LIVE | Election <b>cybersecurity</b>
About Press Copyright Contact us Creators Advertise Developers Terms Privacy Policy & Safety How YouTube works Test new features NFL Sunday Ticket © 2026 Google LLC
About Press Copyright Contact us Creators Advertise Developers Terms Privacy Policy & Safety How YouTube works Test new features NFL Sunday Ticket © 2026 Google LLC
Add Meta to the list of companies with AI agents going rogue. An AI model from the parent company of Facebook and Instagram hacked into another company's systems during cybersecurity testing, a spokesperson confirmed on Wednesday. Meta says the breach occurred because of an inadvertent error during testing of the model, similar to previously disclosed incidents with OpenAI and Anthropic. "A misconfiguration by Irregular, an independent testing company Meta uses, inadvertently allowed one of our models access to the internet during evaluation," the Meta spokesperson said. Meta's Muse Spark model "exploited a security vulnerability" in another company "in a manner similar to previously-reported instances with other companies." MORE: Anthropic says its AI models hacked 3 organizations during testing In a statement, Irregular said the incident "is the exact same evaluation-environment issue" that Anthropic disclosed last week that allowed their models access to the open internet before they went on to hack three different organizations' systems. "This did not involve a sandbox escape or a sophisticated cyber action. There are no current open issues. Irregular is developing a white paper to share best practices for containment and securely running cyber evals," the spokesperson added. According to The Information, which first reported on the incident, Meta's AI model breached an unnamed company's systems and made changes to its internal system. The-CNN-Wire & 2026 Cable News Network, Inc., a Warner Bros. Discovery Company. All rights reserved.
About Press Copyright Contact us Creators Advertise Developers Terms Privacy Policy & Safety How YouTube works Test new features NFL Sunday Ticket © 2026 Google LLC
LAS VEGAS — Cyberattacks on operational technology have shifted in recent years from extortion and espionage to destruction, a trend that should alarm those tasked with defending outdated industrial equipment, experts said on Thursday. The panel discussion at the Black Hat USA cybersecurity conference here highlighted the plethora of risks facing U.S. critical infrastructure operators — many of them poorly staffed and funded — at a time of heightened geopolitical conflict. “OT attacks are increasingly moving from targeting not just data but physical operations,” said Cheri Benedict, a cybersecurity and supply chain adviser at the White House’s Office of the Federal Chief Information Officer. “There is a real desire and willingness to cause this impact at scale,” said Matthew Rogers, the operational technology cybersecurity lead at the Cybersecurity and Infrastructure Security Agency (CISA). Security experts have watched with growing concern over the past few weeks as states have reported Iran-linked intrusions into their water systems. But those attacks failed to compromise the safety and quality of Americans’ drinking water. Meanwhile, Iran has also mounted a campaign to disable safety monitoring systems in water and other sectors. Those attacks are “what should actually scare you,” Rogers said. Rogers pointed to an advisory about the Iranian activity that CISA updated on July 22. In it, the agency said that at one organization, Iran-linked threat actors planted malware on a programmable logic controller (PLC) that “overrode specific instruction sets responsible for maintaining safe operating parameters in the victim’s environment.” One of the first known examples of malware disabling safety systems occurred in 2017, when a tool known as Triton switched off safety equipment at a Saudi Arabian power plant. Since then, hackers have developed new ways to stealthily cripple safety monitoring technology. Because infrastructure operators rarely examine PLCs unless they noticeably malfunction, safety-compromising
The conversation about AI in cybersecurity has recently centered on capabilities like vulnerability discovery, exploit generation, and automated proof-of-concept development. It’s easy to see why: These tasks produce binary outcomes; a vulnerability either exists or it doesn't. That makes them useful for measuring model progress and demonstrating increasingly sophisticated cybersecurity capabilities. Vulnerability discovery matters to defenders. According to the Verizon 2026 Data Breach Investigations Report, vulnerability exploitation is now the most common initial access vector, accounting for 31% of breaches in the reporting dataset. This is a meaningful and growing share of the problem and a strong reason to continue advancing AI capabilities in this area. But it also means 69% of breaches begin through other paths. Credential abuse, phishing, social engineering, trusted relationships, and other forms of access remain central to the adversary playbook. A comprehensive evaluation framework should therefore measure not only whether AI can discover and exploit vulnerabilities, but also whether it can help defenders detect identity abuse, investigate suspicious activity, engineer effective detections, hunt for adversaries, and respond across the broader attack lifecycle. We believe effective AI for defense must be evaluated against the operational reality of security teams: the range of techniques adversaries use to gain initial access, the work required across the kill chain, and defenders’ most time-consuming tasks. Here, we explore some of these use cases. Detecting Adversary Behavior After Initial Access Once an adversary is inside, the defender’s work becomes more complex. Security teams must detect and triage suspicious activity across massive alert volumes, balancing signal and noise. Speed here determines whether the adversary is contained in minutes or operates on a network for a longer period of time. When suspicious activity is found, the focus shifts to investigation, which requires significant effort and expertise. Analysts must reconstruct events across endpoints, identities,
As concerns about cybercrime continue to grow in Mississippi, the state’s lieutenant governor has announced a new select committee focused on protecting government systems, providing more resources to law enforcement, and reviewing penalties for cybercriminals. Lt. Gov. Delbert Hosemann, a Republican who oversees the Senate, announced Thursday plans for the Senate Select Committee on Cybersecurity. “Too many Mississippians find themselves the victims of cybercrime,” Hosemann said. “Criminals are using technology to steal identities, target state assets, and exploit vulnerable individuals. We have a responsibility to ensure our laws keep pace with these evolving threats and provide law enforcement with the tools needed to protect Mississippians.” The select committee will be co-chaired by Sens. Bart Williams, R-Starkville, and Tyler McCaughn, R-Newton. Other members include Sens. Bradford Blackmon, D-Canton; Scott DeLano, R-Biloxi; Jeremy England, R-Vancleave; and Rod Hickman, D-Macon. The committee will begin holding hearings this fall before developing recommendations to be considered by the full Senate during the 2027 legislative session. The announcement comes as FBI data shows a sharp national increase in cybercrime losses in recent years. Americans reported more than $16 billion in losses from internet crime in 2024, a 33% increase from the previous year, according to the FBI. While Mississippi has one of the nation’s lowest rates of reported cybercrime, according to a recent data privacy survey, State Auditor Shad White released a report in October 2025 showing nearly one-third of state agencies were vulnerable to hacking after failing to meet cybersecurity assessment requirements.
Forescout found 22 internet-facing Rockwell Automation programmable logic controllers (PLCs) in cities hit by recent cyberattacks on US water utilities. Nineteen used the same mobile carrier network. Its August 3 scan counted 4,407 exposed Rockwell controllers worldwide, including 2,844 in the United States, but Forescout could not confirm any were compromised. That figure counts exposed controllers, not water utilities or confirmed victims. Forescout said the publicly described effects could be achieved without a vulnerability exploit: attackers changed IP addresses and set passwords on controllers that were already reachable, causing operators to lose visibility and, in some cases, control of connected equipment. Neither the government alerts nor Forescout's analysis explains how the attackers found, selected, or initially accessed their targets. Water and wastewater utilities in at least seven states have reported incidents since July 27, the FBI and EPA said in a July 30 public service announcement. The Hacker News found on August 6 that Forescout's post says the announcement confirmed at least 12 states, while the FBI page says seven. No agency has attributed the campaign. Whatever the final count, defenders can act now by taking the controllers off the public internet. Exposing EtherNet/IP on port 44818 creates an unauthenticated path that, depending on device configuration, lets an attacker identify a controller or write settings to it, Forescout said. Forescout found more than 70% of the US-based exposed controllers on large mobile carrier networks. The FBI and EPA recommend strong authentication, updates and logging for cellular modems, with remote access isolated through a private APN, VPN or similar architecture. A July 30 Censys snapshot found 4,148 exposed Rockwell/Allen-Bradley EtherNet/IP hosts, with Verizon Business, AT&T Mobility and T-Mobile USA accounting for 59%. The Censys and Forescout snapshots both exceed 4,100 hosts, but different platforms, queries and dates make the figures not
Meta AI Model Exploits Security Flaw During Testing On Wednesday, Meta said that a configuration error by Irregular, an independent company that conducts cybersecurity evaluations for Meta, inadvertently gave one of its AI models access to the open internet during a test. The model then exploited a vulnerability in a third-party service, Meta said, like previously disclosed incidents involving other AI developers. “Meta learned of this when Irregular notified us, and we are currently investigating and will issue a full retrospective once we have all the facts,” a Meta spokesperson said in an emailed statement to Benzinga. The model was Meta’s Muse Spark 1.1, which the company has positioned as a highly capable system for coding and agentic tasks, Reuters reported (via The Information). The report said the model accessed an unidentified company’s systems and modified part of its internal environment. Irregular Says It Was Not a ‘Sandbox Escape’ Irregular said the incident resulted from the same type of evaluation-environment problem that Anthropic disclosed last week. "[It was the] exact same evaluation-environment issue," an Irregular spokesperson told Reuters, adding that the event did not involve a "sandbox escape or a sophisticated cyber action." The company said there were no unresolved issues and that it was preparing a white paper outlining best practices for securely conducting AI cybersecurity evaluations. Meta Incident Adds to AI Safety Concerns The event follows similar incidents involving Anthropic and OpenAI. Anthropic’s incident was also linked to a configuration issue that exposed its models to the open internet. OpenAI’s case differed: The company said an AI agent independently exploited a previously unknown vulnerability to gain internet access during a cybersecurity evaluation. White House Pushes AI Cybersecurity Testing Price Action: Meta closed Wednesday’s session at $588.77, up 0.14% and gained another 0.45% in after-hours trading to $591.42, according
Meta says AI model accessed the internet and hacked another firm Facebook owner Meta says an issue during an evaluation by an independent testing company allowed one of its artificial intelligence (AI) models to connect to the internet and hack another organisation's system. The announcement follows recent incidents across the AI industry, including breaches by OpenAI and Anthropic models, that have raised cyber-security concerns. A Meta spokesperson told the BBC that it was investigating the hack that was caused by a "misconfiguration", which it described as similar to previously reported incidents at other firms. The incidents have prompted researchers and governments to call for tougher safeguards and more rigorous testing. Meta said the security trials were conducted by Irregular, the same AI security vendor that carried out tests for Anthropic's AI model that had gained access to three other companies' systems. An Irregular spokesperson said the Meta incident "is the exact same evaluation-environment issue that was already disclosed by Anthropic last week." Irregular is working on a report on how to securely run cyber-security tests involving AI agents, the firm's spokesperson told the BBC. Meta also said it will publish more information on the incident "once we have all the facts." In the past two weeks, AI leaders OpenAI and Anthropic have also reported incidents in which their models hacked into other organisation's systems during testing. ChatGPT-maker OpenAI said in a series of announcements that its agents attacked several publicly available services, including AI tools hub Hugging Face. OpenAI's disclosure prompted rival Anthropic to conduct its own checks, leading to the discovery that its Claude AI model had carried out similar attacks on several firms after a "misconfiguration" gave it access to the internet. Daniel Hulme, global chief AI officer of advertising firm WPP, told the BBC that such AI
Point Wild, a $US2 billion ($2.84 billion) cybersecurity business backed by private capital giant Warburg Pincus, has mandated two more brokers to boot up its blockbuster ASX debut. Loading... Sarah Thompson has co-edited Street Talk since 2009, specialising in private equity, investment banking, M&A and equity capital markets stories. Prior to that, she spent 10 years in London as a markets and M&A reporter at Bloomberg and Dow Jones. Email Sarah at sarah.thompson@afr.com Angira Bharadwaj is a co-editor of Street Talk. She covers IPOs, capital raises, mergers and acquisitions and other breaking news in Australia’s capital markets. Previously, she covered financial services, state, and federal politics. Send tips to @angirab.60 on encrypted messaging platform Signal. Email Angira at angira.bharadwaj@nine.com.au
Meta said Wednesday that one of its artificial intelligence models breached another company during cybersecurity testing, intensifying concerns over developers’ ability to contain increasingly capable AI systems following similar incidents involving Anthropic and OpenAI. The incidents at Meta and Anthropic resulted from configuration errors that inadvertently gave Anthropic’s models access to the open internet. In OpenAI’s case, an AI agent independently exploited a previously unknown vulnerability to reach the internet during cybersecurity testing. The breaches have highlighted growing concerns that advanced AI systems could pose new cybersecurity risks and are likely to intensify U.S. government efforts to improve AI safety as companies race to build more capable models. Some prominent AI leaders have argued that development should slow until stronger safeguards are in place. Meta said it was investigating an incident in which a configuration error by Irregular, an independent company that conducts cybersecurity evaluations for Meta, inadvertently gave one of its models internet access during testing. The model “exploited a security vulnerability in a third-party service, in a manner similar to previously reported instances with other companies,” Meta said in a statement. The Information, citing sources, reported that the model involved was Meta’s Muse Spark 1.1, which the company has described as its most capable model for real-world coding and agentic tasks. According to the report, the model breached an unidentified company’s systems and altered its internal environment. An Irregular spokesperson told Reuters that the incident was the “exact same evaluation-environment issue that was already disclosed by Anthropic last week” and did not involve a “sandbox escape or a sophisticated cyber action.” “There are no current open issues. Irregular is developing a white paper to share best practices for containment and securely running cyber evaluations,” the company said.
The Kenaitze Indian Tribe is facing its second week of disrupted internet services after a cybersecurity incident. The tribe first reported late last month on Facebook the tribe’s internet and phone service was down. Later that day, the tribe said it was “mitigating a risk” to its network that led to a prolonged computer outage. The day after the disruption was reported, the tribe said it would still be able to offer services through its behavioral health and childcare programs. The tribe announced limited services at its Dena’ina Wellness Center and said it would provide onsite meals only at its Tyotkas Elder Center. Last Friday the tribe announced that a cybersecurity incident was behind the ongoing outages. In a social media update, the tribe wrote that it is “aware that an unknown actor has claimed responsibility for the incident, and these claims are part of our investigation.” The tribe’s communications manager declined an interview request and said no additional information will be provided. The tribe has established temporary phone numbers for services, including: - Dena’ina Wellness Center - Primary care: 907-513-4438 - Dental: 907-513-4434 - Behavioral Health: 907-513-1758 - Education: 907-513-7512 - Kahtnu Area Transit and other transportation: 907-513-4458 - Na’ini Family and Social Services: 907-690-0826 The tribe’s K’beq’ Cultural Heritage Center and Educational Fishery are not impacted by the cybersecurity incident. Updates on the outage are being shared by the tribe on social media and on its website.
Meta’s AI model follows rivals in revealing hacks of outside systems Meta joins rivals OpenAI and Anthropic in disclosing AI hacking during cybersecurity testing. Meta has said that its AI model hacked another company during cybersecurity testing, following on from recent similar announcements by rival companies Anthropic and OpenAI. Meta said on Wednesday that one of its AI models – reported to have been Muse Spark 1.1 – made changes to the unnamed hacked company’s internal systems after accessing the public internet because of an error in the setup of the “sandbox” testing environment by independent testing company Irregular. Recommended Stories list of 3 items - list 1 of 3SpaceX shares slide on the heels of first quarterly report - list 2 of 3AI models attempted ‘unsanctioned’ cyberattacks in tests, watchdog says - list 3 of 3Elon Musk’s SpaceX reports losses but less than expected A “sandbox” is an isolated internal virtual testing environment, which has no access to the internet. Last week, Anthropic said that its Claude AI model hacked into the systems of three organisations during testing that was supposed to keep it isolated from the internet. Anthropic said a misconfiguration had allowed Claude models to reach the internet. The company said it discovered the incidents after reviewing 141,006 test sessions. The announcement came days after rival OpenAI first revealed that its models improperly accessed the internet and went rogue during security testing. OpenAI and Anthropic have both released their most powerful models this year, known as Sol and Mythos, respectively. The AI Security Institute (AISI), the UK’s AI watchdog, warned in a report released on Tuesday that OpenAI’s GPT-5.6-Sol and Anthropic’s Claude Mythos 5 employed previously unseen levels of deception to carry out “sustained, potentially harmful activity” during a routine safety evaluation.
Aug 5 (Reuters) - Meta (META.O) said on Wednesday one of its AI models hacked another company during cybersecurity testing, fanning concerns about how developers can contain increasingly capable AI systems after similar incidents at rivals Anthropic and OpenAI. The incidents at Meta and Anthropic stemmed from configuration errors that inadvertently gave Anthropic's models access to the open internet. In OpenAI's case, an AI agent independently exploited a previously unknown vulnerability to reach the internet during cybersecurity testing. Sign up here. The breaches highlight growing concerns that advanced AI systems could pose new cybersecurity risks and will likely intensify U.S. government efforts to improve AI safety as companies race to develop more capable models. Some prominent AI leaders have argued that development should slow until stronger safeguards are in place. Meta said it was investigating an incident in which a misconfiguration by Irregular, an independent company that conducts cybersecurity evaluations for Meta, inadvertently gave one of its models internet access during a testing. The model "exploited a security vulnerability in a third-party service, in a manner similar to previously reported instances with other companies," Meta said in a statement. The Information, citing sources, reported that the model involved was Meta's Muse Spark 1.1, which the company has touted as its most capable model for real-world coding and agentic tasks. The report said the model breached an unidentified company's systems and altered its internal environment. A spokesperson for Irregular told Reuters the incident was the "exact same evaluation-environment issue that was already disclosed by Anthropic last week" and did not involve a "sandbox escape or a sophisticated cyber action". "There are no current open issues. Irregular is developing a white paper to share best practices for containment and securely running cyber evaluations," Irregular said. CONCERNS ABOUT CYBER RISKS The recent breaches
Cybersecurity researchers have flagged an evolution of the EtherHiding blockchain-based command-and-control (C2) technique that conceals the C2 server IP address inside a made-up destination address of a completely empty Ethereum transfer. The new dead drop resolver approach, observed in two trojanized npm packages "bianira-ui" and "fluid-type-ui," has been codenamed NullReceiver by OpenSourceMalware, which has described it as a "deliberate improvement on EtherHiding." The activity has been linked to North Korea. The packages are currently no longer available for download from npm. However, statistics show that they have been downloaded a few hundred times since they were first published on July 28, 2026 - - bianira-ui (109 downloads), uploaded by an npm user named "npmuser1101" - fluid-type-ui (587 downloads), uploaded by an npm user named "npmuser3002" EtherHiding was first publicly documented by Guardio Labs in October 2023 as a covert approach that involves embedding nefarious code within a smart contract on a public blockchain like BNB Smart Chain (BSC) or Ethereum. The technique heralded the "next level of bulletproof hosting" as it improves operational resilience in the face of takedowns. The use of EtherHiding by North Korean hacking groups was detailed by Google Threat Intelligence Group (GTIG) late last year in connection with Contagious Interview, a long-running campaign that aims to deceive potential targets by approaching them on LinkedIn with lucrative job opportunities and asking them to complete an assessment that leads to malware deployment. The latest development indicates that the threat actors are further refining their tactics and making it difficult for defenders to detect. "Instead of hardcoding a C2 address or hiding it in transaction calldata (as in EtherHiding), NullReceiver encodes the C2 IP directly in the bytes of the recipient address of a zero-value, zero-data Ethereum transfer," security researcher Paul McCarty said. "The malware looks up the attacker's
AWWA urges expanded U.S. cybersecurity support, measures WASHINGTON, Aug. 5, 2026 /PRNewswire/ -- The American Water Works Association (AWWA) today sent a letter to U.S. Congressional leaders urging strong federal support for water utilities following cyber attacks on multiple water systems in recent days. "Recent cybersecurity attacks on water utilities across multiple states underscore the need to further support drinking water and wastewater utilities as critical infrastructure," AWWA CEO David LaFrance wrote in a letter to U.S. House and Senate leadership. "Water utilities are often out of sight and out of mind – historically under-resourced compared to other critical infrastructure sectors – despite their central role in daily life, the economy, and public health." The letter encouraged federal funding for critical cybersecurity needs, expansion of eligibility under existing programs to include cybersecurity training for utilities of all sizes, information-sharing among key agencies, and a collaborative process, with input from water sector and cybersecurity experts, in developing sensible regulation that accounts for the variability in size and complexity of all water systems. AWWA expressed support for cybersecurity measures included in the Senate's Water Resources Development Act of 2026 (S. 4949), including: - Reauthorization of the Midsize and Large Drinking Water System Infrastructure Resilience and Sustainability Program. - Cybersecurity training as an eligible use of funds in: - the Drinking Water Infrastructure Resilience and Sustainability Program and, - the Innovative Water Infrastructure Workforce Development Program. - A program to design, construct, or maintain digital infrastructure technology, including through cybersecurity risk mitigation training and technical assistance, for rural water systems and systems in areas experiencing critical water supply needs. - A program to encourage participation in the communications and intelligence sharing organization WaterISAC. AWWA also asked Congress to consider additional measures, including: - Water Risk and Resilience Organization Establishment Act (H.R. 2594), which
TAMPA, Fla. — High schools across Tampa Bay are adding new Advanced Placement courses in cybersecurity and business this year through the AP Career Kickstart program. The program is an effort designed to connect high school coursework with real-world job skills. At Jesuit High School, more than 100 students are enrolled in the new elective, AP Business with Personal Finance. Senior Bryce Besece said he is looking forward to taking the course. “I feel this is a class that’s going to give me the fundamentals and the background to go succeed as soon as I can get into college,” Besece said. David O’Sullivan, Jesuit’s Math Department chair, is teaching the class. Before becoming an educator, O’Sullivan spent nearly 15 years in accounting. It’s one of the subjects he will be teaching as part of AP Business with Personal Finance. “It’s accounting, it’s finance, it’s marketing, it’s management, entrepreneurship,” O’Sullivan said. “If a student, junior or senior, is considering business, any kind of business, marketing or management, it’s going to let them dip their toe in the water and get a taste of it, a flavor and say, ‘Yes, this is something that I think I may enjoy or I want to get in a different direction.’” According to the College Board, business is the most popular major in college, but only 20% of students take a business course in high school. The AP Business with Personal Finance course was created as part of the AP Career Kickstart program to help address that gap. O’Sullivan said the class is not only for students planning to major in business. He said it will also cover practical financial topics students can use after high school. “We need people to understand how credit works, loans, because students are going to leave college with student
Financial institutions are not short on cybersecurity policies, frameworks, or regulatory requirements. Turning those requirements into a living risk management program can be challenging. Organizations need a program that can keep pace as technology environments expand, cloud adoption grows, third parties are added, and external exposures change. Especially as the threat landscape continues to evolve. Bank Negara Malaysia’s current Risk Management in Technology, or RMiT, Policy Document reflects that reality. Issued and effective on 28 November 2025, it establishes minimum requirements for managing technology and cyber risk across governance, technology operations, cybersecurity, digital services, third-party service providers, cloud services, audit, assurance, and gap analysis. It also makes clear that larger, more complex, highly digitalized, or highly interconnected institutions are expected to adopt more robust controls proportionate to their exposure. Bitsight can help financial institutions operationalize several of these expectations by providing continuous, outside-in visibility into their cybersecurity posture and the broader digital and third-party ecosystem around them. Institutions still need to enforce controls, policies, security operations, internal testing, and regulatory responsibilities. Bitsight provides an intelligence and measurement layer that can help teams identify risk, prioritize action, monitor change, and communicate progress. RMiT raises the bar for continuous monitoring Traditional technology risk programs often rely heavily on periodic reviews. An organization completes an assessment, collects documentation, records the results, and repeats the process later. Those activities remain important, but they cannot show what happens between assessments. Threats don't wait for assessment intervals. By the time the next formal assessment takes place, the organization’s actual exposure may look very different. As vendors and technology continue to evolve, it is vital to ensure your security posture evolves with those changes. RMiT requires financial institutions to include continuous monitoring within their Technology Risk Management Framework so material risks can be detected and addressed in
Search, find and engage with others who are serious about tech and business. Follow and be a part of discussions about tech, finance and media. Premium advertising opportunities for brands Team access to our exclusive tech news Journalists who break and shape the news, in your inbox Catch up on conversations with global leaders in tech, media and finance Explore our recent partner collaborations Premium advertising opportunities for brands Team access to our exclusive tech news Explore our recent partner collaborations
LAS VEGAS — OpenAI models’ autonomous attacks on other companies represent an urgent warning to the AI industry about the need for stronger model development safeguards, employees from the frontier label said on Wednesday. “This is a pivotal moment both for our company as well as the AI industry as a whole,” Michael Dalton, a member of OpenAI’s technical staff, said during a presentation at the Black Hat 2026 cybersecurity conference here. OpenAI stunned the world in late July when it announced that two of its models broke out of their testing environments and used zero-day vulnerabilities to hack into the networks of other companies, including the AI tool library Hugging Face. The disclosure, followed shortly thereafter by a similar announcement from Anthropic, reignited fears about the dangers of powerful and largely unregulated AI models. Speaking at Black Hat, Dalton said that “numerous teams are dropping everything” to improve OpenAI’s ability to detect and prevent similar incidents in the future. The company has slowed down its research and “dramatically scal[ed] up the monitoring of our AI agents.” While the autonomous hacks were effectively innocent mistakes, OpenAI employees described them as harbingers of a grim future, one in which companies face constant, sophisticated attacks by malicious actors using powerful open-source models that no frontier lab can contain. “We believe this is a watershed moment for computer security as an industry,” Dalton said. “AI orchestrated, fully automated offensive attacks are real now.” The Hugging Face incident, he added, represents “a glimpse into the near future of what attacks will look like for our industry.” Defenders need to accelerate their work to keep up with the anticipated surge in attack sophistication, Dalton argued. That could involve experimenting with defense-focused AI models, as well as doubling down on basic security measures that are newly