This posting is here to collect cyber security news in August 2026.
I post links to security vulnerability news to comments of this article.
You are also free to post related links to comments.
This posting is here to collect cyber security news in August 2026.
I post links to security vulnerability news to comments of this article.
You are also free to post related links to comments.
121 Comments
Tomi Engdahl says:
Open source intelligence and stuxnet
https://www.instagram.com/reel/Dam7CnKuWWf/?igsh=c25iejZuNWV5bWFt
Tomi Engdahl says:
https://www.facebook.com/share/p/1Eiqhc734V/
The FBI says hackers targeted water systems in 7 states this week alone.
And things are getting increasingly worse.
A sophisticated wave of cyberattacks targeting municipal water systems across at least seven states has prompted a nationwide warning from the FBI and the Environmental Protection Agency.
In Minnesota, hackers breached more than 30 water facilities, causing some utilities to lose crucial monitoring and control capabilities. Although there is currently no evidence of drinking water contamination, the disruption has forced several local facilities to issue boil-water notices and switch to manual equipment operations. Investigators have indicated that the breaches show the hallmarks of potential Iranian involvement, coming amidst escalating tensions between Washington and Tehran.
The attackers compromised the systems by gaining remote access to internet-connected industrial control devices, changing IP addresses and passwords to effectively lock municipal operators out. This threat has highlighted the deep vulnerabilities of smaller local utilities, which frequently rely on aging machinery, struggle with limited cybersecurity staff, and use legacy equipment that was never designed to withstand modern online threats. To prevent further disruptions, federal officials are urging water utilities nationwide to immediately secure their systems by removing control networks from direct internet exposure, implementing robust firewalls, and strengthening password security.
source: NBC News. (2026). Hackers targeted municipal water systems in 7 states this week, FBI says. NBC News.
https://www.nbcnews.com/nightly-news/video/fbi-warns-of-cyberattacks-on-water-systems-in-7-states-267611717585
Tomi Engdahl says:
Hackers Targeted Municipal Water Systems In 7 States This Week, FBI Says
https://m.slashdot.org/story/456670
More Than 30 Minnesota Water Systems Targeted In Cyberattack
https://m.slashdot.org/story/456612
More than 30 Minnesota water systems targeted in cyberattack
https://www.fox9.com/news/30-minnesota-water-systems-targeted-cyber-attack
Tomi Engdahl says:
FBI investigating cyberattacks on water facilities across multiple states
Hackers changed passwords and IP addresses of water system controls; Iran has been suggested as a possible culprit
https://www.weau.com/2026/08/02/fbi-investigating-cyberattacks-water-facilities-across-multiple-states/
Tomi Engdahl says:
https://www.theregister.com/os-platforms/2026/08/03/it-boss-left-root-session-open-for-bring-your-kid-to-work-day/5280931
Tomi Engdahl says:
OpenAI CEO Sam Altman visited the White House last week to discuss the voluntary tests
US finalizes voluntary AI safety tests after OpenAI and Anthropic breaches
OpenAI CEO Sam Altman visited the White House last week to discuss the voluntary tests and his company’s upcoming AI models
https://www.independent.co.uk/tech/us-ai-safety-tests-anthropic-openai-hacks-b3026673.html?fbclid=IwdGRjcATd_Z9jbGNrBN39jXBkb2YFZXh0bgNhZW0CMTEAc3J0YwZhcHBfaWQMMzUwNjg1NTMxNzI4AAEetswfDT2C2VeywYbTNi5oEp09tuwbIbOysm1DctP6s0adqe9KVUSVwX4W7fI_aem_Hx-m4NqZLp7LeneWdYEvEA
The Trump administration has finalized voluntary cybersecurity tests designed to measure the hacking capabilities of the most advanced U.S. artificial intelligence models, a White House official said Monday.
The development follows recent disclosures from AI developers Anthropic and OpenAI, whose tools breached other companies’ systems.
While the initiative is moving forward, the White House official did not immediately provide specifics on how results will be reported or the metrics the U.S. government plans to use.
Tomi Engdahl says:
Microsoft laittaa tekoälyagentit hyökkäämään
https://etn.fi/index.php/13-news/19147-microsoft-panee-tekoaelyagentit-hyoekkaeaemaeaen
– Tietoturvatiimit eivät tarvitse lisää tietoa, vaan parempia tuloksia, sanoo Microsoftin tietoturvajohtaja Hayete Gallot. Yhtiön uusi Project Perception panee tekoälyagentit etsimään hyökkäysreittejä, arvioimaan riskit ja korjaamaan havaitut heikkoudet ennen kuin oikea hyökkääjä ehtii käyttää niitä hyväkseen.
Microsoftin mukaan tekoäly muuttaa kyberhyökkäysten nopeutta, laajuutta ja taloudellisia edellytyksiä. Hyökkääjät voivat tuottaa hyväksikäyttömenetelmiä aiempaa nopeammin ja levittää kampanjoita konevauhdilla, kun puolustajat joutuvat edelleen yhdistelemään tietoja useista erillisistä järjestelmistä.
Hayete Gallot sanoo suoraan, että tekoäly muuttaa kaiken. – Vielä 9 kuukautta sitten hyökkääjät käyttivät AI-avusteisia järjestelmiä. Nyt he ovat siirtymässä AI:n toteuttamiin operaatioihin. Esimerkiksi kiinalainen hakkeriryhmä hyökkäsi 30 organisaatioon eri puolilla maailmaa ja 90 prosenttia toiminnasta oli tekoälyn käsialaa.
Skaalasta saa jonkinlaisen kuvan, kun ymmärtää että agentit saivat 15 tuhatta pyyntöä sekunnissa. Ihmisten osana oli vain agenttien ohjaaminen.
Project Perception on Microsoftin vastaus tähän epätasapainoon. Se kokoaa tietoturvasignaalit, organisaation toimintaympäristöä kuvaavan kontekstin, tekoälymallit ja erikoistuneet agentit yhdeksi jatkuvasti toimivaksi puolustusjärjestelmäksi.
Tomi Engdahl says:
https://etn.fi/index.php/13-news/19154-promptit-ovat-uusi-tietoturvariski
Työntekijöiden tekoälyn käyttö on synnyttänyt yritysverkkoihin uudenlaisen tietoturvahaasteen. Verkossa liikkuu yhä enemmän AI-prompteja, autonomisten agenttien kutsuja ja MCP-yhteyksiä, jotka voivat sisältää lähdekoodia, liiketoimintatietoa tai muuta arkaluonteista aineistoa. Perinteiset palomuurit eivät ole osanneet tunnistaa tällaista liikennettä.
Check Point pyrkii paikkaamaan tätä aukkoa uudella AI Network Firewall -ratkaisullaan, joka sisältyy yhtiön R82.20-palomuuriohjelmistoon. Ratkaisu tuo tekoälyliikenteen tunnistuksen ja valvonnan osaksi yritysten nykyisiä fyysisiä ja virtuaalisia palomuureja ilman erillistä infrastruktuuria.
Tomi Engdahl says:
https://etn.fi/index.php/opinion/19145-puhelin-kuumenee-joko-vakooja-kuuntelee
Tomi Engdahl says:
https://etn.fi/index.php/13-news/19138-usb-avain-korvaa-salasanan-ja-allekirjoittaa-saehkoeisesti
Infineonin uusi turva-avain ei tyydy vain kirjautumaan käyttäjän puolesta. SECORA ID Key S USB yhdistää samaan USB- ja NFC-laitteeseen salasanattoman FIDO2-tunnistautumisen, PKI-varmenteet ja hyväksytyn sähköisen allekirjoituksen. Avoimen Java Card -ympäristön ansiosta valmistajat voivat lisäksi ohjelmoida avaimeen omia sovelluksiaan.
Infineonin mukaan SECORA ID Key S USB on ensimmäinen FIDO-sertifioitu Level 3+ -tason ratkaisu. CTAP 2.1 -standardia tukeva avain mahdollistaa tietojenkalastelua kestävän kirjautumisen ilman salasanaa ja suojaa sekä verkon kautta tehtäviltä ohjelmistohyökkäyksiltä että laitteeseen fyysisesti kohdistuvilta hyökkäyksiltä.
Tomi Engdahl says:
https://etn.fi/index.php/13-news/19156-selainkeksi-kelpaa-rikolliselle-paremmin-kuin-salasana
Selaimen tallentamasta keksistä on tullut kyberrikollisille arvokkaampi saalis kuin salasanasta. NordVPN:n tutkijoiden analysoimissa tietovarkausaineistoissa evästetietoja esiintyi 4,6 kertaa enemmän kuin salasanoja, tiedostoja ja maksukorttitietoja yhteensä.
Tutkijat tunnistivat vuoden aikana kaikkiaan 52,4 miljardia varastettua selainkeksiä. Suomesta peräisin oleviksi tunnistettiin 43 miljoonaa evästetietuetta, mikä nosti Suomen maiden välisessä vertailussa sijalle 91.
Selainkeksi ei ole tässä tapauksessa verkkosivuston tarjoama harmiton eväs, vaan selaimeen tallennettu tunniste, jolla palvelu muistaa käyttäjän kirjautuneen sisään. Jos rikollinen saa aktiivisen istuntoevästeen haltuunsa, hän voi joissakin tapauksissa päästä tilille ilman käyttäjänimeä, salasanaa tai uutta kaksivaiheista tunnistautumista.
Hyökkäystä kutsutaan istunnon kaappaukseksi. Rikollinen ei murra salasanaa, vaan ottaa käyttöön valmiiksi avatun istunnon.
– Kyse ei ole enää pelkästään salasanan murtamisesta. Nykyään hakkerit varastavat digitaalisen avaimen, jolla lukko on jo avattu, NordVPN teknologiajohtaja Marijus Briedis kuvailee.
Tomi Engdahl says:
https://www.facebook.com/share/p/18S6ccraQv/
Japan refused to copy Australia’s social media ban for kids.
And Australia just proved them right.
Three months ago, Australia became the first country on Earth to ban social media for everyone under 16.
The government said it would protect children’s mental health.
The platforms were told to enforce it.
Now Australia’s own internet regulator has released the results — and they’re brutal.
More than 81% of teenagers are still using social media.
Account ownership barely dropped.
Half the kids who kept their accounts said the platforms never even checked their age.
Daily usage went from 60% to 58%.
Parental awareness of their children’s online activity actually went down.
Meanwhile, Japan looked at Australia’s approach — and said no.
A Japanese government panel spent months studying whether to follow Australia’s playbook, with a full ban on the table as one option.
In June, they rejected it — calling social media “an important communication tool” and choosing to require stricter age verification and restrictions on addictive features like infinite scroll instead.
Australia bet on a ban.
Japan bet on smarter regulation.
Three months of data just told us who was right.
Tomi Engdahl says:
Hate it when that happens. https://trib.al/csLBYVX
Silent Guardian
Police Department Not Happy When Every Single One of Its Flock Cameras Gets Stolen
Hate it when that happens.
https://futurism.com/future-society/police-annoyed-flock-camera-alpr-stolen-winona?fbclid=IwdGRjcAThPzVjbGNrBOE_HnBkb2YFZXh0bgNhZW0CMTEAc3J0YwZhcHBfaWQMMzUwNjg1NTMxNzI4AAEekw3uApSoOuTT_M-qSSnJmVmE0SltW4yaRF_X4bLbFOyTbuUqiCWdcaGIUmg_aem_eS-eWC0oCa6yv7H0Tups_w
Whether magicians, thieves, or just fed up citizens, somebody has made an entire city’s worth of ALPRs vanish in the night.
According to new reporting by MPR News, police in the city of Winona, Minnesota are incensed after their entire fleet of Flock license plate readers went missing.
Tomi Engdahl says:
Jyoti Mann / The Information:
Source: Muse Spark 1.1 model breached a company’s systems during cybersecurity testing; Meta says evaluation partner Irregular caused a sandbox misconfiguration — A Meta Platforms artificial intelligence model accessed the internet during cybersecurity testing and hacked into another company …
A Meta AI Model Hacked Another Company During Cybersecurity Testing
https://www.theinformation.com/articles/meta-ai-model-hacked-another-company-cybersecurity-testing
Tomi Engdahl says:
Lily Hay Newman / Wired:
OpenAI says the Hugging Face breach involved AI agents creating an internal message board, unnoticed by humans, where they shared exploits and planned the hacks — At the Black Hat security conference, the AI giant revealed new details about how its agents went rogue, hacked several other companies …
https://www.wired.com/story/openai-didnt-notice-its-ai-agents-using-a-message-board-to-plan-their-hacking-spree/
Tomi Engdahl says:
Wired:
A researcher with access to North Korean hackers’ servers says their operations have impacted 1,640 companies across 57 countries over the past 22 months — For nearly two years, researcher Vangelis Stykas has maintained access to North Korean hackers’ servers.
A Security Pro Hacked North Korean Hackers. He Found They’d Breached Hundreds of Networks Worldwide
https://www.wired.com/story/a-security-pro-hacked-north-korean-hackers-he-found-theyd-breached-hundreds-of-networks-worldwide/
For nearly two years, researcher Vangelis Stykas has maintained access to North Korean hackers’ servers. His work shows they pulled off intrusions in a shocking number of systems across the globe.
Tomi Engdahl says:
Meta AI Hacked External Systems During Cybersecurity Testing
https://www.securityweek.com/meta-ai-hacked-external-systems-during-cybersecurity-testing/
The incident involved a testing environment set up by Irregular, similar to what Anthropic reported last week.
Tomi Engdahl says:
The Fourth Battlefield: The Growing Role of Cyber Operations in Global Conflict
https://www.securityweek.com/the-fourth-battlefield-the-growing-role-of-cyber-operations-in-global-conflict/
CrowdStrike co-founder Dmitri Alperovitch discusses how cyber operations support kinetic warfare, signal coming conflicts, and reshape the global battlefield.
Tomi Engdahl says:
https://www.securityweek.com/tp-link-omada-ztp-vulnerabilities-chain-into-full-network-takeover/
Security researchers at Forescout have disclosed 15 new vulnerabilities in the zero-touch provisioning (ZTP) systems used by TP-Link’s Omada networking ecosystem, warning that some of the flaws can be chained to compromise entire fleets of managed devices.
Tomi Engdahl says:
New Attack Methods Enable Malware to Hijack Passkey-Protected Accounts
Palo Alto Networks researchers have demonstrated attacks against Google’s synced passkey implementation.
https://www.securityweek.com/new-attack-methods-enable-malware-to-hijack-passkey-protected-accounts/
Tomi Engdahl says:
Cybersecurity Alliance Drafts SAFE Guidelines for Sharing AI Incident Data
The guidelines are the work of the recently launched Open Secure AI Alliance, which now includes 120 organizations.
https://www.securityweek.com/cybersecurity-alliance-drafts-safe-guidelines-for-sharing-ai-incident-data/
Tomi Engdahl says:
AI Agents Targeted Real People and Projects During Cybersecurity Tests
AI Security Institute reports Anthropic and OpenAI models going rogue against real people, organizations, and open source projects.
https://www.securityweek.com/ai-security-institute-reports-anthropic-and-openai-models-going-rogue-against-organizations/
While testing the capabilities of frontier AI models, the AI Security Institute (AISI) observed first-hand how Anthropic Mythos 5 and OpenAI’s GPT-5.6-Sol went rogue and targeted real people and organizations over the internet.
AISI’s disclosure comes fresh on the heels of Anthropic and OpenAI disclosing that their models broke loose and hacked several organizations.
The institute was evaluating the cyber capabilities of Mythos 5 and GPT-5.6-Sol models that did not have cyber classifiers (mechanisms to prevent misuse) enabled. It ran a challenge 122 times, and in 10 runs “an AI agent took autonomous, unsanctioned action on the live internet.”
Over the 10 runs, the agents engaged in 19 rogue actions. Mythos 5 was responsible for 17 of them, and GPT-5.6-Sol performed the other two.
Tomi Engdahl says:
Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack
The malware was designed to steal and exfiltrate secrets, and to propagate itself via stolen NPM and GitHub credentials.
https://www.securityweek.com/over-400-npm-packages-infected-in-chaindrop-supply-chain-attack/
Tomi Engdahl says:
Rethinking AI Security: Why CASB and DLP Need an Interaction-Aware Layer
Build your strategy around answering these questions to ensure employees use AI productively while keeping sensitive data, IP, and agent behavior within the boundaries set for safe AI use.
https://www.securityweek.com/rethinking-ai-security-why-casb-and-dlp-need-an-interaction-aware-layer/
Employees across organizations are using AI to harness its potential to automate, coordinate, and optimize complex workflows. Some of that happens through tools IT has reviewed and approved. A lot of it happens through personal accounts and browser extensions nobody in security has ever seen, let alone signed off on.
The familiar security playbook to minimize AI risk is to discover the AI tools in use. Gate access with CASB, adding DLP rules to the mix, and tracking their usage. While this is not a bad security model (considering that its worked for years to secure SaaS sprawl) it has its limitations when it comes to AI.
Tomi Engdahl says:
Decades-Old BMC Vulnerability Exposes Thousands of Data Centers to Attacks
Over 24,000 internet-accessible server-management interfaces disclose authentication hashes before login.
https://www.securityweek.com/decades-old-bmc-vulnerability-exposes-thousands-of-data-centers-to-attacks/
Tomi Engdahl says:
Is Patching Dead? Vulnerability Management in the Post-Mythos Era
You cannot out-patch a machine that writes a working exploit from a vulnerability description in twenty hours. Stop trying to optimize a game you cannot win.
https://www.securityweek.com/is-patching-dead-vulnerability-management-in-the-post-mythos-era/
On July 14, 2026, the White House launched Gold Eagle: a federal clearinghouse that uses frontier AI to identify, rank, and coordinate the remediation of software vulnerabilities across government and critical infrastructure before attackers reach them. Bringing together the Treasury, DHS, DoD, open-source software partners, and operators of American critical infrastructure, Gold Eagle’s engine relies on frontier AI—including Anthropic’s Mythos, the same class of system that surfaced critical flaws inside classified U.S. government software during testing.
A government harnessing advanced AI to hunt vulnerabilities is conceding something fundamental: the two-decade model of humans finding and patching vulnerabilities one at a time has stopped keeping pace.
Gold Eagle is the national-scale response. The harder question is: what is required inside your own walls?
Tomi Engdahl says:
When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover
Identity confidence changes throughout every interaction and should be reassessed continuously as new risk signals emerge.
https://www.securityweek.com/when-identity-verification-fails-lessons-from-a-real-world-sim-swap-and-near-account-takeover/
Tomi Engdahl says:
Legacy Systems, Real-World Impacts: The Reality of OT Security
Legacy systems, safety concerns, and critical infrastructure risks make OT vulnerability disclosure one of cybersecurity’s most challenging balancing acts
https://www.securityweek.com/legacy-systems-real-world-impacts-the-reality-of-ot-security/
Tomi Engdahl says:
https://hackaday.com/2026/08/05/hacking-a-tenda-ac1200-wi-fi-router-with-a-cve-combo/
Tomi Engdahl says:
Another massive NPM worm: 444 packages with 2 billion monthly downloads infected with malware
https://cybernews.com/security/npm-supply-chain-attack-shai-hulud-worm/?utm_source=cn_facebook&utm_medium=social&utm_campaign=cybernews&utm_content=post&source=cn_facebook&medium=social&campaign=cybernews&content=post&fbclid=IwVERDUAThaa5wZG9mBWV4dG4DYWVtAjEwAHNydGMGYXBwX2lkDDM1MDY4NTUzMTcyOAABHhdgvUlu_e6LiMRMwojJYsaycNuINk27QKYI6hfYUmNryyZ30JXD3mmEpdru_aem_fb3Vx8d3LF6EHNT1fmA3lA
Key takeaways:
Malware infected at least 444 npm packages spanning 2,000 versions, threatening software with over two billion monthly installs.
Attackers compromised maintainer Jared Wray’s account, then used stolen credentials to automatically poison more packages.
Infected installs steal hundreds of credential types and tamper with Claude and Visual Studio Code configurations.
Experts urge affected organizations to assume exposure, rotate secrets, audit repositories and packages, and clean infected systems.
Tomi Engdahl says:
Fool Me Twice
A Whole Bunch of People’s Claude Chats Are Publicly Accessible Online, and There’s Some Wildly Private Stuff in There
Anthropic said the system is working as intended.
https://futurism.com/artificial-intelligence/claude-chats-publicly-accessible?fbclid=IwVERDUATha0lwZG9mBWV4dG4DYWVtAjEwAHNydGMGYXBwX2lkDDM1MDY4NTUzMTcyOAABHvI5IIdaJcUg6_6VAfbkykmt3ESg-sBg2uCQRfOfPXBjs58i4XVQc9_MKdN3_aem_IliWYnod7BRyIkIqiZlCNg
A trove of chat logs and projects created with Anthropic’s Claude — some including sensitive personal and company information — have been left exposed to Google, making them them searchable to anyone on the web.
Many of the materials appear to have been made public when Claude users opted to distribute a given chat or project to colleagues or associates using the chatbot’s “share” feature. After hitting the “share” button in the top right corner, Claude notes that sharing will create a “public” link, which “anyone with the link can view.” The warning, though, doesn’t alert users that shared content could wind up being indexed by a search engine — meaning that a user could effectively be sharing their Claude-generated document with the entire internet.
Tomi Engdahl says:
Data centers are about to get a big shock.
Source: https://go.ufdmedia.com/gLdcpx
US mulling ban on key Chinese networking tech in data center component crackdown — White House wants to impose restrictions in 2026, China says it will respond if necessary
https://www.tomshardware.com/tech-industry/data-centers/us-mulling-ban-on-key-chinese-networking-tech-in-data-center-component-crackdown-white-house-wants-to-impose-restrictions-in-2026-china-says-it-will-respond-if-necessary?fbclid=IwVERDUAThtDJwZG9mBWV4dG4DYWVtAjEwAHNydGMGYXBwX2lkDDM1MDY4NTUzMTcyOAABHi1-Js-y9idSdTA9Q3tnERpLjTP44qT-4P8M4YehE38RKZHe1ixmmyyRtYvq_aem_J0_Iy0-wt-2ZegLY8oCgsA
The U.S. Federal Communications Commission (FCC) is working on a ruling that will ban the import of Chinese-made optical transceivers, which are widely used in data centers to convert electrical impulse data into light and vice versa. Sources told Reuters that the agency wants to publish the ruling so that it would take effect before the end of the year.
“Transceivers definitely pose a risk,” AI policy expert Divyansh Kaushik of advisory firm Beacon Global Strategies told the publication. “As the data center buildout scales up, you want to make sure the data center supply chain is secure from the get-go.” The administration fears that these components could be used to steal data, install malware, or disrupt data center operations in the U.S.
These optical transceivers are crucial for data centers as they require less electrical energy than traditional copper-based wiring and are also much faster. There are several U.S.-based manufacturers of these components, like Lumentum, Coherent, and Apple Optoelectronics, but Reuters said that they do not have the scale and capacity of leading company Innolight, which has cornered 27% of the global market.
This isn’t the first industry-wide ban that the FCC has imposed in recent months. While the U.S. has banned Huawei products from the country since 2019, it recently enforced several other bans that have primarily affected major Chinese or China-connected companies. This includes the ban on foreign-made drones, applied in December 2025, foreign-manufactured routers, enacted last April, and advanced robotic devices that weigh over 4.4 pounds and have a 200-kbps connection, which was announced just last month.
Tomi Engdahl says:
https://www.facebook.com/share/p/1Q3Wzsdn5P/
Meta said one of its AI models breached another company’s systems during cybersecurity testing after a testing error gave the model unintended internet access.
The model exploited a vulnerability in a third-party service and reportedly altered internal systems.
Meta said it is investigating the incident.
Testing partner Irregular said the breach resulted from a misconfigured evaluation environment and was not a sophisticated cyberattack or sandbox escape.
Similar incidents were recently disclosed by Anthropic and
OpenAI.
Source: The Information
Image: Reuters
Tomi Engdahl says:
ChatGPT’s OpenAI, Claude’s Anthropic and now Meta have all announced that their systems have launched cyber attacks on other people and companies
Out-of-control AI systems are going rogue and hacking people. Is it time to panic?
https://www.independent.co.uk/tech/security/ai-artificial-intelligence-hack-cyber-attack-b3028787.html?fbclid=IwdGRjcATiOPtjbGNrBOI4unBkb2YFZXh0bgNhZW0CMTEAc3J0YwZhcHBfaWQMMzUwNjg1NTMxNzI4AAEeP91VNABnA-peOAgo2R8Hrbc8rav4VYmM5WqytZlHxk7rW5oDx4acDcpVW2A_aem_EfewlCbgRPD5N4SN3958lQ
ChatGPT’s OpenAI, Claude’s Anthropic and now Meta have all announced that their systems have launched cyber attacks on other people and companies. But there are plenty of reasons to stay calm, for now
It sounds terrifying, an indication that our fears about artificial intelligence systems undertaking attacks on their own might be coming true. And it is scary in part because it is among the first time that AI tools have attacked real people and organisations in potentially harmful way
The examples are various: OpenAI, Anthropic and now Meta have all announced that their experimental systems have launched cyber attacks on other companies. Though the details of each case varies, more and more examples are being reported on a near-daily basis.
The story began last month, when OpenAI said that an experimental version of the model that powers ChatGPT had broken out of its safeguards, connected itself to the internet, and hacked into another company, essentially allowing it to cheat on a test it was being set to see how useful it would be for cyber security. In the time since, other companies have announced similar examples, and OpenAI has found that their tools might have been launching more such attacks than it had realised.
But should we worry? Is this really the terrifying scenario that science fiction authors and AI experts have been warning us about for decades?
The truth is a little more nuanced. There are absolutely plenty of causes for concern – but there are plenty of reasons not to panic just yet, too.
As soon as OpenAI announced the initial cyber attack, the world was hit by a wave of worry. It seemed to confirm much of the anxiety around AI: that the tools were becoming powerful more quickly than the safeguards that are intended to keep them controlled, and that if it continues then we might be unable to secure them and avoid potentially disastrous consequences.
In all of the newly reported hacks, the specific nature of the individual cyber attacks was relatively harmless and contained, focused on other AI companies. But it is easy to imagine how the focus of such attacks could change, and that a future AI-powered cyber attack could focus on important infrastructure, for instance.
Similarly, all of the “rogue” AI system were really just carrying out instructions, albeit in roundabout and unexpected ways: if you are told to do what you can to pass a test, then it might make rational sense to cheat on it. But this is exactly why the field of “AI alignment” is so key to the current wave of artificial intelligence – it refers to the practice of ensuring that systems work in keeping with human ethical frameworks, to ensure that they do not accidentally show behaviour that we would disagree with.
This can be complicated, however, and it shows another reason that it is easy to imagine a future scenario in which such an AI attack would be much worse.
the recent run of examples only serves to show: if an AI is given an instruction, it might follow it in ways that we cannot predict and would never want to happen.
“There’s a lot of hype around rogue AI agents, and we can’t ignore the fact AI companies want to present their prototype models as really powerful and even dangerous. But there is a genuine threat here,” said Jake Moore, global security adviser at ESET.
“Right now, the AI-led breaches we’ve seen involve models breaking out of test environments and hitting technology companies that have something they need to achieve their goal.
“But AI doesn’t always get it right. Once it’s decided that accessing a company is key to meeting its objective, aggressive frontier models will hammer an organisation until they are stopped or it has been breached. It’s not a stretch to think more companies will end up in an AI’s crosshairs during future security tests.”
So the cause for worry is not necessarily that the recent run of hacks really threaten anything important. It is that they could be an early example of the dangers that experts warn powerful AI could bring: that increasingly autonomous and capable AI systems could use their powers in ways that are damaging to humanity, and we might not even know that it is happening.
Why we shouldn’t panic
Still, we are not there yet. The recent run of reports might be concerning – but they are also limited in scope and seem to have happened only in experimental testing.
In many ways, it is helpful for the companies involved for us to panic. It is a marketing technique that has been used heavily by the AI companies ever since the current artificial intelligence boom started with the launch of ChatGPT, in 2022; these systems are the future but are dangerous too, so you had better fund the less evil companies, they urge.
This time around, by suggesting their systems are so scarily powerful that we can’t control them, they help to highlight the cyber security capabilities that all major AI companies are currently using as a central way of pushing their products. And, at the same time, they imply that any potential dangers are the fault of the AI itself, rather than the companies making them, which can be convenient.
In all the examples apart from the initial report – that around an OpenAI’s attack on a fellow AI company, Hugging Face – the problems have occurred because the companies have not properly secured their testing environment. In the examples at Anthropic and Meta, for instance, the safeguards were not properly configured, so that the systems did not actually have to break themselves onto the internet in order to get online.
Shifting the response from being about the companies’ failures to the scarily powerful nature of their systems is advantageous for those companies, because it moves the story from being about the potentially insecure nature of the tests to performance of their tools.
You can also see this in the way companies have made their disclosures. First came OpenAI, then came Anthropic, and now Meta has claimed that its AI too has been involved in hacking.
The innocent and probably true reading is that the OpenAI announcement led other companies to investigate their own systems, and found evidence that they too had been launching cyber attacks.
But at the same time the fact that those companies were so keen to disclose what could be an embarrassing or worrying problem suggests that there is some kind of marketing value in doing so – and that, as a consequence, it might be helpful for them for us to panic now.
What can we do?
As ever, in this era of incredibly powerful artificial intelligence firms, it is easy to feel powerless. AI companies are unusual in that many people don’t even actually pay for their products, so it is hard to exercise even that little bit of consumer pressure.
But experts advise that there are steps we can take. They are much the same as with other cyber security threats: ensuring that important data isn’t easily available online, and that we are being vigilant about checking for suspect behaviour and installing updates, for instance.
“The most important changes need to come from the AI firms themselves. They should be putting stronger controls into testing processes to stop AIs breaking out, and limit how persistent the models are at achieving their goals by any means necessary,” said Moore.
Tomi Engdahl says:
https://thehill.com/regulation/court-battles/6013559-mississippi-judge-declares-towers-dumps-unconstitutional/
Tomi Engdahl says:
https://www.facebook.com/share/p/1DW3yGtu8r/
One factor above all others is shaping today’s cybersecurity landscape: artificial intelligence. It is not only transforming business efficiency but also providing cybercriminals with unprecedented resources.
“The stakes in this evolving threat landscape are high: your entire business is at risk. If your cybersecurity does not meet today’s minimum acceptable security baseline, you are exposing your organisation to serious risk,” says Toni Vartiainen, Head of Security Business at DNA.
Read Toni’s blog to find out why the solid stone walls protecting your business now need watchtowers and guards alongside them!
Solid stone walls no longer protect your fortress – modern cybersecurity requires watchtowers and guards
https://www.dna.fi/dnabusiness/blogi/-/blogs/solid-stone-walls-no-longer-protect-your-fortress-modern-cybersecurity-requires-watchtowers-and-guards?utm_source=facebook&utm_medium=social&utm_content=LAA-artikkeli-solid-stone-walls-no-longer-protect-your-fortress-modern-cybersecurity-requires-watchtowers-and-guards&utm_campaign=P_LAA_26-31-36_artikkelikampanja_enkku&fbclid=IwdGRjcATibqBwZG9mBWV4dG4DYWVtATAAYWRpZAGrNrTDN7Jcc3J0YwZhcHBfaWQMMzUwNjg1NTMxNzI4AAEelk3VkTmsxMwDmwvRV_ECUvZaw4NF5_KhQRjjdKOmGlzuOqFKLr_L8Kw2Fu4_aem_deaPifyQM1sGsR02uQDS-w&utm_id=120249963597740556&utm_term=120249963597770556
The world around us has changed faster than many of us ever anticipated. Not long ago, cybersecurity was all about building a fortress. Today, that fortress is under constant attack, breached by ever-evolving methods.
Tomi Engdahl says:
China launches mysterious probe into security of Palo Alto Networks’ products
Beijing’s not saying why, which is just what happened when it investigated Micron
https://www.theregister.com/security/2026/08/07/china-launches-mysterious-probe-into-security-of-palo-alto-networks-products/5284453
China’s Cyberspace Administration (CAC) has conducted a review of Palo Alto Networks’ products.
The regulator’s announcement of its review says it’s needed “to ensure the safe and stable operation of critical information infrastructure, prevent cybersecurity risks and vulnerabilities, and safeguard national security.”
And that’s all Beijing has to say on the matter.
A Palo Alto spokesperson provided The Register with the following statement: “We maintain the highest standards of business conduct and security practices and ethics across our global operations. At this time, there is no impact to our ability to support customers or deliver our products and services in the region.”
This matter has echoes of China’s 2023 investigation into the security of products from memory-maker Micron, which the CAC announced out of the blue.
The CAC published its findings weeks after announcing the probe and decided Micron’s products represented an unacceptable security risk for critical infrastructure operators – effectively banning sales of Micron products to such entities – but didn’t offer a detailed explanation for its decision. The memory-maker eventually stopped selling its datacenter and server products in China, a decision that cost it billions of annual revenue – but created new opportunities for China’s own memory-makers, which are largely prohibited from selling to American companies.
China is home to several security companies whose product portfolios overlap with Palo Alto’s. Huawei and H3C, for example, have plenty to offer local buyers.
Tomi Engdahl says:
https://www.facebook.com/share/p/19EUK2n2qs/
As details emerged about OpenAI’s rogue agent hacking Hugging Face, the cybersecurity community reached a conclusion that cut through the AI frontier narrative: the incident was largely preventable.
The two models that escaped containment did so partly because deployment safeguards were intentionally disabled for testing. Security researchers say the breach also reflects a failure to implement foundational protections, including zero trust architecture and defense in depth, that the industry has spent two decades developing and promoting.
OpenAI is valued at $850 billion. It employs veteran security hires from across the tech industry. The protections that may have prevented the incident are well known and widely available.
A cloud security founder put it plainly: “The fact that OpenAI wasn’t more paranoid about this seems kind of reckless.” A longtime security consultant was equally direct: “The OpenAI mistakes were dead simple.”
OpenAI has since deactivated and encrypted the unreleased model, launched a review with external advisers, and committed to publishing a technical postmortem. The company noted that its existing safeguards, had they been in place, may have prevented or minimized the incident.
The deeper question the episode raises about how AI development culture approaches security is the part most coverage has moved past too quickly.
Read the full story, link in comments.
OpenAI’s Hacking Debacle Comes Down to Human Error
https://www.wired.com/story/openais-hacking-debacle-was-a-human-mistake/?fbclid=IwdGRjcATilRJjbGNrBOKU-nBkb2YFZXh0bgNhZW0CMTEAc3J0YwZhcHBfaWQMMzUwNjg1NTMxNzI4AAEe1ZsBizliGV6yd-ZkyCpcattmOderw6MJwmHSNk8mhnIiimcZHFetKLZj858_aem_aKpe0gw8Y3Qo2YYdyoyf4w
If the generative AI giant had followed well-known security best practices, it’s likely that its AI agent would never have escaped to the open internet and hacked multiple companies.
Tomi Engdahl says:
https://tldr.tech/ai?fbclid=IwdGRjcATilWlwZG9mBWV4dG4DYWVtATAAYWRpZAGrNdWIIBdIc3J0YwZhcHBfaWQMMzUwNjg1NTMxNzI4AAEeTkJEV2JvtE5TV70v0pR7tDDbFSOKWHyrH16TCIJO3cNgotgYAoQo-iiEzQU_aem_AsHmrZLOpr29jwyF6MGTtw&utm_medium=paid&utm_source=fb&utm_id=120247152258560776&utm_content=120249006206090776&utm_term=120247152258600776&utm_campaign=120247152258560776
Tomi Engdahl says:
They’re useless — at best. https://trib.al/vf7oTsb
Cops And Donuts
Flock Surveillance Cameras Are Actually Horrible for Fighting Crime, FBI Data Shows
“The public has been asked to accept a significant expansion of surveillance based on the promise that it would dramatically improve public safety.”
https://futurism.com/future-society/flock-surveillance-atlanta-fbi-data-crime-case-solve?fbclid=IwdGRjcATilqdjbGNrBOKWjXBkb2YFZXh0bgNhZW0CMTEAc3J0YwZhcHBfaWQMMzUwNjg1NTMxNzI4AAEe-hWGEJ64S5CaIhY7-TJiP9jvPWz55A6r2MMIokPzBbQyqHbSeSFPS-tOw5o_aem_DpNVyBEQs-Lu0UXq0xMODw
Since the launch of Flock Safety in 2017, the ACLU estimates the company installed some 100,000 automatic license plate readers throughout the United States. The dragnet comes with plenty of downsides to privacy and civil liberties: it’s ripe for abuse by crooked cops, powered by sweatshop labor, and nearly impossible to escape once it designates you a target.
But police officials insist it’s worth the trade off — because at it least it helps them catch the bad guys, right? Unfortunately, the reality isn’t quite that peachy.
Atlanta, Georgia has experienced far and away the largest influx of ALRPs in the country, with over 5,000 various Flock cameras now blanketing the city. Yet as bombshell data released by the FBI shows, the city’s massive web of surveillance has had virtually zero impact on the Atlanta Police Department’s ability to solve crime, with some clearance rates for offenses like homicide even experiencing a decline over the past few years as the cameras have proliferated.
First reported by the Atlanta Community Press Collective, the FBI data is a damning refutation of Flock’s primary claim: that ALPRs are necessary to help officers keep the public safe.
According to the ACPC, the rates at which the APD resolves crimes like homicide, robbery, miscellaneous larceny, and shoplifting have actually decreased between 2021 and 2025, when the city’s ALPR build-out hit its full stride.
Though the APD actually did show improvement on some crime categories as Flock’s cameras sprouted all over the city, the changes from 2021 to 2025 amount to little more than rounding errors.
Len Phillips, head of the anti-ALPR community group DeFlock Atlanta told ACPC that the “public has been asked to accept a significant expansion of surveillance based on the promise that it would dramatically improve public safety.”
In reality, Phillips continues, that tradeoff between safety and civil liberties “was just a one-way transaction.”
Loud and Clear
In Light of Overwhelming Backlash, Flock Cancels Creepy Audio Surveillance Feature
“After careful consideration and community consultation, we decided to remove the feature.”
https://futurism.com/future-society/flock-surveillance-backlash-audio-distress-screaming-police?fbclid=IwVERDUATil2JwZG9mBWV4dG4DYWVtAjEwAHNydGMGYXBwX2lkDDM1MDY4NTUzMTcyOAABHiB7Pod3cB6Q1OyyO7D5GU_9gk6ukTaALvvQtaULeKImhXCiT_S5rLOrcwIT_aem_gpnlmhCeqPaCqfrCDlBG6g
Tomi Engdahl says:
The outrage is surging. https://bit.ly/4wEsvX6
Flock Around And Find Out
Flock Is Losing Dozens of Contracts as Controversy Grows
The outrage is surging.
https://futurism.com/future-society/flock-dozens-contracts-alprs-controversy-cancellation?fbclid=IwdGRjcATil5FjbGNrBOKXfHBkb2YFZXh0bgNhZW0CMTEAc3J0YwZhcHBfaWQMMzUwNjg1NTMxNzI4AAEeJLnmYNo_NgdGeSfN0xRz8cRO9dt_lmPEeJWhAiJ3_I6O7SSp_NY47dadrsw_aem_p4RYRIMHfrzJKjMzosAjzg
Mass surveillance technology might be popular with police departments, but for the US public, it’s becoming an increasingly difficult sell.
At least 54 cities across the US have voted to cancel, non-renew, or reject Flock’s automatic license plate reader (ALPRs) since the start of the year, according to data collected by the Washington Examiner. That comes after reporting in February that some 30 cities had done the same since 2025, indicative of the rising backlash against the tech.
In all, the Examiner reports cities in 23 states have shredded their Flock contracts so far this year, led by California and Wisconsin, which each have seven rejections, cancellations, or deactivations. Other heavy hitters include New York, Washington, and Massachusetts with four each, and Virginia with three.
Though Flock has its cameras in over 5,000 US cities as of July 2026, the rise in rejections at the municipal level comes amidst a tidal wave of outrage around issues of privacy and civil rights.
Tomi Engdahl says:
Hackers targeted US private equity, other firms including Blackstone, CME, data shows
https://www.reuters.com/world/hackers-targeted-us-private-equity-other-firms-including-blackstone-cme-data-2026-08-06/?link_source=ta_first_comment&taid=6a74c280d486d00001b58c66&utm_campaign=trueAnthem%3A%20Trending%20Content&utm_medium=trueAnthem&utm_source=facebook&fbclid=IwdGRjcATipKpjbGNrBOKknXBkb2YFZXh0bgNhZW0CMTEAc3J0YwZhcHBfaWQMMzUwNjg1NTMxNzI4AAEe6CDWgF9eFQtMj4o_tgRC5WegtMvnRMyQTjv4Rpgs4Rou_XjUKD-nYEB5vQs_aem_488mwvfc483evYd10ZmCfQ
Tomi Engdahl says:
AI slop infiltrates the CVE system: “the cited code didn’t even exist”
https://cybernews.com/ai-news/ai-slop-infiltrates-the-cve-system/?utm_source=cn_facebook&utm_medium=social&utm_campaign=cybernews&utm_content=post&source=cn_facebook&medium=social&campaign=cybernews&content=post&fbclid=IwVERDUATiq8VwZG9mBWV4dG4DYWVtAjEwAHNydGMGYXBwX2lkDDM1MDY4NTUzMTcyOAABHmgtVIbXe6XYwHjYwVKa6eCmYyyDxWcHsPjFciCKRax2xRdqHh2LOsFjL21G_aem_8R2QA9WDpO8UX7mYet4S9A
Nothing is sacred for AI slop
Key takeaways:
JFrog found dozens of likely AI-generated fake vulnerabilities, with some receiving official CVE identifiers and Critical ratings.
Several fabricated advisories targeted SQLite, but researchers said the cited vulnerable code and exploit behavior did not exist.
The fake entries entered trusted security pipelines, risking false alerts, wasted patching work, and reduced trust in vulnerability data.
The incident shows AI-generated junk is moving beyond consumer platforms and threatening core cybersecurity systems.
Tomi Engdahl says:
https://www.securityweek.com/rethinking-ai-security-why-casb-and-dlp-need-an-interaction-aware-layer/
Tomi Engdahl says:
https://www.securityweek.com/timeless-compliance-why-better-questions-beat-bigger-frameworks/
Tomi Engdahl says:
https://www.securityweek.com/is-patching-dead-vulnerability-management-in-the-post-mythos-era/
Tomi Engdahl says:
https://www.securityweek.com/zero-click-ai-browser-hacking-claude-and-chatgpt-atlas-hijacked-via-emails-x-posts/
Tomi Engdahl says:
Black Hat on YouTube:
At Black Hat, OpenAI reconstructs the OpenAI-Hugging Face incident and examines its implications for AI security, cyber resilience, and alignment
Black Hat USA 2026: The ‘Breaking’ News: The OpenAI–Hugging Face Incident
https://www.youtube.com/watch?v=87DyyMV0kCY
Tomi Engdahl says:
Will Knight / Wired:
Security researchers claim that Kimi K3 went outside of its sandbox during defensive cybersecurity tests, but did not hack anything after accessing the internet — Security researchers say that Kimi K3, an open-weight model from China, wandered off to the internet in an attempt to cheat on a test it was given.
One of China’s Most Powerful AI Models Has Also Escaped Containment
https://www.wired.com/story/moonshot-kimi-k3-ai-model-escape-sandbox/
Security researchers say that Kimi K3, an open-weight model from China, wandered off to the internet in an attempt to cheat on a test it was given.
Tomi Engdahl says:
Horrifying. https://trib.al/LGdfIVo
Friendly Fryer
It Appears That the US Military Accidentally Killed Everybody on Board a Civilian Medevac Flight in New Mexico
“When those lights go out, man, you know you are in big trouble.”
https://futurism.com/science-energy/us-military-gps-jamming-signal-medical-flight?fbclid=IwdGRjcATi3RljbGNrBOLdCXBkb2YFZXh0bgNhZW0CMTEAc3J0YwZhcHBfaWQMMzUwNjg1NTMxNzI4AAEeL4FHAYPqCBG3rY4uc0FeB-nErDV7d1ZJqzJuVsc6itaRMMdq4I9LRSFTwAw_aem_ge7ShMVhpvOkN63i0p9WzA