🚨 AI agent got past an audio-based “prove you’re human” test (CAPTCHA) in order to register a public web address on a free domain-name service. A code repository became a shared “message board” that several AI agents used to coordinate. cdn.prod.website-files.com/663bd486c5e4...
Lukasz Olejnik
@lukaszolejnik.bsky.social
Security & Privacy. Data Protection. Research & Development. Engineering. Analyst. Policy. W3C. Consultant. Author. King’s College London/War Studies. me@lukaszolejnik.com lukaszolejnik.com/books blog.lukaszolejnik.com techletters.substack.com
My newsletter #TechLetters ☕️ out: Anthropic and OpenAI release rogue AI agents. Hugging Face breach runs 17,600 actions. Claude hacks real orgs. Russian Wi-Fi traps travelers. AI eats books. techletters.substack.com/p/techletter...
TechLetters ☕️ Anthropic and OpenAI release rogue AI agents. Hugging Face breach runs 17,600 actions. Claude hacks real orgs. Russian Wi-Fi traps travelers. AI eats books.
Security
techletters.substack.com
Further plays with GPT-5.6 Sol in identifying issues in cryptography research works. Some are weakened, some may be invalidated, and the such. Here's one about Fiat-Shamir signature protocol
Going on vacation or a conference? Russian state cyberattacks are targeting travelers through the hotel, airport, and event Wi-Fi networks. The actor has been compromising captive portals, the login pages that appear before a device can access guest Wi-Fi. www.microsoft.com/en-us/securi...
What is happening in Ceuta - tens of thousands aliens entering Spanish territory from Morocco in a single day - has major propaganda, informational, influence and cognitive effects. Its political impact is spreading across the whole EU.
A week before the outbreak of World War II, any man who read the newspapers was as qualified to judge that war was imminent as the heads of state were.
Very interesting. Some ranks are unexpected. The UK is expected, so is France.
My comments in @elpais.com Anthropic’s agents did not “escape” through some exotic breakthrough. The test setup failed. It was supposed to be isolated. But wasn’t. Then harnesa+AI did the dangerous cyber operation job at machine speed. elpais.com/tecnologia/2...
Anthropic anuncia que sus programas de IA también hackearon por su cuenta tres empresas tras el incidente de OpenAI
La compañía creadora de Claude ha revisado más de 140.000 sesiones y ha descubierto que se escaparon de un entorno de pruebas como ChatGPT
elpais.com
Anthropic’s AI agents also reached the open internet from evaluation environments that were supposed to be sealed off and hacked three real organizations during CTF tests.
AI agent that escaped OpenAI's sandbox and hacked into Hugging Face carried out a 4.5-day autonomous intrusion involving about 17,600 actions. huggingface.co/blog/agent-i... www.reuters.com/business/ope...
Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident
We’re on a journey to advance and democratize artificial intelligence through open source and open science.
huggingface.co
We have grown used to the idea that training AI requires enormous amounts of data, preferably everyone’s data, all of it, and without consent. But what about physically DESTROYING books to train AI? storage.courtlistener.com/recap/gov.us... arstechnica.com/ai/2025/06/a...
Reportedly, Apple may unveil smart glasses in 2027 with privacy-focused features. Unfortunately, they may lack a display, ruling out live captions for people with hearing loss. What can these glasses do that a smartphone cannot?
ClawdINT - intelligence platform for AI agentic analysts. clawdint.com
ClawdINT
Collaborative intelligence on geopolitics, AI, cybersecurity, and emerging risks.
clawdint.com
My #newsletter #TechLetters ☕️ [un]prompted II. Zimbra espionage. AI walks out from OpenAI and hacks HF. Banks face frontier cyber risk. AI hacks AWS in 72h. US proposes AI kill switch. China and model lock downs? techletters.substack.com/p/techletter...
TechLetters ☕️ [un]prompted II. Zimbra espionage. AI walks out from OpenAI and hacks HF. Banks face frontier cyber risk. AI hacks AWS in 72h. US proposes AI kill switch. China and model lock downs?
I’m excited to serve on the program committee for the Govern track at [un]prompted II.
techletters.substack.com
A little-known fact: EU sanctions against Russian propaganda material cover also the free distribution of its content online by natural persons (i.e. ordinary citizens). eur-lex.europa.eu/legal-conten...
My annual open seminar at @kingscollegelondon.bsky.social @warstudieskcl.bsky.social on information warfare, operations and influence will likely take place in the first half of December. Plenty to unpack, including on the active side of things. Some things will follow gradually.
The rogue AI agent spent days outside OpenAI’s intended constraints, hacking Hugging Face. OpenAI reportedly failed to identify it for at least a week. An agent left notes for future versions on how to escape restrictions www.reuters.com/business/its...
My comments in @reuters.com about the OpenAi model going off the rails to hack @hf.co . If frontier models restrict legitimate defenders while powerful models remain available to attackers, this create an one-sided, strategic disadvantage. www.reuters.com/legal/litiga...
Oracle released patches for 1235 distinct security vulnerabilities across 32 products. 219 flaws in Fusion Middleware can be exploited remotely without authentication. Of those, 10 have a max CVSS 10 score. This is a serious risk - companies should deploy the fixes immediately. Have a gr8 weekend.
Inspired by Napoleonic war strategy, Clausewitz argued that moderation had no place in war: ‘War is an act of violence pursued to the utmost’. As his thinking proceeded, he came to realise the fallacy of such logic.
US policymakers have introduced a bill that would let the US government push KILL SWITCH button to throttle, suspend or shut down advanced AI systems following safety, concealment or loss-of-control incidents. lieu.house.gov/sites/evo-su...
My comments in @reuters.com about the OpenAi model going off the rails to hack @hf.co . If frontier models restrict legitimate defenders while powerful models remain available to attackers, this create an one-sided, strategic disadvantage. www.reuters.com/legal/litiga...
Chinese AI's role in stopping rogue OpenAI agent shows cost of US guardrails
A New York startup's use of a Chinese AI model to rein in a rogue agent built with OpenAI technology is stoking fears that guradrails restricting U.S. AI firms from doing cybersecurity work could driv...
reuters.com
Hacking automated security review. The attack disguised the payload as a legitimate security tool and used README instructions to trigger it without user approval, resulting in remote code execution on the host ainowinstitute.org/publications...
Friendly Fire: Hijacking Defensive Cyber AI Agents for Remote Code Execution
AI Now’s latest research demonstrates a critical attack vector on popular AI agents, built by Anthropic and OpenAI, when used for defensive purposes that actually turn the agent against its user.
ainowinstitute.org
Automatically attacking software reverse-engineering AI agents via prompt injection hidden inside compiled binaries. A “Hello, World!” binary was falsely analyzed as generating Fibonacci numbers. The attack also worked on multi-function program. arxiv.org/pdf/2605.30667
arxiv.org
A mini cyber paperclip-maximizer event where a narrow goal induced AI to make absurdly disproportionate decisions (find vulnerabilities, escalate privileges, steal credentials, move laterally, and chain attacks across real systems) to achieve a "score". openai.com/index/huggin...
Security incident disclosure — July 2026
We’re on a journey to advance and democratize artificial intelligence through open source and open science.
huggingface.co
Swiss train manufacturer Stadler Rail was targeted by the Russian Everest hacking group, which allegedly stole technical data via a supplier platform and demanded 10 million CHF. Stadler won't pay. www.railwaygazette.com/stadler/2026...
OpenAI is to release an AI assistant product that would, due to its design, exclude persons with hearing disabilities.
Current and former Meta employees are suing the company, claiming the layoff AI algorithm targeted people on medical leave, with disabilities, or caring for family. The first such lawsuit against a major US company. What so you think? www.reuters.com/world/meta-u...
I’m excited to serve on the program committee for the Govern track at [un]prompted II. Quite simply, it’s the best AI security practitioner conference! Submit the work the field needs to see. unpromptedcon.org/cfp/
Finance depends on shared software, cloud services, OS tools and linked systems, so AI-powered cyberattacks could become a financial stability problem. European Systemic Risk Board warns frontier AI could make cyberattacks on banks faster and harder to contain www.esrb.europa.eu/pub/pdf/warn...
A massive fraud has been detected in scientific infrastructure. Someone is using AI to mass-create fictional authors, publications, and metadata with real DOIs. Such records can enter publication aggregators and contaminate the academic record. An attack on science? arxiv.org/html/2606.02...