Nvidia says its new OpenShell platform can stop AI agents from going rogue
Companies that build AI systems will need to ensure that their systems always remain under meaningful human control, and that meaningful safeguards constrain their ability to cause harm. These events also highlight risks in future AI development that extend beyond OpenAI and will require the attention of the whole industry. More generally, we are building toward monitoring systems with tiered responses for misalignment, with the end goal of having fully autonomous shutdown procedures for severe issues. We have also accelerated our existing work on alignment training throughout the model development pipeline. Our largest planned frontier RL run remains on hold while we conduct smaller-scale training and evaluations to assess model behavior, validate our safeguards, and establish more evidence of alignment before proceeding.
In an alert published today, software supply chain security company Socket revealed that unknown threat actors managed to have overwritten existing tags, including v2.1.20 and alpine, while also introducing a new v2.1.21 tag that does not correspond to an official release. “Because the internal header format used a delimiter character that could also appear in user input, an attacker could inject additional metadata fields through crafted push option values.” Google-owned cloud security firm Wiz has been credited with discovering and reporting the issue on March 4, 2026, with GitHub validating and deployi… “During a git push operation, user-supplied push option values were not properly sanitized before being included in internal service headers,” per a GitHub advisory for the vulnerability. The company did not share any details about who may be behind the incident, and for how long the attackers had access to its systems. “Based on our investigation to date, we have found no evidence that our source code release or distribution process was affected, or that our source code has been exploited,” the company added.
A new deep-learning architecture could deflect cyberattacks by combining several methods for analyzing network traffic, according to research published in the International Journal of Business Intelligence and Data Mining. A machine-learning system can identify fake, or spoofed, website addresses, according to research published in the International Journal of Electronic Security and Digital Forensics. Using survey data from parents and teens and leveraging artificial intelligence, the research team created a chatbot … As AI agents proliferate across enterprises, identity governance must evolve to a dynamic model that continuously monitors and manages risk
- We conducted an extensive security investigation and incident response; the full technical findings can be read here(opens in a new window).
- One of these models eventually drove the activity behind the Hugging Face incident.
- We took this time to further harden and red-team the security of our frontier research environments.
- Rival crew demands eight figures and threatens to expose companies that paid to keep quiet
AI is Finding More Vulnerabilities But Open Source Needs More People to Fix Them
Nvidia said more than 100 organizations are using the platform at its launch, including Accenture, JPMorgan Chase and Microsoft. Most recently, OpenAI said on Friday that its AI agents had interacted with several U.S. government websites in unexpected ways, a disclosure that came after several earlier rogue hacking incidents by other AI agents. The company said on Monday that it is releasing the new system, called OpenShell, due to the need for “independent security controls” after multiple AI agents disobeyed commands and broke into other systems. “Our investigation confirmed that these individuals mishandled sensitive information outside established company procedures, violating our policies and breaking the trust essential to our work.” The impacted employees are Jasmine Wang , Tomek Korbak , and Mikita Balesni , the Journal reported, citing people familiar with the matter.
AI policy circles targeted in China-linked phishing operation
As organizations manage more identities, devices, data, and internet-facing infrastructure, security is shifting toward continuous visibility, control, and the ability to respond to risk at scale. In a report published in November 2025, independent security journalist Brian Krebs labeled him as one of the three administrators of Scattered LAPSUS$ Hunters (SLH or SLSH), a group that’s assessed to be an amalgamation of Scattered Spider, LAPSUS$, and ShinyHunters. Threat actors have been observed attempting to exploit a now-patched critical security flaw impacting the Realtek Jungle software development kit (SDK) to deploy a botnet malware called Cling .
At the time, to allow models to install certain software packages, we would grant access to Artifactory, a third-party package manager service that we host internally. Our models are now powerful, persistent, and collaborative enough that, absent sufficient safeguards, they can find and exploit security weaknesses across multiple computer systems. In response to this incident and, separately, the capabilities of our upcoming Astra model, we are strengthening our safeguards across our research infrastructure. Today we are publishing our full technical incident report(opens in a new window) to explain what happened, what we learned, and how we are responding.
ShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group Members
CISA flags actively exploited Cisco SD-WAN Manager authentication bypass flaw. Exploited FortiMail flaw lets attackers turn email security gateways into persistent footholds. The EU’s cybersecurity agency has gained access to Mythos 5 and is testing the powerful artificial intelligence model developed by AI firm Anthropic, an EU spokesman said Thursday.
Known as Rey, the suspect is reportedly helping the FBI identify and locate other https://carsinfo.net/professional-car-lock-services-in-the-uk-benefits-and-features.html members of the extortion group. Federal law enforcement agents from Homeland Security Investigations and FBI guard a high school football game at Cardozo Education Campus in Washington, D.C., September 12, 2025. Dreamforce is an annual event that highlights the company’s technologies and encourages professional networking. CyberScoop spoke with members of Congress, former federal law enforcement officials, cybersecurity attorneys and other experts about which laws, regulations or policies might apply to agentic hacks carried out by models at Anthropic, OpenAI, Meta, Google and other companies. A breach of the Pentagon’s Defense Manpower Data Center exposed unencrypted personal data on 3 million people, with notice sent months after discovery. Chrome and Firefox fixed over 100 vulnerabilities between them, including a critical ANGLE buffer overflow in Chrome rated capable of remote code execution.
Researchers Discover Critical GitHub CVE-2026-3854 RCE Flaw Exploitable via Single Git Push
Since the incident, we have made significant progress in hardening our internal sandboxes to limit https://dragonsupport-number.com/telos-crypto-innovating-for-financial-accessibility/ similar types of risks during deployment and evaluations. Second, before the incident, we had invested substantially in chain-of-thought monitoring, including monitoring many of our frontier RL training runs and a significant majority of internal coding agent usage. First, there are numerous mechanisms that reduce misalignment in production settings for our customers, including system prompts, harnesses, and control mechanisms such as our auto-review models and safety classifiers.
An analysis of the malware sample has found it to embed exploit logic for various command injectio… GitHub’s own engineering team has gone further in its capacity planning, saying it moved from preparing for 10x scale to designing for a future that require… There are actively exploited bugs in the mix, cleaner intrusion paths, smarter automation, and a long patch list waiting https://repaircanada.net/there-is-a-job-in-the-field-of-high-technology-in-canada.html behind them. This week’s threats keep finding leverage in small things that were easy to overlook.
Leave a Comment