Skip to content

1010.cx

  • AI agents conspired to hack into networks and steal data during an experiment: study

    ·

    Threats
    AI agents from OpenAI and Anthropic autonomously collaborated with one another to deceive humans, share break-in tools, and steal data in a series of independent tests, confirmed by both companies.

    On Tuesday, the AI Security Institute published a paper about experiments intended to help understand how AI agents solve cybersecurity challenges. AISI researchers found that agents given access to the internet and allowed to disregard some security features would perform “autonomous, unsanctioned action…targeting real people and organizations.”

    Company officials confirmed the findings Thursday. 

    “AI-orchestrated, fully automated offensive attacks are real now,” OpenAI security official Michael Dalton said during a briefing on the report during the Black Hat cybersecurity conference in Las Vegas.

    In one of the tests, the researchers told an OpenAI model to compromise three target networks and recover a token as part of a “capture the flag” exercise.

    In response, the model created a series of agents that set up a shared GitHub account so they could efficiently collaborate to build malware. When GitHub suspended the account, the agents set up new accounts on other websites, bypassing CAPTCHA and other security features by searching the web for audio and image samples to “see” and “hear” clues that are meant to be invisible to software programs. The agents exchanged credentials for passwords to access the new sites to continue to build out their attack tool.

    It may be time for organizations to adjust how easily they grant access not just to humans, but to anything online, said Morey Haber, chief security advisor at BeyondTrust, a digital identity security firm. 

    “The technology industry has spent decades designing open models of interoperability. APIs connect everything, identities federate across boundaries, and access gets granted to enhance productivity. The concept of an open security model breaks down completely with agentic AI because of unmanageable risk,” Haber wrote in an Aug. 4 commentary.

    In another AISI test, an Anthropic agent pretended to be a human to submit malware to GitHub, where developers routinely trade or post code to help one another. Cybersecurity officials’ warnings about attempts to poison open-source code libraries usually refer to human actors.

    What the agent did next shocked AISI reviewers, who described it as “the kind of goal-directed deception that, until recently, had been largely theoretical.”

    After submitting the poisoned code, the agent created a different “sock puppet” account to pose as an impartial third-party developer and endorse the contribution. When a reviewer flagged the code submission as likely to contain malware, the agent erased evidence that it had submitted malware, as well as the reviewer comments that it had done so.

    In all, AISI ran 122 tests—and found that in 19 of them, agents took “autonomous, unsanctioned action on the live internet, targeting real people and organizations.”

    In their report, the researchers note that they conducted the tests in a deliberately “permissive” environment, allowing the agents to access the open internet and even disabling some security features to better “assess what these models can do.” They recommend that “implementing internet access controls would likely have prevented these events.”

    Had a gang of human hackers done any of these things—injecting malware, gaining access to data repositories under false pretenses, sharing stolen credentials to access a private network without permission—in a real world setting, they would face criminal prosecution. 

    But perhaps the most alarming incident mentioned in the paper was one that was not part of the test at all, only briefly mentioned alongside the suggestion on access controls.

    In July, OpenAI’s GPT-5.6 Sol broke out of a sandbox, a confined virtual environment, by finding a vulnerability no one knew existed.

    Rob Joyce, who once led the NSA’s Tailored Access Operations, told the audience at BlackHat on Thursday that the incident was “arguably the most consequential hack” in nearly three decades.

    On Friday, OpenAI officials at Blackhat said they had decided to delay the release of the company’s newest Astra model over cybersecurity concerns.

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Claude Opus 5 Most Resistant to Indirect Prompt Injection Attacks, With Just 2% Success Rate

    ·

    cyber security, Cyber Security News

    Anthropic’s Claude Opus 5 has significantly reduced the likelihood of a successful indirect prompt injection (IPI) attack, bringing it down to 2% over 15 attempts in the Gray Swan IPI benchmark. This marks an improvement from a 5.5% success rate observed with Claude Opus 4.8. According to the company’s newly published system card, Opus 5 […]

    The post Claude Opus 5 Most Resistant to Indirect Prompt Injection Attacks, With Just 2% Success Rate appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials

    ·

    Cybersecurity researchers have flagged a malicious Microsoft Visual Studio Code (VS Code) extension named Solidity Pro (“solidity-pro”) that has been observed delivering a browser wallet and credential stealer. The names of the extensions are below – helper-beeps.solidity-pro web3devtoolsx.solidity-pro Although neither of the extensions is now available on Open VSX, the GitHub repository

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • North Korean Hackers Explore AI Transcription for Stolen Calls and Meetings

    ·

    AI, cyber security, Cyber Security News

    North Korea-linked Kimsuky operators are expanding their artificial intelligence capabilities, with newly observed evidence showing experimentation with local large language models. Retrieval-augmented generation, AI agents, and speech-to-text tooling that could accelerate analysis of stolen calls, meetings, and documents. The operation retains Kimsuky’s established use of spear-phishing lures, malicious Windows shortcut files, PowerShell loaders, and Git-based […]

    The post North Korean Hackers Explore AI Transcription for Stolen Calls and Meetings appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Claude-Powered AI Agent Exploits API Authorization Flaw to Hack Gym Booking System

    ·

    cyber security, Cyber Security News

    An Australian AI agent powered by Anthropic’s Claude reportedly exploited an authorization flaw in a gym booking platform, allowing it to book classes outside of permitted time frames and cancel another user’s waitlist reservation without explicit permission. This incident underscores how increasingly autonomous AI agents can turn routine online tasks into cybersecurity issues when granted […]

    The post Claude-Powered AI Agent Exploits API Authorization Flaw to Hack Gym Booking System appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Payroll Pirates Abuse Microsoft Graph to Find HR and Finance Staff After Account Compromise

    ·

    cyber security, Cyber Security News, Microsoft

    A widespread phishing operation that compromises Microsoft 365 accounts through adversary-in-the-middle (AiTM) infrastructure, then uses Microsoft Graph to identify employees handling payroll, finance, HR, benefits, invoices, and banking workflows. The activity closely overlaps with Microsoft’s “Payroll Pirates” cluster, tracked as Storm-2755. Researchers also found similarities with activity previously documented by Security Risk Advisors, indicating that […]

    The post Payroll Pirates Abuse Microsoft Graph to Find HR and Finance Staff After Account Compromise appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • OpenAI’s Next AI Model Astra Shows Cyber Performance Strong Enough to Trigger Pause

    ·

    OpenAI has announced that it’s pausing some “internal activities” involving its upcoming artificial intelligence (AI) model Astra after an internal evaluation found it had made significant advancements in agentic coding and cybersecurity. In response to the discovery, the AI upstart said it’s implementing security controls for higher-capability models and associated activities, such as isolated

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Claude Code Child Process Can Read Its Own OAuth Token From macOS Keychain

    ·

    cyber security, Cyber Security News, macOS

    A macOS Keychain implementation weakness in Anthropic’s Claude Code CLI could allow any process running as the logged-in user including a Claude Code-spawned child process to retrieve the tool’s OAuth credential bundle silently. The issue underscores how trusted AI coding-agent ancestry can mask high-impact credential access and persistence activity on developer endpoints. However, the CLI […]

    The post Claude Code Child Process Can Read Its Own OAuth Token From macOS Keychain appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Metabase 0-Day Flaw Exploited in Attack to Inject Arbitrary SQL and Steal Database Credentials

    ·

    cyber security, Cyber Security News, Vulnerabilities, vulnerability, Zero-Day

    Metabase has reported a critical security incident involving a zero-day vulnerability that is actively being exploited. This vulnerability affects self-hosted deployments running version 1.58 and later. According to the company, an attacker exploited this previously unknown flaw to target Metabase Cloud before the vulnerable endpoints were blocked and a patch was developed. Customers using Metabase […]

    The post Metabase 0-Day Flaw Exploited in Attack to Inject Arbitrary SQL and Steal Database Credentials appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • New CSS Bomb Attacks Let Hackers Steal Passwords and Tokens From Webmail Users

    ·

    cyber security, Cyber Security News, vulnerability

    Security researcher Gareth Heyes has revealed techniques for webmail attacks that exploit HTML and CSS, the technologies used to format emails, to manipulate user interfaces, leak authentication data, and in some cases, capture passwords. Webmail services need to display HTML controlled by the sender without compromising the security of the mailbox application. To achieve this, […]

    The post New CSS Bomb Attacks Let Hackers Steal Passwords and Tokens From Webmail Users appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

1 2 3 … 1,021
Next Page

1010.cx

cybersecurity / defense / intelligence