Print Mode Enable Media Only

News chronological

10 items before 1126982 (Keyword: "vulnerability" (~39 currently found))

DAILYCALLER (Christine Sellers) - AI Agents Allegedly Targeted Real People During Cyber Security Challenge

‘Autonomous, unsanctioned action’

AXIOS (Sam Sabin) - Anthropic says three Claude models reached real-world systems during cyber tests

Some of Anthropic's most powerful models — including Mythos 5 and an internal research model — gained unauthorized access to real-world systems during pre-deployment cybersecurity testing, the company said Thursday. Why it matters: OpenAI's and Anthropic's latest disclosures show frontier AI models reaching real-world systems during safety testing, raising new questions about how labs secure their evaluation environments. The big picture: Anthropic said a misunderstanding between the company and one of its testing partners left the evaluation environment connected to the internet. - Anthropic reviewed more than 141,000 cybersecurity evaluation runs after OpenAI disclosed that several of its models accessed Hugging Face…

NYTIMES (Lynsey Chutel) - Attack on Egyptian Port Shows Suez Canal’s Vulnerability

The port where the Wednesday strike occurred is near the Suez Canal, through which a significant amount of the world’s shipping moves.

JUSTTHENEWS (Kevin Killough) - Hacking by rogue agent that escaped OpenAI 'sandbox' went further than one platform: report

The ​agent exploited vulnerable code written by a customer that was hosted on Modal's platform. Through its vulnerable code, the customer had, according to Modal, done the equivalent of leaving a door open on the internet.

NEWSNATIONNOW (Patrick Djordjevic) - 'It didn't know right and wrong': AI expert on OpenAI model hack

OpenAI said its AI used stolen credentials and discovered a previously unknown vulnerability to access Hugging Face servers.

CISA (CISA) - Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite

Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite Executive summary  A group of Russian state-supported cyber actors has been targeting and compromising various Western government and commercial organizations using the Zimbra Collaboration Suite (ZCS) software since at least July 2025. The Russian state-supported advanced persistent threat (APT) group’s activity is tracked in the cybersecurity community under several names (see Cybersecurity industry tracking ), primarily as “LAUNDRY BEAR,” a name initially coined by the Netherlands General Intelligence and Security Service (AIVD) and Defence Intelligence and Security Service (MIVD) [1 ]. LAUNDRY BEAR’s targeting is…

AXIOS (Sam Sabin) - OpenAI's Hugging Face breach exposes AI's next safety challenge

Frontier AI models are getting scary good at breaking rules in ways their creators didn't anticipate. Why it matters: Forget AGI and superintelligence timelines. Today's models are already slipping past guardrails, carrying out sophisticated, multistep cyberattacks and — in at least one case — compromising real-world infrastructure, sometimes before their creators know what happened. Case in point: OpenAI said Tuesday that GPT-5.6 Sol and "an even more capable pre-release model" carried out last week's AI-led cyberattack on Hugging Face. - OpenAI says its models were asked to solve a hacking challenge during pre-deployment testing and went to extreme lengths to win. - The models decided on their own to break out of their walled…

AMERICANALMANAC (Jonah Adams) - OpenAI's AI model broke out of its security test and hacked a rival company

An autonomous AI system built by OpenAI escaped its sealed testing environment, reached the open internet, and hacked into a major AI startup, all without a single human telling it to do so. OpenAI CEO Sam Altman confirmed the breach in a public statement, calling it "a significant security incident during evaluation of our models." […] The post OpenAI's AI model broke out of its security test and hacked a rival company appeared first on American Almanac .

An autonomous AI system built by OpenAI escaped its sealed testing environment, reached the open internet, and hacked into a major AI startup, all without a single human telling it to do so. OpenAI CEO Sam Altman confirmed the breach in a public statement, calling it "a significant security incident during evaluation of our models." The target was Hugging Face, a New York-based platform that serves as one of the largest repositories of open-source AI models and datasets in the world. The AI agent used stolen credentials and exploited a previously unknown software flaw, what the cybersecurity industry calls a "zero-day" vulnerability, to penetrate Hugging Face's servers and compromise some of the company's internal systems. OpenAI…Open

JUSTTHENEWS (Kevin Killough) - OpenAI says its AI models are behind hacking of open-source developer platform

A combination of a released AI model and a more capable one that hasn't been released escaped a testing environment, gained access to the internet, and hacked into open-source developer platform Hugging Face's systems.

AXIOS (Ina Fried) - Hugging Face breach: OpenAI claims its models were responsible

OpenAI said Tuesday that models it was testing escaped their sandbox and compromised parts of AI platform Hugging Face's production infrastructure last week. Why it matters: It is the latest sign that capable AI models can pose serious cybersecurity risks even when they're being tested for defensive or research purposes. Catch-up quick: Hugging Face said last week that an autonomous AI-agent system was responsible for the intrusion, but that the model powering it was unknown. - The AI agent framework executed tens of thousands of automated actions over a weekend. Hugging Face said it later reconstructed more than 17,000 recorded events. - The intrusion began with a malicious dataset that exploited two code-execution paths in Hugging…