All posts tagged: vulnerabilities

Chrome Needs Twice-a-Week Patching Thanks to AI Bug Hunting

Chrome Needs Twice-a-Week Patching Thanks to AI Bug Hunting

Google’s Chrome browser has always been focused on pushing security updates. A decade ago it was controversial that the browser, the first to add automatic updates, distributed patches every six weeks. Now it’s the norm for critical, widely used software to get security fixes every few weeks, but as AI vulnerability hunting produces a torrent of bugs in any and all software, the quantity and frequency of patches is spiking—and the race to deliver them is on. In a report published Thursday, the Chrome security team says the browser’s two major version releases in June included fixes for 1,072 security bugs—more patches than the team shipped in the prior 23 big releases combined. And though many of these bugs come from researcher submissions, the spike has largely been driven by the Chrome security team’s rapidly evolving internal process for using AI tools in vulnerability discovery, triage, and patch development. “In chrome we’ve been using machine learning—using AI before it was called AI—to help find vulnerabilities in particular and automate security fuzz testing work since at …

OpenAI’s Hacking Debacle Was a Human Mistake

OpenAI’s Hacking Debacle Was a Human Mistake

The age of rogue AI hacker agents has arrived—but it didn’t have to happen this way. After an OpenAI agent breached the Hugging Face platform earlier this month, the two companies said this week that the hacking spree was more extensive than previously thought and also involved intrusions into multiple third-party accounts and services as part of the attack on Hugging Face. The incident has made waves in the cybersecurity community amid broader discussions about how evolving AI capabilities are changing both offensive hacking and digital defense. But as more information emerges, many researchers have concluded that rather than elucidating AI’s next frontier, the episode simply highlighted long-standing cybersecurity problems that are more consequential than ever in the AI age. “People are YOLO-ing really hard. It’s shocking how little people have really thought about a scenario like this,” says Alex Zenla, cofounder and chief technology officer of the cloud security firm Edera. “I consider all AI and anything AI touches to be fully untrusted—which is fine, you just need to build against that. And this …

The OpenAI Models That Hacked Hugging Face Were ‘Active on the Internet’ for Days

The OpenAI Models That Hacked Hugging Face Were ‘Active on the Internet’ for Days

Two of OpenAI’s cybersecurity-focused models broke out of a testing sandbox this week and went on to hack the AI research platform Hugging Face in an effort to solve a security benchmark test. Plus, researchers this week shed light on newly identified malware that is capitalizing on blind spots in AI software development infrastructure to grab logins and other sensitive data, even causing destruction to victims’ target files and systems. Looking at the more traditional security nightmare of embedded devices, researchers this week shed light on a car alarm that was installed in vehicles across the US—and that is still silently lurking with a flaw that leaves millions of vehicles vulnerable to hacking and paralysis. There’s a patch available, and WIRED has details on how to check whether your car may have been exposed. US states have worked to bar ICE agents from wearing masks, but Trump administration lawyers are pushing back, claiming that anti-mask laws endanger agents. Their public evidence is incredibly thin, though. Meanwhile, a WIRED investigation revealed that Madison Square Garden briefly …

OpenAI Models Escaped Containment and Hacked Hugging Face

OpenAI Models Escaped Containment and Hacked Hugging Face

OpenAI disclosed on Tuesday that it lost control of two AI models during a security test that ended in a breach of the open AI research platform Hugging Face. Describing the incident as “unprecedented,” OpenAI said its AI models broke out of a sealed testing environment last week and hacked into Hugging Face’s production system to steal the answers to a test they were being graded on. The models—the publicly available GPT-5.6 Sol and an unreleased, reportedly more capable one—were being evaluated on their offensive hacking skills with the safeguards that normally block high-risk cyber activity switched off. “The models identified and chained vulnerabilities across OpenAI’s research environment and Hugging Face’s production infrastructure to obtain test solutions directly from Hugging Face’s production database,” OpenAI and Hugging Face wrote in a joint blog post disclosing the intrusion. According to OpenAI and Hugging Face, the models escaped through a package registry cache proxy—software that allows developers to install outside code without connecting to the internet. The proxy was the only component in OpenAI’s isolated testing environment permitted …

A Sneaky Hacking Tool Targeting AI Infrastructure Is Lurking in Victims’ Blind Spots

A Sneaky Hacking Tool Targeting AI Infrastructure Is Lurking in Victims’ Blind Spots

As AI tools proliferate and become deeply ingrained in software development around the world, new research from the cybersecurity firm Crowdstrike shows how attackers are actively targeting the AI toolchain to steal access credentials, gain deeper access to a target environment, exfiltrate sensitive data, and even destroy target files and systems—all while finding new ways to cover their tracks. Researchers discovered a worm in the wild while investigating AI software supply chain attacks. Adam Meyers, CrowdStrike’s senior vice president of counter adversary work, says that the company has not yet attributed the activity to a specific actor, but that it fits into larger evolutions in how attackers like TeamPCP (which Crowdstrike tracks as “Altered Spider”) and North Korean groups are targeting the AI software supply chain. “This is one of the campaigns that we’ve seen showing that this is an emerging attack class,” Meyers tells WIRED. “As AI coding agents become the development standard, supply chain threats are evolving to exploit those trust relationships. For the first time we’re experiencing how much AI and the …

A Device Hidden in Cars Across the US Leaves Them Vulnerable to Hacking and Paralysis. Patch It Now

A Device Hidden in Cars Across the US Leaves Them Vulnerable to Hacking and Paralysis. Patch It Now

As modern cars have evolved into multi-ton computers on wheels, drivers are beginning to learn they need to install security updates for their vehicles’ code, just as they would for a phone or laptop. Yet not even the most tech-savvy car owners would expect they’d need to install a patch for an insecure third-party component they never installed or requested—and likely aren’t even aware of—that’s been wired into some of the most sensitive systems of their vehicle, leaving it vulnerable to stealthy hacking, tracking, and even roadside paralysis. That’s the disturbing discovery of a team of security researchers at UC San Diego, who found that a model of aftermarket car alarm known as the KARR Security System, installed in more than 2 million vehicles across the US by their estimate, can let any hacker within Bluetooth range send radio commands to silently unlock the car at will, turn off its alarm, honk the car’s horn or flash its lights, or even disable its ignition and leave a driver stranded. The KARR alarm devices are typically …

Prompt Injection Attacks Are Thwarting AI Hacking Agents

Prompt Injection Attacks Are Thwarting AI Hacking Agents

Prompt injections, the malicious commands attackers embed into content to entice large language models to follow them, have been attackers’ go-to tool for turning AI platforms against their users. A well-phrased command sneaked into an email or calendar invitation is often all it takes to cause the LLM to exfiltrate sensitive data or follow other harmful actions. Now, defenders are embracing the prompt injection, too. Researchers from Tracebit on Monday said they found that placing prompt injections alongside passwords, cryptographic keys, and other secrets stored on Amazon Web Services was often all that was needed to shut down attacks from AI hacking agents. The prompts direct the attacking LLM to perform an action forbidden by its guardrails, the safety barriers AI developers erect to prevent it from taking harmful actions. The LLM responds by shutting down. Examples are a prompt that orders the LLM to provide steps for developing inhalable Anthrax spores, or, in the case of LLMs from Chinese developers, make references to the iconic Tank Man from the 1989 Tiananmen Square massacre. Once …

The Pentagon Is Looking Into the Dialog Data Exposure for Unmasking National Security Officials

The Pentagon Is Looking Into the Dialog Data Exposure for Unmasking National Security Officials

A data exposure at Dialog, the private events group cofounded by Peter Thiel, exposed personal information of multiple US national security personnel. These include an intelligence official on the National Security Council (NSC) and an active-duty intelligence officer supporting sensitive military operations, WIRED has learned. The Pentagon is now examining the matter. Personal information about intelligence and military personnel is among the data most sought by foreign intelligence services, which use it to identify, surveil, and approach US operatives abroad and at home. For active-duty officers and the units they support, the exposure can add operational risks. The White House asked WIRED to not name the NSC official on national security grounds but otherwise declined to comment about the exposure. The Dialog exposure, which evidence shows was enabled by a misconfigured website, included the private information and login tokens of 222 Dialog event registrants, including current and former senior military and national security officials from the United States and its allies. Among them are the NSC official, whose role includes advising President Donald Trump and …

Dialog Claims It Was Hacked. A Misconfigured Website Left Its Members Exposed

Dialog Claims It Was Hacked. A Misconfigured Website Left Its Members Exposed

Dialog, the invite-only group cofounded by Peter Thiel, notified members and past event participants last week that a database containing their personal information had been breached, supposedly by a criminal hacker. But a WIRED analysis found that the files were readable to anyone who visited a landing page for the group’s app—what cybersecurity experts describe as a misconfiguration that effectively made the data publicly accessible. The notification to people affected by the data exposure, emailed by Dialog managing director Juliette Levine and provided to WIRED, said that forensic investigators found that the names of 113 past participants in Dialog events had been exposed and, separately, “some” people registered for this summer’s Dialog retreat had their information accessed. Levine said the organization had temporarily closed many of its systems in response. The exposure, Levine alleged, “was a hack executed by a well-known criminal who is wanted in the United States,” adding that the group had acted “out of caution” to protect “the safety, privacy, and reputation of every Dialoger past and present.” Multiple reviews of the …

OpenAI Launches Full-Scale Effort to Patch Open-Source Bugs as It Takes on Anthropic’s Mythos

OpenAI Launches Full-Scale Effort to Patch Open-Source Bugs as It Takes on Anthropic’s Mythos

As fears about AI hacking capabilities grow, OpenAI on Monday made a slew of cybersecurity-focused announcements, including an improved version of its limited-access security-specialized model GPT-5.5-Cyber, expanded international work with governments and other institutions to give them “trusted access” to the company’s latest cybersecurity-focused models, and releasing its Codex Security scanner as an app plug-in. As advances across the AI industry leave critical open-source projects at increasing risk of falling behind, though, the company also said on Monday that it is launching an effort known as Patch the Planet, founded with the prominent research-focused security firm Trail of Bits and in collaboration with vulnerability management firms HackerOne and Calif. The project has already begun its work offering free security consulting services to open source maintainers to not only help them find and patch vulnerabilities, but also support them in strengthening their code bases and incorporating AI security tools into their development process. The idea is to give individualized support to as many open-source projects as possible to improve both their current security and long-term resilience …