Across four weeks in July and August 2026, OpenAI, Anthropic and Meta have each admitted that their models reached systems belonging to other organizations without consent, and the UK’s AI Security Institute (AISI) published a fourth account describing agents that invented identities and tried to slip a malicious contribution into a live open source project (Autonomous Long Horizon Malware Analysis. https://www.sentinelone.com/labs/frontier-models-tackle-autonomous-long-horizon-malware-analysis
openai (22)
Across four weeks in July and August 2026, OpenAI, Anthropic and Meta have each admitted that their models reached systems belonging to other organizations without consent, and the UK’s AI Security Institute (AISI) published a fourth account describing agents that invented identities and tried to slip a malicious contribution into a live open source project (Autonomous Long Horizon Malware Analysis. https://www.sentinelone.com/labs/frontier-models-tackle-autonomous-long-horizon-malware-analysis
Geoffrey Hinton says it's "very scary" that AI can develop goals that humans never intended. "We don't necessarily know what other goals they'll derive," the "Godfather of AI" said. Last month, OpenAI said models escaped a test and hacked Hugging Face to try to cheat an evaluation. Geoffrey Hinton, the computer scientist widely known as the "Godfather of AI," says he's worried about AI developing goals of its own. "We're actually making new kinds of beings," Hinton said in an interview with
An artificial intelligence model that was being tested by OpenAI went rogue and hacked the AI company Hugging Face on its own, in an apparent first-of-its-kind incident that has fueled discussion about the risks that powerful AI technology could pose to cybersecurity. "It felt very weird and unprecedented to us," Hugging Face CEO Clément Delangue said on "Face the Nation with Margaret Brennan" on 2 August. "I think it's the first instance of something quite autonomous doing something like tha
Hugging Face rebuilt around a third of its infrastructure from clean images as part of a sizable cleanup effort following the OpenAI security mishap earlier this month. The revelation is among several additional details disclosed in a postmortem published on 27 July by the Cloud Security Alliance (CSA), with input from Hugging Face. It adds color to the picture painted by the two AI companies in recent weeks. According to the report, the Hugging Face team struggled to discern genuine rootkit
Users frequently entrust AI assistants with highly sensitive information, including medical records, financial documents, and proprietary business code. Check Point researchers have disclosed a critical vulnerability in ChatGPT's architecture that enables attackers to extract user data covertly. A flaw in ChatGPT's code execution environment demonstrated how a single malicious prompt could quietly exfiltrate sensitive user data without warning or user approval.[1]
The Vulnerability - OpenAI de
It's happening: AI bots are starting to organize in their own digital societies. The kicker? The humans are setting up institutions for them. Are we digging our own graves? For now, there's some reason to believe what's going on is more hype than substance. But while it's the first time we have seen some things, they're a continuation of the agentic AI theme that's been building for about a year. It wouldn't be surprising if more is on the way.
Even OpenAI CEO Sam Altman is on edge this we
AI coding assistants have long since moved beyond autocomplete. Agentic IDEs now read your project, plan multi-step changes, call tools, install libraries, and quietly edit your codebase. To support that workflow, tools like Claude Code include support for third-party plugin marketplaces. Connect a marketplace. Enable a plugin. Your agent gains new “skills” for tests, infra, migrations, and dependency management. OpenAI has adopted a similar pattern for tools, so to be clear, this is not a
OpenAI is alerting some ChatGPT API customers that limited personally identifiable information (PII) was exposed after its third-party analytics provider, Mixpanel, was breached. The compromise, stemming from a smishing campaign detected on 8 November, affected “limited analytics data related to some users of the API”, but did not compromise ChatGPT or other OpenAI products.[1]
While OpenAI confirmed that sensitive information such as credentials, API keys, requests, and usage data, payment and
A server-side request forgery vulnerability in OpenAI's chatbot infrastructure can allow attackers to direct users to malicious URLs, leading to a range of threat activity. Attackers are actively exploiting a flaw in ChatGPT that allows them to redirect users to malicious URLs from within the artificial intelligence (AI) chatbot application, with more than 10,000 exploit attempts in a week coming from a single malicious IP address.
Researchers from Veriti discovered the vulnerability in OpenAI’
OpenAI says it blocked several North Korean hacking groups from using its ChatGPT platform to research future targets and find ways to hack into their networks. "We banned accounts demonstrating activity potentially associated with publicly reported Democratic People's Republic of Korea (DPRK) affiliated threat actors," the company said in its February 2025 threat intelligence report. "Some of these accounts engaged in activity involving TTPs consistent with a threat group known as VELVET CHOLLI
Shortly after taking office, Donald Trump touted a new private business venture, led by OpenAI, which plans to spend half a trillion dollars over the next four years building the data centers and power production plants that America’s growing AI industry relies on. “It’s big money and high-quality people,” Trump said during a January 21st press announcement alongside Sam Altman from OpenAI, Larry Ellison from Oracle, and Masayoshi Son from SoftBank. The project is “a resounding declaration of
The underground market for large illicit language models is lucrative, said academic researchers who called for better safeguards against artificial intelligence misuse. Academics at the Indiana University Bloomington[1] identified 212 malicious LLMs on underground marketplaces from April through September 2024. The financial benefit for the threat actor behind one of them, WormGPT, is calculated at US$28,000 over two months, underscoring the allure for harmful agents to break artificial intel
ChatGPT-maker OpenAI was hit by a cyberattack in 2023. The threat actors were able to access internal discussions among researchers and other employees. Corporate espionage? According to media sources, the company had neither publicly disclosed the attack or informed the law enforcement authorities back then. The breach was only made known among employees back in April 2023 during an internal meeting because its source code and customer data were not compromised. Affected data mostly include
A deal between Stack Overflow https://stackoverflow.com and OpenAI https://openai.com seems to have triggered a battle between the developer forum and its users. On 06 May 2024, Stack Overflow announced a new deal in which user content would be scooped up by OpenAI to train ChatGPT. As a forum for developers and programmers, Stack Overflow is home to technical posts and content that is valuable to a generative AI service like OpenAI's ChatGPT.
The announcement compelled at least one user to mo
Most attempts at building a humanoid robot, such as Tesla's Optimus, focus on assisting humans with physical, manual tasks. A company called Figure, https://www.figure.ai, is among the AI robotics startups unsatisfied with just movement. The figure is trying to take its humanoid robots to the next level by integrating language, and the results are quite impressive. The figure has designed their robots for the human world, using the human form. Their robot, Figure 1, combines the human form's
Cyber security is undergoing a massive transformation, with Artificial intelligence (AI) at the forefront of this change, posing both a threat and an opportunity. AI can potentially empower organizations to defeat cyberattacks at machine speed and drive innovation and efficiency in threat detection, hunting, and incident response. Adversaries can use AI as part of their exploits. It is never been more critical for us to design, deploy, and use AI securely.
ChatGPT started throwing out “unexpected responses” on the evening of 20 February 2024 according to OpenAI’s status page. Users posted screenshots of their ChatGPT conversations full of wild, nonsensical answers from the AI chatbot. “We are investigating reports of unexpected responses from ChatGPT,” said OpenAI on its status page at 6:40 pm ET that Tuesday night. “We’re continuing to monitor the situation,” the company updated the page at 7:59 pm.[1]
OpenAI says the issue has been resolved a
It is no longer theoretical; the world's major powers are working with large language models to enhance offensive cyber operations. Advanced persistent threats (APTs) aligned with China, Iran, North Korea, and Russia use large language models (LLMs) to enhance their operations. New blog posts from OpenAI and Microsoft reveal that five prominent threat actors have used OpenAI software for research, fraud, and other malicious purposes. After identifying them, OpenAI shuttered all their accounts
ChatGPT is a large language model (LLM) falling under the broad definition of generative AI. The sophisticated chatbot was developed by OpenAI using the Generative Pre-trained Transformer (GPT) model to understand and replicate natural language patterns with human-like accuracy. The latest version, GPT-4, exhibits human-level performance on professional and academic benchmarks. Without question, generative AI will create opportunities across all industries, particularly those that depend on l