Tag: openai
-
Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises
Microsoft on Tuesday announced the takedown of the EvilTokens device code phishing service that it said used artificial intelligence (AI) “at every step of the attack chain.”The action, carried out with authorization from the U.S. District Court for the Eastern District of Virginia, involved the efforts of Health-ISAC, alongside Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The…
-
Google AI models broke out of sandbox, hacked three companies
The incidents stemmed from the same testing environment defects that tripped up OpenAI, Anthropic and Meta. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/google-ai-gemini-autonomous-hacks/830884/
-
Nach Anthropic, OpenAI und Meta – Googles KI Gemini hackte ebenfalls andere Unternehmen
First seen on security-insider.de Jump to article: www.security-insider.de/google-gemini-hackte-sicherheitstests-fremde-systeme-a-d65d8622ecab4b164e8d78b9697fcf25/
-
Malicious HEIF Upload Reached OpenAI’s Internal GitHub, Researchers Reveal
A malicious HEIF upload exploited Discourse, crossed OpenAI’s identity layer, and reached an internal GitHub repo through a connected Codex account. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/news/news-openai-heif-github-vulnerability/
-
Rogue Behavior: OpenAI Reveals More Model Misalignment Incidents
The AI giant disclosed six examples of concerning model activity and published a new framework for investigating and disclosing such incidents. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/rogue-behavior-openai-more-model-misalignment-incidents
-
New Remus Infostealer Steals OpenAI and Anthropic API Tokens, Passwords and Crypto Wallets
A newly tracked Windows infostealer dubbed Remus is expanding its credential-theft playbook by targeting API tokens and local usage data tied to AI platforms, including OpenAI and Anthropic. Researchers at SpyCloud Labs found that recent Remus builds harvest browser data, password-manager and 2FA-extension artifacts, cryptocurrency-wallet files, application credentials, and AI assistant credential folders, potentially exposing…
-
New Remus Infostealer Steals OpenAI and Anthropic API Tokens, Passwords and Crypto Wallets
A newly tracked Windows infostealer dubbed Remus is expanding its credential-theft playbook by targeting API tokens and local usage data tied to AI platforms, including OpenAI and Anthropic. Researchers at SpyCloud Labs found that recent Remus builds harvest browser data, password-manager and 2FA-extension artifacts, cryptocurrency-wallet files, application credentials, and AI assistant credential folders, potentially exposing…
-
Researchers escape OpenAI Codex sandbox to run commands on host
Tags: openaiResearchers escaped OpenAI’s Codex sandbox two ways, one running commands on a developer’s machine from its most locked-down mode. OpenAI has patched both. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/researchers-escape-openai-codex-sandbox-to-run-commands-on-host/
-
Security Affairs newsletter Round 595 by Pierluigi Paganini INTERNATIONAL EDITION
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. Google Gemini also Broke Out of Its Test Environment AI Helps Hackers Hijack OpenAI Staff Accounts Through…
-
AI Helps Hackers Hijack OpenAI Staff Accounts Through a Forum
AI helped researchers exploit a Discourse flaw in under 72 hours, hijacking OpenAI staff accounts and exposing the risks of shared SSO. Three researchers at Hacktron just took over ChatGPT and Codex accounts belonging to OpenAI staff. The attack did not rely on phishing techniques or a leaked password. Through an image upload on OpenAI’s…
-
Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws
Three researchers at the security firm Hacktron used Anthropic’s Claude Opus 5 to chain two flaws and take over the ChatGPT and Codex accounts of several OpenAI employees, then reach an internal OpenAI code repository.The chain began with a bug in the software that runs OpenAI’s public help forum and moved through a weakness in…
-
Researchers use AI to find widespread software decoder flaw
The bug, since patched, gave attackers remote code execution privileges and access to user accounts and production environments, including Meta’s core product suite and an OpenAI software repository. First seen on cyberscoop.com Jump to article: cyberscoop.com/hacktron-ai-heif-heist-vulnerability/
-
Researchers used Claude to hack OpenAI
Researchers used Claude to reach an OpenAI employee account and sensitive GitHub data. First seen on arstechnica.com Jump to article: arstechnica.com/ai/2026/09/researchers-used-claude-to-hack-openai/
-
Researchers used Anthropic’s Claude to hack into OpenAI
Security researchers used Anthropic’s Claude to exploit vulnerabilities in OpenAI’s systems, taking over employee accounts and gaining access to an internal code repository before reporting the flaws. First seen on techcrunch.com Jump to article: techcrunch.com/2026/09/18/researchers-used-anthropics-claude-to-hack-into-openai/
-
Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents
A flaw in four widely used AI coding agents lets someone who controls a plugin’s code repository swap the plugin an agent installs for a malicious one, even when the agent locked that plugin to a specific reviewed version, security firm Air Security said on Thursday.The firm said Anthropic has patched the flaw in Claude…
-
ChatGPT Phishing Campaign Targets Both Work and Personal OpenAI Accounts
Threat actors are increasingly impersonating OpenAI’s ChatGPT service in credential-phishing campaigns, exploiting the growing use of generative AI across both enterprise and personal environments. A recently observed campaign uses a fraudulent subscription-payment notice to lure victims into disclosing OpenAI account credentials and potentially payment details through a convincing fake ChatGPT login page. The lure claims…
-
Plugin4Shell Zero-Click RCE Hits Claude Code, Codex, Copilot and Gemini CLI
A newly disclosed vulnerability known as Plugin4Shell reveals a supply chain weakness in major AI coding agents. This flaw allows attackers to replace trusted, SHA-pinned plugins with malicious code, enabling remote code execution without user interaction. Researchers Or Nevo, Dor Granat, and Niv Hoffman have identified that the issue impacts Anthropic Claude Code, OpenAI Codex,…
-
OpenAI Reveals AI Models Concealing Mistakes, Using Exposed API Keys and Sharing Files
OpenAI has introduced a new framework for reporting model misalignment after discovering instances where its AI systems concealed mistakes, accessed exposed API keys, fabricated data, uploaded files without authorization, and communicated through unintended channels. The company released six initial reports detailing behaviors observed during model training and evaluation. They argue that AI developers need more…
-
OpenAI admits its models lie to cover their own mistakes
OpenAI launches a formal framework to disclose model misalignment, publishing six reports on models that lied, faked data, or bypassed rules. Most companies don’t publish a document explaining how their product misbehaves. OpenAI just did. On September 16, it released a formal framework for tracking, investigating, and disclosing cases of model misalignment, paired with six…
-
A fake ChatGPT billing email is after your OpenAI password
A fake ChatGPT billing email is steering users to a copy of the OpenAI login page that keeps whatever username and password they type. Josh Varden of Cofense’s Phishing … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/17/chatgpt-phishing-email-openai-password/
-
Agenten beim Schummeln erwischt: OpenAI gesteht Kontrollverlust über seine KI
OpenAI will besorgniserregende KI-Vorfälle künftig schneller offenlegen. Zum Start liefert der ChatGPT-Entwickler gleich sechs reale Beispiele. First seen on golem.de Jump to article: www.golem.de/news/agenten-beim-schummeln-erwischt-openai-gesteht-kontrollverlust-ueber-seine-ki-2609-213140.html
-
Agenten beim Schummeln erwischt: OpenAI gesteht Kontrollverlust über seine KI
OpenAI will besorgniserregende KI-Vorfälle künftig schneller offenlegen. Zum Start liefert der ChatGPT-Entwickler gleich sechs reale Beispiele. First seen on golem.de Jump to article: www.golem.de/news/agenten-beim-schummeln-erwischt-openai-gesteht-kontrollverlust-ueber-seine-ki-2609-213140.html
-
Hugging Face Calls for Wider Access to AI Cyber Defenses
CEO Clem Delangue Urges Frontier Labs to Share Models, Compute and Threat Data. Organizations need more transparency and access to models and tools to fight against cyberattacks, according to Hugging Face CEO Clem Delangue, who said Wednesday that frontier should provide more compute and information. Hugging Face asked OpenAI for $100 million in compute. First…
-
Black Hat USA 2026 | OpenAI’s Deep Dive Into Hugging Face Incident
At Black Hat USA, OpenAI engineers reconstruct the Hugging Face incident and explore lessons learned about AI safeguards and cyber resilience. First seen on darkreading.com Jump to article: www.darkreading.com/vulnerabilities-threats/bhusa26huggingfacetalk
-
Advice for CIOs on AI’s ‘existential threat’
Statements by OpenAI chief Sam Altman, following an essay by Anthropic chief Dario Amodei, raise concerns over the safety of frontier models First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366650475/Advice-for-CIOs-on-AIs-existential-threat
-
Shared AI Memory Lets Hundreds of Agents Inherit Exploits and Join Coordinated Attacks
A shared message board turned isolated AI agents into an effective offensive collective during OpenAI’s July 2026 ExploitGym evaluations, enabling roughly 1,200 agents to exchange more than 70,000 messages and files. About 700 eventually participated in activity that compromised portions of Hugging Face’s production environment showing that shared agent memory can become a high-risk coordination…
-
OpenAI Agent Swarm Linked to 3,022 Malicious RubyGems Packages in GemStuffer Campaign
3,022 RubyGems packages associated with the GemStuffer campaign, expanding the known scope of an incident that researchers have linked to an alleged OpenAI agent swarm. The inventory covers 3,315 distinct package name-and-version pairs and reveals a sustained campaign that combined documentation-worker abuse, data collection, credential-theft attempts, and metadata-based web attack tests. When a documentation worker…

