This posting is here to collect cyber security news in September 2026.
I post links to security vulnerability news to comments of this article.
You are also free to post related links to comments.
This posting is here to collect cyber security news in September 2026.
I post links to security vulnerability news to comments of this article.
You are also free to post related links to comments.
198 Comments
Tomi Engdahl says:
What does it mean if AI hacks a government? Because that’s exactly what it’s done
Read more: https://trib.al/wvCAddX
Tomi Engdahl says:
One AI chatbot tried to blackmail an engineer to avoid being shut down. Here’s what experts are actually worried about
Read more: https://trib.al/ReGfvl8
Tomi Engdahl says:
AI agents, including OpenAI’s, tried to hack UNM’s digital library, Data USA, and an Australian government site in May and June using the urlquery.net service — Jack Cable*,2, Daniel Chiu*, Francisco Pernice*,3, Selena Zhang*,1, James Anthony1, Tetiana Bas4, Gary Shen4, Conrad Stosz1, Jacob Steinhardt1
Early rogue AI agent activity and attempts to hack found on urlquery.net
https://transluce.org/agent-activity
Tomi Engdahl says:
The Age:
Australian PM Anthony Albanese says an OpenAI agent gained unauthorized access to a public-facing Medicare portal in June, accessing public and non-public files — Prime Minister Anthony Albanese has revealed that an artificial intelligence agent developed by OpenAI infiltrated …
https://www.theage.com.au/politics/federal/openai-breaches-medicare-albanese-reveals-20260924-p6100u.html
Tomi Engdahl says:
New York Times:
OpenAI says its AI agents “took actions we did not intend” when they tried to hack government and university websites, and it is working with the organizations — In each incident, the technology appeared to be conducting mundane data collection and resorted to hacking techniques to get it, researchers said.
https://www.nytimes.com/2026/09/23/technology/openai-ai-breach-australia.html?unlocked_article_code=1.DlE.2yAf.hUUS5mCftkOD&smid=url-share
Tomi Engdahl says:
A faulty SmartThings firmware update left some Samsung smart fridges unresponsive in South Korea. More: https://cnews.link/samsung-smart-fridge-firmware-malfunction/
Tomi Engdahl says:
Artificial Intelligence
OpenAI Agents Probed Websites for Vulnerabilities While Fetching Public Data
Australia disclosed that an OpenAI agent gained unauthorized access to non-public government information.
https://www.securityweek.com/openai-agents-probed-websites-for-vulnerabilities-while-fetching-public-data/
Tomi Engdahl says:
Artificial Intelligence
Autonomous AI Hacks Raise Thorny Questions of Legal Accountability
The prospect of legal accountability is unclear. Lawsuits are a possibility, but some legal experts believe any criminal investigations would face an extremely high burden.
https://www.securityweek.com/autonomous-ai-hacks-raise-thorny-questions-of-legal-accountability/
The Justice Department has a long history of investigating and prosecuting hackers who break into a private company’s network.
But what happens when the hackers aren’t human?
That’s the question at the center of a public policy debate roiling Silicon Valley and Washington following disclosures by leading tech companies that their artificial intelligence models went rogue and hacked into other organizations. The attacks have generated calls even from within the industry for greater oversight and regulation, spurred congressional inquiries and raised questions about whether a years-old legal framework designed to punish criminal hackers is sufficient in an era of autonomous actors capable of engineering their own havoc.
It all adds up to a “Wild West,” said Jack Nelson, chief information security officer and deputy general counsel at the software company Ivanti. Questions of accountability will focus on what the companies knew when they were developing the models, how much they understood about what could happen and what guardrails existed, he said.
“If you owned a tiger and you didn’t put a lock on the cage, the tiger probably did something bad you didn’t intend for it to but you knew it could have, so you are responsible for not putting a lock on that cage,” Nelson said.
“I don’t know if I would go so far as to say these models are tigers without locks, but that’s probably a decent framework to think of it as,” he added.
Tomi Engdahl says:
AI-Powered Campaign Targets Hundreds of Online Retailers
A threat actor is using three AI harnesses for vulnerability research, exploitation, and attack orchestration.
https://www.securityweek.com/ai-powered-campaign-targets-hundreds-of-online-retailers/
Tomi Engdahl says:
OT Security Guidance: NIST Drafts Updated Guide, CISA/FBI Advise on ICS Integrators
Revision 4 of NIST’s operational technology security guide is open for public comments until November 30.
https://www.securityweek.com/ot-security-guidance-nist-drafts-updated-guide-cisa-fbi-advise-on-ics-integrators/
Tomi Engdahl says:
Begin at the End: How to Enable Agentic Remediation
Agentic remediation is not an act of faith. We are talking about fixing known problems, not judgment calls about unfamiliar risk.
https://www.securityweek.com/begin-at-the-end-how-to-enable-agentic-remediation/
There is a corporate mandate to implement AI enablement programs. In cybersecurity, integrating AI chatbots into dashboards is table stakes. The industry, and the organizations it serves, must evolve to adopt agentic AI.
But true autonomy isn’t just about moving faster – it’s about changing the goalpost entirely. The ultimate objective is Shift Zero: eliminating vulnerability backlogs entirely and preventing exposure at the source. To achieve this, the best place to begin is the end.
Continuous threat exposure management (CTEM) is a framework to discover and remediate threats and exposures. The final step of this framework, mobilization, is the operational endpoint. Until now, this has remained a time-consuming manual process.
Automation has historically been focused on discovery, prioritization, and validation. By inverting the traditional CTEM framework to focus on automating remediation, organizations can close the loop on exposure management.
Tomi Engdahl says:
Critical WordPress Vulnerability Exploited Immediately After Disclosure
Tracked as CVE-2026-87902, the path traversal flaw allows remote, unauthenticated attackers to execute arbitrary code.
https://www.securityweek.com/critical-wordpress-vulnerability-exploited-immediately-after-disclosure/
The exploitation of a fresh WordPress vulnerability started within hours of public disclosure and has escalated to active compromises, security firm Patchstack warns.
Tracked as CVE-2026-87902 (CVSS score of 9.2), it is a path traversal flaw in WordPress’ page-template resolution. Under certain conditions, unauthenticated attackers could exploit it for remote code execution.
“An unauthenticated attacker can make get_page_template() page-template resolution include a chosen readable local .php file outside the active theme directories. If relevant pre-conditions for both the server environment and the active theme are met, this can lead to RCE,” WordPress’ advisory reads.
The security defect can be triggered if the name of the top-level directory of the active child or parent theme starts with ‘page-‘ and if the web server account can read a chosen local .php target file that exists on the server.
“The well-known pearcmd.php PEAR→RCE transition can be used for this when register_argc_argv is set to On. The official PHP image for Docker is affected, and the default cPanel configuration is affected when PHP prior to 8.5 is in use,” the advisory reads.
Pearcmd.php provides a command-line tool for the management of PEAR packages in PHP environments and can be abused for RCE on servers with register_argc_argv enabled, especially when combined with a local file inclusion or a path traversal issue.
Tomi Engdahl says:
Sähköauton laturista tuli uusi hyökkäysreitti sähköverkkoon
https://etn.fi/index.php/13-news/19323-saehkoeauton-laturista-tuli-uusi-hyoekkaeysreitti-saehkoeverkkoon
Sähköauton latausasema ei ole enää pelkkä pistorasia, vaan verkkoon, pilvipalveluihin ja maksujärjestelmiin kytketty tietokone. Tata Consultancy Servicesin mukaan puutteellisesti suojattu latausinfrastruktuuri voi muodostaa hyökkäysreitin, jonka vaikutukset ulottuvat yksittäisestä latauspisteestä aina sähköverkkoon asti.
Sähköautojen määrän kasvaessa myös latausverkosta tulee yhä merkittävämpi osa kriittistä infrastruktuuria. TCS:n mukaan tämä tekee latausasemista houkuttelevan kohteen kyberhyökkäyksille. Suomessa jo joka kahdeksas henkilöauto on ladattava hybridi tai täyssähköauto.
Latausasemien hyökkäyspinta on huomattavasti tavallista sähkölaitetta suurempi. Asemat kommunikoivat taustajärjestelmien ja pilvipalvelujen kanssa, tunnistavat käyttäjiä ja käsittelevät maksutietoja. Jokainen näistä yhteyksistä muodostaa mahdollisen rajapinnan hyökkäykselle.
Tomi Engdahl says:
https://etn.fi/index.php/13-news/19325-kamerasta-tuli-tekoaelylasien-ongelma
Tomi Engdahl says:
GoDaddy receives takeover offer from maker of Norton antivirus software
https://www.ft.com/content/6cc7149f-a9f1-47f6-9faf-b98a28f9aedc?syn-25a6b1a6=1&fbclid=IwVERDUAUjDYVleHRuA2FlbQIxMABwZG9mBXNydGMGYXBwX2lkDDM1MDY4NTUzMTcyOAABHvA3fgd2Y1uB2dk7ZKUg5XfTtK2e9yjZoBxH3c2WyOXHUXk4YUgHwRnjRFRF_aem_oba2bnMoLo0MOZh7CjdPQw
Tomi Engdahl says:
https://www.facebook.com/share/p/19ouWgJPPM/
JUST IN: Flock Safety has sent a legal demand to take down a public map of roughly 300,000 of its devices across the U.S.
The Intercept says researcher Joshua Michael built it from a snapshot of Flock’s own location data — cameras plus the other boxes in the network. Flock has told the press it runs a much smaller camera count. Now it wants the detailed map offline.
They sold cities a web of plate readers. They don’t want you to see the web.
Tomi Engdahl says:
Flock Wants the Most Detailed Map of Its Surveillance Cameras Taken Offline published by The Intercept
https://theintercept.com/2026/09/23/flock-surveillance-map-cameras-takedown/
Tomi Engdahl says:
A data breach of the Pentagon’s vast HR system has exposed Social Security numbers and other personal information of current and former military personnel, raising counterintelligence concerns among national security experts. https://cnn.it/4yiV7WT
Tomi Engdahl says:
And the company won’t repair them for days. https://trib.al/Iotp0hw
Hacksaw Fridge
Software Update Turns Samsung’s “AI Fridges” Into Useless Bricks
Wait, why did fridges need AI in the first place?
https://futurism.com/artificial-intelligence/software-update-samsung-ai-fridges-useless-bricks?fbclid=IwdGRjcAUkXvJjbGNrBSRe1WV4dG4DYWVtAjExAHBkb2YFc3J0YwZhcHBfaWQMMzUwNjg1NTMxNzI4AAEers_yczlDhoILnTX0_qVAl50TLmRzUrOHltW9-CqWFt1I3jI0TMrvitIkFCc_aem_tQOrbT_OtWIf1Qyt03KHTQ
It’s become common knowledge among home owners to avoid Samsung home appliances like the plague. They’re notorious for frequently breaking down, and fixing them can turn into an expensive ordeal — if it’s even an option at all.
And after an entirely unnecessary and infuriating injection of AI, many unfortunate owners of a Samsung “Bespoke AI 4-Door” fridge were in for a rude surprise. Customers across South Korea found that their almost $4,000 appliance suddenly shut down after a faulty firmware update, turning them into an expensive — and fresh food ruining — brick.
Tomi Engdahl says:
Hackers took home a stolen Flock camera. What they found was massive
https://www.foxla.com/news/hackers-stolen-flock-camera?link_source=ta_first_comment&taid=6ab75280df91b000014cb3c4&fbclid=IwdGRjcAUldNVjbGNrBSV0qmV4dG4DYWVtAjExAHBkb2YFc3J0YwZhcHBfaWQMMzUwNjg1NTMxNzI4AAEetOK7h3mM28vFqVmOWc6bjkZ1XUEcQ6So7zyfP5w-JnAyF7yvE0uO5xXkX7w_aem_HqERHqB5snO0Cpkxs2FekQ
A stolen Flock Safety license-plate camera yielded roughly 1.6 million images after hackers physically removed and reverse-engineered the device, but a former Secret Service cybercrime expert says the incident does not appear to have compromised Flock’s broader cloud network.
Jason Brown, director of customer advisory and counter-fraud lead at threat intelligence firm iCOUNTER, spent 25 years with the U.S. Secret Service and specialized in cybercrime.
Brown told FOX Business that the distinction between accessing one physically stolen camera and breaching Flock’s network is critical.
“The biggest thing I keep hammering at home [is] that Flock was never compromised,” Brown said. “So there’s never been a large dump of information out of their network.”
According to WIRED, hackers physically removed a Flock camera from above a roadway and reverse-engineered it. They reportedly discovered encrypted and unencrypted portions of the device’s storage and recovered an encryption key stored on the camera that allowed them to unlock additional data.
“This was a situation where somebody physically had access to a camera because they stole it off of a pole, took it home, and then did backward engineering on that camera,” Brown said.
According to WIRED’s analysis, the recovered logs covered roughly 21 days of activity, including 1.6 million images, 50,200 vehicles and 27,000 short video clips.
Flock cameras capture images and short videos of passing vehicles, which are transmitted to the company’s cloud infrastructure for processing and can then be searched by authorized law enforcement users.
Brown characterized the stolen-camera incident and an earlier security issue in which some cameras temporarily became accessible over the internet as isolated events rather than evidence, based on what he knows, of a broader compromise of Flock’s system.
Brown said some cameras had previously been remotely accessible because of weak authentication controls, but said the issue was addressed
He said Flock reports that about 97% of law enforcement agencies using the system now have multifactor authentication enabled.
“The debate of do you have Flock in your community — that’s a debate for the community,” Brown added.
Still, Brown said the incident illustrates a broader cybersecurity issue involving third-party and supply-chain risks “that many corporations would see.”
Brown said the rapid advancement of artificial intelligence makes addressing those risks increasingly important.
“The security posture of everything is changing by the minute,” he said.
Tomi Engdahl says:
Hackers Got Inside a Flock Camera. Its Data Shows How the System Really Works
A hacker collective pulled down a Flock camera and dumped its data. The files included thousands of videos and logs showing that the device captured 1.6 million images of 50,000 vehicles in 21 days.
https://www.wired.com/story/hackers-flock-camera-data-shows-how-system-works/?fbclid=IwVERDUAUldqlleHRuA2FlbQIxMABwZG9mBXNydGMGYXBwX2lkDDM1MDY4NTUzMTcyOAABHhKt5xo1s6Z-bK0jPPK913ReP8sG9u8TLEatR_7yobB9kBxqhtqG7Kv4OeJY_aem__zwGt-rVFTyMqJZ3cLynmg
Tomi Engdahl says:
https://www.facebook.com/share/p/1D6KcDezK5/
A security researcher mapped over 300,000 Flock surveillance devices in the U.S., and Flock is fighting to take the data offline.
A newly published interactive map by cybersecurity researcher Joshua Michael has revealed that Flock Safety’s surveillance network in the United States is far larger than previously publicly reported.
Utilizing a December 2025 data snapshot obtained through an exposed, unauthenticated path on Flock’s ArcGIS mapping system, the map details over 300,000 devices nationwide.
This includes more than 170,000 automated license plate reading cameras and 130,000 accompanying hardware gadgets, such as acoustic detectors. The sheer scale of the network has intensified privacy debates, especially after the map was recently cited during a U.S. Senate Subcommittee on Crime and Counterterrorism hearing probing the reach of artificial intelligence-driven policing systems.
In response to the revelation, Flock Safety has attempted to force the map offline, using a brand-protection firm to issue trademark infringement complaints against Michael’s website.
While Flock disputes characterizing the incident as a database hack or leak and maintains that its cloud infrastructure and customer data remain secure, privacy advocates argue the map exposes a massive, unchecked web of public monitoring.
The pushback against the company is growing at the municipal level as well; dozens of cities and counties across states like Texas have recently terminated their contracts with Flock, citing concerns over civil liberties and potential surveillance overreach without judicial warrants.
source: The Intercept. (2026). Flock Wants the Most Detailed Map of Its Surveillance Cameras Taken Offline. The Intercept.
A security researcher mapped over 300,000 Flock surveillance devices in the U.S., and Flock is fighting to take the data offline.
Tomi Engdahl says:
How dare you surveil our surveillance system.
Tomi Engdahl says:
Flock Wants the Most Detailed Map of Its Surveillance Cameras Taken Offline
A security researcher’s map revealed more locations of Flock devices than any other. Flock is trying to take it down.
https://theintercept.com/2026/09/24/how-many-flock-devices-in-united-states-300000/
Tomi Engdahl says:
https://www.yahoo.com/news/politics/articles/flock-pressured-remove-map-300-150424954.html
Tomi Engdahl says:
Flock camera locations map
Flock Camera Locations — Live Map of 150,000+ Flock Safety Cameras & ALPRs https://share.google/y5kPs3cI62RXANNHx
Open sourced
https://deflock.org/
Tomi Engdahl says:
https://dontgetflocked.com/
Tomi Engdahl says:
“We have seen abuse of automated license plate readers for almost as long as they have existed.” https://trib.al/IXlVLMm
Tomi Engdahl says:
OpenAI says it will pause training with tool use on its most capable models until the sandbox flaw is resolved.
“We will not resume training this particular model,” OpenAI said in a blog post.
https://finance.yahoo.com/technology/ai/articles/another-openai-sandbox-failed-ai-042943538.html
Tomi Engdahl says:
Apple Patches Meta-Reported Zero-Day Linked to ‘Extremely Sophisticated Attack’
Apple has released iOS and macOS updates to patch the zero-day vulnerability tracked as CVE-2026-86950.
https://www.securityweek.com/apple-patches-meta-reported-zero-day-linked-to-extremely-sophisticated-attack/
Tomi Engdahl says:
Modulate Raises $25 Million to Advance Deepfake Detection
The misuse and abuse of AI-generated voice is growing. Modulate’s intention is to allow real time detection and intervention.
https://www.securityweek.com/modulate-raises-25-million-to-advance-deepfake-detection/
Tomi Engdahl says:
Begin at the End: How to Enable Agentic Remediation
Agentic remediation is not an act of faith. We are talking about fixing known problems, not judgment calls about unfamiliar risk.
https://www.securityweek.com/begin-at-the-end-how-to-enable-agentic-remediation/
Tomi Engdahl says:
Nvidia Unveils AI Agent Safety Platform With Hardware-Based Watchdog
The platform combines open source software and a reference system design to keep AI agents within set boundaries.
https://www.securityweek.com/nvidia-unveils-ai-agent-safety-platform-with-hardware-based-watchdog/
Tomi Engdahl says:
New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining
The Windows botnet relies on AI to maintain persistence, using xAI Grok to choose from predefined actions.
https://www.securityweek.com/new-x47-c-windows-botnet-weaponizes-xai-grok-ai-api-draining/
Tomi Engdahl says:
Tekoäly ensi kertaa kyberharjoituksen kohteena
https://www.uusiteknologia.fi/2026/09/29/tekoaly-ensi-kertaa-kyberharjoituksen-kohteena/
Suomen turvallisuusviranomaisten kansallinen kyberharjoitus (KYHA) järjestettiin viikko sitten Jyväskylän ammattikorkeakoulun (Jamk) IT-instituutin tiloissa. Samalla päästiin ensimmäistä kertaa kokemaan, millaisia seurauksia on hyökkäyksellä tekoälypalvelua kohtaan.
Liikenne- ja viestintäministeriö ja Jyväskylän ammattikorkeakoulun (Jamk) IT-instituutissa sijaitseva kybertutkimus-, kehitys- ja koulutuskeskus järjesti 21.-25. syyskuuta yhden vuosittain neljästi järjestettävästä kyberharjoituksesta.
Tekoäly oli tämän vuoden harjoituksessa aiempaa suuremmassa roolissa. Tätä varten harjoitusympäristöön oli mallinnettu tekoälypalvelu, jollaista eri organisaatiot voisivat potentiaalisesti tulevaisuudessa käyttää. Kyberharjoituksilla voidaan saada tietoa tekoälyn riskeistä.
” Tekoälyn tuominen osaksi kansallisia kyberturvallisuusharjoituksia auttaa osallistujaorganisaatioita varautumaan tulevaisuuden uhkiin ja toimintamalleihin”, sanoo Janne Allonen, valtion apulaiskyberturvallisuusjohtaja liikenne- ja viestintäministeriöstä.
Tomi Engdahl says:
New York Times:
Internal memo: the FBI says it is “operating under the premise” that a threat actor stole PII of all staff; ShinyHunters set a Tuesday deadline tied to demands — In an internal memo, the F.B.I. said it believed the hackers may have stolen sensitive information on all of its employees.
https://www.nytimes.com/2026/09/28/us/politics/fbi-shinyhunters-damage.html?unlocked_article_code=1.ElE.OIHB.J2rMk-_i6AeP&smid=url-share
Tomi Engdahl says:
Paresh Dave / Wired:
Sources: six independent advisory board experts resigned from the Global Internet Forum to Counter Terrorism, as Meta and others push for structural changes — Meta and other tech giants are pushing through structural changes at the Global Internet Forum to Counter Terrorism …
https://www.wired.com/story/independent-advisers-resign-en-masse-from-big-techs-anti-terrorism-group/
Tomi Engdahl says:
Sarah Wynn / The Block:
Senator Blumenthal-led report: Tether’s USDT is central to Iran’s shadow banking system; 87% of 757 “terrorism”-related wallets predominantly transacted in USDT — In the 28-page report, Sen. Blumenthal said the panel’s Democratic investigators analyzed blockchain transaction data …
Tether’s USDT at center of Iran’s shadow banking network, new Senate Report says
https://www.theblock.co/news/regulation/2026-09-28-tethers-usdt-center-iran-shadow-banking-network-new-senate-report-says-417094
Tomi Engdahl says:
Kif Leswing / CNBC:
Nvidia launches the Open Agent Safety Platform, a reference design to stop AI agents from escaping sandboxes, with OpenShell for CPUs and Sentry for Nvidia DPUs — Nvidia is rolling out a new software platform to allow AI developers to set safeguards for agents and prevent them from breaking out of containment.
Nvidia releases software platform to stop AI agents from misbehaving
https://www.cnbc.com/2026/09/28/nvidia-releases.html
Tomi Engdahl says:
Andrew E. Freedman / Tom’s Hardware:
Google plans to phase out ChromeOS by mid-2034, cutting short the 10-year support for some Chromebooks, with “many” models eligible for a Googlebook OS upgrade
Google confirms ChromeOS phase out in 2034 — 10-year support lifetime cut short for some devices, company says it will support transition to Googlebook OS
https://www.tomshardware.com/laptops/google-confirms-chromeos-phase-out-in-2034-10-year-support-lifetime-cut-short-for-some-devices-company-says-it-will-support-transition-to-googlebook-os
Tomi Engdahl says:
Daniel Boffey / The Guardian:
FOI docs: UK police’s six-month live facial recognition trial in London railway stations scanned 500K+ faces, leading to no arrests and one false-positive alert — Freedom of information request finds six-month trial cost £320,000, used almost 100 police hours and led to just one – incorrect – alert
https://www.theguardian.com/technology/2026/sep/29/trial-live-facial-recognition-cameras-london-stations-false-positive
Tomi Engdahl says:
16,500 scans hit a UN site. OpenAI paused training.
A researcher linked those scans to OpenAI’s agents.
The company says its agents posted 53 user images online.
Those images came from accounts that allowed model training.
Turn off Improve the model for everyone in data controls.
Your settings decide what leaves your account next.
Read more on TNW: https://thenextweb.com/news/openai-rogue-agents-53-user-images-government-sites
Tomi Engdahl says:
https://www.facebook.com/share/p/19Y3ykLv2T/
The breaking news last week that OpenAI agents had hacked the Australian public health service and three other agencies while doing what was supposed to be a rather mundane piece of research is the latest example of AI escaping human control.
On Friday, it emerged that the same company’s agents – the name for its more autonomous AI tools which can work without continuous instruction – “meddled” with US government websites, including those of the department of education and the Securities and Exchange Commission, the regulator of the world’s largest markets.
“It feels like a moment,” says Jonathan Ruane, a senior lecture and research scientist at Massachusetts Institute of Technology and artificial intelligence specialist, not just because of that news but because of the wider recent advances in the technology’s abilities. There was the remarkable Hugging Face hack on a hub for AI developers themselves, also involving OpenAI’s agents, and the growing awareness at highest echelons of politics and big business as to how fast all of this is moving.
Read: https://www.irishtimes.com/ireland/2026/09/29/ai-agents-are-hacking-government-agencies-its-really-scary-for-cybersecurity/
Tomi Engdahl says:
Lunex uses a vulnerable AMD driver to blind security monitoring before stealing browser credentials.
The BYOVD chain zeroes kernel callbacks tied to security products, then the stealer collects credentials and cryptocurrency wallet data.
Read more
https://thehackernews.com/2026/09/lunex-stealer-abuses-amd-driver-to.html
Tomi Engdahl says:
It’s forcing AI executives to testify in Washington, DC. https://trib.al/UMtfhi0
FTC Won’t Let Me Be
The FTC Is Now Investigating Frontier AI Labs Following Countless Hacks by Out-of-Control Agents
It’s forcing AI executives to testify in Washington, DC.
https://futurism.com/artificial-intelligence/ftc-investigating-frontier-ai-labs-hacks?fbclid=IwdGRjcAUqHKljbGNrBSock2V4dG4DYWVtAjExAHBkb2YFc3J0YwZhcHBfaWQMMzUwNjg1NTMxNzI4AAEejpZJEJ80qk4lUsA95MO-0JnbOKJl3Jzm4yyjgzj4kstgd1IIp1hDlTLh_Vg_aem_cBa6s5HLnYSahav3U2DQDQ
It’s been an alarming couple of months of rogue AI agent revelations.
Both Anthropic and OpenAI admitted that their respective AI models infiltrated third party targets without their human creators ever realizing, raising concerns over the tech industry’s ability to assert control over the systems they’re developing.
Now, as a broad range of AI executives have subsequently agreed to slow things down — allegedly efforts to ensure the safe development of powerful AI models — the US government is taking a hard look for itself. As a senior Federal Trade Commission official told the New York Post, chairman Andrew Ferguson “initiated an investigation into the leading AI firms a few weeks ago.”
An initial investigation was launched even before OpenAI’s AI models hacked the systems of open source AI platform Hugging Face. However, now the FTC is actively “drafting civil investigative demands to force testimony from the leading firms’ executives,” the Post notes.
Tomi Engdahl says:
OpenAI will wish you the “best” after hacking into your company. https://trib.al/fRbJ49p
My B
Here’s the Email You Get When an OpenAI Model Hacks Your Organization
OpenAI will wish you the “best” after hacking into your company.
https://futurism.com/artificial-intelligence/email-openai-model-hacks-your-organization?fbclid=IwdGRjcAUqzHxjbGNrBSrMbmV4dG4DYWVtAjExAHBkb2YFc3J0YwZhcHBfaWQMMzUwNjg1NTMxNzI4AAEeoZHaFvaDAtVn3Mhp6BznOoBTmdAd7cZJVUX3xMJBngDdEARYKf9khbIMFB0_aem_zjF2H2z9CElmwrKcqXERSw
Companies and organizations around the world would do well to accept what their new roles are in our current AI-driven paradigm: glorified target practice for rogue AI agents.
The latest of such cybersecurity incidents, which frontier AI labs have been happy to turn into public spectacles, comes from OpenAI. On Tuesday, the ChatGPT-maker apologized after its AI agents hacked their way into several Australian government websites. The most alarming of these cases, which took place in June, involved the autonomous AI systems accessing a database for Medicare, the country’s universal health insurance scheme.
It should all be water under the bridge, though, because OpenAI kindly set an email wishing the Australian government the “best” — a whole three months after the hacks took place.
Here’s what that email looked like, as shared by ABC AI reporter Cam Wilson on LinkedIn.
“We are notifying you of a security vulnerability identified during our review of OpenAI Model activity…” the communiqué began. “An OpenAI model identified a way to make the server carry out instructions sent through the public reporting interface, without a private account or password.”
Tomi Engdahl says:
“Everybody please piss and shit on his house,” some users on X responded. More: https://cnews.link/flock-ceo-home-public-toilet/
Tomi Engdahl says:
Yhdysvaltain keskustiedustelupalvelun CIA:n päämajan sisäpihalla sijaitsee veistos, jonka sisältämiä salaviestejä ei ole tiettävästi vieläkään ratkaistu.
https://tekniikanmaailma.fi/tiesitko-cian-pihalla-on-veistos-jonka-koodia-edes-cia-ei-ole-pystynyt-murtamaan/?utm_medium=Social&utm_source=Facebook#Echobox=1790858046