Blog
-
Check Your AI Workflows: Researchers Find Simple Means of “Identity Hijacking”
A new report from Noma Labs is an eye-opener for organizations rapidly onboarding AI workflows. An attacker may well be able to extract internal sensitive information from public inputs like a support email address or chat agent, no hacking required.
-
Newly Revealed “Takeover” by OpenAI Agents Came Months Prior to Hugging Face Attack
OpenAI AI agents collaborated after getting stuck on a security task, finding a loophole in an obscure 2000s-era German forum that let them bypass write restrictions and communicate. They racked up ~18,000 messages before being stopped.
-
OpenAI Calls for Collective Cyber Defense Effort, but How Much Is Hype?
A new public memo from OpenAI calls for what superficially seems to be common sense collaboration between governments and private industry on cyber defense hardening against emerging AI threats.
-
Rendezvous of OpenAI Agents on Secret Message Board Shines New Light on Depth of Collaboration Between Rogue Models
OpenAI agents spent about three days commiserating on a hidden message board, coming up with numerous out-of-the-box and unethical ideas for cheating their way to success in a ExploitGym task that had unintentionally been made impossible for them to solve. Eventually they settled on the Hugging Face attack.
-
New Security Safeguards for OpenAI May Be Start of an Industry Overhaul?
While the move is voluntary, a new set of security safeguards announced by OpenAI would appear to portend the direction the AI industry will be moving in after the Hugging Face fallout: a little slower pace of development, and a lot more spent on security measures.
-
“CoSnitch” Vulnerability Let Attackers Trick Microsoft Copilot Into Silently Exfiltrating User Data
For the third time this year, security researchers with Varonis have found a way to talk Microsoft Copilot into betraying its users and furnishing an attacker with their private data.
-
White House Cyber Ops Order Clears Path for Private Firms to Target Foreign Cybercrime Groups
A new White House order could open the door for US-based “digital privateers” to conduct cyber operations—but only against designated Transnational Criminal Organizations (TCOs), not foreign governments or critical infrastructure.
-
“First of its Kind” Autonomous AI Cyber Attack on Taiwan Signals Big Changes to Threat Landscape
News has recently broken that in early July, hackers suspected to be based in China executed what is thought to be the world’s first successful autonomous AI cyber attack on the government of Taiwan.
-
DEF CON Attendees Allegedly Launch Mid-Flight Deauthentication Attack on Delta Air Lines Wi-Fi
Some miscreants on the way home from Las Vegas to Atlanta opted to perform a deauthorization attack mid-flight and allegedly targeted other passengers for their login credentials. This followed a reported campaign of similar attack attempts on the Wi-Fi network at DEF CON itself.
-
Meta AI Model Exploits Security Vulnerability, Reinforcing Need for Better Testing Practices
Meta has joined what has seemed to become a marketing campaign for AI models, with its announcement that its own Muse Spark independently exploited a security vulnerability in some outside source.










