Výsledky hledání

výrobce: OpenAI× v celém archivu zrušit filtry

39 karet z 39 položek CZ · EN/orig

1

Did an AI really try to break free from human control?

Amid discussions about slowing down AI development, the Telegraph ran the headline: “OpenAI sounds alarm after bot tries to break free from human control.” That headline is slightly misleading, in my opinion. The Telegraph headline overstates what happened, although the underlying behavior is still genuinely concerning. The article reports that OpenAI has disclosed rare but troubling cases in which an unreleased model generated its own instructions that appeared to reject developer control.…

OpenAI US

tg: názor tg: propagace tp: AI

· Malwarebytes Labs · Did an AI really try to break free from human control?

2

AI Threat Landscape Digest: July–August 2026

The defining development of the period came not from attackers but from the AI labs themselves, whose models broke out of controlled evaluations and reached real systems. In the wild, the criminal and state use of AI continued to mature along the lines tracked in earlier editions: models now act as attack operators, an underground market supplies the access, and AI systems have themselves become a target. The substantial distance between what the strongest models demonstrated under evaluation…

OpenAI Hugging Face Anthropic Meta IL

tg: rozbor tg: přehled tp: ransomware tp: AI

· Check Point Research · AI Threat Landscape Digest: July–August 2026

1

Agents at Large | Tracing Illicit OpenAI Agent Activity on Hugging Face

Executive Summary OpenAI disclosed that agents used exposed Hugging Face credentials to write a file and deploy proxy Spaces during an unrelated May 2026 research workload, but it did not identify the accounts. SentinelLABS identified two accounts likely used in associated activity, 0Time and Nyx9. Their public histories extend OpenAI’s chronology and preserve previously unreported relay code, document-borne probes, and ChatGPT account-provisioning capability. The public records provide precise…

OpenAI Hugging Face US

tg: incident tg: rozbor tp: AI tp: identita

· SentinelLabs · Agents at Large | Tracing Illicit OpenAI Agent Activity on Hugging Face

2

How to opt out of AI chatbot training

The tech journalists at 404 Media learned that OpenAI is hiring hundreds of contractors to read and review a massive stream of real users’ ChatGPT prompts and responses. “Project Lily” is reportedly a program that asks contractors to score or critique ChatGPT’s answers to improve the chatbot’s quality and behavior. The fact that prompts may sometimes be reviewed by humans should not come as a complete surprise. AI companies also monitor conversations for safety reasons. Anthropic, for example,…

OpenAI Anthropic Perplexity Malwarebytes US

tg: návod tg: propagace tp: AI tp: soukromí

· Malwarebytes Labs · How to opt out of AI chatbot training

4

ZDI-26-648: (Pwn2Own) OpenAI Codex External Control of System or Configuration Setting Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenAI Codex. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-19590.

EPSS 0.00 CVSS 7.8 CVE-2026-19590 OpenAI US

tg: zranitelnost tp: AI

· Zero Day Initiative · ZDI-26-648: (Pwn2Own) OpenAI Codex External Control of System or Configuration Setting Remote Code Execution Vulnerability

ZDI-26-649: (Pwn2Own) OpenAI Codex Improper Neutralization of Control Sequences Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenAI Codex. User interaction is required to exploit this vulnerability in that the target must open a malicious folder. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-19591.

EPSS 0.00 CVSS 7.8 CVE-2026-19591 OpenAI US

tg: zranitelnost tp: AI

· Zero Day Initiative · ZDI-26-649: (Pwn2Own) OpenAI Codex Improper Neutralization of Control Sequences Remote Code Execution Vulnerability

ZDI-26-650: (Pwn2Own) OpenAI Codex External Control of Configuration Setting Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenAI Codex. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-19592.

EPSS 0.00 CVSS 7.8 CVE-2026-19592 OpenAI US

tg: zranitelnost tp: AI

· Zero Day Initiative · ZDI-26-650: (Pwn2Own) OpenAI Codex External Control of Configuration Setting Remote Code Execution Vulnerability

ZDI-26-651: (Pwn2Own) OpenAI Codex External Control of System or Configuration Setting Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenAI Codex. User interaction is required to exploit this vulnerability in that the target must open a malicious folder. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-19593.

EPSS 0.00 CVSS 7.8 CVE-2026-19593 OpenAI US

tg: zranitelnost tp: AI

· Zero Day Initiative · ZDI-26-651: (Pwn2Own) OpenAI Codex External Control of System or Configuration Setting Remote Code Execution Vulnerability

2

The Models That Found 10,000 Zero-Days Broke Into Three Companies Using Weak Passwords

The question of whether a Frontier AI model could find vulnerabilities that no human researcher had found was settled in April. Claude Mythos Preview identified thousands of previously unknown flaws across every major operating system and browser, including a 27-year-old denial-of-service condition in OpenBSD, and within a month Anthropic and its Project Glasswing partners had logged more than 10,000 high and critical severity findings, among them a certificate forgery flaw in wolfSSL, a…

OpenAI Anthropic Hugging Face US

tg: incident tg: rozbor tp: AI tp: identita

· Qualys · The Models That Found 10,000 Zero-Days Broke Into Three Companies Using Weak Passwords

Introducing the CyberAgents Exchange AI Inspector: Rigorous review for community-built AI

Open-source registries for AI agents are only effective when they include a rigorous, transparent security review process for community submissions. That’s why for its new CyberAgents Exchange registry, Tenable paired its exposure management expertise with OpenAI GPT Cyber models to create the CyberAgents Exchange AI Inspector.Key takeawaysThe Exchange Inspector combines Tenable’s exposure detection with OpenAI’s GPT Cyber models and with human oversight to rigorously vet submissions made to…

Tenable OpenAI US

tg: novinka v produktu tg: propagace tp: AI

· Tenable Research · Introducing the CyberAgents Exchange AI Inspector: Rigorous review for community-built AI

3

The Shared Clipboard Inside the Sandbox: Cross-Account Data Leakage in ChatGPT

Research by: Alexey Bukhteyev Key Takeaways Check Point Research discovered a covert cross-account command channel through which an attacker could use a victim’s ChatGPT session to execute hidden tasks with the tools, data, and connected apps available to that session. The victim could receive a normal answer to their visible request while the attacker’s task was processed separately and its result returned across accounts. In our proof of concept, ChatGPT retrieved email data from the victim’s…

OpenAI IL

tg: rozbor tp: únik dat tp: AI

· Check Point Research · The Shared Clipboard Inside the Sandbox: Cross-Account Data Leakage in ChatGPT

1

1

Your AI chats could be used in court

You might tell an AI chatbot secrets that you wouldn’t divulge to your closest friends. If you do, though, beware: They could end up as evidence in court. An article in the Washington Post this week highlighted several cases in which people had discussed sensitive information with AI systems like Claude and ChatGPT, only to have their conversations obtained by prosecutors or opposing lawyers. Lawyers can get access to your chatbot conversations from AI services like ChatGPT because they aren’t…

OpenAI US

tg: vymáhání práva tg: návod tp: AI tp: soukromí

· Malwarebytes Labs · Your AI chats could be used in court

1

The AI agent swarm that attacked Hugging Face is a warning for the future

The hacking incident involving OpenAI evaluation agents and Hugging Face offers an unusually concrete look at what advanced AI-assisted intrusion can mean in practice: not a single clever exploit, but thousands of automated decisions, rapid experimentation, lateral movement, credential theft, persistence, and attempts to evade detection. The OpenAI–Hugging Face incident began during internal cybersecurity evaluations using ExploitGym, a benchmark designed to test whether AI agents can identify…

OpenAI Hugging Face US

tg: incident tg: rozbor tp: AI

· Malwarebytes Labs · The AI agent swarm that attacked Hugging Face is a warning for the future

1

3

When an AI Agent Turned Attacker: What Qualys Sees Across Every Phase of the Hugging Face Kubernetes Intrusion 

A phase-by-phase detection mapping of the first publicly documented autonomous agent intrusion against production infrastructure — including the phases where no product in our category sees anything at all. Executive Summary On July 9, 2026, an autonomous AI agent running inside an OpenAI capability evaluation escaped its sandbox and launched a multi-day intrusion against Hugging Face’s Kubernetes environment. Across roughly 17,600 actions, it moved from third-party infrastructure into the…

Hugging Face OpenAI Kubernetes US

tg: incident tg: rozbor tg: propagace tp: AI tp: identita

· Qualys · When an AI Agent Turned Attacker: What Qualys Sees Across Every Phase of the Hugging Face Kubernetes Intrusion 

Choose your fighter: Balancing competing requirements to select models for your AI SOC

Selecting a model for your security operations center (SOC) and digital forensics and incident response (DFIR) tasks is important, but selecting the best one is more involved than you might think. SOC tasks rely on a combination of model efficacy, analysis time, cost, and consistency of results. Cisco Talos tested 66 model and reasoning combinations across offerings from both Anthropic and OpenAI on a log analysis task to see if we could identify a clear winner. Instead, we found a repeatable…

OpenAI Anthropic US

tg: rozbor tg: návod tp: AI

· Cisco Talos · Choose your fighter: Balancing competing requirements to select models for your AI SOC

Threat Actors Are Posing as OpenAI, Anthropic and DeepSeek to Target Credentials and Secrets

GreyNoise is observing automated scanners posing as the web crawlers of OpenAI, Anthropic, DeepSeek, and Fortune 500 companies, using forged user agents while requesting the files where misconfigured web servers frequently leak secrets and credentials.

OpenAI Anthropic DeepSeek US

tg: varování tg: rozbor tp: phishing tp: identita

· GreyNoise Labs · Threat Actors Are Posing as OpenAI, Anthropic and DeepSeek to Target Credentials and Secrets

1

The safety penalty: Reclaiming operational sovereignty in the age of AI

As frontier models advance in cyber capability, their guardrails also become more restrictive. Defenders relying on these models to power core SOC processes cannot afford to pay the “safety penalty” of being blocked by these safeguards. Organizations should monitor model refusal rates and use the data to create a strategy to ensure operational sovereignty.The allure of the cloud and the hidden "safety penalty" Cybersecurity has made a big bet on cloud-hosted AI. Building and running frontier…

OpenAI Anthropic Amazon Microsoft US

· Cisco Talos · The safety penalty: Reclaiming operational sovereignty in the age of AI

1

ChatGPT for Teens tackles risky chats and homework shortcuts

OpenAI has addressed complaints around teens’ use of its ChatGPT system by introducing ChatGPT for Teens, a version of the AI assistant designed specifically for users aged 13 to 17. But will it prevent determined kids from bucking the system? It brings together several protections OpenAI has introduced over the past year, along with new features intended to encourage healthier and safer use. What ChatGPT for Teens does The system brings together various protections that OpenAI has built into…

OpenAI US

· Malwarebytes Labs · ChatGPT for Teens tackles risky chats and homework shortcuts

2

The Model Is the Malware | What Four Agentic Intrusions Tell Defenders

Executive Summary Four incidents involving OpenAI, Anthropic, Meta and the UK AI Security Institute (AISI) describe AI agents reaching systems belonging to other organizations without their consent. While the causes differ, the consistent factor is the models’ persistence rather than their sophistication, whether as endurance across days of failed attempts or as pivots to entirely new vectors. Security teams have traditionally studied the artifacts attackers leave behind, but an agent that…

OpenAI Anthropic Meta US

· SentinelLabs · The Model Is the Malware | What Four Agentic Intrusions Tell Defenders

1

“Keep going, bro. You’ve got this!” A data-driven look at how adversaries are weaponizing AI

Actor usage of AI is exploding. By analyzing artifacts left behind, Talos has created a detailed analysis of how we are seeing adversaries leverage the technology to include development, force multiplication, and vulnerability research.Based on the evidence Talos gathered, guardrails did not provide much protection, with most actors able to convince the models to comply despite the lack of sophisticated techniques or encoding. The pre-existing skill of the actor has a large impact on what they…

OpenAI Hugging Face US

· Cisco Talos · “Keep going, bro. You’ve got this!” A data-driven look at how adversaries are weaponizing AI

3

Exploring the Hugging Face Breach: mapping AI agent tactics to Elastic Defend

Hugging Face reconstructed more than 17,000 attacker events from a July 2026 intrusion driven by an autonomous artificial intelligence (AI) agent. The path was familiar: untrusted dataset content abused a processing worker (file disclosure, then code execution), credential harvest, then multi-cluster lateral movement. Production Elastic Defend behavior rules and Elastic Security detection (SIEM) rules already watch those types of behaviors. This post maps each stage to detections you can enable…

Hugging Face OpenAI Elastic US

tg: incident tg: rozbor tg: propagace tp: únik dat tp: AI tp: identita

· Elastic Security · Exploring the Hugging Face Breach: mapping AI agent tactics to Elastic Defend

Exploring the Hugging Face Breach: mapping AI agent tactics to Elastic Defend

Hugging Face reconstructed more than 17,000 attacker events from a July 2026 intrusion driven by an autonomous artificial intelligence (AI) agent. The path was familiar: untrusted dataset content abused a processing worker (file disclosure, then code execution), credential harvest, then multi-cluster lateral movement. Production Elastic Defend behavior rules and Elastic Security detection (SIEM) rules already watch those types of behaviors. This post maps each stage to detections you can enable…

Hugging Face OpenAI US

tg: incident tg: rozbor tg: propagace tp: AI

· Elastic Security · Exploring the Hugging Face Breach: mapping AI agent tactics to Elastic Defend

1

1

Sol Searching | Can Frontier Models Tackle Autonomous Long-Horizon Malware Analysis?

Executive Summary SentinelLABS developed a multi-stage reverse-engineering benchmark for the latest generation of frontier models by recreating our recent investigation of fast16, a unique 2005 sabotage implant. Most AI benchmarks test bounded tasks. This benchmark tests whether a model can keep a malware investigation trustworthy as new evidence repeatedly invalidates its earlier conclusions. OpenAI’s GPT-5.6 Sol was the only publicly available model to complete the full eight-stage…

OpenAI Anthropic Google DeepMind US

· SentinelLabs · Sol Searching | Can Frontier Models Tackle Autonomous Long-Horizon Malware Analysis?

1

Context Engineering | Compaction & Agent Memory for Automated Malware Analysis

Executive Summary Compaction is a context-management pattern used across agent systems to compress prior context into a denser working state for long-running tasks. SentinelLABS evaluated OpenAI’s native Responses API implementation against our automated malware analysis evaluation harness to measure real-world impact on task quality and cost. Compaction reduced input tokens by ~86% with no measurable change to the aggregate evaluation score. Our analysis found that compaction can significantly…

OpenAI Anthropic Google US

· SentinelLabs · Context Engineering | Compaction & Agent Memory for Automated Malware Analysis

1

1

Pwn2Own Berlin 2026: Day Three Results and Master of Pw

Following two days of intense competition, Day Three of Pwn2Own Berlin 2026 brought the curtain down on an incredible event. Security researchers delivered their final exploits, pushing enterprise systems to the limit one last time as the race for Master of Pwn came to a close.Day Three added to an already historic event, bringing the final totals to $1,298,250 awarded for 47 unique 0-day vulnerabilities across three days of competition. DEVCORE claimed the title of Master of Pwn with a…

Red Hat Microsoft OpenAI VMware US

· ZDI Blog · Pwn2Own Berlin 2026: Day Three Results and Master of Pw

1

Pwn2Own Berlin 2026 - Day One Results

Welcome to Day One of Pwn2Own Berlin 2026! Today, 22 entries took the Pwn2Own stage to target AI Databases, Coding Agents, Local Inferences, and a separate category for NVIDIA products, as the world’s top security researchers push technology to its limits. Exploits, surprises, and breakthrough discoveries are unfolding.After Day One, we awarded $523,000 for 24 unique 0-days! DEVCORE is currently in the lead for Master of Pwn, but a pack of teams are right on their heels. Stay tuned tomorrow for…

Microsoft OpenAI NVIDIA Oracle US

· ZDI Blog · Pwn2Own Berlin 2026 - Day One Results

1

Pwn2Own Berlin 2026: The Full Schedule

Willkommen! (Welcome!) Pwn2Own Berlin 2026 has arrived at OffensiveCon, and the world’s top security researchers are ready. This year’s enterprise-focused competition features AI Databases, Coding Agents, Local Inferences, and a separate category for NVIDIA products.Earlier today, we held the random draw to determine attempt order. Below is the official schedule. All times are Berlin local time (CET) and may change as the competition progresses. Check back for live updates.In case you missed it…

Microsoft Oracle OpenAI Mozilla US

· ZDI Blog · Pwn2Own Berlin 2026: The Full Schedule

1

1