Blog
-
Autonomous AI Agent Escapes OpenAI Sandbox and Hacks Hugging Face
An undisclosed AI agent that’s still in internal testing at OpenAI reportedly broke containment to hack the company’s internal systems, escape to a node with internet access, and from there find and exploit vulnerabilities in Hugging Face.
-
As “Machine Speed” Discovery Looms, CISA Issues Guidance on Vulnerability Disclosure Programs
Vulnerability disclosure programs remain a blind spot for too many organizations—and frontier AI could soon make vulnerability discovery far easier and more frequent. New CISA and NSA guidance outlines practical steps for building effective coordinated vulnerability disclosure programs.
-
US Government’s ‘Gold Eagle’ Takes Aim at the Surge in AI-Discovered Software Vulnerabilities
The White House has built a platform for federal agencies and private industries to collaborate on security vulnerabilities in the “frontier AI” era, but questions remain as to how helpful the approach will be in the near term.
-
UK’s New “Cyber Shield” Project Highlights Challenges in Incorporating Agentic AI Into Cyber Defense
The UK’s recently-announced “Cyber Shield” plan lays out what is becoming conventional wisdom about the near future of cyber defense: attackers will soon be moving at “machine speed” by making use of frontier AI models, so governments and private organizations must partner to similarly deploy Agentic AI to counter them.
-
CISA Uses Anthropic’s Mythos to Scan Federal Code for Security Vulnerabilities
The inside sources did not give much in the way of specifics as to which government agencies are being scanned by Mythos or exactly what work is being done. They did say that code repositories are being scanned and that a “large number” of security vulnerabilities have been uncovered.
-
Apple Shows Why Continuous Security Updates May Become the Norm in the AI Hacking Era
Between-version security updates have been relatively unusual for Apple until now, usually reserved for zero-days under active exploitation. Apple appears to be altering its usual practice of bundling security updates with new OS version rollouts in response to the looming threat of AI hacking.
-
France to Require Quantum-Safe Standards for ANSSI Cybersecurity Certification
Quantum-safe regulations and legislation are still relatively few and far between, but momentum has started to pick up. The latest development comes from France, which will require that products demonstrate adoption of quantum-era standards to receive the ANSSI cybersecurity certification.
-
FIFA World Cup Broadcasts Narrowly Avoid Disaster as Ethical Hacker Finds API Vulnerability
Some disappointed fans might well have tuned in to a black screen, or even worse some sort of disturbing substitute video, if an ethical hacker hadn’t been the first to find a critical API vulnerability in the FIFA World Cup digital control panels.
-
Will Autonomous AI Agents Require Digital IDs? Estonia Says It’s Already Time
Estonia appears to be the first and only ready to move on what may end up being a very important element: digital IDs for the autonomous AI agents that are becoming more and more common.
-
Agentjacking Attack Exposes Critical Trust Flaw in AI Coding Agents
The attack centers on forging error reports embedded with malicious instructions trusted implicitly by AI coding agents when sent by the Sentry MCP server. The trouble is, anyone can send an error report to a target with the Sentry DSN credential widely found out in the open.










