Skip to main content

Comment Loader Save StorySave this story

Comment Loader Save StorySave this story

Two of OpenAI’s cybersecurity-focused models broke out of a testing sandbox this week and went on to hack the AI research platform Hugging Face in an effort to solve a security benchmark test. Plus, researchers this week shed light on newly identified malware that is capitalizing on blind spots in AI software development infrastructure to grab logins and other sensitive data, even causing destruction to victims’ target files and systems.

Looking at the more traditional security nightmare of embedded devices, researchers this week shed light on a car alarm that was installed in vehicles across the US—and that is still silently lurking with a flaw that leaves millions of vehicles vulnerable to hacking and paralysis. There’s a patch available, and WIRED has details on how to check whether your car may have been exposed.

US states have worked to bar ICE agents from wearing masks, but Trump administration lawyers are pushing back, claiming that anti-mask laws endanger agents. Their public evidence is incredibly thin, though. Meanwhile, a WIRED investigation revealed that Madison Square Garden briefly disabled its sprawling, controversial surveillance system for Taylor Swift’s rehearsal dinner on July 2. And the ACLU is equipping lawyers in Massachusetts with a new toolkit to expose state surveillance technologies used for building criminal cases—shedding light on everything from face recognition tools to AI-written police reports.

Analysis of satellite images of Myanmar shows dozens of alleged scam compounds cropping up in recent months following a purported crackdown on the criminal operations in the region. Plus, a novel analysis of apps marketed to US service members found that more than one in eight contained foreign code, including code developed by US adversaries like Russia and China.

And there’s more. Each week, we round up the security and privacy news we didn’t cover in depth ourselves. Click the headlines to read the full stories. And stay safe out there.

The OpenAI Models’ Hack of Hugging Face Comes Into Focus

Additional details on the Hugging Face breach from The Wall Street Journal include findings that OpenAI’s models seem to have escaped containment and were apparently “active on the internet for several days before anyone stopped them.” The models, which had been tasked with completing a cybersecurity benchmarking test, were essentially attempting to cheat by simply accessing the solutions on Hugging Face’s infrastructure. Hugging Face cofounder and chief science officer Thomas Wolf says that before the company had any idea that it had been hacked by OpenAI models, he and his colleagues knew something about the breach was unusual because the attackers were simply tapping cybersecurity datasets rather than grabbing sensitive or potentially valuable data. He adds that the company eventually brought the situation under control with the help of an open-weight Chinese AI model that lacked the guardrails other models place on cybersecurity-related tasks.

Russian Operatives Go After Emails of US Nuclear Scientists and Defense Contractors

US and allied intelligence agencies warned on Thursday that a Russian state-backed hacking group had targeted nuclear scientists, defense contractors, and government employees in a year-long cyberespionage campaign aimed at stealing sensitive information from Western institutions.

To compromise their targets, the Russian hacking group known as Laundry Bear and Void Blizzard exploited a previously unknown flaw in Zimbra, an email platform used by governments and other organizations. According to security firm Proofpoint, simply viewing or previewing a malicious message in a vulnerable version of Zimbra’s webmail client could cause hidden code in the email to run, a technique the firm described as a “half-click” exploit. The flaw was exploited as early as July 2025, months before it was patched that November.

Once activated, the malicious code could copy the previous 90 days of a victim’s email, collect an organization’s address directory, steal saved passwords and two-factor authentication codes, and create a new application password that allowed the hackers to maintain access to the account.

Most Popular

  • A Teen Reporter Searched for His Community in the Epstein Files. Adults Freaked Out

The Big Story

A Teen Reporter Searched for His Community in the Epstein Files. Adults Freaked Out

By Ara Rosenthal

  • For Taylor Swift, Madison Square Garden’s Controversial Cameras Briefly Went Dark

The Big Story

For Taylor Swift, Madison Square Garden’s Controversial Cameras Briefly Went Dark

By Noah Shachtman

  • OpenAI Models Escaped Containment and Hacked Hugging Face

Cyberattacks and Hacks

OpenAI Models Escaped Containment and Hacked Hugging Face

By Lily Hay Newman

  • Some Kids Will Never Think AI Is Cool

Artificial Intelligence

Some Kids Will Never Think AI Is Cool

By Elana Klein

The hackers targeted organizations involved in nuclear research, energy, and the defense industries, as well as government agencies, universities, law enforcement organizations, media outlets, and technology companies.

US Restricts Visas for Scammers

The State Department said on Thursday that it would restrict visas for foreign cybercriminals involved in scams and extortion, expanding the Trump administration’s campaign against criminal networks that target Americans from overseas. Secretary of State Marco Rubio said the restrictions could apply both to people who carry out the crimes and, in some cases, their immediate family members.

Rubio authorized the restrictions under a 1952 immigration law that allows the US government to deny entry to people whose presence could have serious consequences for American foreign policy. The administration has used the same authority to restrict visas targeting members of groups it labels far-left extremists, raising concerns that lawful protesters or political opponents could be swept in.

The Trump administration has increasingly focused on large scam operations that use romance schemes, fraudulent cryptocurrency investments, and sexual blackmail to steal money or coerce victims. Many of the networks operate outside the US, making arrests and prosecutions difficult. In June, the Justice Department seized infrastructure connected to subsidiaries of the Huione Group, a Cambodian conglomerate that officials have linked to a major marketplace used by cybercriminals.

US Says Iran-Backed Hackers Are Targeting American Water and Energy Suppliers—Again

The US Cybersecurity and Infrastructure Security Agency, FBI, NSA, and Department of Energy warned on Wednesday that hackers linked to the Iranian government are actively targeting American water and energy providers. The attacks have targeted programmable logic controllers (PLCs), on internet-connected infrastructure with malware that enabled the hackers to manipulate data on targeted systems, “resulting in operational disruption and financial loss,” according to the advisory.

The notice, which was published amid ongoing hostilities between the US, Iran, and Israel, expands the number of impacted systems from just the Rockwell Automation PLC systems that Iran exploited earlier this year to also include Schneider Electric, Siemens, and that “potentially all internet exposed PLCs” may be impacted. Critical infrastructure operators are instructed to take action to protect their systems as, according to the advisory, the Iran-linked hackers are “conducting this activity to cause disruptive effects within the United States.”

Comments

Back to top

Join the discussion

Comments

Back to topTriangle

You Might Also Like

Lily Hay Newman is a senior writer at WIRED focused on information security, digital privacy, and hacking. She previously worked as a technology reporter at Slate, and was the staff writer for Future Tense, a publication and partnership between Slate, the New America Foundation, and Arizona State University. Her work ... Read More

Senior Writer

Dhruv Mehrotra is an investigative data reporter at WIRED, where he uses technology to find, build, and analyze datasets for accountability journalism. His reporting has examined surveillance, policing, data brokers, platforms, and the government agencies and companies that use them. Before joining WIRED, he worked at Bloomberg News, the Center for ... Read More

Senior Correspondent, Investigations

Topics security roundup hacking cybersecurity security Russia vulnerabilities artificial intelligence OpenAI

LastPass Users Had Their Data Stolen—Again

LastPass Users Had Their Data Stolen—Again

Plus: Former national security advisor John Bolton pleads guilty in classified-materials case, Microsoft helps take down major infostealer infrastructure, and more.

Lily Hay Newman

Your Period Tracker Is (Probably) Spying on You

Your Period Tracker Is (Probably) Spying on You

Plus: Russian cyberspies turn to infrastructure hacking, DHS repeatedly fails to realize it’d been hacked, a breach exposes an AI music generator’s scraping ways, and more.

Andy Greenberg

Prompt Injection Attacks Are Thwarting AI Hacking Agents

Prompt Injection Attacks Are Thwarting AI Hacking Agents

“Context bombing” tricks malicious AI agents into shutting down before they can do harm.

Dan Goodin, Ars Technica

AI Found a Root Bug in Linux That Everyone Missed for 15 Years

AI Found a Root Bug in Linux That Everyone Missed for 15 Years

Plus: The Pentagon is training amateurs to become part of its hacker army, a Flock license plate reader error led to cops surrounding a car reviewer, and more.

Dell Cameron

What Happens if China Hacks the US Water Supply? I Went to a Secret War Game to Find Out

What Happens if China Hacks the US Water Supply? I Went to a Secret War Game to Find Out

Burst water mains. Evacuated hospitals. In a closed-door simulation, insurers played out their response to a mass disruption by China’s Volt Typhoon hackers—and found a nightmare scenario.

Andy Greenberg

You Can Now Sound the Alarm on AI Behaving Badly

You Can Now Sound the Alarm on AI Behaving Badly

Are you worried your AI chatbot is trying to build a bomb or leak personal information about you? There’s a website for that.

Will Knight

Apple’s Hide My Email Service Fails to Hide Your Email

Apple’s Hide My Email Service Fails to Hide Your Email

Plus: Alleged Scattered Spider hacking member extradited, dozens of license plate reader errors, and Indian officials are concerned about WhatsApp’s username rollout.

Matt Burgess

The Pentagon Is Looking Into the Dialog Data Exposure for Unmasking National Security Officials

The Pentagon Is Looking Into the Dialog Data Exposure for Unmasking National Security Officials

Exposed records from the private group included the personal information of a senior White House intelligence official and an active-duty special operations officer.

Dell Cameron

Intel Officials Predict the Pentagon’s Bill for the Iran War Will Exceed $100 Billion

Intel Officials Predict the Pentagon’s Bill for the Iran War Will Exceed $100 Billion

The Trump administration has not disclosed its cost estimates for the Iran war.

Hugo Lowell

How People in China Keep Outsmarting Anthropic’s Geolocation Restrictions

How People in China Keep Outsmarting Anthropic’s Geolocation Restrictions

As Anthropic tightens restrictions on access to Claude in China, users keep finding new workarounds, from proxy services to fake identities sourced on Telegram.

Zeyi Yang

Apps Marketed to US Troops Are Shipping Chinese and Russian Code

Apps Marketed to US Troops Are Shipping Chinese and Russian Code

A first-of-its-kind analysis found more than one in eight apps built for US service members carried foreign code—some from firms in nations the Pentagon designates as adversaries.

Dell Cameron

Meta Contractors Posed as Teens to Prompt Rival Chatbots About Suicide, Sex, and Drugs

Meta Contractors Posed as Teens to Prompt Rival Chatbots About Suicide, Sex, and Drugs

Hundreds of contractors working on a project for Meta pretended to be kids in order to see how other chatbots like Gemini and ChatGPT would respond to high-risk subjects, WIRED found.

Dhruv Mehrotra

Read Original at WIRED