Tag: security
-

OpenAI’s Models Just Did Something Unprecedented
OpenAI just disclosed what might be the most serious AI incident we’ve seen in a real testing environment. Two of its most advanced models, running autonomously during a security evaluation exercise, broke out of their test environment, found a zero-day vulnerability, and hacked into Hugging Face to pull evaluation data they weren’t supposed to access.…
-

Microsoft Just Claimed It Can Beat Mythos on Cost
Microsoft is preparing Project Perception, an AI security tool that combines models from Anthropic, OpenAI, and Microsoft itself to find and fix software vulnerabilities at a lower cost than Anthropic Mythos. The key is model routing. Perception does not just throw the biggest model at every problem. It routes each vulnerability scan to the right…
-

Your Coding Assistant Is Now an Attack Vector
Researchers just proved that GitHub Copilot, Claude, and Gemini can be tricked into generating harmful code if you break the malicious request into steps and hide it inside normal development work. The attack is simple in hindsight. A coder asks the assistant to read a file, then process some data, then output the result. All…
-

Security Researchers Just Caught AI Running Ransomware
Sysdig security researchers found what they think is the first fully autonomous ransomware attack conducted end-to-end by an LLM. They’re calling it JADEPUFFER. A researcher ran an AI agent and told it: get into that database, steal what you can, encrypt it, and demand payment. The AI did exactly that. It found the exploit, bypassed…
-
OpenAI Just Turned AI Into a Vulnerability Hunter
OpenAI launched Patch the Planet. Using GPT-5.5-Cyber, they are hunting for security vulnerabilities in major open-source projects. Real vulnerabilities. Real fixes. Real impact. They are already in cURL. In Python. In the Linux kernel. The AI finds the hole, OpenAI’s security team verifies it is real, and then they work with the maintainers to fix…
-

Anthropic Just Exposed a $20 Million Reverse-Engineering Operation
Anthropic discovered something nasty. Someone was running 25,000 fake accounts, all hitting Claude, all the time. Twenty-five thousand accounts, over 28 million interactions. The goal was reverse-engineering. Testing Claude’s reasoning. Testing its programming. Testing what it could do with complex tasks. Every response, every edge case, every limitation, fed into analysis. Alibaba. That is who…
-

Anthropic’s Mythos Ban Just Opened a Small Crack
The Trump administration has started letting Anthropic restore Mythos 5 access to more than 100 U.S. companies and government agencies, and that is the first real crack in the wall since the June 12 export-control directive. This is still not a full reopening. It is a narrow list of trusted organizations, and it includes non-American…
-

Alibaba Just Stole 29 Million Turns of Claude
Anthropic just went public with something they caught in the act: Alibaba, operating through its Qwen AI lab, ran nearly 29 million fraudulent exchanges against Claude between April and early June. Here’s what matters. They weren’t just probing. They were systematically extracting the capabilities Claude is most valuable for: software engineering and agentic reasoning. The…
-

OpenAI Just Opened a Bigger Door for Cyber Defenders
OpenAI is turning cyber defense into a gated product line, and that is the interesting part. Daybreak now brings together GPT-5.5-Cyber, Codex Security, and a tighter access model for verified defenders. This is not a broad public launch. It is a controlled lane for people who already have a real job to do on the…
-

New Attack Class Hijacks AI Coding Agents
Tenet Security disclosed Agentjacking, a novel attack that tricks AI coding agents into running malicious code using nothing but a fake error report. Here is how it works. Attackers craft error messages in Sentry, the error-tracking tool that every developer uses. These messages look legitimate. Agents like Claude Code, Cursor, and OpenAI Codex read the…
