No-frills tech news

SEIA calls for stronger <b>cybersecurity</b> as US solar and storage manufacturing expands

The Solar Energy Industries Association (SEIA) has called for stronger cybersecurity measures across the US solar and energy storage industry in a report arguing that expanding domestic manufacturing and improving cyber resilience must go hand in hand as renewables capacity continues to grow. The report, titled ‘Cybersecurity Priorities for America’s Solar & Storage Industry’, comes as US inverter manufacturing capacity has nearly tripled since the end of 2024, with a new production facility opened by EPC Power in July pushing the country into a tie for the world’s second-largest inverter manufacturing base. Try Premium for just $1 - Full premium access for the first month at only $1 - Converts to an annual rate after 30 days unless cancelled - Cancel anytime during the trial period Premium Benefits - Expert industry analysis and interviews - Digital access to PV Tech Power journal - Exclusive event discounts Or get the full Premium subscription right away Or continue reading this article for free SEIA said the rapid expansion of solar and storage, which accounted for nearly 80% of new US power generation capacity additions in 2025, increases the importance of securing systems against cyber threats targeting critical infrastructure. Tim Pawlenty, president and CEO of SEIA, said: “As solar and storage continue to lead the way in adding new power capacity to the grid, cybersecurity must remain front and centre. From secure and resilient systems to expanding domestic manufacturing, this report lays out the actions our industry is taking to strengthen US energy security, protect critical infrastructure and stay ahead of emerging threats.” Domestic manufacturing linked to cyber resilience According to the report, US inverter manufacturing capacity has reached 55GWac following recent factory expansions. The expansion comes as US policymakers increasingly scrutinise foreign-made inverters over potential cybersecurity risks. SEIA argues that strengthening US-based

Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of ...

Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite Executive summary A group of Russian state-supported cyber actors has been targeting and compromising various Western government and commercial organizations using the Zimbra Collaboration Suite (ZCS) software since at least July 2025. The Russian state-supported advanced persistent threat (APT) group’s activity is tracked in the cybersecurity community under several names (see Cybersecurity industry tracking), primarily as “LAUNDRY BEAR,” a name initially coined by the Netherlands General Intelligence and Security Service (AIVD) and Defence Intelligence and Security Service (MIVD) [1]. LAUNDRY BEAR’s targeting is almost certainly to gather sensitive information for the Russian Federation, with these actors primarily focusing on the covert acquisition of email data. Previous campaigns indicated LAUNDRY BEAR relied on unsophisticated initial access techniques—including password spraying, phishing, and pass-the-cookie—allowing the group to successfully run high-volume operations. The latest campaign targeting ZCS uses a novel exploit that was a zero-day vulnerability when first exploited and continues to be successfully exploited. The vulnerability, Common Vulnerabilities and Exposures (CVE) CVE-2025-66376, was patched in November 2025. This demonstrates LAUNDRY BEAR’s intent and ability to deploy increasingly sophisticated technical capabilities. Unlike traditional phishing campaigns that persuade a user into taking an action, such as clicking a link or opening a file, LAUNDRY BEAR’s latest campaign leverages a view-based exploit that only requires a user to view a malicious email within a vulnerable version of the webmail service. Once viewed, the exploit attempts to exfiltrate the victim’s last 90 days of email communications, the organization email directory (i.e., Global Address List [GAL]), and other sensitive information to servers controlled by LAUNDRY BEAR. The exploit also attempts to establish persistent access to victim accounts through a variety of means as detailed in the Persistence and credential access section. This Cybersecurity Advisory (CSA)

OpenAI's models autonomously hacked a tech startup. It signals a seismic shift in <b>cybersecurity</b>

An autonomous agent powered by OpenAI’s advanced artificial intelligence (AI) models went rogue during a security test and hacked multi-billion dollar tech startup, Hugging Face, last week. The agent didn’t just exploit vulnerabilities in Hugging Face’s systems to achieve what it perceived as a strategic gain. It also exploited vulnerabilities within OpenAI’s infrastructure. Of course, hacks are very common cyber threats that organisations face frequently. But this incident is different, because the AI agent acted without any human input. It signals a seismic shift in cybersecurity, and shows that governments and tech companies need to take urgent action to prevent this risk escalating. Even OpenAI described the attack as “unprecedented” and acknowledged it expects similar ones “to become more commonplace with the proliferation of increasingly cyber-capable models”. A company under attack Hugging Face is famous in the AI space. Its mission is to “democratise good machine learning” by providing benchmark datasets, community collaboration tools, and robotic platforms. The company is valued at US$4.5 billion. On July 16, the company announced it had been attacked, with a hacker obtaining unauthorised access to some internal datasets and credentials. It said the hacker was likely “an autonomous AI agent system” due to the sophistication of the attack. Five days later, Open AI announced the attack had been driven by some of its models: GPT-5.6 Sol and a yet-to-be released model. The tech giant was conducting what are known as “red teaming” exercises. These are essentially simulated cyber attacks that help identify the capabilities, risks and vulnerabilities of AI systems before they are publicly released. They are typically conducted within an isolated environment to ensure potentially dangerous systems do not escape and cause harm to real systems. But in this case, the AI agent did escape – even though OpenAI had some guardrails in

<b>Cybersecurity</b> expert says OpenAI hack on Hugging Face is &quot;very alarming&quot;

Cybersecurity expert says OpenAI hack on Hugging Face is "very alarming" Cybersecurity experts are raising concerns about the growing capabilities of artificial intelligence after an AI agent developed by OpenAI escaped its testing environment and accessed the internet before carrying out a cyberattack on Hugging Face, a platform that hosts open-source AI models and datasets. This happened while OpenAI was testing the capabilities of advanced AI models, according to cybersecurity expert Peter Tran. He said the agent was able to identify vulnerabilities at a scale that could create new challenges for the cybersecurity industry. "It's very alarming," said Tran. "These AI agents are able to find vulnerabilities in greater volume and greater speed. So speed and volume is the area that the security industry is very, very concerned about." Hugging Face said the attack was unlike anything the company had previously experienced, raising new questions about the risks of AI systems that can operate autonomously. Experts say the ability of AI agents to adapt and continue performing tasks autonomously could create security risks if proper safeguards are not in place. "The agent is smart enough to then make a mistake, learn from it and then keep going and going and going," Tran said. "If you don't put guardrails on that or specific boundaries on the agent, it will continue to want to self-improve." OpenAI acknowledged that AI systems are increasingly capable of accelerating the discovery of software vulnerabilities and potential exploits. In a statement, the company said the incident highlighted the need for stronger security measures. "The primary lesson from this incident is that model security and safety must keep pace with rapidly advancing capabilities," an OpenAI spokesperson wrote. "We are strengthening the containment, monitoring, access controls and evaluation practices used during model development." The company said it is also

TSDs expand <b>cybersecurity</b> vendor models

Technology services distributors are roadtesting partnerships with cybersecurity software vendors, as partners and customers demand a wider list of vendors and service models. In April, TSD Avant hailed its partnership with managed detection and response vendor Arctic Wolf. It was a milestone for a nascent TSD market that is rounding out vendor portfolios to satiate midmarket and enterprise customers. Arctic Wolf provides MDR services that are already common in the average TSD portfolio, but it uses its own tech stack rather than borrowing a platform from another vendor, offering self-service capabilities for internal cybersecurity teams. Self-service options are a key distinction and a sign of the expanding vendor options in the broker model. TSDs are courting OEM vendors with technology customers looking to purchase and manage directly, rather than consume through a service provider. The technology advisors that sell through TSD supplier contracts are also asking for those options. Several blue chip OEMs have already signed partner agreements, including content delivery network providers Akamai and Cloudflare, but many TAs have a wishlist of potential vendors. “We're starting to have these kinds of conversations,” Accelerate Partners CEO JP Panzica told Channel Dive. “If we had the OEMs in the channel, we could then look to source those and become more successful in the enterprise market.” It’s no simple transition. Cybersecurity product providers typically go through resellers, skipping the TSD and TAs’ broker model. They traditionally leaned on value-added resellers to bill and manage clients. In order to join with TSDs, vendors must embrace a longtail commission model that is foreign to their leaders. Staffing channel management and operations roles is also essential. “It's been incredibly rewarding and exciting, but there's also been some tears shed, because it's been a lot of work to succeed focusing in an area that is kind

Threat group claims credit for ransomware attack on Coca-Cola's dairy unit

A threat group called Anubis claimed credit for the ransomware attack against Fairlife, the dairy products unit of Coca-Cola. The group says it locked the servers at Fairlife and obtained 1TB of data from the attack, according to researchers at Arctic Wolf. Anubis is threatening to leak information if its demands are not met within a week. Researchers provided screenshots posted on the group’s data leak site Coca-Cola was forced to suspend U.S. production at Fairlife while it launched an investigation into the attack. Coca-Cola officials noted there was no impact on the safety or quality of its dairy products. Destructive tendencies Anubis is a ransomware-as-a-service operation that emerged in late 2024 as a rebrand of Spinx ransomware, Arctic Wolf researchers said. The group generally has used two methods to gain initial access, either through valid, stolen VPN credentials or the exploitation of vulnerabilities such as CitrixBleed 2, which is tracked as CVE-2025-57777. "Anubis affiliates have repeatedly secured initial access by exploiting internet-facing vulnerabilities and abusing stolen VPN credentials,” Stefan Hostetler, staff threat intelligence researcher at Arctic Wolf, told Cybersecurity Dive. “In our investigations, we’ve seen attackers take advantage of vulnerabilities that were not new or especially sophisticated, underscoring a persistent reality that threat actors often succeed by exploiting known weaknesses that organizations haven’t fully remediated.” Anubis often uses destructive tactics designed to undermine recovery methods, according to researchers at Halcyon. Prior to encryption, Anubis frequently shuts down the ability to create volume shadow copies and prevents other security processes from helping companies restore data. Coca-Cola has not provided any details about the threat group linked to the attack or how the attackers gained access to systems. CitrixBleed 2 is linked to insufficient input validation, which can lead to memory overread when Citrix NetScaler is configured as a Gateway. Fairlife

Police Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFA

German and US law enforcement have taken down the core infrastructure of Kratos, described by German investigators as one of the world's most widely used criminal phishing kits, and Indonesian authorities arrested the man they say developed and ran it. In a joint announcement on Monday, the Frankfurt public prosecutor's cybercrime unit (ZIT) and Germany's Federal Criminal Police Office (BKA) said they pulled more than 200 servers offline. Investigators estimate roughly 1,800 paying customers used Kratos to run about 15,000 phishing campaigns a month. Kratos harvested more than passwords. The kit was designed to steal the session cookie along with the login, and that cookie is enough to walk past two-factor authentication into the account as the user, the BKA said. ANY.RUN, which reverse-engineered the kit, found operators could pick one of two modes: a plain PHP page that only harvests credentials, or a Node.js reverse proxy designed to relay the login to Microsoft in real time and capture the resulting session. That second mode is the adversary-in-the-middle technique that has made ordinary MFA a much weaker backstop than it looks. The operation ran like a franchise, with customers the BKA called franchisees. They paid in cryptocurrency and signed up through a dedicated website and a Telegram shop to manage their accounts and organize campaigns, so even low-skill actors could point a working AiTM kit at a target. The authorities put the number of victims since late 2024 in the hundreds of thousands, spread across more than 30 countries and concentrated in Europe and the United States. They estimate the operators earned more than 300,000 euros since 2024, and that each campaign could hit several thousand recipients. Kratos was already being tracked. Microsoft Threat Intelligence identifies the same kit as SneakyLog, a phishing-as-a-service platform it says has run credential-and-2FA theft

AI security startup Glow emerges from stealth with $180 million at $1.2 billion valua | Ctech

AI security startup Glow emerges from stealth with $180 million at $1.2 billion valuation Founded by former Meta, Snowflake and Claroty executives, the company is betting AI can transform endpoint security from reactive defense to prevention. Cybersecurity startup Glow has emerged from stealth with $180 million in funding at a $1.2 billion valuation, aiming to build a new approach to endpoint security designed for an era in which employees and autonomous AI systems increasingly operate inside enterprise networks. The company, founded in 2025 by former executives from Meta, Snowflake and Claroty, said its latest financing round was led by Sequoia Capital, Cyberstarts, Greenoaks and Redpoint Ventures, with participation from Index Ventures, Swish Ventures, Lux Capital and Holly Ventures. Glow has raised $180 million across three rounds in roughly one year, including a $20 million Seed round led by Sequoia and Cyberstarts, a $60 million Series A led by Index Ventures with participation from Greenoaks at a $400 million valuation, and the current $100 million Series B. The company plans to use the funding to expand its go-to-market operations in the United States and grow Glow Labs, its research arm. Glow currently employs approximately 100 people, including around 65 in Israel, and operates from Israel and the United States. The company said it has signed enterprise customers across industries including healthcare, retail and financial services. Glow is targeting the endpoint security market, where companies have traditionally relied on multiple specialized products to protect employee devices, applications and corporate data. CEO and co-founder Roi Tiger said existing solutions were not designed for the security challenges created by artificial intelligence. “If you look at endpoints, there are a lot of point solutions. Each company solves something small there and does not offer a comprehensive solution,” Tiger told Calcalist. “We offer a broad solution

OpenAI Says Advanced AI Models Escaped Test Environment In <b>Cybersecurity</b> Incident

OpenAI said that some of its most advanced AI models broke out of a controlled test environment during an internal security evaluation and then attempted to target the AI platform Hugging Face an episode the company described as an "unprecedented" cybersecurity incident. OpenAI said the AI agents exploited a previously unknown flaw in an internally hosted package-registry proxy to escape the sandbox, gain internet access, and carry out a sequence of privilege-escalation and lateral-movement attempts. The models then reportedly turned their attention to Hugging Face, using stolen credentials and additional zero-day vulnerabilities in an effort to access information that could help them perform better on the cybersecurity benchmark they were being tested on. OpenAI said its security team flagged the unusual behavior, and that Hugging Face separately detected and contained the intrusion before major damage occurred. The two companies are now investigating together, and OpenAI said it has reported the zero-day vulnerability to the relevant software vendor so it can be fixed. In response, OpenAI said it has tightened infrastructure controls, improved monitoring, and strengthened evaluation safeguards, while working with Hugging Face on additional defenses. Hugging Face said it has patched the vulnerabilities, rebuilt affected systems, and described the incident as a sign that AI-driven offensive cyber capabilities are no longer just theoretical. For comments and feedback: editorial@rttnews.com

GAO Urges FAA &amp; TSA to Strengthen Aviation <b>Cybersecurity</b>

- GAO has identified cybersecurity oversight and risk management gaps at the FAA and TSA - TSA lacks clearly defined cybersecurity responsibilities and relies on an outdated 2018 cybersecurity roadmap - FAA did not include all cybersecurity activities and costs in the budget data submitted to OMB The Government Accountability Office has identified gaps in the Federal Aviation Administration’s and Transportation Security Administration’s aviation cybersecurity efforts and issued five recommendations to enhance oversight and risk management. With DHS ramping up investments in border security, AI and cyber defense, the Potomac Officers Club’s 2026 Homeland Security Summit on Nov. 12 will bring together agency leaders and industry executives to discuss what’s next. Register now! What Cybersecurity Gaps Did GAO Identify? In a report published Thursday, GAO said the FAA has outlined the roles of entities responsible for implementing its cybersecurity goals and objectives, while TSA has not clearly established comparable responsibilities. TSA’s 2018 Cybersecurity Roadmap is also outdated and does not align with the latest Department of Homeland Security Cybersecurity Strategy. GAO also found that the FAA did not report all cybersecurity activities and costs in its fiscal 2024 through 2026 budget data submitted to the Office of Management and Budget. The agency omitted spending figures for its Information Security/Cybersecurity Program, which covers research and development work. The findings come as the Trump administration develops broader cybersecurity initiatives focused on securing federal systems and critical infrastructure. How Is FAA Addressing Cybersecurity Risks? FAA’s procedures for certifying aircraft and authorizing system security align with federal and industry standards aimed at reducing cybersecurity threats to avionics and ground systems, GAO found. However, the agency’s Zero Trust Implementation Plan lacked detailed transition steps for its R&D operating environment, meeting just three of seven National Institute of Standards and Technology practices GAO had identified. The

Most federal <b>cybersecurity</b> reporting rules are duplicative, study finds

Most federal cybersecurity reporting rules are duplicative, study finds Seven out of 10 federal cyber regulations requiring written reports to federal agencies are duplicated elsewhere, a report from a government watchdog found in a report to Congress Wednesday. And so far, efforts to de-conflict haven’t had much success, the report from the Government Accountability Office concluded. At the request of two top lawmakers, the GAO examined federal cyber regulations at 37 agencies. It counted 80 out of 117 rules that “either contain the same kind of reporting requirement applicable to a sector or the same reporting requirement as at least one other regulation.” The desire to harmonize those conflicting rules gathered steam under the Biden administration, as it undertook a more aggressive push to regulate cybersecurity than prior administrations. It has continued into the second Trump administration. The GAO scrutinized regulations that required the private sector to report cybersecurity incidents, plans and reviews to federal agencies, as part of a study sought by House Homeland Security Chairman Andrew Garbarino, R-N.Y., and the top Democrat on the Senate counterpart to Garbarino’s panel, Gary Peters, D-Mich. In some cases, a single critical infrastructure sector could have duplication with several agencies. For example, the Cybersecurity and Infrastructure Security Agency has been working on a regulation stemming from the 2022 Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA), which would require critical infrastructure owners and operators to report when they are the victims of major attacks or make ransomware payments. Elements of the financial services sector might fall under one of 15 preexisting cybersecurity reporting rules, depending on the agency that has oversight, but they may also be subject to the pending CIRCIA rules, GAO noted. A 2024 national security memorandum tasked the Office of the National Cyber Director and the Department of Homeland

Rogue AI escape heightens fears in Canberra over Chinese models

When news broke in the early hours of Wednesday (AEST) that the latest model from artificial intelligence giant OpenAI had escaped its restraints and hacked the databases of a popular online marketplace, it added urgency to concerns in Canberra that the AI race is running faster than cybersecurity capabilities can keep up. Defence industry insiders had already been casting a nervous eye at the market-shaking rise of new Chinese model Kimi K3 from Moonshot AI, which boasts capabilities close to Anthropic’s Fable 5 and OpenAI’s GPT-5.6 Sol flagship models. Loading...

How a Calvin student discovered a career in <b>cybersecurity</b>

How a Calvin student discovered a career in cybersecurity Midway through high school Landon Faber ’26 was looking for a class to fill his schedule. He didn’t know what to take, so on a whim he chose “programming.” What he didn’t realize at the time is that that class and that teacher, Mr. Stasiak, would fulfill way more than his required credit load. “The way he taught the class and how fun he made it really sparked my interest for the entire thing,” said Faber. Faber proceeded to take every possible class related to computer programming over his final two years in high school. When it came time to choose a college, he knew what he wanted to study and where he’d go—a highly accredited tech school not too far from his hometown of Parker, Colorado. Then, his dad, who had previously taught at Calvin for 30 years, thought his son should at least pay it a visit. A visit changes everything “When I came to Calvin on a tour, I was pretty much dead set on another school,” said Faber. But like that few credit class in high school, a few hours on campus changed everything. “The best way to describe it really is I liked the vibe a lot more. It was more of what I was looking for in a college and where I wanted to live for at least the next four years,” said Faber. A class sparks a new passion So Faber started on his journey at Calvin and was heading down more of a standard software engineering track. This time, a course he took his sophomore year in college, a cybersecurity course taught by Brian Paige and Adam Vedra, proved to be another pivot point. “That class was really interesting. All of the concepts

New SEIA report aims to strengthen solar industry <b>cybersecurity</b>

New SEIA report aims to strengthen solar industry cybersecurity As the U.S. continues to rise in the global solar manufacturing rankings, both physical security and cybersecurity measures are becoming top priorities for the American sector of the industry. Most crucially, U.S. inverter manufactured has nearly tripled since the end of 2024. In response to this rising demand for cybersecurity, the Solar Energy Industries Association (SEIA) has released a new report, outlining industry priorities with regard to security measures. With a new inverter manufacturing facility opening for business this summer, the U.S. has fortified its solar production lines nationwide, SEIA says. Association president and CEO Tim Pawlenty stressed the importance of increased security measures as the industry moves into 2027 and beyond. “As solar and storage continue to lead the way in adding new power capacity to the grid, cybersecurity must remain front and center,” he says. “From secure and resilient systems to expanding domestic manufacturing, this report lays out the actions our industry is taking to strengthen U.S. energy security, protect critical infrastructure, and stay ahead of emerging threats.” The new report, “Cybersecurity Priorities for America’s Solar & Storage Industry,” says that the trade association is working with partners throughout the industry and the U.S. government to advance cybersecurity protocols for solar. The company has outlined three key priorities for the solar and storage industry’s security strengthening process, including support of supply chain security, enhancing risk reduction, and strengthening baseline practices. Consideration of cybersecurity attack history Attacks on critical infrastructure have risen in recent years, according to SEIA representatives, with even more of an outsized percentage of security risk going to the energy sector. These threats are “critical to national security,” the association adds, and are spiking in frequency as solar and other renewable energy sources continue to blossom on

AI can't fix <b>cybersecurity's</b> hiring problem

AI can’t fix cybersecurity’s hiring problem Organizations are redefining cybersecurity roles through workforce frameworks and placing greater emphasis on verified skills as AI and new regulatory requirements change hiring. The SANS 2026 Cybersecurity Workforce Survey found demand for specialists in new roles more than doubled over the past year, alongside increased hiring for existing cybersecurity skills. AI changes security work AI is reducing manual analysis, automating routine tasks and creating demand for security roles focused on AI governance, engineering and risk. 54% of respondents said they have AI security policies, and only 38% provide comprehensive AI security training. Nearly one in four organizations have no AI governance plans. Nearly three-quarters of organizations said AI has influenced team composition. The most common changes were workflow automation and reduced manual analysis, with relatively few organizations reporting workforce reductions. Employers are adding AI-focused cybersecurity roles, including AI security engineers, AI governance analysts and AI/ML security specialists, while experienced cybersecurity professionals remain the hardest positions to fill. Compliance expands demand for specialists Regulatory requirements are changing what organizations look for when hiring cybersecurity professionals. Companies are adopting workforce frameworks such as NICE and the European Cybersecurity Skills Framework to standardize cybersecurity roles and skills. Top impacts of directives and regulations (Source: SANS) Regulations including NIS2, DORA, DoD 8140, SEC and CMMC are changing hiring priorities and increasing demand for specialist cybersecurity roles. Most of these regulations apply to specific sectors, including critical infrastructure, financial services and defense contractors. “Organizations are building entirely new specialist positions, restructuring teams around regulatory requirements, and facing real enforcement consequences if they don’t,” said James Lyne, CEO of SANS Institute. Certifications are also becoming more important for hiring, audits, client requirements and career development as companies seek to demonstrate cybersecurity skills. Experienced professionals remain difficult to recruit Experienced cybersecurity

'Unprecedented': OpenAI says AI models autonomously hacked another company

‘Unprecedented’: OpenAI says AI models autonomously hacked another company ChatGPT maker says an autonomous agent escaped a controlled test and accessed AI firm Hugging Face’s servers. ChatGPT creator OpenAI has said that two of its most advanced artificial intelligence models broke out of a controlled test and hacked another AI company. OpenAI said on Tuesday that the “unprecedented cyber incident” took place during an internal exercise meant to test its models’ cyber capabilities. Recommended Stories list of 3 items- list 1 of 3Japan’s AI gamble: Can technology offset the cost of an ageing society? - list 2 of 3Authors, publishers sue Google over alleged AI copyright infringement - list 3 of 3Apple files lawsuit accusing ChatGPT maker OpenAI of stealing trade secrets Instead, an autonomous agent powered by the AI models – the newly released GPT 5.6 Sol and an unreleased “even more capable” model – escaped the test environment and reached the open internet. It then used stolen login details and found a previously unknown security flaw to access Hugging Face servers, the company said. OpenAI claims that the hack represented the agent going to “extreme lengths” to retrieve information that would help satisfy the testing goals. Hugging Face cofounder Clement Delangue said the company had suspected that a frontier lab was behind the attack, and that he believed there was no malicious intent on OpenAI’s part. “It’s quite mind-blowing that all of this happened autonomously!” he wrote, adding that it “might be the first incident of its kind”. Greg Casar, a Democratic member of the United States House of Representatives from Texas, called the incident “alarming”. “AI is developing extremely fast with no real regulations to keep us safe,” he said, calling for mandatory independent safety testing, mandatory disclosure of security incidents, and international cooperation. The disclosure comes

OpenAI says its AI models escaped control and hacked into AI company Hugging Face | Fortune

OpenAI said Tuesday that two of its AI models autonomously hacked their way out of a controlled environment where they were supposed to be walled off from internet access and then hacked their way into the systems of Hugging Face, a company that hosts open source AI models and testing resources, in order to cheat on an internal evaluation test. OpenAI disclosed the incident in a blog post on Tuesday, a stunning announcement that is certain to set off alarm bells across the industry about the increasing power of AI models and the risk of them going rogue. According to OpenAI, the incident involved “a combination” of both its latest and most powerful publicly-available model, GPT-5.6 Sol, as well as an even more powerful unreleased model. It said the models were being used in an internal test designed to evaluate their cyber security capabilities and that they were being tested without guardrails in place that might normally limit the models’ ability to conduct cyber attacks. The models were being tested against a freely-available cybersecurity benchmark evaluation called ExploitGym. The models, accordingly to OpenAI, correctly surmised that the solutions to that test were maintained by Hugging Face. “The models identified and chained vulnerabilities across OpenAI’s research environment and Hugging Face’s production infrastructure to obtain test solutions directly from Hugging Face’s production database,” OpenAI said in its blog post. “All evidence suggests that the models were hyperfocused on finding a solution for ExploitGym, going to extreme lengths to achieve a rather narrow testing goal.” OpenAI said that it considered this to be “an unprecedented cyber incident, involving state-of-the-art cyber capabilities, and are responding accordingly.” Cybersecurity researchers have long been warning that advanced AI systems are capable of such attacks. Roman Yampolskiy, an AI safety researcher and computer science professor at the University

Rapid7's Antoine Harden on Moving Public Sector <b>Cybersecurity</b> from Reaction to Preemption

Antoine Harden is direct about the cybersecurity challenge facing government: the problem isn’t just the attackers; it’s how defense has traditionally been approached. “Technology that protects public institutions isn’t a career; it’s a calling,” he told WashingtonExec. As head of public sector at Rapid7, Harden is focused on helping federal, state and local agencies move beyond siloed, reactive security models and toward a more unified, preemptive approach. Drawing on leadership roles at Oracle, Google and Elastic, Harden brings a perspective shaped by both enterprise innovation and the realities of mission-driven government work. In this Q&A, he discusses the shrinking window for vulnerability exploitation, the risks created by disconnected security tools, and why he sees preemption — not reaction — as the future of public sector cybersecurity. Can you provide a brief overview of your professional background and career progression? My career has been built at the intersection of enterprise technology and mission-critical government operations, with leadership tenures at organizations like Oracle, Google, and Elastic. Throughout this journey, my focus has remained constant: solving complex operational challenges for the public sector. Transitioning to Rapid7 was a strategic choice driven by the company’s position as the preemptive security leader. In a landscape where adversaries now weaponize AI and exploit vulnerabilities within hours of disclosure, Rapid7’s Command Platform, which unifies exposure management and detection & response on a single data layer, is exactly what agencies need to get ahead of threats before they become breaches. Why was this the path you chose, and how influential was it to your career? Technology that protects public institutions isn’t a career; it’s a calling. I’ve always gravitated toward roles where what I build has real consequences, and government is the ultimate proving ground for that. This path taught me that technology isn’t just about the software;