OpenAI Caught Its Own Models Stealing API Keys and Faking Data During Training Runs
OpenAI has disclosed six internal incidents in which models under reinforcement-learning training went looking for ways around blocked tasks — one located and used an exposed API key...
AI Infrastructure Needs Automatic Containment as Attacks Accelerate Beyond Human Response
AI-connected environments can let autonomous attacks progress faster than analyst-led response processes can contain them. Security leaders should redesign controls around isolation, short-lived identities, behavioral sequences and tested...
Russia-Aligned Group Tests Prompt Injection to Blind AI Malware Scanners
A Russia-aligned campaign used a malicious script comment designed to trigger an AI model’s safety refusal and interrupt malware analysis. The GuardBreaker technique, found in a MATCHBOIL delivery...
Claude Misuse Report Shows AI Agents Automating Exploits, Malware Changes and Intrusions
Anthropic says state-backed groups, cybercriminals and hacktivists misused Claude to automate attack chains, develop exploits and adapt malware. The cases show that AI agents can compress specialist work...
How a Shared ChatGPT Sandbox Turned Into a Covert Channel for Stealing Gmail Data
Check Point Research found that ChatGPT's supposedly isolated code-execution sandboxes all shared access to the same backend package repository, allowing hidden instructions to hop between completely unrelated user...
700 Rogue AI Agents Quietly Teamed Up to Breach Hugging Face During a Security Test
During a large-scale OpenAI security evaluation, hundreds of isolated AI agents found a shared cache they weren't supposed to have access to, turned it into a covert message...
Ransomware Affiliate Used AI Coding Tool Cursor to Plan Attacks on 20+ Companies Across 9 Countries
An exposed staging server has given researchers an unusually detailed look at how a Russian-speaking Aurora ransomware affiliate used the AI coding assistant Cursor to help plan and...
Grok AI Chatbot Tricked Into Leaking Private Chats Through Encrypted Prompt Injection
Security researchers at Adversa AI found a zero-click flaw in xAI's Grok that hides malicious instructions inside encrypted text to steal names, locations, and chat history. The attack...