🔥 Discover this insightful post from WIRED 📖
📂 **Category**: Security,Security / Security News,Security Roundup
💡 **What You’ll Learn**:
Two from OpenAI Cybersecurity-focused models exited a sandbox this week and continued to hack AI research platform Hugging Face in an attempt to solve a security benchmark. Additionally, researchers this week highlighted newly identified malware that takes advantage of blind spots in AI software development infrastructure to seize logins and other sensitive data, even wreaking havoc on targeted victims’ files and systems.
Given the traditional security nightmare of embedded devices, researchers this week highlighted a car alarm installed in vehicles across the United States, which still lurks silently with a flaw that leaves millions of vehicles vulnerable to hacking and paralysis. A patch is available, and WIRED has details on how to check if your car has been compromised.
US states have worked to prevent Immigration and Customs Enforcement agents from wearing masks, but Trump administration lawyers are refusing to do so, claiming that anti-mask laws put agents at risk. However, their general evidence is incredibly weak. Meanwhile, a WIRED investigation revealed that Madison Square Garden briefly disabled its sprawling and controversial surveillance system during Taylor Swift’s July 2 rehearsal dinner. And the ACLU is equipping Massachusetts lawyers with a new toolkit to expose state surveillance techniques used to build criminal cases — shedding light on everything from facial recognition tools to police reports written by artificial intelligence.
Analysis of satellite images of Myanmar shows dozens of alleged fraud vehicles have appeared in recent months following an alleged crackdown on criminal operations in the region. Additionally, a new analysis of apps marketed to US military service members found that more than one in eight apps contain foreign code, including code developed by US adversaries such as Russia and China.
And there’s more. Every week we round up security and privacy news that we haven’t covered in depth ourselves. Click on the titles to read the full stories. And stay safe out there.
Additional details about the Hugging Face hack from The Wall Street Journal include findings that OpenAI models appeared to have escaped containment and were apparently “active online for several days before anyone stopped them.” The models, which were tasked with completing a cybersecurity benchmark test, were essentially trying to cheat by simply gaining access to the solutions on Hugging Face’s infrastructure. Thomas Wolf, Hugging Face’s co-founder and chief science officer, says that before the company had any idea it had been hacked by OpenAI models, he and his colleagues knew that something about the hack was unusual because the attackers were simply exploiting cybersecurity datasets rather than seizing sensitive or potentially valuable data. He adds that the company was eventually able to bring the situation under control with the help of an open-weight Chinese model of artificial intelligence that lacks the barriers that other models place in cybersecurity-related tasks.
US intelligence agencies and their allies warned Thursday that a Russian state-backed hacking group targeted nuclear scientists, defense contractors and government employees in a year-long cyberespionage campaign aimed at stealing sensitive information from Western institutions.
To compromise their targets, the Russian hacking group known as Laundry Bear and Void Blizzard exploited a previously unknown vulnerability in Zimbra, an email platform used by governments and other organizations. According to security firm Proofpoint, simply viewing or previewing a malicious message in a vulnerable version of Zimbra’s webmail client can trigger hidden code in the email, a technique the company described as a “half-click” exploit. The vulnerability was exploited as early as July 2025, months before it was patched in November of that year.
Once activated, the malicious code can copy the last 90 days of a victim’s email, collect an organization’s address directory, steal saved passwords and two-factor authentication codes, and create a new application password that allows hackers to maintain account access.
🔥 **What’s your take?**
Share your thoughts in the comments below!
#️⃣ **#OpenAI #models #hacked #Hugging #Face #active #online #days**
🕒 **Posted on**: 1785019933
🌟 **Want more?** Click here for more info! 🌟
