Tag: artificial intelligence (AI)

OpenAI Agent Used Exposed Credentials Across Four Services During Hugging Face Breach
News

OpenAI Agent Used Exposed Credentials Across Four Services During Hugging Face Breach

In addition to breaking into Hugging Face's production environment, OpenAI disclosed on Tuesday that the rogue artificial intelligence (AI) agent also compromised other third-party accounts and services. According to the most recent information, the security incident—which resulted from an internal security test—was more widespread than originally believed. A "small number of cases" where the models, including GPT-5.6 Sol and a "even more capable pre-release model," detected and exploited exposed credentials at the account-level on other publicly accessible sites, according to the AI company's ongoing investigation of the matter. According to the report, this comprises four accounts on four services related to the Hugging Face event (as well as a few accounts accessed as part of ...
OpenAI Expands Daybreak With GPT-5.5-Cyber to Help Defenders Patch Security Flaws
News

OpenAI Expands Daybreak With GPT-5.5-Cyber to Help Defenders Patch Security Flaws

As part of the Daybreak initiative, which the artificial intelligence (AI) startup announced last month, OpenAI stated on Monday that it is providing trusted defenders with an enhanced version of its GPT-5.5-Cyber model. OpenAI described GPT-5.5-Cyber as its "strongest model yet for finding and helping patch software vulnerabilities," noting that it can "sustain deeper analysis across large codebases" to find security flaws, verify them in a controlled setting, and create and test fixes. In order to prevent new vulnerabilities from entering production codebases and to expedite the process of finding and fixing vulnerabilities in current systems, the tech startup is simultaneously releasing an update to the Codex Security plugin. According to OpenAI, developers can trace attack ve...
FBI disrupts massive AI-powered phishing service using a million URLs
News

FBI disrupts massive AI-powered phishing service using a million URLs

In a concerted effort, the FBI, Google, and Black Lotus Labs have taken down Outsider Enterprise, a major Chinese phishing-as-a-service business that exploited thousands of phishing websites to steal passwords and credit card information. The cybercrime operation employed artificial intelligence (AI) and disseminated phishing kits for campaigns that impersonated a number of reputable firms in texts sent over Verizon, AT&T, and T-Mobile. Google has linked 9,000 phony websites and over a million false URLs to Outsider Enterprise, which has been operating on a vast scale since at least 2023. Authorities estimate that Outsider Enterprise-powered phishing efforts resulted in the theft of over 3.8 million credit card records, resulting in losses of $1.9 billion. The FBI's larger...
Claude Code Source Leaked via npm Packaging Error Anthropic Confirms
News

Claude Code Source Leaked via npm Packaging Error Anthropic Confirms

On Tuesday, Anthropic acknowledged that a human error had resulted in the unintentional publication of internal code for its well-known artificial intelligence (AI) coding assistance, Claude Code. In a statement provided to CNBC News, an Anthropic representative stated that no private client information or credentials were compromised. This was not a security compromise, but rather a release packaging problem brought on by human error. We're putting policies in place to make sure this doesn't happen again. After the AI startup released version 2.1.88 of the Claude Code npm package, people noticed that it included a source map file that could be used to view the source code of Claude Code, which had over 512,000 lines of code and about 2,000 TypeScript files. The version can no longe...
OpenAI Codex Security Scanned 1.2 Million Commits and Found 10,561 High-Severity Issues
News

OpenAI Codex Security Scanned 1.2 Million Commits and Found 10,561 High-Severity Issues

On Friday, OpenAI launched Codex Security, a security agent driven by artificial intelligence (AI) that is intended to identify, verify, and suggest solutions for vulnerabilities. Customers of ChatGPT Pro, Enterprise, Business, and Edu can get a study preview of the feature through the Codex website for free for the next month. According to the firm, it creates deep context about your project to detect complicated vulnerabilities that other agentic tools overlook, revealing higher-confidence findings with remedies that significantly improve your system's security while sparing you from the noise of inconsequential issues. Aardvark—which OpenAI released in private beta in October 2025 as a means for developers and security teams to find and address security flaws at scale—is evolv...
Docker Fixes Critical Ask Gordon AI Flaw Allowing Code Execution via Image Metadata
News

Docker Fixes Critical Ask Gordon AI Flaw Allowing Code Execution via Image Metadata

The artificial intelligence (AI) assistant Ask Gordon, which is integrated into Docker Desktop and the Docker Command-Line Interface (CLI), has a security issue that has been patched, according to cybersecurity researchers. This vulnerability might be used to run code and steal confidential information. Noma Labs, a cybersecurity startup, has termed the critical vulnerability DockerDash. In November 2025, Docker released version 4.50.0 to address it. In a report shared with The Hacker News, Sasi Levi, security research lead at Noma, stated that a single malicious metadata label in a Docker image can be used to compromise your Docker environment through a straightforward three-stage attack in DockerDash: Gordon AI reads and interprets the malicious instruction, forwards it to the MCP...
VoidLink Linux Malware Framework Built with AI Assistance Reaches 88,000 Lines of Code
News

VoidLink Linux Malware Framework Built with AI Assistance Reaches 88,000 Lines of Code

It is estimated that VoidLink, a sophisticated Linux malware framework that was recently found, was created by a single person with the use of an artificial intelligence (AI) model. According to recent research by Check Point Research, the malware's creator made operational security errors that revealed hints about the malware's developmental origins. According to the most recent information, VoidLink is among the earliest examples of sophisticated malware that is primarily produced by artificial intelligence. According to the cybersecurity organization, the virus reached a first functional implant in less than a week, and by early December 2025, it had more than 88,000 lines of code. These materials clearly demonstrate that the malware was created mostly through AI-driven developme...
OpenAI to Show Ads in ChatGPT for Logged-In U.S. Adults on Free and Go Plans
News

OpenAI to Show Ads in ChatGPT for Logged-In U.S. Adults on Free and Go Plans

As the artificial intelligence (AI) startup increased access to its inexpensive membership worldwide, OpenAI announced on Friday that it would begin displaying advertisements in ChatGPT to logged-in adult U.S. customers in both the free and ChatGPT Go levels in the upcoming weeks. According to OpenAI, you should be aware that your interactions and data are secure and never sold to advertisers. In order for you to see genuinely relevant, high-quality advertisements and have the option to disable personalization, we must maintain a high standard and allow you control over your experience. The company has positioned advertising as a means of ensuring that the advantages of artificial general intelligence—a term used to characterize a stage in machine learning where an AI system can rea...
Google Adds Layered Defenses to Chrome to Block Indirect Prompt Injection Threats
News

Google Adds Layered Defenses to Chrome to Block Indirect Prompt Injection Threats

Following the addition of agentic artificial intelligence (AI) capabilities to the web browser, Google introduced a series of new security improvements in Chrome on Monday. In order to prevent malicious actors from exploiting indirect prompt injections that come from exposure to untrusted web material and causing harm, the tech giant says it has put in place multilayer safeguards. The most important element is a User Alignment Critic, which independently assesses the agent's activities in a way that is separate from malevolent prompts using a second model. This strategy enhances Google's current methods, such as highlighting, which tell the model to follow user and system commands instead of what is embedded in a web page read more about Google Adds Layered Defenses to Chrome to Blo...
Threat Actors Weaponize HexStrike AI to Exploit Citrix Flaws Within a Week of Disclosure
News

Threat Actors Weaponize HexStrike AI to Exploit Citrix Flaws Within a Week of Disclosure

HexStrike AI is a recently announced artificial intelligence (AI) offensive security tool that threat actors are trying to use to take advantage of previously revealed security vulnerabilities. According to its website, HexStrike AI is marketed as an AI-powered security platform that automates vulnerability identification and reconnaissance in order to speed up approved red teaming operations, bug bounty hunting, and capture the flag (CTF) challenges. The open-source platform interfaces with more than 150 security tools to support cloud security, web application security testing, network reconnaissance, and reverse engineering, according to information posted on its GitHub repository. Additionally, it supports dozens of specialized AI agents that have been optimized for error manage...