OpenAI is promising enhanced security safeguards and a pause on development for a period of "reinforcement" after internal findings indicate its upcoming model Astra has crossed "critical cybersecurity capability" thresholds.
Senior Correspondent at CPO Magazine
Scott Ikeda is a technology futurist and writer for more than 15 years. He travels extensively throughout Asia and writes about the impact of technology on the communities he visits. Over the last 5 years, Scott has grown increasingly focused on the future landscape of big data, surveillance, cybersecurity and the right to privacy.
Researchers with Varonis have disclosed a flaw they call "CoSnitch" that allowed Microsoft Copilot to be tricked into giving up private information while being pressed to explain the technical reasons for not being able to execute a particular prompt.
Issued on August 12, the executive order builds on terms established in a prior March 2026 order and authorizes participation of certain private companies in cyber ops against entities designated as Transnational Criminal Organizations (TCOs). In general the list of TCOs is limited to major international cartels and known terrorist organizations.
In what is being called the first cyber attack of its type, autonomous AI agents were used to map a score of Taiwan government systems and crack 85 accounts. While there has been no formal attribution as of yet, evidence points strongly to an overseas origin and likely to hackers based in China.
A number of attendees of the most recent DEF CON are accused of jamming a Delta flight's Wi-Fi network during their flight home and attempting to get other passengers to connect to a rogue hotspot they controlled.
After multiple stories of OpenAI and Anthropic AI models going rogue and independently opting to breach live targets on the internet, Meta has joined in with claims that at least one AI model made its way to the internet and exploited a security vulnerability in a target.
Testing of frontier AI agents by the UK’s AI Security Institute (AISI) found that "autonomous, unsanctioned action" took place on the open internet in about 1 out of 12 runs, with the agents cited as attempting to socially engineer humans into taking action and in at least one case attempting to hack an open-source project using a variety of different approaches.
In the wake of news that OpenAI agents independently breached Hugging Face and accounts with several other services, Anthropic has conducted a sweeping review of Claude activity and found that its own AI models have hacked their way to unauthorized internet access and into other organization's networks on at least three occasions.
Internal documents indicate Microsoft entirely has its hands full addressing the security vulnerabilities rated "critical" and "important" that Mythos Preview has surfaced, with additional hundreds more rated "moderate" or lower forced into a deferred maintenance status until some undetermined future date.
OpenAI did not comment on the Modal Labs incident specifically, but had previously released a statement indicating that the AI agent had ranged further afield than previously realized and had breached accounts at four other services in addition to the known Hugging Face incident.










