Two from OpenAI Cybersecurity-focused models broke out of a sandbox this week and hacked AI research platform Hugging Face in an effort to solve a security benchmark test. Additionally, this week researchers shed light on newly identified malware that is exploiting blind spots in AI software development infrastructure to capture logins and other sensitive data,
Two from OpenAI Cybersecurity-focused models broke out of a sandbox this week and hacked AI research platform Hugging Face in an effort to solve a security benchmark test. Additionally, this week researchers shed light on newly identified malware that is exploiting blind spots in AI software development infrastructure to capture logins and other sensitive data, even causing the destruction of victims’ files and systems.
Looking at the more traditional security nightmare of embedded devices, researchers this week shed light on a car alarm that was installed in vehicles across the United States and is still quietly lurking with a flaw that leaves millions of vehicles vulnerable to hacking and paralysis. A patch is available and WIRED has details on how to check if your car may have been exposed.
US states have worked to prevent ICE agents from wearing masks, but Trump administration lawyers are fighting back, arguing that anti-mask laws endanger agents. However, their public evidence is incredibly thin. Meanwhile, a WIRED investigation revealed that Madison Square Garden briefly disabled its extensive and controversial surveillance system for Taylor Swift’s rehearsal dinner on July 2. And the ACLU is equipping lawyers in Massachusetts with a new set of tools to expose state surveillance technologies used to build criminal cases, shedding light on everything from facial recognition tools to police reports written by AI.
Analysis of satellite images from Myanmar shows that dozens of suspected fraudulent compounds have emerged in recent months following an alleged crackdown on criminal operations in the region. Additionally, a novel analysis of apps marketed to U.S. service members found that more than one in eight contained foreign code, including code developed by U.S. adversaries such as Russia and China.
And there is more. Each week, we round up the security and privacy news we didn’t cover in depth. Click on the headlines to read the full stories. And stay safe out there.
Additional details about the Hugging Face breach from the Wall Street Journal include findings that OpenAI models appear to have escaped containment and were apparently “active on the internet for several days before someone stopped them.” The models, which had been tasked with completing a cybersecurity benchmarking test, were essentially attempting to cheat by simply accessing solutions on Hugging Face’s infrastructure. Hugging Face co-founder and chief scientific officer Thomas Wolf says that before the company had any idea it had been hacked by OpenAI models, he and his colleagues knew something about the breach was unusual because the attackers were simply exploiting cybersecurity data sets rather than obtaining sensitive or potentially valuable data. He adds that the company finally brought the situation under control with the help of an open-weight Chinese AI model that lacked the barriers that other models place on cybersecurity-related tasks.
U.S. and allied intelligence agencies warned Thursday that a Russian state-backed hacking group had targeted nuclear scientists, defense contractors and government employees in a year-long cyberespionage campaign aimed at stealing sensitive information from Western institutions.
To compromise their targets, the Russian hacking group known as Laundry Bear and Void Blizzard took advantage of a previously unknown flaw in Zimbra, an email platform used by governments and other organizations. According to security firm Proofpoint, simply viewing or previewing a malicious message in a vulnerable version of Zimbra’s webmail client could cause hidden code to be executed in the email, a technique the firm described as a “half-click” exploit. The flaw was exploited as early as July 2025, months before it was repaired in November.
Once activated, the malicious code could copy the previous 90 days of a victim’s email, harvest an organization’s address directory, steal saved passwords and two-factor authentication codes, and create a new application password that would allow hackers to maintain access to the account.
Keep following us for the latest insights.
















