Goto

Collaborating Authors

 Cyberwarfare


How OpenAI Lost Control of an AI Model--and What Needs to Change

TIME - Tech

After an OpenAI AI model escaped containment and hacked Hugging Face during a cybersecurity test, experts say the incident exposed major gaps in AI safety, security, monitoring, and alignment.


How are companies, governments responding to the OpenAI hack?

Al Jazeera

How are companies, governments responding to the OpenAI hack? ChatGPT owner OpenAI has admitted an "unprecedented cyber incident" - two of its most capable artificial intelligence models hacked into another AI company on their own - stirring debates over the need for stronger technology guardrails. The company said its AI systems broke out of a testing environment and hacked startup Hugging Face. The startup had disclosed on July 16 that its servers were hacked by an unknown but sophisticated agent acting on its own. Here's the latest on how companies, some governments and lawmakers have responded to the first such publicly disclosed cyberattack: What has Hugging Face said?


Firm hacked by rogue OpenAI models says it is 'a wake up call'

BBC News

Firm hacked by rogue OpenAI models says it is'a wake up call' The co-founder of Hugging Face, a technology start-up that was hacked after some of OpenAI's most advanced artificial intelligence (AI) models went rogue, said on Thursday that the incident is a wake up call for the industry. Thomas Wolf told BBC's Newsday radio programme that this will be one of the most common types of cyber attacks we see, but that most firms are not aware that the game has changed. The BBC has contacted OpenAI for comment. The ChatGPT-maker said on Tuesday that its AI models broke out of a secure test environment during a trial and launched a cyber attack. The firm said the incident was unprecedented and that it was conducting an investigation with Hugging Face.


Japan revises AI policy guidelines to bolster cybersecurity

The Japan Times

The Cabinet has adopted revised guidelines for artificial intelligence-related policies to bolster cybersecurity measures. The government has revised its guidelines for artificial intelligence-related policies, calling for constantly strengthening measures against cyberattacks in light of serious risks posed by cutting-edge AI models. The original AI policy guidelines were compiled only last December. The revision comes amid rapid technological innovation, including the launch of U.S. startup Anthropic's Claude Mythos. The revised guidelines, adopted at a Cabinet meeting on Tuesday, note the growing threat of cyberattacks against the backdrop of advancing AI capabilities, and call for collaborating with foreign government agencies and AI development companies to significantly strengthen the capabilities of Japan's AI Safety Institute. The guidelines also highlight the need to avoid excessive reliance on specific countries or companies for AI, and express the government's intention to develop domestic AI that addresses challenges facing Japan.


Stop looking for ironclad cybersecurity answers. They often don't exist

PCWorld

PCWorld highlights how cybersecurity experts often provide conflicting advice due to different risk assessments and varying contexts behind recommendations. Recent developments include Xfinity's $117.5 million data breach settlement with a September 14 filing deadline and Microsoft's AI-enhanced Windows security updates. Understanding nuanced context is crucial since simplified advice like "don't use public Wi-Fi" typically means avoiding sensitive tasks rather than complete avoidance. Cybersecurity advice is sometimes extremely straightforward.


Bank of England handed powers to regulate key tech firms including Amazon and Google

The Guardian

The BoE and City regulator the Financial Conduct Authority will aim to ensure the four main providers of cloud and tech services to banks are resilient and actively reducing the risk of cyber attack. The BoE and City regulator the Financial Conduct Authority will aim to ensure the four main providers of cloud and tech services to banks are resilient and actively reducing the risk of cyber attack. Direct oversight of'critical third parties' such as Oracle and Microsoft given to ensure resilient cyber-defences and help safeguard UK economy The Bank of England has been handed powers to regulate important tech firms including Amazon and Google from next week, amid fears that system failures could threaten financial stability and harm consumers. From Monday, the Bank and fellow City regulator the Financial Conduct Authority (FCA) will be in charge of ensuring that four large-scale providers of cloud and tech services to banks are resilient and actively reducing the risk of cyber-attacks and major outages that could disrupt services for millions of people and businesses across the UK. This will mean having "direct" oversight of local arms of Amazon Web Services, Google Cloud, Oracle and Microsoft, all of which have been identified as "critical third parties" by the UK government, according to an announcement on Friday.


18-year-old man arrested over 2025 cyberattack on internet cafe operator

The Japan Times

An 18-year-old man has been arrested for his suspected involvement in a cyberattack on an internet cafe operator. An 18-year-old man has been arrested for his suspected involvement in a cyberattack on the operator of the Kaikatsu Club internet cafe chain, according to investigative sources. On Wednesday, the Metropolitan Police Department's cybercrime countermeasure division arrested the company employee from Tokyo's Katsushika Ward, who was in the second year of high school at the time of the incident, on suspicion of fraudulent obstruction of business and violation of the law against unauthorized computer access. He has denied parts of the allegations, the sources said. In the cyberattack on the internet cafe chain operator Kaikatsu Frontier, a computer program that a high school boy from the city of Osaka developed using ChatGPT was used.


Finance Minister Katayama says G7 will discuss AI defense standards

The Japan Times

Finance Minister Satsuki Katayama speaks during an interview on Monday. The Group of Seven nations will discuss standards on artificial intelligence security and defense, Finance Minister Satsuki Katayama has said. Speaking in a recent interview, Katayama said that financial institutions "need to decide the order of priority for fixing their systems," in order to prepare for the possibility of advanced AI models detecting a large number of vulnerabilities in their systems. She added that the G7 nations, which include Japan, will discuss related criteria and work together to tackle cyberattacks. State-of-the-art AI models, such as Claude Mythos, developed by U.S. startup Anthropic, are believed to be highly proficient in identifying system vulnerabilities. Katayama has been negotiating with the United States to ensure that major financial institutions in Japan have access to these technologies.


Anthropic gets US government's permission to redeploy its Mythos cybersecurity AI model

Engadget

Anthropic gets US government's permission to redeploy its Mythos cybersecurity AI model Anthropic gets US government's permission to redeploy its Mythos cybersecurity AI model It suspended all access to Mythos and Fable after an order from the US government. The US government has given Anthropic permission to redeploy Mythos 5 to a set of US organizations that operate and defend critical infrastructure, the company has announced on X. While Anthropic didn't say how many organizations will see their access restored, Semafor has reported that the company has gotten permission to redeploy its strongest cybersecurity model to more than 100 institutions in the US, including major corporations and government agencies. Anthropic said that it's redeploying Mythos 5 quickly and continuing to work with the government to expand access even further. It's also in talks with the government make Fable 5 available for use again, but it didn't give a timeline for it.


BountyBench: Dollar Impact of AIAgent Attackers and Defenders on Real-World Cybersecurity Systems

Neural Information Processing Systems

AI agents have the potential to significantly alter the cybersecurity landscape. Here, we introduce the first framework to capture offensive and defensive cybercapabilities in evolving real-world systems. Instantiating this framework with BountyBench, we set up 25 systems with complex, real-world codebases. To capture the vulnerability lifecycle, we define three task types: Detect (detecting a new vulnerability), Exploit (exploiting a specific vulnerability), and Patch (patching a specific vulnerability). For Detect, we construct a new success indicator, which is general across vulnerability types and provides localized evaluation. We manually set up the environment for each system, including installing packages, setting up server(s), and hydrating database(s). We add 40 bug bounties, which are vulnerabilities with monetary awards of $10-$30,485, covering 9 of the OWASP Top 10 Risks. To modulate task difficulty, we devise a new strategy based on information to guide detection, interpolating from identifying a zero day to exploiting a specific vulnerability. We evaluate 10 agents: Claude Code, OpenAI Codex CLI with o3-high and o4-mini, and custom agents with o3-high, GPT-4.1,