A final, particularly vivid finding in the Hugging Face incident was the agent “ecosystem” that emerged on the message board. Agent communication is not problematic behavior on its own—we train and deploy multi-agent systems that can communicate on the same task via a collaboration tool. This allowed them to pool work and computing power across separate evaluations, amplifying their capabilities well beyond what any individual agent might achieve alone. Unauthorized, persistent message boards were at the heart of this incident.
These unsolved https://uofa.ru/en/voznikli-etnicheskie-konflikty-primery-istorii-samye-gromkie/ tasks ended up being a substantial contributor to the agents’ activity—93% of the tasks that were discussed on the Artifactory message board during the Hugging Face incident came from this set of 198 questions. In the following days, the agents exploited our internal research infrastructure and the Hugging Face platform. Soon after, agents struggling with their assigned tasks began to look for solutions on unrelated third-party services, including Modal and Hugging Face.
Mini Shai-Hulud malware was injected into keyv and eight related npm packages on August 4, 2026 after an attacker compromised the maintainer’s GitHub account We detected XCSSET malware inside a compromised Flutter https://medicalcases.eu/category/news/page/23/ package on pub.dev. A known Shai-Hulud worm payload sat dormant for 111 days, then republished to npm, right past the malware scanning meant to catch it.
- Recent headlines cast artificial intelligence as a threat to humanity.
- Dell has released security updates to address multiple critical security flaws in Dell Container Storage Modules (CSM) that could be exploited by bad actors to take over susceptible systems.
- A suspected ShinyHunters member known online as Rey was reportedly detained in Jordan on September 29 and is said to be cooperating with FBI investigators.
- Later, an agent used these credentials to discover and chain together several security exploits that gave it full code execution capabilities on several Hugging Face servers.
- To do so, we did not enable the same level of safeguards as our externally deployed systems.
- Learn how to address potential risks and not restrict AI adoption in your organization.
Hacking Without Boundaries – Michael Jenkins – PSW #946
Gemini 3.8 Flash Cyber and Wiz’s Red Agent team up to protect hospitals, public transit, and tech Security researchers report that Microsoft considers the side-channel leak of file events to be by design Glow Security finds more than 13,000 publicly accessible images that expose corporate development work Mostly ‘routine research tasks,’ and ‘some involved government websites, which our models often use,’ AI giant tells The Reg
Popular Rust crates arrayref, append-only-vec, and internment compromised in Supply Chain Attack
Cybersecurity researchers have disclosed details of two now-patched security flaws in the n8n workflow automation platform, including two critical bugs that could result in arbitrary command execution. A dozen critical security vulnerabilities have been disclosed in the vm2 Node.js library that could be exploited by bad actors to break out of the sandbox and execute arbitrary code on susceptible systems. The development is the latest attack orchestrated by TeamPCP targeting Checkmarx. The attacks targeted the US Department of Education and Library and Archives Canada, and researchers linked some agents to OpenAI. Doxx.net’s new ADN platform prevents agentic misadventure while the agent is operating under the user’s authority. The announcement comes after Trump hosted top executives of AI companies at the White House last week.
ShowDoc RCE Flaw CVE-2025-0520 Actively Exploited on Unpatched Servers
Rate of out-of-bounds environment and infrastructure probing during a training run that contributed to the model responsible for the main Hugging Face activity. Most reward hacks are simple shortcuts, such as finding answers on public websites or in https://vectorart1.com/forum/2-453-1 code version history. We have significantly invested in methods to identify and patch such hacks. Agents attempting to cheat on their tasks by looking up solutions online was a primary driver of the Hugging Face incident.
OpenAI safety employee resigns, claiming the company’s ‘culture is broken’
- The malware uses a unique Unicode-based method to hide the user’s password in a fake Zoom configuration file.
- Known as Rey, the suspect is reportedly helping the FBI identify and locate other members of the extortion group.
- Unauthorized, persistent message boards were at the heart of this incident.
- Threat actors have been observed attempting to exploit a now-patched critical security flaw impacting the Realtek Jungle software development kit (SDK) to deploy a botnet malware called Cling .
- As discussed in our report(opens in a new window), our response focuses on strengthening research security and monitoring, accelerating model alignment, and improving how we identify, escalate, and respond to incidents.
The dropper “carries a complete universal Mach-O inside itself, roughly 756 KB in the development build, and extracts it at runtime. More than 730 cyber breaches affected over 270 million Americans last year, costing an average of $10 million per breach. Google has temporarily stopped accepting product vulnerability reports through its Open Source Software Vulnerability Reward Program (OSS VRP).