weeks before OpenAI's agents hacked Hugging Face , the agents worked together to find and exploit a vulnerability in the infrastructure supporting the company's cybersecurity testing, OpenAI researchers said Wednesday. Why it matters: The new findings raise questions about how frontier AI labs are monitoring their testing environments — and the challenges safety testers are finding as they try to rein in increasingly powerful AI. Driving the news: OpenAI's internal research model, one of the models involved in the Hugging Face breach, first discovered and exploited a vulnerability in Artifactory, a third-party file repository connected to the company's testing sandbox, on May 26, two researchers said at the Black Hat cybersecurity…
Weeks before OpenAI's agents hacked Hugging Face , the agents worked together to find and exploit a vulnerability in the infrastructure supporting the company's cybersecurity testing, OpenAI researchers said Wednesday. Why it matters: The new findings raise questions about how frontier AI labs are monitoring their testing environments — and the challenges safety testers are finding as they try to rein in increasingly powerful AI. Driving the news: OpenAI's internal research model, one of the models involved in the Hugging Face breach, first discovered and exploited a vulnerability in Artifactory, a third-party file repository connected to the company's testing sandbox, on May 26, two researchers said at the Black Hat cybersecurity…Open
At least a dozen states are reportedly responding to cyberattacks against local water systems . Why it matters: This appears to be one of the broadest known coordinated cyber campaigns against U.S. municipal water systems to date, validating years of warnings that poorly secured utilities could become attractive targets. Driving the news: Hackers have targeted water and wastewater utilities in at least 12 states, ABC News reported on Tuesday. - Last week, the FBI said that at least seven states had experienced cyberattacks targeting the systems that control pumps, water pressure and valves in plants. - Multiple news outlets have reported that officials suspect Iran is behind the widespread attacks, although President Trump said…
At least a dozen states are reportedly responding to cyberattacks against local water systems . Why it matters: This appears to be one of the broadest known coordinated cyber campaigns against U.S. municipal water systems to date, validating years of warnings that poorly secured utilities could become attractive targets. Driving the news: Hackers have targeted water and wastewater utilities in at least 12 states, ABC News reported on Tuesday. - Last week, the FBI said that at least seven states had experienced cyberattacks targeting the systems that control pumps, water pressure and valves in plants. - Multiple news outlets have reported that officials suspect Iran is behind the widespread attacks, although President Trump said…Open
GLM-5.2 — the latest Chinese open-source model capturing Silicon Valley's attention — is raising fresh concerns among security researchers that advanced AI hacking capabilities are becoming dramatically cheaper and more accessible. Why it matters: The barrier to entry for malicious hackers eager to automate and personalize their attacks is getting lower and lower. Driving the news: Z.ai's GLM-5.2, which was released last week, has agentic capabilities that rival those of Claude Opus 4.8 and OpenAI's GPT-5.5 while costing roughly half as much to run. - Two separate security evaluations from Graphistry and Semgrep found that GLM-5.2 performed on par with leading U.S. models on cybersecurity investigation and vulnerability-discovery…
GLM-5.2 — the latest Chinese open-source model capturing Silicon Valley's attention — is raising fresh concerns among security researchers that advanced AI hacking capabilities are becoming dramatically cheaper and more accessible. Why it matters: The barrier to entry for malicious hackers eager to automate and personalize their attacks is getting lower and lower. Driving the news: Z.ai's GLM-5.2, which was released last week, has agentic capabilities that rival those of Claude Opus 4.8 and OpenAI's GPT-5.5 while costing roughly half as much to run. - Two separate security evaluations from Graphistry and Semgrep found that GLM-5.2 performed on par with leading U.S. models on cybersecurity investigation and vulnerability-discovery…Open
Researchers at the University of Toronto showed how hackers could use artificial intelligence to create a program that could target any known flaw in the world’s computers.
Beijing has hacked America, but we have all the tools we need to fight back.
OpenAI is rolling out a more permissible version of GPT-5.5 — aka "Spud" — to vetted cyber defenders, the company said Thursday. Why it matters: Recent security testing suggests that GPT-5.5 model is nearly as good at finding and exploiting software bugs as Anthropic's Mythos Preview . The capabilities of the new models have sparked an urgent debate in Silicon Valley and the White House about how to keep them out of the hands of bad actors. Driving the news: OpenAI is opening a limited preview of GPT-5.5-Cyber to vetted cyber defenders who are "responsible for securing critical infrastructure," per a press release. - A source familiar with GPT-5.5-Cyber's abilities told Axios that they were roughly on par with Mythos. One major…
OpenAI is rolling out a more permissible version of GPT-5.5 — aka "Spud" — to vetted cyber defenders, the company said Thursday. Why it matters: Recent security testing suggests that GPT-5.5 model is nearly as good at finding and exploiting software bugs as Anthropic's Mythos Preview . The capabilities of the new models have sparked an urgent debate in Silicon Valley and the White House about how to keep them out of the hands of bad actors. Driving the news: OpenAI is opening a limited preview of GPT-5.5-Cyber to vetted cyber defenders who are "responsible for securing critical infrastructure," per a press release. - A source familiar with GPT-5.5-Cyber's abilities told Axios that they were roughly on par with Mythos. One major…Open
Suspected North Korean hackers are believed to be behind an ongoing compromise of the widely used open-source package Axios, which is downloaded millions of times per week, researchers at Google said Tuesday. Why it matters: Hackers briefly turned a widely trusted developer tool into a vehicle for credential-stealing malware that could give attackers ongoing access to infected systems. - Axios, a widely used JavaScript library for making HTTP requests, is not affiliated with Axios Media. Driving the news: Researchers at Google linked the activity to a North Korean group tracked as UNC1069 , which has previously targeted cryptocurrency and decentralized finance companies. - Earlier this week, a maintainer account for the Axios npm…
Suspected North Korean hackers are believed to be behind an ongoing compromise of the widely used open-source package Axios, which is downloaded millions of times per week, researchers at Google said Tuesday. Why it matters: Hackers briefly turned a widely trusted developer tool into a vehicle for credential-stealing malware that could give attackers ongoing access to infected systems. - Axios, a widely used JavaScript library for making HTTP requests, is not affiliated with Axios Media. Driving the news: Researchers at Google linked the activity to a North Korean group tracked as UNC1069 , which has previously targeted cryptocurrency and decentralized finance companies. - Earlier this week, a maintainer account for the Axios npm…Open
Cybercriminal groups are now using spyware tools once utilized mainly by spies and law enforcement to hack into iPhones, new research shows. Why it matters: Anyone with an iPhone can now be the target of invasive malware that siphons off personal text messages, photos, notes and calendar data. Driving the news: In the last month, researchers at Google, iVerify and Lookout uncovered two campaigns exploiting iPhone vulnerabilities. - Earlier this month, Google researchers said they identified a sophisticated iPhone hacking toolkit, called Coruna , originally built for an unnamed government customer that later ended up in the hands of a Chinese cybercriminal group. TechCrunch later reported that defense contractor L3Harris created the…
Cybercriminal groups are now using spyware tools once utilized mainly by spies and law enforcement to hack into iPhones, new research shows. Why it matters: Anyone with an iPhone can now be the target of invasive malware that siphons off personal text messages, photos, notes and calendar data. Driving the news: In the last month, researchers at Google, iVerify and Lookout uncovered two campaigns exploiting iPhone vulnerabilities. - Earlier this month, Google researchers said they identified a sophisticated iPhone hacking toolkit, called Coruna , originally built for an unnamed government customer that later ended up in the hands of a Chinese cybercriminal group. TechCrunch later reported that defense contractor L3Harris created the…Open
Stryker, a U.S. medical equipment company, says a cyberattack has disrupted its global networks