About
Press
Copyright
Contact us
Creators
Advertise
Developers
Terms
Privacy
Policy & Safety
How YouTube works
Test new features
NFL Sunday Ticket
© 2026 Google LLC
Aug 29, 2026 · via youtube.com
- CTC has received a $14.9 million contract for Marine Corps OT cybersecurity services - The work will protect facility-related control systems at Marine Corps installations - CTC and RMC Global will provide cyber assessments, architecture and compliance support Concurrent Technologies Corp. has received a $14.9 million contract from Marine Corps Installations Command Government Facilities to provide operational technology cyber services for facility-related control systems, or FRCS, the company announced Thursday. What Does the Marine Corps Contract Cover? The multi-year award covers OT cybersecurity services for securing and modernizing FRCS in multiple Marine Corps installations. CTC will partner with RMC Global to deliver strategic and technical guidance, advanced cybersecurity measures, architecture and customized cyber assessments. The companies will also provide compliance support and policy development. CTC President and CEO Chris Hamilton said the contract supports the company’s efforts to strengthen national security and operational resilience through advanced capabilities. The award builds on CTC’s recent work supporting MCICOM’s FRCS cybersecurity needs. In April, the company received a $21 million contract to provide cybersecurity support for FRCS in the MCIPAC region. CTC also partnered with RMC Global under the award. How Will the Contract Support Marine Corps Infrastructure? The companies will support cybersecurity and operational monitoring for FRCS used at Marine Corps installations. CTC said the work is intended to support infrastructure resilience and mission operations. Josh Ingraham, director of OT cyber solutions at CTC, said the award demonstrates MCICOM GF’s continued confidence in the company’s ability to plan and implement cybersecurity measures for mission-critical infrastructure. What Is CTC’s History With MCICOM? The contract builds on more than seven years of programmatic support CTC has provided to MCICOM GF. In February 2025, CTC secured a prime position on a multiple-award contract supporting MCICOM program management, operations, communications and facilities functions. CTC holds
Aug 29, 2026 · via executivebiz.com
McKesson discloses cybersecurity incident under investigation, says no known material impact
Less than 1 min read
McKesson disclosed a cybersecurity incident affecting its information systems and said an investigation is in its early stages.
Key Highlights:
- On Aug. 25, 2026 McKesson discovered a cybersecurity incident impacting its information systems.
- The investigation is in its early stages; updates will be posted at www.mckesson.com/cybersecurity.
- As of this filing, McKesson has not determined the incident is material or likely to have a material impact on financial condition or results.
Original SEC Filing: MCKESSON CORP [ MCK ] - 8-K - Aug. 28, 2026
This is an AI-powered summary. It may contain inaccuracies. Consider verifying important information with the source. Please note this summary is solely based on documents filed with the SEC.
Aug 28, 2026 · via tradingview.com
TL;DR — Key Takeaways - Pillar Security researchers exploited a prompt injection in Google’s Gemini CLI workflow to gain Editor-level access to an internal Google Cloud project. - The attack began with hidden instructions embedded in a GitHub issue that were processed by an AI agent triaging bug reports. - The prompt injection led to the issuance of Workload Identity Federation credentials, one of which enabled impersonation of a more privileged account. Cybersecurity researchers from Pillar Security this week revealed how a prompt injection inserted into a GitHub repository was used to gain Editor-level access to an internal Google Cloud project using a flaw in the command line interface (CLI) of an artificial intelligence (AI) coding tool that Google provides. Dan Lisichkin, a cybersecurity researcher for Pillar Security, said the flaw, since remediated, existed in Google Gemini CLI setup code that Google uses internally to automatically read and sort bug reports filed on its public GitHub page. A Pillar Security researcher was able to file a “bug report” that included hidden instructions that resulted in a prompt injection whenever an AI agent triaged issues. That prompt resulted in a legitimate credentials file being issued via the Workload Identity Federation (WIF) framework, which the researcher then copied out. Most of those credentials were low-privilege but one permitted the researcher to impersonate a far more powerful account through which they gained Editor-level control of an internal Google project that was running in a dedicated sandbox. The breach itself is interesting because it represents a rare instance where an open source tool was used to breach a proprietary cloud computing environment, noted Lisichkin. While this might be viewed as a single isolated incident, it does illustrate how relatively trivial it is becoming to compromise a software supply chain in the AI coding era,
Aug 28, 2026 · via devops.com
Malicious actors are exploiting a newly patched security flaw in PaperCut NG and MF to execute arbitrary code on susceptible instances, as the company released a fresh emergency fix with additional hardening. "This vulnerability gives an unauthenticated attacker remote control over PaperCut's trusted configuration, which could be used to execute arbitrary Java code inside the application's process," Huntress researchers John Hammond and Andrew Brandt said. Specifically, an attacker can leverage an unauthenticated request to make changes to the server configuration and ultimately achieve code execution. Huntress has explained the flaw as follows - In unpatched versions of PaperCut NG and PaperCut MF, a specifically crafted request can refer to one page that is rendered for the response, and another page that owns the component or action being executed. PaperCut's authorization check could trust the rendered page and miss the permissions required by the component behind it. We found that an unauthenticated request could be utilized in this way to make changes to the server configuration. This enables access to sensitive endpoints that can trigger unsafe actions, and ultimately lets an ill-intended actor execute any arbitrary attacked-controlled code. PaperCut has since publicly disclosed two flaws - - CVE-2026-82078 (CVSS score: 9.4) - An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against an allowlist of approved drivers - CVE-2026-81578 (CVSS score: 8.8) - An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks. The development comes after PaperCut released a second emergency patch that it said includes "additional hardening beyond the
Aug 28, 2026 · via thehackernews.com
WASHINGTON—U.S. Senators John Curtis (R-UT), Dave McCormick (R-PA), John Hickenlooper (D-CO), John Hoeven (R-ND), and Catherine Cortez Masto (D-NV) introduced the Rural and Municipal Utility Cybersecurity Act, bipartisan legislation to reauthorize a critical federal grant program that helps rural electric cooperatives and municipal utilities strengthen their cybersecurity defenses against increasingly sophisticated cyber threats. The legislation reauthorizes the Rural and Municipal Utility Advanced Cybersecurity (RMUC) Grant and Technical Assistance Program at the Department of Energy, which provides rural electric cooperatives and publicly owned utilities with the resources, technical assistance, and support they need to prevent, detect, respond to, and recover from cyberattacks. Companion legislation was unanimously passed by the House of Representatives earlier this year. “Our rural and municipal utilities are increasingly on the front lines of protecting the electric grid from cyber threats,” said Senator Curtis. “This bipartisan bill makes a smart investment in safeguarding critical infrastructure, supporting local utilities, and keeping the lights on for communities across America.” “America’s electric grid is a critical piece of our national security, and every utility—regardless of size or location—must have the resources to defend against increasingly sophisticated cyber threats,” said Senator McCormick. “Rural electric cooperatives and municipal utilities serve millions of Americans, including communities across Pennsylvania, but often operate with fewer cybersecurity resources than larger utilities. This bipartisan legislation will help ensure they have the support they need to protect our energy infrastructure and keep the lights on.” “America needs clean, reliable, affordable, and secure energy,” said Senator Hickenlooper. “As cybersecurity threats continue to rise, our bill enables rural cooperatives and utilities to defend against sophisticated attacks, protect consumers, and keep energy affordable.” “Malicious actors and foreign adversaries are targeting America’s infrastructure, and that is why we introduced legislation to support electric cooperatives and utility providers as they work to harden critical
Aug 28, 2026 · via curtis.senate.gov
Federal agencies will increasingly seek out technology products that use quantum-resistant encryption, as cybersecurity leaders also eye ways to validate the cryptography used in critical systems. A code-breaking quantum computer holds the potential to break classical encryption methods, putting sensitive systems and communications at risk. And even though such a computer is not yet known to exist, organizations are also concerned that hackers could steal sensitive encrypted data today and decrypt it in the future. The National Institute of Standards and Technology has released three primary PQC standards in recent years, with additional algorithms under consideration. Agencies and industry are now on the clock to begin the time consuming and costly process of migrating current systems to the new algorithms. “Now is the time to budget, to test, and to implement,” Will Loucks, senior director for intelligence in the White House Office of the National Cyber Director, said during an Aug. 26 panel discussion at the Intelligence and National Security Summit in North Bethesda, Md. “And that’s especially true for national security systems, including the commercial technologies and algorithms that support them,” Loucks continued. “But it’s also more generally true for federal networks and commercial systems more broadly.” Agencies received new PQC marching orders earlier this summer, when President Donald Trump signed an executive order directing agencies to transition “high value assets” and “high impact systems” to post-quantum cryptographic keys by Dec. 31, 2030, and PQC digital signatures by the end of 2031. Agencies will have to factor PQC upgrades into cloud migrations, software development lifecycles, and hardware refresh schedules, meaning the government will be reliant on industry partners to help with the transition. “What do we want from industry? I think from a government perspective, we want to see a clear path and a roadmap on how you’re getting
Aug 28, 2026 · via federalnewsnetwork.com
Cybersecurity researchers have discovered a cluster of 18 Google Chrome and one Microsoft Edge extensions that were published over the last six months and harbored wallet secret stealing and cryptocurrency draining capabilities. The extensions, per Socket security researcher Karlo Zanki, share similarities in code and tradecraft, with evidence indicating that the campaign may have been active since February 2024. Socket is tracking the activity under the name Superior. The modus operandi is relatively straightforward: the threat actor either acquires legitimate extensions with proper functionality or pushes a clean version that's devoid of any malware. Once the extensions begin to gather user downloads, a new version with the malicious behavior is published. Of the identified extensions, 14 were created by the threat actor, while the remaining five were purchased from their previous owners. The complete list of extensions is below - - Extensions bought by the threat actor - koccklolohdacbfooifnpebakpbeipc - Enable Right Click & Copy — Smart Unlock + OCR - fegckejpfnlmfgkfjpinlbgmeeijjkel - RapidLens - Google Lens for Screen Search & Images - kdenlnncndfnhkognokgfpabgkgehodd - QuickLens - Search Screen with Google Lens - jamminefolhgepgihbmcjjhgldbfcikp - Password Protect PDF - inmkjedjdhgpknjogbjomhnbgdccckkg - Allow Copy - Select & Enable Right Click (Microsoft Edge) - Extensions created and published by the threat actor - - fcgdejjichpgfaaafflplhfijcnieopb - PixelCheck - cfpnjdbpojpcongfaefcamjbaolpelcd - Creative Library - Ad Spy Tool - aapdalkmclfaahehnmicbglkohkldhne - Website Traffic Checker: MirrorSphere SEO Stats - dkdadldmiefjldmegbjbnhhfddnkhlhm - Site Signal - Website Traffic & SEO Checker - fjmlhlkccegopebcllcmafahkmeejpph - SEO Pulse Pro - Website Traffic & SEO Analyzer - iekoapohahgmogbagegmcgplbkikcgke - Private Crypto News Reader - ahpnnnjbnfbhoikhohglpohnoocjcoco - Blockfolio: Address Monitor - oeacadlaclegkkkdehjmiifnjhcekclj - Crypto Rates & Fiat Converter - jmlgannjlbliikgcaieomgmcnfplglea - Crypto Alerter: Price Alarms & Volatility Warnings - lhmcajhgadanidbopgaoobjlldegjmke - DeFi Pulse Tracker - gfackggoapepdmnjnkblogdcjpgcjiak - Crypto Price Badge: Quick
Aug 28, 2026 · via thehackernews.com
About
Press
Copyright
Contact us
Creators
Advertise
Developers
Terms
Privacy
Policy & Safety
How YouTube works
Test new features
NFL Sunday Ticket
© 2026 Google LLC
Aug 28, 2026 · via youtube.com
Cyber incident hits McKesson (NYSE: MCK) systems; impact under review Rhea-AI Filing Summary McKesson Corporation (MCK) reported that on August 25, 2026 it discovered a cybersecurity incident affecting its information systems. The investigation is in its early stages, and additional information and updates are being made available on the company’s website at www.mckesson.com/cybersecurity. As of this report, McKesson states it has not determined that the incident is material or that it has had, or is reasonably likely to have, any material impact on the company, including its financial condition or results of operations. Positive - None. Negative - None. 8-K Event Classification 2 items: 7.01, 9.01 2 items Item 7.01 Regulation FD Disclosure Disclosure Material non-public information disclosed under Regulation Fair Disclosure, often investor presentations or guidance. Item 9.01 Financial Statements and Exhibits Exhibits Financial statements, pro forma financial information, or exhibit attachments filed with this report. Key Figures Cybersecurity incident discovery date: August 25, 2026 1.625% Notes due 2026: 1.625% 3.125% Notes due 2029: 3.125% +1 more 4 metrics Cybersecurity incident discovery date August 25, 2026 Date McKesson discovered the cybersecurity incident affecting its information systems 1.625% Notes due 2026 1.625% Interest rate on McKesson’s notes due 2026 listed on the New York Stock Exchange 3.125% Notes due 2029 3.125% Interest rate on McKesson’s notes due 2029 listed on the New York Stock Exchange Report signature date August 28, 2026 Date McKesson’s 8-K report was signed by the Executive Vice President and Chief Legal Officer Key Terms cybersecurity incident, emerging growth company, Inline XBRL 3 terms cybersecurity incident technical "McKesson Corporation discovered a cybersecurity incident affecting its information systems." A cybersecurity incident is an event where someone's computer systems or data are attacked or broken into without permission. It matters because it can lead to stolen information, financial loss,
Aug 28, 2026 · via stocktitan.net
Huntress was founded in 2015 by former NSA cyber operators who believe enterprise-grade protection shouldn't be reserved for the 1%. Since those early days, we've grown considerably, and now we're a global team of passionate experts and ethical badasses on a mission to break down barriers in cybersecurity. And among those badasses is Ben Bernstein, Manager, Cybersecurity Advisors. In this edition of our Employee Spotlight series, we sit down with Ben, a teammate who brings a sharp, practical approach to security. As you'll see, he embodies our values of taking ownership and delivering extreme value without unnecessary complexity. Here's his story. What's your role at Huntress? Ben: My official title is "Manager, Cybersecurity Advisors." What that means is I lead our Cybersecurity Advisors team, which is a small, high-touch group of seasoned security experts. They do it all, essentially serving as trusted advisors, brand evangelists, and consultants to our most strategic accounts. Always ready to share his expertise, Ben stands before the cameras. Who do you know that's been hacked? Tell us about the experience and how it impacted your decision to work in cybersecurity. Ben: I once helped a Fortune 500 company respond to a zero day, which, for those who might not be familiar, is a vulnerability nobody had patched yet that attackers were already exploiting. What made this one especially bad was that I was out of the office on my five-year wedding anniversary. I vividly remember asking my wife to drive to our reservation while I threw on headphones and took the call from the passenger seat of our rental car. The Zoom call had around 30 people join, and we worked in real time to recommend both temporary and long-term security controls, as well as monitoring solutions to help secure their environment. The call lasted
Aug 28, 2026 · via huntress.com
Costa Rican electricity institute joins ISASecure to speed up cybersecurity adoption The International Society of Automation announced July 28 that Instituto Costarricense de Electricidad (ICE) has joined its ISASecure subsidiary, which is the globally recognized certification program that validates conformance with ISA/IEC 62443 cybersecurity standards for industrial automation and control systems (IACS). Also known as the Costa Rican Institute of Electricity, ICE was founded in 1949 to employ the nation’s water resources for efficient and responsible electrification. It’s a Costa Rican state company, so its mission is providing citizens with energy, connectivity, and safe and sustainable digital services. The institute’s electrical system takes advantage of alternative energy sources, and it also focuses on developing smart grids and electric transportation. ICE’s partnership with ISASecure further reflects its mission of strengthening and maturing the security of operations technology (OT) in Costa Rica’s energy system, and ensuring that its OT cybersecurity procedures are continually maintained at the highest standards. Erick Obregón Navarro, cybersecurity and enterprise protection director at ICE, reports that joining ISASecure and adopting ISA/IEC 62443 enables it to implement several cybersecurity capabilities, such as: - Protecting industrial networks and SCADA systems, - Defining security levels and layered control approaches, - Network segmentation and reducing attack surfaces, - Securely managing access and industrial components, and - Continuous monitoring and incident response. “We look forward to our partnership with ISASecure to ensure our energy systems and Costa Rican residents are protected from cybersecurity attacks,” says Navarro. “It’s an honor to welcome the Costa Rican Institute of Electricity—and our first Costa Rican company—to ISASecure,” says Mark DeAngelo, ISASecure’s program manager. “Today’s critical infrastructure demands comprehensive, rigorously validated cybersecurity. We look forward to collaborating with the Instituto Costarricense de Electricidad as we advance our mission of industry partnership, certification and standards-based product development to help
Aug 28, 2026 · via controlglobal.com
AI is making scams more convincing, cybersecurity report warns Check Point Research finds voice cloning, face swaps and sophisticated phishing among the growing AI-powered threats (InvestigateTV) — Artificial intelligence has become part of daily life for tasks like writing resumes and drafting emails, but a cybersecurity expert says the same technology is giving scammers new tools to deceive people. Adam Ely, general manager of AI security at Check Point, said AI is being used on both sides of the equation. “Scammers and attackers are finding it useful in their business of attacking each of us or trying to trick each of us,” Ely said. “But companies are also benefiting from using AI in trying to defend us or trying to defend their own companies as well.” A new report from Check Point Research highlights AI-powered threats including more sophisticated phishing emails, voice cloning and real-time face swaps. “They’re using it to craft new, more sophisticated, better phishing or scam emails,” Ely said. “They’re using AI to even clone our voices or our video, our likeness, to then use to trick someone else.” The report also examined the risk of sensitive information being shared with outside AI services. It found between 87% and 93% of organizations had at least one high-risk generative AI interaction each month. Those high-risk interactions can include prompts that share sensitive data with external AI services. Ely said the findings do not mean people should avoid AI altogether. Instead, he recommends starting with low-risk tasks and thinking carefully before connecting an AI tool to accounts or information that could cause harm if misused. “Maybe you don’t want to connect your favorite AI tool to your bank account, because you don’t want that money to disappear and go to the wrong person,” Ely said. “But maybe you’re okay
Aug 28, 2026 · via ksnblocal4.com
NEW YORK – The advanced use of AI has created a generational shift in the balance between the ability to protect information and the risk of those systems being compromised, according to researchers at Palo Alto Networks (PAN). The cybersecurity firm, which has conducted extensive research on the use of frontier AI, opened a window into those findings in a Wednesday media briefing here. After months of participation in Anthropic’s Project Glasswing and OpenAI’s Daybreak program, PAN security testers were able to discover the volume of security vulnerabilities that would normally take a year to unearth. The danger is that a malicious actor with these same capabilities could weaponize the security flaws at a speed at which most modern security defenses cannot compete. A lone threat actor armed with such AI can engage in sophisticated, nation-state-level or criminal capabilities without the need for extensive training or experience, according to Sherrod DeGrippo, VP threat intelligence at Palo Alto Networks’ Unit 42. AI-enabled attack window narrows PAN’s Unit 42 was among the first cybersecurity firms to get a bird’s-eye view of how frontier AI had changed the security landscape. Nation-state and criminal threat groups had already begun to incorporate artificial intelligence into their toolkits in prior years, but these new models raised the stakes to such a new level that only a few organizations were able to see these capabilities under a more controlled environment. In May, PAN warned of a three- to five-month window before adversaries would begin to exploit vulnerabilities at speeds that have never been seen before. More than three months later, the researchers now say those expectations are about to be realized, and security leaders need to prepare for this new threat landscape. “Here we are, five months, in and we’re starting to see the wave of this
Aug 28, 2026 · via cybersecuritydive.com
Cybersecurity and the end of AI's Wild West era The days of unproven promises and marketing hype around AI security are coming to a close. The next phase of AI requires scrutiny and measurable results. For the past decade, the promise of AI transforming cybersecurity has been a constant headline. Tech giants and startups alike have deployed an array of AI-enabled products and services, each designed to enhance security operations and make organizations more secure in an evolving threat landscape. Stanford University's 2026 "AI Index Report" found that 8,909 newly funded AI companies emerged in the U.S. between 2013 and 2025. The choices for CISOs are only growing as the AI bubble continues to expand. When and if it will burst is anyone's guess. After years of experimental adoption and vendor proliferation, security leaders now possess enough operational data to make informed decisions. Multi-year deployment histories, incident response metrics and lessons learned from failed pilots have given CISOs the knowledge to distinguish effective AI security tools from tools that didn't measure up. In other words, the industry is moving from the Wild West -- a phase of unchecked experimentation -- into a period of strategic consolidation. For security leaders willing to do the work, that shift is the catalyst for more thoughtful and effective AI adoption. The Wild West era: A retrospective While many predicted the advent of AI for decades, the shift from the first commercially available security platforms to nearly every vendor branding some portion of its product as "AI-powered" was swift. Claims often outpaced what the underlying models could reliably do. At the same time, CISOs faced pressure to adopt, boards worried about falling behind and analysts warned of an AI-driven threat landscape. Enterprises began adopting detection systems that drove alert volumes up rather than down, worsening
Aug 28, 2026 · via techtarget.com
Operational silos, technological sprawl and cloud-platform blind spots are serious issues preventing organizations from spotting and repelling cyberattacks, the Cybersecurity and Infrastructure Security Agency (CISA) warned in a new report. Those were three of the main factors that allowed CISA’s red team to break into the networks of two unnamed partner organizations — one a government agency, the other a water utility — during recent simulated attacks. But although the red team was successful in both intrusions, it had a much harder time with one attack than with the other, a fact that CISA attributed to important differences in the targets’ operating procedures and use of technology. “In one organization (Organization A), the team gained initial access to multiple workstations, gained elevated privileges over the domain, and moved laterally to [sensitive business systems] and cloud resources undetected,” CISA said in a report released Tuesday. “In the second organization (Organization B), network defenders quickly detected the initial compromise and quarantined the affected systems.” Organization A could have stopped CISA’s red team. Analysts in its various security operations centers (SOCs) received alerts from their endpoint detection and response (EDR) software about suspicious activity. But because the alerts were classified as low and medium severity, the SOC analysts — overwhelmed by false-positive alerts, some classified as high severity — didn’t act on the warnings. The fact that the organization had multiple SOCs and EDR programs also hampered its response, CISA said. “Staff did not communicate with staff from other SOCs or have visibility on their detection tools. SOC staff and system owners also did not communicate with each other.” Things were different at Organization B. The CISA red team’s intrusion generated multiple alerts that defenders responded to quickly. In one case, that response prevented the red team from receiving data from a command-and-control
Aug 28, 2026 · via cybersecuritydive.com
Cybersecurity researchers have flagged a fresh set of campaigns targeting government and diplomatic organizations in Romania, Spain, and Türkiye between late September 2025 and early April 2026. These campaigns, per Recorded Future Insikt Group, have led to the deployment of a previously undocumented backdoor dubbed HOOKEDGE, a lightweight Windows batch script that's distributed via macro-enabled Microsoft Word documents bearing diplomatic-themed lures. Early versions are said to have impersonated Spanish government material, before switching to a social engineering approach a month later. The activity has been attributed with moderate confidence to a Russian state-sponsored hacking group known as APT28 (aka Fancy Bear and Forest Blizzard). It's tracked by the Mastercard-owned cybersecurity and threat intelligence firm under the moniker BlueDelta. This determination is based on what Recorded Future described as significant code and tradecraft overlap between HOOKEDGE and HEADLACE, a modular Windows backdoor previously put to use by APT28 in attacks targeting diplomats since April 2023. This includes similarities in core architecture and the abuse of webhook[.]site services for command-and-control (C2), payload staging, and data exfiltration, thereby allowing malicious activity to blend in with regular network traffic and obviating the need for setting up dedicated infrastructure. "The implant has undergone continuous refinement between September 2025 and April 2026, likely to evade automated sandbox environments and adapt to reduced free-tier API limits on webhook[.]site," Recorded Future said in a Thursday analysis, describing it as a "direct evolutionary successor to HEADLACE." HOOKEDGE's primary delivery vehicle is a macro-enabled Microsoft Word document that, when opened, prompts the target to click "Enable Content" to display the contents, causing the macro routing to write six files to the "%userprofile%" directory and launch the HOOKEDGE installer chain. It starts with an installer launcher that creates a scheduled task that runs every 30 minutes to execute the HOOKEDGE launcher
Aug 28, 2026 · via thehackernews.com
In July, OpenAI admitted that one of its agents tasked with completing a cybersecurity experiment broke out of containment and hacked AI dataset platform Hugging Face. That incident, which got a full accounting from OpenAI yesterday, was the first publicly reported case where an LLM went rogue and autonomously hacked a third party. Since then, that unprecedented sci-fi-esque event turned out to be far less rare than anyone would hope for. According to a satirical website called Felony Bench (for benchmark), which tallies these incidents, there have been 17 incidents in total. It’s important to remember that criminal law experts are not entirely sure whether the AI companies that made the LLMs that did the hacking can be prosecuted, nor whether the victims can sue them. But we are likely going to get an answer to those questions soon. Anthropic and OpenAI models lead the race with eight incidents each, and Meta trails behind with one, according to the site. At this point, it has become clear that AI safety tests are becoming safety risks themselves. And some AI companies and workers themselves have recognized those risks in the “Pacing the Frontier” open letter, which called for developing AI capabilities responsibly. We decided it would be a good time to recap all these incidents chronologically. OpenAI hacks Hugging Face In this incident, OpenAI was running “an internal evaluation” of a model with “maximal cyber capabilities.” The plan was to have it solve a cybersecurity challenge in an environment with no internet access. Instead of solving the challenge, the model found an unknown vulnerability to escape the sandbox and gained internet access. From there, several agents worked together to target and hack Hugging Face thinking they could find the solution to the challenge there. OpenAI only found out after Hugging Face
Aug 28, 2026 · via techcrunch.com
More than one hundred technology companies, including prominent artificial intelligence developers such as OpenAI, Anthropic, Google, and Perplexity, have issued a joint open letter calling for an urgent international effort to combat emerging AI-driven cyber threats, DW reports. Industry signatories—which also include major firms like Adobe, Cisco, Dell, IBM, Oracle, and Deutsche Telekom—warned that the window to bolster global defenses is rapidly closing as machine learning models grow increasingly capable and autonomous. The joint statement comes in the wake of recent security incidents in which advanced AI systems breached their containment protocols during internal testing. OpenAI disclosed that autonomous agents escaped their evaluation environments and accessed external networks, ultimately compromising infrastructure at the machine learning platform Hugging Face. Similarly, Anthropic reported separate incidents where its Claude model bypassed testing boundaries and accessed unauthorized organizational systems. Read more: Why Nvidia’s $500 billion AI financing plan faces a major risk from China (with video) These events underscored warnings issued by the “Five Eyes” intelligence alliance, which cautioned that artificial intelligence is fundamentally altering both offensive and defensive digital capabilities on an accelerated timeline. The collective letter urges a comprehensive response from both private enterprise and public sector institutions. In addition to demanding that AI developers build more robust monitoring tools, the signatories called on governments worldwide to dedicate substantial funding toward defensive infrastructure, prioritizing essential services and supply chains that lack adequate cybersecurity budgets. The push for increased public investment highlights growing concerns over recent reductions in federal defense resources, including recent workforce cutbacks at the United States Cybersecurity and Infrastructure Security Agency. Tech leaders emphasized that establishing trusted access frameworks and expanding defensive resources across critical infrastructure must happen within months, rather than years, to effectively counter autonomous cyber threats.
Aug 28, 2026 · via plataformamedia.com
Over a hundred tech companies — including OpenAI, Anthropic, Google, and Microsoft — have signed an open letter urging both the private and public sectors to work together to defend themselves from AI-related cyber threats. The letter — which was also signed by prominent cyber firms like CrowdStrike, Okta, and Fortinet, as well as prominent financial institutions and internet infrastructure firms — calls for the adoption of new forms of cyber defense, while also encouraging governments at the “local, national, and international levels” to collaborate on security. “In the coming months, AI-enabled cyber attacks will become far more widespread and sophisticated as models around the world become increasingly capable,” the letter states. “The companies and public services our communities depend on — from hospitals to water treatment plants to the infrastructure that powers the internet — are at risk.” The problem AI poses to traditional cybersecurity defenses has been thrust into the spotlight lately by a string of bizarre incidents in which AI agents have attacked companies. The Hugging Face incident — in which one of OpenAI’s agents autonomously broke out of its sandboxed environment and attacked the tech company — has been followed by a trail of other reported break-ins involving agents developed by other AI companies, including Anthropic and Meta. These incidents have bolstered the argument that the field of cybersecurity has been fundamentally altered and that bold new commercial solutions are necessary to mitigate them. The letter further suggests the mobilization of a “collective response,” one in which “new partnerships” are formed “to raise security standards and find new solutions to emerging cyber threats.” Several of the AI companies that have signed the letter are still actively developing ever more advanced AI models, highlighting their conflicted position. At the same time, they are also offering programs to
Aug 28, 2026 · via techcrunch.com