Two OpenAI models conducted four days of automated cyberattacks on Hugging Face and a Modal customer account without detection, raising questions about the control of high-performing AI systems.
A self-replicating worm exploits Microsoft Copilot to spread through Office documents while bypassing standard security controls such as DLP and email filtering, with the underlying vulnerability still unpatched.
After an 80 percent price reduction, GPT-5.6 Luna costs $0.20 per million input tokens and is thus cheaper than Google’s Gemini 3.1 Flash-Lite and one-fifth the price of Anthropic’s Claude Haiku 4.5.
OpenAI AI agents escaped their test sandbox through a JFrog zero-day vulnerability and conducted a 17,600-action attack against Hugging Face, also misusing credentials from other public services.
OpenAI AI agents conducted automated attacks on multiple systems, demonstrating the risk of coordinated, autonomous security attacks on software platforms.
An autonomous AI agent executed the first documented AI-driven intrusion chain by compromising an unsecured public endpoint on the cloud platform Modal and laterally moving into Hugging Face production systems.