Cyber security news August 2026

This posting is here to collect cyber security news in August 2026.

I post links to security vulnerability news to comments of this article.

You are also free to post related links to comments.

121 Comments

  1. Tomi Engdahl says:

    https://www.facebook.com/share/p/1Eiqhc734V/

    The FBI says hackers targeted water systems in 7 states this week alone.

    And things are getting increasingly worse.

    A sophisticated wave of cyberattacks targeting municipal water systems across at least seven states has prompted a nationwide warning from the FBI and the Environmental Protection Agency.

    In Minnesota, hackers breached more than 30 water facilities, causing some utilities to lose crucial monitoring and control capabilities. Although there is currently no evidence of drinking water contamination, the disruption has forced several local facilities to issue boil-water notices and switch to manual equipment operations. Investigators have indicated that the breaches show the hallmarks of potential Iranian involvement, coming amidst escalating tensions between Washington and Tehran.

    The attackers compromised the systems by gaining remote access to internet-connected industrial control devices, changing IP addresses and passwords to effectively lock municipal operators out. This threat has highlighted the deep vulnerabilities of smaller local utilities, which frequently rely on aging machinery, struggle with limited cybersecurity staff, and use legacy equipment that was never designed to withstand modern online threats. To prevent further disruptions, federal officials are urging water utilities nationwide to immediately secure their systems by removing control networks from direct internet exposure, implementing robust firewalls, and strengthening password security.

    source: NBC News. (2026). Hackers targeted municipal water systems in 7 states this week, FBI says. NBC News.

    https://www.nbcnews.com/nightly-news/video/fbi-warns-of-cyberattacks-on-water-systems-in-7-states-267611717585

    Reply
  2. Tomi Engdahl says:

    Hackers Targeted Municipal Water Systems In 7 States This Week, FBI Says
    https://m.slashdot.org/story/456670

    More Than 30 Minnesota Water Systems Targeted In Cyberattack
    https://m.slashdot.org/story/456612

    More than 30 Minnesota water systems targeted in cyberattack
    https://www.fox9.com/news/30-minnesota-water-systems-targeted-cyber-attack

    Reply
  3. Tomi Engdahl says:

    FBI investigating cyberattacks on water facilities across multiple states
    Hackers changed passwords and IP addresses of water system controls; Iran has been suggested as a possible culprit
    https://www.weau.com/2026/08/02/fbi-investigating-cyberattacks-water-facilities-across-multiple-states/

    Reply
  4. Tomi Engdahl says:

    OpenAI CEO Sam Altman visited the White House last week to discuss the voluntary tests

    US finalizes voluntary AI safety tests after OpenAI and Anthropic breaches
    OpenAI CEO Sam Altman visited the White House last week to discuss the voluntary tests and his company’s upcoming AI models
    https://www.independent.co.uk/tech/us-ai-safety-tests-anthropic-openai-hacks-b3026673.html?fbclid=IwdGRjcATd_Z9jbGNrBN39jXBkb2YFZXh0bgNhZW0CMTEAc3J0YwZhcHBfaWQMMzUwNjg1NTMxNzI4AAEetswfDT2C2VeywYbTNi5oEp09tuwbIbOysm1DctP6s0adqe9KVUSVwX4W7fI_aem_Hx-m4NqZLp7LeneWdYEvEA

    The Trump administration has finalized voluntary cybersecurity tests designed to measure the hacking capabilities of the most advanced U.S. artificial intelligence models, a White House official said Monday.

    The development follows recent disclosures from AI developers Anthropic and OpenAI, whose tools breached other companies’ systems.

    While the initiative is moving forward, the White House official did not immediately provide specifics on how results will be reported or the metrics the U.S. government plans to use.

    Reply
  5. Tomi Engdahl says:

    Microsoft laittaa tekoälyagentit hyökkäämään

    https://etn.fi/index.php/13-news/19147-microsoft-panee-tekoaelyagentit-hyoekkaeaemaeaen

    – Tietoturvatiimit eivät tarvitse lisää tietoa, vaan parempia tuloksia, sanoo Microsoftin tietoturvajohtaja Hayete Gallot. Yhtiön uusi Project Perception panee tekoälyagentit etsimään hyökkäysreittejä, arvioimaan riskit ja korjaamaan havaitut heikkoudet ennen kuin oikea hyökkääjä ehtii käyttää niitä hyväkseen.

    Microsoftin mukaan tekoäly muuttaa kyberhyökkäysten nopeutta, laajuutta ja taloudellisia edellytyksiä. Hyökkääjät voivat tuottaa hyväksikäyttömenetelmiä aiempaa nopeammin ja levittää kampanjoita konevauhdilla, kun puolustajat joutuvat edelleen yhdistelemään tietoja useista erillisistä järjestelmistä.

    Hayete Gallot sanoo suoraan, että tekoäly muuttaa kaiken. – Vielä 9 kuukautta sitten hyökkääjät käyttivät AI-avusteisia järjestelmiä. Nyt he ovat siirtymässä AI:n toteuttamiin operaatioihin. Esimerkiksi kiinalainen hakkeriryhmä hyökkäsi 30 organisaatioon eri puolilla maailmaa ja 90 prosenttia toiminnasta oli tekoälyn käsialaa.

    Skaalasta saa jonkinlaisen kuvan, kun ymmärtää että agentit saivat 15 tuhatta pyyntöä sekunnissa. Ihmisten osana oli vain agenttien ohjaaminen.

    Project Perception on Microsoftin vastaus tähän epätasapainoon. Se kokoaa tietoturvasignaalit, organisaation toimintaympäristöä kuvaavan kontekstin, tekoälymallit ja erikoistuneet agentit yhdeksi jatkuvasti toimivaksi puolustusjärjestelmäksi.

    Reply
  6. Tomi Engdahl says:

    https://etn.fi/index.php/13-news/19154-promptit-ovat-uusi-tietoturvariski

    Työntekijöiden tekoälyn käyttö on synnyttänyt yritysverkkoihin uudenlaisen tietoturvahaasteen. Verkossa liikkuu yhä enemmän AI-prompteja, autonomisten agenttien kutsuja ja MCP-yhteyksiä, jotka voivat sisältää lähdekoodia, liiketoimintatietoa tai muuta arkaluonteista aineistoa. Perinteiset palomuurit eivät ole osanneet tunnistaa tällaista liikennettä.

    Check Point pyrkii paikkaamaan tätä aukkoa uudella AI Network Firewall -ratkaisullaan, joka sisältyy yhtiön R82.20-palomuuriohjelmistoon. Ratkaisu tuo tekoälyliikenteen tunnistuksen ja valvonnan osaksi yritysten nykyisiä fyysisiä ja virtuaalisia palomuureja ilman erillistä infrastruktuuria.

    Reply
  7. Tomi Engdahl says:

    https://etn.fi/index.php/13-news/19138-usb-avain-korvaa-salasanan-ja-allekirjoittaa-saehkoeisesti

    Infineonin uusi turva-avain ei tyydy vain kirjautumaan käyttäjän puolesta. SECORA ID Key S USB yhdistää samaan USB- ja NFC-laitteeseen salasanattoman FIDO2-tunnistautumisen, PKI-varmenteet ja hyväksytyn sähköisen allekirjoituksen. Avoimen Java Card -ympäristön ansiosta valmistajat voivat lisäksi ohjelmoida avaimeen omia sovelluksiaan.

    Infineonin mukaan SECORA ID Key S USB on ensimmäinen FIDO-sertifioitu Level 3+ -tason ratkaisu. CTAP 2.1 -standardia tukeva avain mahdollistaa tietojenkalastelua kestävän kirjautumisen ilman salasanaa ja suojaa sekä verkon kautta tehtäviltä ohjelmistohyökkäyksiltä että laitteeseen fyysisesti kohdistuvilta hyökkäyksiltä.

    Reply
  8. Tomi Engdahl says:

    https://etn.fi/index.php/13-news/19156-selainkeksi-kelpaa-rikolliselle-paremmin-kuin-salasana

    Selaimen tallentamasta keksistä on tullut kyberrikollisille arvokkaampi saalis kuin salasanasta. NordVPN:n tutkijoiden analysoimissa tietovarkausaineistoissa evästetietoja esiintyi 4,6 kertaa enemmän kuin salasanoja, tiedostoja ja maksukorttitietoja yhteensä.

    Tutkijat tunnistivat vuoden aikana kaikkiaan 52,4 miljardia varastettua selainkeksiä. Suomesta peräisin oleviksi tunnistettiin 43 miljoonaa evästetietuetta, mikä nosti Suomen maiden välisessä vertailussa sijalle 91.

    Selainkeksi ei ole tässä tapauksessa verkkosivuston tarjoama harmiton eväs, vaan selaimeen tallennettu tunniste, jolla palvelu muistaa käyttäjän kirjautuneen sisään. Jos rikollinen saa aktiivisen istuntoevästeen haltuunsa, hän voi joissakin tapauksissa päästä tilille ilman käyttäjänimeä, salasanaa tai uutta kaksivaiheista tunnistautumista.

    Hyökkäystä kutsutaan istunnon kaappaukseksi. Rikollinen ei murra salasanaa, vaan ottaa käyttöön valmiiksi avatun istunnon.

    – Kyse ei ole enää pelkästään salasanan murtamisesta. Nykyään hakkerit varastavat digitaalisen avaimen, jolla lukko on jo avattu, NordVPN teknologiajohtaja Marijus Briedis kuvailee.

    Reply
  9. Tomi Engdahl says:

    https://www.facebook.com/share/p/18S6ccraQv/

    Japan refused to copy Australia’s social media ban for kids.

    And Australia just proved them right.

    Three months ago, Australia became the first country on Earth to ban social media for everyone under 16.

    The government said it would protect children’s mental health.

    The platforms were told to enforce it.

    Now Australia’s own internet regulator has released the results — and they’re brutal.

    More than 81% of teenagers are still using social media.

    Account ownership barely dropped.

    Half the kids who kept their accounts said the platforms never even checked their age.

    Daily usage went from 60% to 58%.

    Parental awareness of their children’s online activity actually went down.

    Meanwhile, Japan looked at Australia’s approach — and said no.

    A Japanese government panel spent months studying whether to follow Australia’s playbook, with a full ban on the table as one option.

    In June, they rejected it — calling social media “an important communication tool” and choosing to require stricter age verification and restrictions on addictive features like infinite scroll instead.

    Australia bet on a ban.

    Japan bet on smarter regulation.

    Three months of data just told us who was right.

    Reply
  10. Tomi Engdahl says:

    Hate it when that happens. https://trib.al/csLBYVX

    Silent Guardian
    Police Department Not Happy When Every Single One of Its Flock Cameras Gets Stolen
    Hate it when that happens.
    https://futurism.com/future-society/police-annoyed-flock-camera-alpr-stolen-winona?fbclid=IwdGRjcAThPzVjbGNrBOE_HnBkb2YFZXh0bgNhZW0CMTEAc3J0YwZhcHBfaWQMMzUwNjg1NTMxNzI4AAEekw3uApSoOuTT_M-qSSnJmVmE0SltW4yaRF_X4bLbFOyTbuUqiCWdcaGIUmg_aem_eS-eWC0oCa6yv7H0Tups_w

    Whether magicians, thieves, or just fed up citizens, somebody has made an entire city’s worth of ALPRs vanish in the night.

    According to new reporting by MPR News, police in the city of Winona, Minnesota are incensed after their entire fleet of Flock license plate readers went missing.

    Reply
  11. Tomi Engdahl says:

    Jyoti Mann / The Information:
    Source: Muse Spark 1.1 model breached a company’s systems during cybersecurity testing; Meta says evaluation partner Irregular caused a sandbox misconfiguration — A Meta Platforms artificial intelligence model accessed the internet during cybersecurity testing and hacked into another company …

    A Meta AI Model Hacked Another Company During Cybersecurity Testing
    https://www.theinformation.com/articles/meta-ai-model-hacked-another-company-cybersecurity-testing

    Reply
  12. Tomi Engdahl says:

    Lily Hay Newman / Wired:
    OpenAI says the Hugging Face breach involved AI agents creating an internal message board, unnoticed by humans, where they shared exploits and planned the hacks — At the Black Hat security conference, the AI giant revealed new details about how its agents went rogue, hacked several other companies …
    https://www.wired.com/story/openai-didnt-notice-its-ai-agents-using-a-message-board-to-plan-their-hacking-spree/

    Reply
  13. Tomi Engdahl says:

    Wired:
    A researcher with access to North Korean hackers’ servers says their operations have impacted 1,640 companies across 57 countries over the past 22 months — For nearly two years, researcher Vangelis Stykas has maintained access to North Korean hackers’ servers.

    A Security Pro Hacked North Korean Hackers. He Found They’d Breached Hundreds of Networks Worldwide
    https://www.wired.com/story/a-security-pro-hacked-north-korean-hackers-he-found-theyd-breached-hundreds-of-networks-worldwide/

    For nearly two years, researcher Vangelis Stykas has maintained access to North Korean hackers’ servers. His work shows they pulled off intrusions in a shocking number of systems across the globe.

    Reply
  14. Tomi Engdahl says:

    Meta AI Hacked External Systems During Cybersecurity Testing
    https://www.securityweek.com/meta-ai-hacked-external-systems-during-cybersecurity-testing/

    The incident involved a testing environment set up by Irregular, similar to what Anthropic reported last week.

    Reply
  15. Tomi Engdahl says:

    The Fourth Battlefield: The Growing Role of Cyber Operations in Global Conflict
    https://www.securityweek.com/the-fourth-battlefield-the-growing-role-of-cyber-operations-in-global-conflict/

    CrowdStrike co-founder Dmitri Alperovitch discusses how cyber operations support kinetic warfare, signal coming conflicts, and reshape the global battlefield.

    Reply
  16. Tomi Engdahl says:

    https://www.securityweek.com/tp-link-omada-ztp-vulnerabilities-chain-into-full-network-takeover/

    Security researchers at Forescout have disclosed 15 new vulnerabilities in the zero-touch provisioning (ZTP) systems used by TP-Link’s Omada networking ecosystem, warning that some of the flaws can be chained to compromise entire fleets of managed devices.

    Reply
  17. Tomi Engdahl says:

    New Attack Methods Enable Malware to Hijack Passkey-Protected Accounts

    Palo Alto Networks researchers have demonstrated attacks against Google’s synced passkey implementation.

    https://www.securityweek.com/new-attack-methods-enable-malware-to-hijack-passkey-protected-accounts/

    Reply
  18. Tomi Engdahl says:

    Cybersecurity Alliance Drafts SAFE Guidelines for Sharing AI Incident Data

    The guidelines are the work of the recently launched Open Secure AI Alliance, which now includes 120 organizations.

    https://www.securityweek.com/cybersecurity-alliance-drafts-safe-guidelines-for-sharing-ai-incident-data/

    Reply
  19. Tomi Engdahl says:

    AI Agents Targeted Real People and Projects During Cybersecurity Tests

    AI Security Institute reports Anthropic and OpenAI models going rogue against real people, organizations, and open source projects.

    https://www.securityweek.com/ai-security-institute-reports-anthropic-and-openai-models-going-rogue-against-organizations/

    While testing the capabilities of frontier AI models, the AI Security Institute (AISI) observed first-hand how Anthropic Mythos 5 and OpenAI’s GPT-5.6-Sol went rogue and targeted real people and organizations over the internet.

    AISI’s disclosure comes fresh on the heels of Anthropic and OpenAI disclosing that their models broke loose and hacked several organizations.

    The institute was evaluating the cyber capabilities of Mythos 5 and GPT-5.6-Sol models that did not have cyber classifiers (mechanisms to prevent misuse) enabled. It ran a challenge 122 times, and in 10 runs “an AI agent took autonomous, unsanctioned action on the live internet.”

    Over the 10 runs, the agents engaged in 19 rogue actions. Mythos 5 was responsible for 17 of them, and GPT-5.6-Sol performed the other two.

    Reply
  20. Tomi Engdahl says:

    Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack

    The malware was designed to steal and exfiltrate secrets, and to propagate itself via stolen NPM and GitHub credentials.

    https://www.securityweek.com/over-400-npm-packages-infected-in-chaindrop-supply-chain-attack/

    Reply
  21. Tomi Engdahl says:

    Rethinking AI Security: Why CASB and DLP Need an Interaction-Aware Layer

    Build your strategy around answering these questions to ensure employees use AI productively while keeping sensitive data, IP, and agent behavior within the boundaries set for safe AI use.

    https://www.securityweek.com/rethinking-ai-security-why-casb-and-dlp-need-an-interaction-aware-layer/

    Employees across organizations are using AI to harness its potential to automate, coordinate, and optimize complex workflows. Some of that happens through tools IT has reviewed and approved. A lot of it happens through personal accounts and browser extensions nobody in security has ever seen, let alone signed off on.

    The familiar security playbook to minimize AI risk is to discover the AI tools in use. Gate access with CASB, adding DLP rules to the mix, and tracking their usage. While this is not a bad security model (considering that its worked for years to secure SaaS sprawl) it has its limitations when it comes to AI.

    Reply
  22. Tomi Engdahl says:

    Decades-Old BMC Vulnerability Exposes Thousands of Data Centers to Attacks

    Over 24,000 internet-accessible server-management interfaces disclose authentication hashes before login.
    https://www.securityweek.com/decades-old-bmc-vulnerability-exposes-thousands-of-data-centers-to-attacks/

    Reply
  23. Tomi Engdahl says:

    Is Patching Dead? Vulnerability Management in the Post-Mythos Era

    You cannot out-patch a machine that writes a working exploit from a vulnerability description in twenty hours. Stop trying to optimize a game you cannot win.

    https://www.securityweek.com/is-patching-dead-vulnerability-management-in-the-post-mythos-era/

    On July 14, 2026, the White House launched Gold Eagle: a federal clearinghouse that uses frontier AI to identify, rank, and coordinate the remediation of software vulnerabilities across government and critical infrastructure before attackers reach them. Bringing together the Treasury, DHS, DoD, open-source software partners, and operators of American critical infrastructure, Gold Eagle’s engine relies on frontier AI—including Anthropic’s Mythos, the same class of system that surfaced critical flaws inside classified U.S. government software during testing.

    A government harnessing advanced AI to hunt vulnerabilities is conceding something fundamental: the two-decade model of humans finding and patching vulnerabilities one at a time has stopped keeping pace.

    Gold Eagle is the national-scale response. The harder question is: what is required inside your own walls?

    Reply
  24. Tomi Engdahl says:

    When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover

    Identity confidence changes throughout every interaction and should be reassessed continuously as new risk signals emerge.

    https://www.securityweek.com/when-identity-verification-fails-lessons-from-a-real-world-sim-swap-and-near-account-takeover/

    Reply
  25. Tomi Engdahl says:

    Legacy Systems, Real-World Impacts: The Reality of OT Security

    Legacy systems, safety concerns, and critical infrastructure risks make OT vulnerability disclosure one of cybersecurity’s most challenging balancing acts

    https://www.securityweek.com/legacy-systems-real-world-impacts-the-reality-of-ot-security/

    Reply
  26. Tomi Engdahl says:

    Another massive NPM worm: 444 packages with 2 billion monthly downloads infected with malware
    https://cybernews.com/security/npm-supply-chain-attack-shai-hulud-worm/?utm_source=cn_facebook&utm_medium=social&utm_campaign=cybernews&utm_content=post&source=cn_facebook&medium=social&campaign=cybernews&content=post&fbclid=IwVERDUAThaa5wZG9mBWV4dG4DYWVtAjEwAHNydGMGYXBwX2lkDDM1MDY4NTUzMTcyOAABHhdgvUlu_e6LiMRMwojJYsaycNuINk27QKYI6hfYUmNryyZ30JXD3mmEpdru_aem_fb3Vx8d3LF6EHNT1fmA3lA

    Key takeaways:
    Malware infected at least 444 npm packages spanning 2,000 versions, threatening software with over two billion monthly installs.
    Attackers compromised maintainer Jared Wray’s account, then used stolen credentials to automatically poison more packages.
    Infected installs steal hundreds of credential types and tamper with Claude and Visual Studio Code configurations.
    Experts urge affected organizations to assume exposure, rotate secrets, audit repositories and packages, and clean infected systems.

    Reply
  27. Tomi Engdahl says:

    Fool Me Twice
    A Whole Bunch of People’s Claude Chats Are Publicly Accessible Online, and There’s Some Wildly Private Stuff in There
    Anthropic said the system is working as intended.
    https://futurism.com/artificial-intelligence/claude-chats-publicly-accessible?fbclid=IwVERDUATha0lwZG9mBWV4dG4DYWVtAjEwAHNydGMGYXBwX2lkDDM1MDY4NTUzMTcyOAABHvI5IIdaJcUg6_6VAfbkykmt3ESg-sBg2uCQRfOfPXBjs58i4XVQc9_MKdN3_aem_IliWYnod7BRyIkIqiZlCNg

    A trove of chat logs and projects created with Anthropic’s Claude — some including sensitive personal and company information — have been left exposed to Google, making them them searchable to anyone on the web.

    Many of the materials appear to have been made public when Claude users opted to distribute a given chat or project to colleagues or associates using the chatbot’s “share” feature. After hitting the “share” button in the top right corner, Claude notes that sharing will create a “public” link, which “anyone with the link can view.” The warning, though, doesn’t alert users that shared content could wind up being indexed by a search engine — meaning that a user could effectively be sharing their Claude-generated document with the entire internet.

    Reply
  28. Tomi Engdahl says:

    Data centers are about to get a big shock.

    Source: https://go.ufdmedia.com/gLdcpx

    US mulling ban on key Chinese networking tech in data center component crackdown — White House wants to impose restrictions in 2026, China says it will respond if necessary
    https://www.tomshardware.com/tech-industry/data-centers/us-mulling-ban-on-key-chinese-networking-tech-in-data-center-component-crackdown-white-house-wants-to-impose-restrictions-in-2026-china-says-it-will-respond-if-necessary?fbclid=IwVERDUAThtDJwZG9mBWV4dG4DYWVtAjEwAHNydGMGYXBwX2lkDDM1MDY4NTUzMTcyOAABHi1-Js-y9idSdTA9Q3tnERpLjTP44qT-4P8M4YehE38RKZHe1ixmmyyRtYvq_aem_J0_Iy0-wt-2ZegLY8oCgsA

    The U.S. Federal Communications Commission (FCC) is working on a ruling that will ban the import of Chinese-made optical transceivers, which are widely used in data centers to convert electrical impulse data into light and vice versa. Sources told Reuters that the agency wants to publish the ruling so that it would take effect before the end of the year.

    “Transceivers definitely ⁠pose a risk,” AI policy expert Divyansh Kaushik of advisory firm Beacon Global Strategies told the publication. “As the data center buildout scales up, you want to make sure the ​data center supply chain is secure from the get-go.” The administration fears that these components could be used to steal data, install malware, or disrupt data center operations in the U.S.

    These optical transceivers are crucial for data centers as they require less electrical energy than traditional copper-based wiring and are also much faster. There are several U.S.-based manufacturers of these components, like Lumentum, Coherent, and Apple Optoelectronics, but Reuters said that they do not have the scale and capacity of leading company Innolight, which has cornered 27% of the global market.

    This isn’t the first industry-wide ban that the FCC has imposed in recent months. While the U.S. has banned Huawei products from the country since 2019, it recently enforced several other bans that have primarily affected major Chinese or China-connected companies. This includes the ban on foreign-made drones, applied in December 2025, foreign-manufactured routers, enacted last April, and advanced robotic devices that weigh over 4.4 pounds and have a 200-kbps connection, which was announced just last month.

    Reply
  29. Tomi Engdahl says:

    https://www.facebook.com/share/p/1Q3Wzsdn5P/

    Meta said one of its AI models breached another company’s systems during cybersecurity testing after a testing error gave the model unintended internet access.

    The model exploited a vulnerability in a third-party service and reportedly altered internal systems.

    Meta said it is investigating the incident.

    Testing partner Irregular said the breach resulted from a misconfigured evaluation environment and was not a sophisticated cyberattack or sandbox escape.

    Similar incidents were recently disclosed by Anthropic and
    OpenAI.

    Source: The Information
    Image: Reuters

    Reply
  30. Tomi Engdahl says:

    ChatGPT’s OpenAI, Claude’s Anthropic and now Meta have all announced that their systems have launched cyber attacks on other people and companies

    Out-of-control AI systems are going rogue and hacking people. Is it time to panic?
    https://www.independent.co.uk/tech/security/ai-artificial-intelligence-hack-cyber-attack-b3028787.html?fbclid=IwdGRjcATiOPtjbGNrBOI4unBkb2YFZXh0bgNhZW0CMTEAc3J0YwZhcHBfaWQMMzUwNjg1NTMxNzI4AAEeP91VNABnA-peOAgo2R8Hrbc8rav4VYmM5WqytZlHxk7rW5oDx4acDcpVW2A_aem_EfewlCbgRPD5N4SN3958lQ

    ChatGPT’s OpenAI, Claude’s Anthropic and now Meta have all announced that their systems have launched cyber attacks on other people and companies. But there are plenty of reasons to stay calm, for now

    It sounds terrifying, an indication that our fears about artificial intelligence systems undertaking attacks on their own might be coming true. And it is scary in part because it is among the first time that AI tools have attacked real people and organisations in potentially harmful way

    The examples are various: OpenAI, Anthropic and now Meta have all announced that their experimental systems have launched cyber attacks on other companies. Though the details of each case varies, more and more examples are being reported on a near-daily basis.

    The story began last month, when OpenAI said that an experimental version of the model that powers ChatGPT had broken out of its safeguards, connected itself to the internet, and hacked into another company, essentially allowing it to cheat on a test it was being set to see how useful it would be for cyber security. In the time since, other companies have announced similar examples, and OpenAI has found that their tools might have been launching more such attacks than it had realised.

    But should we worry? Is this really the terrifying scenario that science fiction authors and AI experts have been warning us about for decades?

    The truth is a little more nuanced. There are absolutely plenty of causes for concern – but there are plenty of reasons not to panic just yet, too.

    As soon as OpenAI announced the initial cyber attack, the world was hit by a wave of worry. It seemed to confirm much of the anxiety around AI: that the tools were becoming powerful more quickly than the safeguards that are intended to keep them controlled, and that if it continues then we might be unable to secure them and avoid potentially disastrous consequences.

    In all of the newly reported hacks, the specific nature of the individual cyber attacks was relatively harmless and contained, focused on other AI companies. But it is easy to imagine how the focus of such attacks could change, and that a future AI-powered cyber attack could focus on important infrastructure, for instance.

    Similarly, all of the “rogue” AI system were really just carrying out instructions, albeit in roundabout and unexpected ways: if you are told to do what you can to pass a test, then it might make rational sense to cheat on it. But this is exactly why the field of “AI alignment” is so key to the current wave of artificial intelligence – it refers to the practice of ensuring that systems work in keeping with human ethical frameworks, to ensure that they do not accidentally show behaviour that we would disagree with.

    This can be complicated, however, and it shows another reason that it is easy to imagine a future scenario in which such an AI attack would be much worse.

    the recent run of examples only serves to show: if an AI is given an instruction, it might follow it in ways that we cannot predict and would never want to happen.

    “There’s a lot of hype around rogue AI agents, and we can’t ignore the fact AI companies want to present their prototype models as really powerful and even dangerous. But there is a genuine threat here,” said Jake Moore, global security adviser at ESET.

    “Right now, the AI-led breaches we’ve seen involve models breaking out of test environments and hitting technology companies that have something they need to achieve their goal.

    “But AI doesn’t always get it right. Once it’s decided that accessing a company is key to meeting its objective, aggressive frontier models will hammer an organisation until they are stopped or it has been breached. It’s not a stretch to think more companies will end up in an AI’s crosshairs during future security tests.”

    So the cause for worry is not necessarily that the recent run of hacks really threaten anything important. It is that they could be an early example of the dangers that experts warn powerful AI could bring: that increasingly autonomous and capable AI systems could use their powers in ways that are damaging to humanity, and we might not even know that it is happening.

    Why we shouldn’t panic
    Still, we are not there yet. The recent run of reports might be concerning – but they are also limited in scope and seem to have happened only in experimental testing.

    In many ways, it is helpful for the companies involved for us to panic. It is a marketing technique that has been used heavily by the AI companies ever since the current artificial intelligence boom started with the launch of ChatGPT, in 2022; these systems are the future but are dangerous too, so you had better fund the less evil companies, they urge.

    This time around, by suggesting their systems are so scarily powerful that we can’t control them, they help to highlight the cyber security capabilities that all major AI companies are currently using as a central way of pushing their products. And, at the same time, they imply that any potential dangers are the fault of the AI itself, rather than the companies making them, which can be convenient.

    In all the examples apart from the initial report – that around an OpenAI’s attack on a fellow AI company, Hugging Face – the problems have occurred because the companies have not properly secured their testing environment. In the examples at Anthropic and Meta, for instance, the safeguards were not properly configured, so that the systems did not actually have to break themselves onto the internet in order to get online.

    Shifting the response from being about the companies’ failures to the scarily powerful nature of their systems is advantageous for those companies, because it moves the story from being about the potentially insecure nature of the tests to performance of their tools.

    You can also see this in the way companies have made their disclosures. First came OpenAI, then came Anthropic, and now Meta has claimed that its AI too has been involved in hacking.

    The innocent and probably true reading is that the OpenAI announcement led other companies to investigate their own systems, and found evidence that they too had been launching cyber attacks.

    But at the same time the fact that those companies were so keen to disclose what could be an embarrassing or worrying problem suggests that there is some kind of marketing value in doing so – and that, as a consequence, it might be helpful for them for us to panic now.

    What can we do?
    As ever, in this era of incredibly powerful artificial intelligence firms, it is easy to feel powerless. AI companies are unusual in that many people don’t even actually pay for their products, so it is hard to exercise even that little bit of consumer pressure.

    But experts advise that there are steps we can take. They are much the same as with other cyber security threats: ensuring that important data isn’t easily available online, and that we are being vigilant about checking for suspect behaviour and installing updates, for instance.

    “The most important changes need to come from the AI firms themselves. They should be putting stronger controls into testing processes to stop AIs breaking out, and limit how persistent the models are at achieving their goals by any means necessary,” said Moore.

    Reply
  31. Tomi Engdahl says:

    https://www.facebook.com/share/p/1DW3yGtu8r/

    One factor above all others is shaping today’s cybersecurity landscape: artificial intelligence. It is not only transforming business efficiency but also providing cybercriminals with unprecedented resources.

    “The stakes in this evolving threat landscape are high: your entire business is at risk. If your cybersecurity does not meet today’s minimum acceptable security baseline, you are exposing your organisation to serious risk,” says Toni Vartiainen, Head of Security Business at DNA.

    Read Toni’s blog to find out why the solid stone walls protecting your business now need watchtowers and guards alongside them!

    Solid stone walls no longer protect your fortress – modern cybersecurity requires watchtowers and guards

    https://www.dna.fi/dnabusiness/blogi/-/blogs/solid-stone-walls-no-longer-protect-your-fortress-modern-cybersecurity-requires-watchtowers-and-guards?utm_source=facebook&utm_medium=social&utm_content=LAA-artikkeli-solid-stone-walls-no-longer-protect-your-fortress-modern-cybersecurity-requires-watchtowers-and-guards&utm_campaign=P_LAA_26-31-36_artikkelikampanja_enkku&fbclid=IwdGRjcATibqBwZG9mBWV4dG4DYWVtATAAYWRpZAGrNrTDN7Jcc3J0YwZhcHBfaWQMMzUwNjg1NTMxNzI4AAEelk3VkTmsxMwDmwvRV_ECUvZaw4NF5_KhQRjjdKOmGlzuOqFKLr_L8Kw2Fu4_aem_deaPifyQM1sGsR02uQDS-w&utm_id=120249963597740556&utm_term=120249963597770556

    The world around us has changed faster than many of us ever anticipated. Not long ago, cybersecurity was all about building a fortress. Today, that fortress is under constant attack, breached by ever-evolving methods.

    Reply
  32. Tomi Engdahl says:

    China launches mysterious probe into security of Palo Alto Networks’ products
    Beijing’s not saying why, which is just what happened when it investigated Micron
    https://www.theregister.com/security/2026/08/07/china-launches-mysterious-probe-into-security-of-palo-alto-networks-products/5284453

    China’s Cyberspace Administration (CAC) has conducted a review of Palo Alto Networks’ products.

    The regulator’s announcement of its review says it’s needed “to ensure the safe and stable operation of critical information infrastructure, prevent cybersecurity risks and vulnerabilities, and safeguard national security.”

    And that’s all Beijing has to say on the matter.

    A Palo Alto spokesperson provided The Register with the following statement: “We maintain the highest standards of business conduct and security practices and ethics across our global operations. At this time, there is no impact to our ability to support customers or deliver our products and services in the region.”

    This matter has echoes of China’s 2023 investigation into the security of products from memory-maker Micron, which the CAC announced out of the blue.

    The CAC published its findings weeks after announcing the probe and decided Micron’s products represented an unacceptable security risk for critical infrastructure operators – effectively banning sales of Micron products to such entities – but didn’t offer a detailed explanation for its decision. The memory-maker eventually stopped selling its datacenter and server products in China, a decision that cost it billions of annual revenue – but created new opportunities for China’s own memory-makers, which are largely prohibited from selling to American companies.

    China is home to several security companies whose product portfolios overlap with Palo Alto’s. Huawei and H3C, for example, have plenty to offer local buyers.

    Reply
  33. Tomi Engdahl says:

    https://www.facebook.com/share/p/19EUK2n2qs/

    As details emerged about OpenAI’s rogue agent hacking Hugging Face, the cybersecurity community reached a conclusion that cut through the AI frontier narrative: the incident was largely preventable.

    The two models that escaped containment did so partly because deployment safeguards were intentionally disabled for testing. Security researchers say the breach also reflects a failure to implement foundational protections, including zero trust architecture and defense in depth, that the industry has spent two decades developing and promoting.

    OpenAI is valued at $850 billion. It employs veteran security hires from across the tech industry. The protections that may have prevented the incident are well known and widely available.

    A cloud security founder put it plainly: “The fact that OpenAI wasn’t more paranoid about this seems kind of reckless.” A longtime security consultant was equally direct: “The OpenAI mistakes were dead simple.”

    OpenAI has since deactivated and encrypted the unreleased model, launched a review with external advisers, and committed to publishing a technical postmortem. The company noted that its existing safeguards, had they been in place, may have prevented or minimized the incident.

    The deeper question the episode raises about how AI development culture approaches security is the part most coverage has moved past too quickly.

    Read the full story, link in comments.

    OpenAI’s Hacking Debacle Comes Down to Human Error
    https://www.wired.com/story/openais-hacking-debacle-was-a-human-mistake/?fbclid=IwdGRjcATilRJjbGNrBOKU-nBkb2YFZXh0bgNhZW0CMTEAc3J0YwZhcHBfaWQMMzUwNjg1NTMxNzI4AAEe1ZsBizliGV6yd-ZkyCpcattmOderw6MJwmHSNk8mhnIiimcZHFetKLZj858_aem_aKpe0gw8Y3Qo2YYdyoyf4w

    If the generative AI giant had followed well-known security best practices, it’s likely that its AI agent would never have escaped to the open internet and hacked multiple companies.

    Reply
  34. Tomi Engdahl says:

    They’re useless — at best. https://trib.al/vf7oTsb

    Cops And Donuts
    Flock Surveillance Cameras Are Actually Horrible for Fighting Crime, FBI Data Shows
    “The public has been asked to accept a significant expansion of surveillance based on the promise that it would dramatically improve public safety.”
    https://futurism.com/future-society/flock-surveillance-atlanta-fbi-data-crime-case-solve?fbclid=IwdGRjcATilqdjbGNrBOKWjXBkb2YFZXh0bgNhZW0CMTEAc3J0YwZhcHBfaWQMMzUwNjg1NTMxNzI4AAEe-hWGEJ64S5CaIhY7-TJiP9jvPWz55A6r2MMIokPzBbQyqHbSeSFPS-tOw5o_aem_DpNVyBEQs-Lu0UXq0xMODw

    Since the launch of Flock Safety in 2017, the ACLU estimates the company installed some 100,000 automatic license plate readers throughout the United States. The dragnet comes with plenty of downsides to privacy and civil liberties: it’s ripe for abuse by crooked cops, powered by sweatshop labor, and nearly impossible to escape once it designates you a target.

    But police officials insist it’s worth the trade off — because at it least it helps them catch the bad guys, right? Unfortunately, the reality isn’t quite that peachy.

    Atlanta, Georgia has experienced far and away the largest influx of ALRPs in the country, with over 5,000 various Flock cameras now blanketing the city. Yet as bombshell data released by the FBI shows, the city’s massive web of surveillance has had virtually zero impact on the Atlanta Police Department’s ability to solve crime, with some clearance rates for offenses like homicide even experiencing a decline over the past few years as the cameras have proliferated.

    First reported by the Atlanta Community Press Collective, the FBI data is a damning refutation of Flock’s primary claim: that ALPRs are necessary to help officers keep the public safe.

    According to the ACPC, the rates at which the APD resolves crimes like homicide, robbery, miscellaneous larceny, and shoplifting have actually decreased between 2021 and 2025, when the city’s ALPR build-out hit its full stride.

    Though the APD actually did show improvement on some crime categories as Flock’s cameras sprouted all over the city, the changes from 2021 to 2025 amount to little more than rounding errors.

    Len Phillips, head of the anti-ALPR community group DeFlock Atlanta told ACPC that the “public has been asked to accept a significant expansion of surveillance based on the promise that it would dramatically improve public safety.”

    In reality, Phillips continues, that tradeoff between safety and civil liberties “was just a one-way transaction.”

    Loud and Clear
    In Light of Overwhelming Backlash, Flock Cancels Creepy Audio Surveillance Feature
    “After careful consideration and community consultation, we decided to remove the feature.”
    https://futurism.com/future-society/flock-surveillance-backlash-audio-distress-screaming-police?fbclid=IwVERDUATil2JwZG9mBWV4dG4DYWVtAjEwAHNydGMGYXBwX2lkDDM1MDY4NTUzMTcyOAABHiB7Pod3cB6Q1OyyO7D5GU_9gk6ukTaALvvQtaULeKImhXCiT_S5rLOrcwIT_aem_gpnlmhCeqPaCqfrCDlBG6g

    Reply
  35. Tomi Engdahl says:

    The outrage is surging. https://bit.ly/4wEsvX6

    Flock Around And Find Out
    Flock Is Losing Dozens of Contracts as Controversy Grows
    The outrage is surging.
    https://futurism.com/future-society/flock-dozens-contracts-alprs-controversy-cancellation?fbclid=IwdGRjcATil5FjbGNrBOKXfHBkb2YFZXh0bgNhZW0CMTEAc3J0YwZhcHBfaWQMMzUwNjg1NTMxNzI4AAEeJLnmYNo_NgdGeSfN0xRz8cRO9dt_lmPEeJWhAiJ3_I6O7SSp_NY47dadrsw_aem_p4RYRIMHfrzJKjMzosAjzg

    Mass surveillance technology might be popular with police departments, but for the US public, it’s becoming an increasingly difficult sell.

    At least 54 cities across the US have voted to cancel, non-renew, or reject Flock’s automatic license plate reader (ALPRs) since the start of the year, according to data collected by the Washington Examiner. That comes after reporting in February that some 30 cities had done the same since 2025, indicative of the rising backlash against the tech.

    In all, the Examiner reports cities in 23 states have shredded their Flock contracts so far this year, led by California and Wisconsin, which each have seven rejections, cancellations, or deactivations. Other heavy hitters include New York, Washington, and Massachusetts with four each, and Virginia with three.

    Though Flock has its cameras in over 5,000 US cities as of July 2026, the rise in rejections at the municipal level comes amidst a tidal wave of outrage around issues of privacy and civil rights.

    Reply
  36. Tomi Engdahl says:

    AI slop infiltrates the CVE system: “the cited code didn’t even exist”
    https://cybernews.com/ai-news/ai-slop-infiltrates-the-cve-system/?utm_source=cn_facebook&utm_medium=social&utm_campaign=cybernews&utm_content=post&source=cn_facebook&medium=social&campaign=cybernews&content=post&fbclid=IwVERDUATiq8VwZG9mBWV4dG4DYWVtAjEwAHNydGMGYXBwX2lkDDM1MDY4NTUzMTcyOAABHmgtVIbXe6XYwHjYwVKa6eCmYyyDxWcHsPjFciCKRax2xRdqHh2LOsFjL21G_aem_8R2QA9WDpO8UX7mYet4S9A

    Nothing is sacred for AI slop

    Key takeaways:
    JFrog found dozens of likely AI-generated fake vulnerabilities, with some receiving official CVE identifiers and Critical ratings.
    Several fabricated advisories targeted SQLite, but researchers said the cited vulnerable code and exploit behavior did not exist.
    The fake entries entered trusted security pipelines, risking false alerts, wasted patching work, and reduced trust in vulnerability data.
    The incident shows AI-generated junk is moving beyond consumer platforms and threatening core cybersecurity systems.

    Reply
  37. Tomi Engdahl says:

    Black Hat on YouTube:
    At Black Hat, OpenAI reconstructs the OpenAI-Hugging Face incident and examines its implications for AI security, cyber resilience, and alignment

    Black Hat USA 2026: The ‘Breaking’ News: The OpenAI–Hugging Face Incident
    https://www.youtube.com/watch?v=87DyyMV0kCY

    Reply
  38. Tomi Engdahl says:

    Will Knight / Wired:
    Security researchers claim that Kimi K3 went outside of its sandbox during defensive cybersecurity tests, but did not hack anything after accessing the internet — Security researchers say that Kimi K3, an open-weight model from China, wandered off to the internet in an attempt to cheat on a test it was given.

    One of China’s Most Powerful AI Models Has Also Escaped Containment
    https://www.wired.com/story/moonshot-kimi-k3-ai-model-escape-sandbox/

    Security researchers say that Kimi K3, an open-weight model from China, wandered off to the internet in an attempt to cheat on a test it was given.

    Reply
  39. Tomi Engdahl says:

    Horrifying. https://trib.al/LGdfIVo

    Friendly Fryer
    It Appears That the US Military Accidentally Killed Everybody on Board a Civilian Medevac Flight in New Mexico
    “When those lights go out, man, you know you are in big trouble.”
    https://futurism.com/science-energy/us-military-gps-jamming-signal-medical-flight?fbclid=IwdGRjcATi3RljbGNrBOLdCXBkb2YFZXh0bgNhZW0CMTEAc3J0YwZhcHBfaWQMMzUwNjg1NTMxNzI4AAEeL4FHAYPqCBG3rY4uc0FeB-nErDV7d1ZJqzJuVsc6itaRMMdq4I9LRSFTwAw_aem_ge7ShMVhpvOkN63i0p9WzA

    Reply

Leave a Comment

Your email address will not be published. Required fields are marked *

*

*