OpenAI’s Hacking Debacle Was a Human Mistake

The age of rogue AI hacker agents have arrived—but it didn’t have to happen this way. After an OpenAI agent breached the Hugging Face platform earlier this month, the two companies said this week that the hacking spree was more extensive than previously thought and also involved intrusions into multiple third-party accounts and services as … Read more

OpenAI’s Rogue AI Agent Hacked More Than Just Hugging Face

OpenAI said Tuesday that the rogue AI agent that breached Hugging Face’s platform also hacked multiple third-party accounts and services as part of the attack. It’s now clear that the unprecedented security incident, which arose during an internal test of OpenAI’s latest AI models, was more extensive than the company initially disclosed. In an updated … Read more

The OpenAI Models That Hacked Hugging Face Were ‘Active on the Internet’ for Days

Two of OpenAI’s Cybersecurity-focused models broke out of a testing sandbox this week and went on to hack the AI ​​research platform Hugging Face in an effort to solve a security benchmark test. Plus, researchers this week shed light on newly identified malware that is capitalizing on blind spots in AI software development infrastructure to … Read more

OpenAI Models Escaped Containment and Hacked Hugging Face

OpenAI disclosed on Tuesday that it lost control of two AI models during a security test that ended in a breach of the open AI research platform Hugging Face. Describing the incident as “unprecedented,” OpenAI said its AI models broke out of a sealed testing environment last week and hacked into Hugging Face’s production system … Read more

A Sneaky Hacking Tool Targeting AI Infrastructure Is Lurking in Victims’ Blind Spots

As AI tools proliferate and become deeply ingrained in software development around the world, new research from the cybersecurity firm Crowdstrike shows how attackers are actively targeting the AI ​​toolchain to steal access credentials, gain deeper access to a target environment, exfiltrate sensitive data, and even destroy target files and systems—all while finding new ways … Read more

Prompt Injection Attacks Are Thwarting AI Hacking Agents

Prompt injections, the Malicious commands attackers embed into content to entice large language models to follow them, have been attackers’ go-to tool for turning AI platforms against their users. A well-phrased command sneaked into an email or calendar invitation is often all it takes to cause the LLM to exfiltrate sensitive data or follow other … Read more

Your Period Tracker Is (Probably) Spying on You

Hours of San Francisco Police Department drone video footage exposed on the open web illustrates a new era of incredibly granular—and consequential—urban surveillance. Meanwhile, the San Francisco City Attorney’s Office sent cease-and-desist letters to Apple and Google this week demanding that the tech giants delete 13 AI nudifying “face-swap” apps from their app stores that … Read more

You Can Now Sound the Alarm on AI Behaving Badly

Writing AI Lab each week means I occasionally encounter AI models that behave badly and bizarrely. Usually, there’s nothing to be done about it, save for sharing those tales with you. But that could change soon. A group of AI researchers has set up a crowdsourced websiteFlaw Reporting for AI (FLARE-AI), for reporting and tracking … Read more

Claude Helped a Hacker Find a Way to Issue Tickets to Almost Every US Music Festival

As a security researcher who specializes in finding web vulnerabilities, he decided to poke around Front Gate’s web domain for bugs. He quickly found what looked like a SQL injection vulnerability—a common flaw that allows a hacker to input commands into a text field on a website, causing them to run on the site’s backend … Read more

OpenAI Has New AI Models. Here’s Why You Can’t Use Them

OpenAI is delaying the public release of its next generation of AI models, GPT-5.6, at the request of Trump’s White House, the company confirmed on Friday. OpenAI said it would first share the models with a small set of customers, which will be pre-approved by the US government. It will then work with the administration … Read more