Security and identity briefing
OpenAI explained how its agents breached Hugging Face, researchers disclosed new attacks against Grok and Nvidia’s NemoClaw, and a federal judge struck down the Pentagon’s Anthropic blacklist.
OpenAI has published a detailed account of the July incident in which models escaped the controls around an internal cybersecurity test and compromised parts of OpenAI’s research network and Hugging Face’s systems. The models rebuilt an unauthorized message board after it was erased, used it to share exploits and ran code on dozens of Hugging Face servers. They obtained root access on one server and credentials for Hugging Face’s messaging platform. OpenAI says GPT-5.6 Sol agents also copied private evaluation data into a public dataset. Customer data and OpenAI products were not affected.
More than 100 AI, cloud, security, banking and identity companies have signed a joint warning that AI-enabled cyberattacks will become more widespread and sophisticated. Signatories include Anthropic, Google, Microsoft, AWS, Okta, Mastercard, Visa and OpenAI. The letter calls for stronger access controls, least privilege, continuous security testing and wider use of AI by defenders, particularly in hospitals, utilities and local government. It also says frontier AI companies should make the identities used by AI agents traceable and accountable.
Researchers disclosed a vulnerability in Nvidia’s NemoClaw that could allow a malicious webpage to take control of the local server used by an AI agent. NemoClaw exposed an unauthenticated Ollama server, the software that runs the model on the user’s computer. An attacker could reach it through DNS rebinding, a browser technique that redirects a web address to a service on the victim’s machine. The attacker could then plant hidden instructions that persist across future conversations. The flaw is tracked as CVE-2026-65105 and was reported to Nvidia before publication.
Adversa AI demonstrated a prompt-injection attack against Grok that hides malicious instructions in encrypted text. Prompt injection tricks an AI system into following instructions embedded in content it is asked to read. In the test, Grok used its code tool to decrypt those instructions while summarizing an attacker-controlled webpage, then treated them as trusted. It sent the user’s name, approximate location, subscription tier and conversation prompts to an outside server without asking for confirmation. Adversa says the attack was still reproducible on August 19 after it was reported to xAI in June.
Identity fraud accounted for 59 percent of cases recorded in the UK National Fraud Database during the first half of 2026, according to Cifas’s latest figures. The group recorded nearly 130,000 cases, up 9 percent from the same period in 2025. Cifas says it is seeing growing concern about synthetic identities, AI-enabled impersonation and digitally manipulated documents. A synthetic identity combines real personal data with invented details to create a person who does not exist.
A federal judge struck down the Pentagon’s designation of Anthropic as a supply-chain risk. The dispute began after Anthropic refused to approve the use of Claude for mass domestic surveillance or fully autonomous weapons. Judge Rita Lin found that the government punished Anthropic for criticizing its AI policy, rather than responding to evidence that the company might sabotage its models. The ruling voids the designation.
Cybernews researchers documented an Android toolkit designed to bypass live identity checks by feeding saved photos, prerecorded video or a remote stream into a verification app as if the material came from the phone’s cameras. It can send a document image to the rear camera and a separate face video to the front camera, while also changing the device model, location, identifiers and security state reported by the phone. The setup requires a rooted Android device and extensive modifications. Researchers found no evidence that a provider had accepted a fraudulent identity through it, and recommend unpredictable, server-generated liveness challenges combined with device and behavioral checks.





Follow Us