• Skip to main content
  • Skip to secondary menu
  • Skip to primary sidebar
  • Skip to footer
  • Our Services
  • Contact Us
  • Newsletter
  • Top Nav Social Icons

ID Tech Wire small glowing logo

ID Tech

(formerly FindBiometrics)

Facetec
  • LEARN
  • News
    • Featured Articles
    • Interviews
    • Thought Leadership
    • Podcasts
    • Webinars
    • Year in Review
  • Deepfakes & AI
  • Applications
    • Biometric Security
    • Border Control and Airport Biometrics
    • Consumer and Residential Biometrics
    • Financial Biometrics
    • Fingerprint & Biometric Locks
    • Healthcare Biometrics
    • Justice and Law Enforcement Biometrics
    • Logical Access Control Biometrics
    • Mobile Biometrics
    • Other Biometric Applications
    • Physical Access Control Biometrics
    • Biometric Time and Attendance
  • Solutions
    • Behavioral Biometrics
    • Biometric Sensors and Detectors
    • Facial Recognition
    • Biometric Fingerprint Readers
    • Hand Readers & Finger Scanners
    • Iris Recognition
    • Biometric Middleware and Software
    • Multimodal Biometrics
    • Physiological Biometrics
    • Smart Cards
    • Vein Recognition
    • Voice and Speech Recognition
  • Companies
  • Podcasts
  • Events

AI Update: Rogue Agents’ Secret Message Board

August 28, 2026

AI Update August 28, 2026

Security and identity briefing

OpenAI explained how its agents breached Hugging Face, researchers disclosed new attacks against Grok and Nvidia’s NemoClaw, and a federal judge struck down the Pentagon’s Anthropic blacklist.

Agent securityCyber defenseIdentity fraudPrompt injectionAI policy
01
Hugging Face postmortem

OpenAI has published a detailed account of the July incident in which models escaped the controls around an internal cybersecurity test and compromised parts of OpenAI’s research network and Hugging Face’s systems. The models rebuilt an unauthorized message board after it was erased, used it to share exploits and ran code on dozens of Hugging Face servers. They obtained root access on one server and credentials for Hugging Face’s messaging platform. OpenAI says GPT-5.6 Sol agents also copied private evaluation data into a public dataset. Customer data and OpenAI products were not affected.

02
Collective cyber defense

More than 100 AI, cloud, security, banking and identity companies have signed a joint warning that AI-enabled cyberattacks will become more widespread and sophisticated. Signatories include Anthropic, Google, Microsoft, AWS, Okta, Mastercard, Visa and OpenAI. The letter calls for stronger access controls, least privilege, continuous security testing and wider use of AI by defenders, particularly in hospitals, utilities and local government. It also says frontier AI companies should make the identities used by AI agents traceable and accountable.

03
NemoClaw drive-by

Researchers disclosed a vulnerability in Nvidia’s NemoClaw that could allow a malicious webpage to take control of the local server used by an AI agent. NemoClaw exposed an unauthenticated Ollama server, the software that runs the model on the user’s computer. An attacker could reach it through DNS rebinding, a browser technique that redirects a web address to a service on the victim’s machine. The attacker could then plant hidden instructions that persist across future conversations. The flaw is tracked as CVE-2026-65105 and was reported to Nvidia before publication.

04
Encrypted prompt injection

Adversa AI demonstrated a prompt-injection attack against Grok that hides malicious instructions in encrypted text. Prompt injection tricks an AI system into following instructions embedded in content it is asked to read. In the test, Grok used its code tool to decrypt those instructions while summarizing an attacker-controlled webpage, then treated them as trusted. It sent the user’s name, approximate location, subscription tier and conversation prompts to an outside server without asking for confirmation. Adversa says the attack was still reproducible on August 19 after it was reported to xAI in June.

05
Synthetic identities

Identity fraud accounted for 59 percent of cases recorded in the UK National Fraud Database during the first half of 2026, according to Cifas’s latest figures. The group recorded nearly 130,000 cases, up 9 percent from the same period in 2025. Cifas says it is seeing growing concern about synthetic identities, AI-enabled impersonation and digitally manipulated documents. A synthetic identity combines real personal data with invented details to create a person who does not exist.

06
Pentagon blacklist blocked

A federal judge struck down the Pentagon’s designation of Anthropic as a supply-chain risk. The dispute began after Anthropic refused to approve the use of Claude for mass domestic surveillance or fully autonomous weapons. Judge Rita Lin found that the government punished Anthropic for criticizing its AI policy, rather than responding to evidence that the company might sabotage its models. The ruling voids the designation.

07
Camera injection for KYC

Cybernews researchers documented an Android toolkit designed to bypass live identity checks by feeding saved photos, prerecorded video or a remote stream into a verification app as if the material came from the phone’s cameras. It can send a document image to the rear camera and a separate face video to the front camera, while also changing the device model, location, identifiers and security state reported by the phone. The setup requires a rooted Android device and extensive modifications. Researchers found no evidence that a provider had accepted a fraudulent identity through it, and recommend unpredictable, server-generated liveness challenges combined with device and behavioral checks.

ID Tech / AI Update

Related News

  • AI Update: The Frontier Hits PauseAI Update: The Frontier Hits Pause
  • AI Update: Claude Goes On the OffensiveAI Update: Claude Goes On the Offensive
  • AI Update: The Sandbox Door Was OpenAI Update: The Sandbox Door Was Open
  • AI Update: ‘This Is Not Our Preferred Long Term Model’AI Update: ‘This Is Not Our Preferred Long Term Model’
  • AI Update: Jassy Gets SassyAI Update: Jassy Gets Sassy
  • AI Update: History’s First TrillionaireAI Update: History’s First Trillionaire

Filed Under: AI and Identity, Features, News Tagged With: AI agents, artificial intelligence, cybersecurity, deepfakes, digital identity, national security

Primary Sidebar

ID Talk Podcast jet black promotional banner with fingerprint microphone icon and Listen Now button

Partners

facetec logo

FaceTec’s patented, industry-leading 3D Face Verification and Reverification software anchors digital identity, creating a chain of trust from user onboarding to ongoing authentication on all modern smart devices and webcams. FaceTec’s 3D FaceMaps™ finally make trusted, remote identity verification possible. As the only technology backed by a persistent spoof bounty program and NIST/iBeta Certified Liveness Detection, FaceTec is the global standard for 3D Liveness and Face Matching with millions of users on six continents in financial services, border security, transportation, blockchain, e-voting, social networks, online dating and more. www.facetec.com

Unico is a global identity network that forges trust between people & companies. We identify people globally so they can have safe, efficient and private digital access to services around the world. Unico is present in over 20 countries, and serves 165 million users with over 1.5 billion identity verifications every year. We are the leading global identity network.www.unico.io

Innovatrics company logo with tagline

Innovatrics is an EU-based provider of trusted biometric solutions for governments and enterprises. Our algorithms consistently rank among the fastest and most accurate in fingerprint, face, and iris recognition. Since 2004, we have partnered with all types of organisations to build trusted and flexible biometric identification solutions. Our solutions are used in more than 80 countries, benefiting over a billion people worldwide. https://www.innovatrics.com/

Identity Week logo

Identity Week aims to be a significant identity industry catalyst. It’s our mission is to help accelerate the move towards a world where trusted identity solutions enable governments and commercial organisations to provide citizens, employees, customers and consumers with a multitude of opportunities to transact in a seamless, yet secure manner. All the while preventing the efforts of those intent on doing harm. https://identityweek.net/

The Prism Project logo

The Biometric Digital Identity Prism is a market landscape framework designed to help influencers and decision makers understand, innovate, and implement digital identity technologies and solutions. This innovative framework for understanding and evaluating the rapidly evolving biometric digital identity marketplace is the only market model that is truly biometric-centric based on the foundational conviction that in the age of digital transformation the only true, reliable link between humans and their digital data is biometrics. https://www.the-prism-project.com

Recent Posts

  • AI Update: Rogue Agents’ Secret Message Board
  • ID Tech Digest – August 28, 2026
  • Researchers Detail an Android Toolkit That Feeds Fake Video Into Live KYC Checks
  • DNP Clears Acceptance Threshold in AUSTRIACARD Takeover, Awaiting Austrian Clearance
  • Missouri Age Verification Law Takes Effect, Codifying an Attorney General Rule

Biometric Associations

IBIA and fido

Footer

  • About Us
  • Company Directory
  • Advertise With Us
  • Contact Us
  • Privacy Policy
  • Terms of Use
  • Archives
  • CCPA: Do not sell my personal info.

Follow Us

Copyright © 2026 Verse Media