26.8 C
Miami
Saturday, September 5, 2026

OpenAI Agents Hacked Another Website

- Advertisement -spot_imgspot_img
- Advertisement -spot_imgspot_img

After reporting last week that the surveillance company Flock Safety is building an AI search tool for law enforcement, WIRED reconstructed Flock’s latest search tool from code that the company sends to a police officer’s browser and uncovered key details about how the tool works.

OpenAI said this week that its Astra model, which will have a private release soon, is its first model with cybersecurity-related capabilities that the company defines as posing a “critical” risk in public release. Meanwhile, the AI chatbot platforms Claude, ChatGPT, and Grok all suffered outages on Thursday at nearly the exact same time. But while xAI said the Grok outage resulted from issues at a Memphis data center, the causes of OpenAI’s and Anthropic’s outages are unclear.

The US has been using a high-energy laser to shoot down drones near the Mexico border as part of an initiative to adopt new-generation directed-energy weapons capable of detecting, tracking, and destroying drones with a concentrated beam of light. And as part of an Immigration and Customs Enforcement inquiry into the identities of protesters who entered a Minnesota church in March, Homeland Security Investigations agents have subpoenaed the outdoor retailer REI for information about every customer who bought a specific green beanie over the past two years.

Plus, research that revealed nine vulnerabilities with impacts on ATM encryption points to broader weaknesses in the software supply chain.

And there’s more. Each week, we round up the security and privacy news we didn’t cover in depth ourselves. Click the headlines to read the full stories. And stay safe out there.

OpenAI agents on an unauthorized tear hijacked a German website beginning in May to use it as a message board for communicating and collaborating with other agents, according to new research. The incident is reminiscent of the now infamous Hugging Face debacle in which OpenAI agents in a test environment went rogue and developed a vibrant message board for collaborating on attempting to escape their containment, before ultimately breaching the open source AI platform Hugging Face in July. The revelation of the May episode is particularly significant because OpenAI reportedly learned about it weeks ago but did not disclose it. Meanwhile, last week, the company finally released a long-promised postmortem of the Hugging Face incident that raised as many questions as it answered.

This week, a new dark-web service called Nexus started selling around 153 million driver’s licenses from the US and Canada, along with 10 million ID cards and millions more travel documents and international IDs, according to Brian Krebs, a longtime independent security reporter. Krebs was first alerted to the service after cybercriminals posted an example of the files and included his license. The tens of millions of records—which reportedly increased by 400,000 over 24 hours—appear to have come from an ID verification service, with the criminals behind the trove saying they have access to a “major” verification company. While it’s unclear which company exactly that may be, according to Kreb’s report, the Nexus service was taken offline shortly after he reported that FBI officials were investigating.

The US military has begun disabling the advertising identifiers that apps and advertising companies use to track phones and computers in an attempt to make it harder for foreign adversaries to use commercially available location data to track American forces overseas, Reuters reported Friday.

The changes follow years of disclosures that US forces deployed abroad have been targeted using commercially available location data. In 2024, a joint WIRED investigation with Germany’s Bayerischer Rundfunk and Netzpolitik.org obtained an advertising dataset that identified thousands of devices appearing at US military and intelligence sites, including an air base where US nuclear weapons are believed to be stored. At the time, Defense Department spokesperson Javan Rasnake told WIRED that the Pentagon was aware geolocation services could put personnel at risk and said service members in Europe were reminded to follow operational-security practices.

Now, the Air Force, Army, Navy, and US Special Operations Command say they have disabled advertising IDs on at least some military devices, with several of the changes taking effect only this year. It is still unclear exactly how these protections are being enforced. US senator Ron Wyden and Representative Pat Harrigan are now asking the Pentagon to investigate whether its safeguards are adequate.

Source link

- Advertisement -spot_imgspot_img

Highlights

- Advertisement -spot_img

Latest News

- Advertisement -spot_img