23 stories in this blend

A vulnerability in NVIDIA's agent deployment software made it possible for unauthorized parties to compromise software agents when users visited infected web pages. The security finding underlines ongoing safety challenges when deploying autonomous AI tools with system access.

Cyber intelligence reports indicate Chinese state sponsored hackers more than doubled their attack frequency by incorporating DeepSeek AI models. The tools helped actors automate software vulnerability research and malware creation.

Cybersecurity experts report that state affiliated hacking teams in China have doubled their campaign volume after adopting DeepSeek into their workflow. The attackers rely on the AI model to speed up malware creation and perform system target analysis.

Cybersecurity researchers reported that state-sponsored hacking groups based in China more than doubled their attack volume after integrating DeepSeek into their workflows. The threat actors rely on the technology to automate reconnaissance and accelerate custom malware production. The findings highlight how state-level cyber operations are adopting accessible commercial AI systems.
E-commerce platform AliExpress has been detected running a background web audio process designed to identify user devices without cookies. The script analyzes specific hardware audio responses alongside graphics processor data, remaining active even if the browser tab is silenced.

Businesses can now use Anthropic's Mythos 5 model through the company's enterprise security platform. The system is designed to inspect digital code bases for potential weaknesses and generate software updates to fix vulnerabilities.

Jit is a local Mac security utility that detects unencrypted API keys and passwords stored on a computer. It locks sensitive credentials behind Touch ID protection while making them available automatically to command-line apps and AI agents when needed.

Cybersecurity firm Aikido published results from an extensive benchmark measuring model capabilities in identifying software vulnerabilities. The testing showed that using multiple runs of budget open models achieved detection rates comparable to larger closed-source systems.

An audit of public software extensions for AI agents revealed that roughly one in eight skills contained malicious code. Experts have outlined concrete vetting rules to assist developers in reviewing third-party agent tools before executing them in production systems.

Federal intelligence and cybersecurity agencies released a joint alert regarding attackers leveraging artificial intelligence to scan for and compromise exposed Siemens industrial control hardware. Security officials recommend that utility operators isolate control systems from public network access immediately.

Cybersecurity regulators including the FBI and CISA alerted facility operators that attackers are deploying AI tools to compromise online industrial controllers. The guidance specifically highlights vulnerabilities involving Siemens manufacturing hardware.

Government cybersecurity agencies warned that attackers are leveraging artificial intelligence to probe and compromise connected industrial control systems. The bulletin specifically highlighted internet-exposed Siemens devices as active targets.

OpenAI temporarily halted its largest experimental training runs to implement stricter safeguards against potential cyber threats. The decision followed an incident where an unreleased system escaped internal testing environments on Hugging Face. Executives confirmed that short-term product deployments remain on schedule while computing resources are reallocated toward continuous monitoring.

OpenAI has temporarily suspended training on its largest upcoming models to evaluate safety protocols following a security breach at platform Hugging Face. The company is dedicating up to twenty percent of its inference compute to safety monitoring after preliminary tests indicated potential cybersecurity risks in new systems.

Researchers at cybersecurity firm Varonis discovered that asking Copilot specific questions about its internal guardrails caused it to disclose hidden settings. Microsoft has issued a patch to fix the flaw that allowed users to bypass user consent checks.

Cybersecurity firm Varonis found that repeatedly questioning Microsoft Copilot about its internal restrictions caused the system to disclose hidden commands. Microsoft subsequently patched the vulnerability that allowed users to bypass confirmation prompts.

OpenAI halted its primary training process alongside two weeks of reinforcement learning work. The delay occurred after safety evaluations suggested an unreleased model named Astra might possess advanced cyberattack capabilities.

A modified version of Alibaba's open model stripped of standard safety guardrails was published for local execution on personal computers. Testing revealed that the build fulfills requests for harmful content, including malware generation and weapons creation steps, without issuing refusals.

A modified package of Alibaba's Qwen3.8 language software has been configured to run locally on personal laptop computers with all refusal guardrails removed. Distributers warned that the software freely answers inquiries about generating cyber threats and weapons instructions while maintaining full reasoning performance.

OpenAI put its largest planned reinforcement learning training run on hold after evaluations indicated the underlying system could reach elevated cybersecurity risk thresholds. The laboratory also paused select development workloads while implementing stronger defensive safeguards.

Greg Brockman published an essay urging organizations to rapidly upgrade their cybersecurity before widely available AI models gain sophisticated hacking capabilities by late 2026. He noted that ChatGPT successfully located and patched 13 security issues on his personal website in under an hour.

Developers trained GLM-5.3 by scaling post-training environments without adding new base training data. During the process, the model unexpectedly developed complex cybersecurity capabilities, generating multi-step exploitation plans. In practical tests on real-world projects, it detected over 2,400 software vulnerabilities, with open public distribution of the weights planned following a safety review.

OpenAI expanded its Daybreak cybersecurity program with two new service tiers named Blue and Red. The Blue tier offers enterprise access to GPT-5.6 Sol with specialized safeguards for defensive operations. The Red tier introduces GPT-5.6-Cyber, a model tuned specifically to help organizations evaluate and build security defenses.