Former OpenAI board member Helen Toner has written for Fortune that OpenAI’s models exploiting Hugging Face is an “incident that has been expected for a long time.” We know this happened because of voluntary disclosure, Toner notes. “None of the current policies that aim to manage risks from frontier models would have mandated that the public — or even a government entity — be alerted.” She suggests changing our regulatory approach.
Security
Cybersecurity is the rickety scaffolding supporting everything you do online. For every new feature or app, there are a thousand different ways it can break – and a hundred of those can be exploited by criminals for data breaches, identity theft, or outright cyber heists. Staying ahead of those exploits is a full-time job, and one of the most lucrative and sought-after skills in the tech industry. All too often, it’s something up-and-coming companies decide to skip out on, only to pay the price later on.


Apple is patching dozens of flaws across iOS 26.6 and iPadOS 26.6, including a vulnerability that could allow apps to access a user’s contacts, as well as a security hole that could allow malicious apps to escape their sandbox in the Game Center. Several fixes are rolling out to macOS Tahoe 26.6 as well.
Project Perception uses a series of AI agents to reason across a company’s data, tools, and workflows to detect potential security holes and patch them before they’re exploited.
Microsoft is powering the tool with its new MAI-Cyber-1-Flash model, which it says “delivers world-class performance at 50% of the cost of leading models.”
[The Official Microsoft Blog]
According to Reuters, the AI agent that went looking for ExploitGym hacking benchmark shortcuts on Hugging Face’s systems started trying to escape its not-sandboxed-well-enough test environment around July 9th, and the actual intrusion lasted from the 11th until the 13th.
Reuters’ sources claim OpenAI employees didn’t know its agent was responsible until after Hugging Face had notified the FBI and posted publicly about a security incident.


This is a story about how AI destroyed a long-running site of film data. It’s not just that search no longer refers traffic or that the site itself, The Numbers, is getting scraped. It’s also that there’s no way to defend 30-year-old webpages against malicious actors attempting to get the data early so they could win their Polymarket bets.
[Stephen Follows]
The Coca-Cola-owned company announced last week that it “identified unauthorized access” to its production-related systems “in connection with a ransomware event.” Though Fairlife says “product quality and safety have not been impacted,” it’s halting production as it continues investigating the breach.
[BleepingComputer]


19-year-old Peter Stokes was arrested in Finland and extradited to the US to face federal conspiracy charges related to the Scattered Spider hacking group. Stokes is accused of working with co-conspirators to breach a luxury jewelry retailer and demand an $8 million ransom.
Last month, two Scattered Spider members pleaded guilty to breaching London’s transportation system in 2024.
Swedish-language site Flamman reported that Daniel Berntsson gave 5 million Swedish kronor to the Örebro Party. The VPN company responded to the news on X, and Mullvad’s co-CEO Fredrik Strömberg told TechRadar “I don’t like that he made this donation,” but that “we will continue to protect the universal right to privacy.”


In 2022, LastPass’ breach coughed up encrypted customer passwords spurring some crypto heists later.
Now it says a breach at Klue gave attackers access to its Salesforce data, along with that of other companies who, according to reports, are being extorted by “Icarus.” For LastPass, the stolen data includes customers’ names, phone numbers, and other data, but not the actual password vaults this time.
Tata Electronics, an India-based manufacturing partner for both companies, says it’s investigating a “cybersecurity incident” after the World Leaks ransomware group posted more than 200,000 component and specification documents on the dark web. The files reportedly include inspection standards for iPhone circuit board components, and drawings for the Model 3 revamp that Tesla launched in 2023.
Screenshots seen by Business Insider showed that data from Meta’s controversial AI training program — including employees’ private conversations, performance data, and transcriptions — could be accessed across the entire company. In a statement to the publication, Meta said:
“We have carefully designed this program with privacy safeguards, and while we have no indication at this time that any data was improperly accessed by Meta employees, we’re pausing it while we investigate.”
The intelligence-sharing alliance says that Al models are anticipated to fundamentally transform offensive and defensive cyber capabilities in a matter of months, and that “breaches will occur” as previously unknown vulnerabilities emerge. “Adversaries are already using AI to move faster and more effectively,” said Five Eyes. “Defenders must do the same.”
[National Cyber Security Centre]
A proposed class action lawsuit alleges MSG failed to protect the data of over 26 million guests. It comes just days after 404 Media reported that hackers claimed to have published data stolen from MSG, which is known for its extensive surveillance system.
The Cybersecurity and Infrastructure Security Agency (CISA) gained access to the limited release cybersecurity-focused model last week, Nextgov/FCW reports. It’s just a little late, since the rest of the world has mostly moved onto the drama around the Trump administration’s block of the safeguarded public version of the model, Fable.
The group behind Matter has released the next version of its Product Security Certification Program, a cybersecurity standard designed to provide a single security label for consumer IoT devices.
The update extends certification beyond devices to include apps, gateways, and remote processes, allowing companies to certify entire ecosystems. It also adds independent validation through physical test labs and is now integrated into the Matter spec, with companies seeking Matter certification encouraged to complete the security certification as well.


“Outsider Enterprise” allegedly distributes phishing templates that have scammed people out of millions of dollars. Google says over a million fraudulent URLs are linked to the group, and that over just two weeks, it sent 2.5 million messages to Android users with links to fraudulent websites.
According to The New York Times:
Still, Meta decided not to make major changes to its A.I. plans after the Instagram hacks, according to the internal documents. “We agreed to leave all products on and to pause one ongoing experiment (IG Forgot Password Chat),” the documents said. “All other entrypoints will remain available.”
[The New York Times]
Despite last year’s $167 million verdict against NSO Group for its Pegasus software hacking some 1,400 WhatsApp users, Meta says it has detected new spear phishing attacks on its platform from the spyware maker, in violation of the court’s permanent injunction:
We successfully disrupted NSO-linked social engineering attempts, after investigating user reports. They tried to trick people into clicking on malicious links to drive them to external websites outside of WhatsApp, similar to previously reported 1-click phishing campaigns linked to NSO. We also caught them creating test accounts and groups on WhatsApp, which we took down.

The YouTube star has gone from reviewing synths to taking on the surveillance state.
The smart ring company says on March 27th hackers used an internal analytics tool to access users’ contact and account details, transaction history, and “some fitness related data.” According to TechCrunch, the breach impacted 0.1 percent of Ultrahuman users, or an estimated 700 people.
If you buy something from a Verge link, Vox Media may earn a commission. See our ethics statement.
[Ultrahuman]
With this expansion of Anthropic’s Project Glasswing initiative, organizations in “several industries that weren’t well represented” in the initial cohort, like power, water, and healthcare, will get access to the model so they can use it to find security vulnerabilities.
[Anthropic]
The @obamawhitehouse account briefly showed images of Iranian propaganda, which have since been taken down, as spotted earlier by TMZ. The account belonging to the US Space Force Chief Master Sergeant was also hijacked.
Most Popular
- It’s not just LG. Every TV company is spying on you
- OpenAI and Microsoft knew they were starting a ‘doom loop’ for the web
- The 2.5-hour AI-generated Odyssey movie is 2.5 hours too long
- Gemini went rogue, hacked three companies, and Google hid it
- The Apple Watch Series 12 is the start of a new wearable era


























