TechLetters ☕️ Anthropic and OpenAI release rogue AI agents. Hugging Face breach runs 17,600 actions. Claude hacks real orgs. Russian Wi-Fi traps travelers. AI eats books.
Security
AI agent that escaped OpenAI’s sandbox and hacked into Hugging Face carried out a 4.5-day autonomous intrusion involving about 17,600 actions. It gained arbitrary code execution in an external sandbox whose jobs already ran as root and used it as a launchpad, exploited two dataset-processing flaws, reached node root, gained cluster-admin access across multiple clusters, created a self-respawning fleet on 11 nodes, created a custom C2 protocol, stole secrets, joined the corporate mesh network and obtained source-control write access. When channels were blocked, it rebuilt tooling, changed egress paths, encoded payloads and reused public services and datasets for command-and-control. The AI agent behaved as a persistent, adaptive cyber operator and showed how thousands of low-signal attempts can overwhelm conventional defence. “the volume and cadence of the actions were far beyond what an operator could sustain by hand”. OpenAI AI agent that escaped the sandbox also broke into a customer of Modal, exploiting an unauthenticated code-execution endpoint a s a launchpad. Modal itself was not compromised. Hugging Face was unable to use american frontier AI labs because they refused to help. So Nvidia’s GLM-5.2-NVFP4 was used instead and this sufficed.
https://huggingface.co/blog/agent-intrusion-technical-timeline
Anthropic’s AI agents also reached the open internet from evaluation environments that were supposed to be sealed off and hacked three real organizations during CTF tests. One Claude model kept attacking after recognising that it was likely inside a production system. Another published a malicious package to PyPI Python package repository, where it was downloaded and executed on 15 real machines, then used credentials stolen from a security scanner to access further infrastructure. A third scanned ~9000 targets, picked one, and compromised it using leaked credentials and SQL injection, then stopped. The cause was a misconfigured evaluation environment with live internet access.
Going on vacation or a conference? Russian state cyberattacks are targeting travelers through the hotel, airport, and event Wi-Fi networks. The actor has been compromising captive portals, the login pages that appear before a device can access guest Wi-Fi. By manipulating DNS and HTTP traffic, the attackers can redirect users to infrastructure they control while making the experience look like a normal connectivity check, browser update, or a sign-in. The campaign combines network interception, phishing, malware delivery, and cloud-account theft.. The main access trojan can log keystrokes, monitor the clipboard, capture screenshots, record audio and video, steal browser credentials, exfiltrate data, and more. There are more such tools. The campaign can be tailored by the attackers. The result could be account takeover, identity theft, covert surveillance, or loss of data. For an employer it may be a data breach. The real targets may likely be business travelers, diplomats, and other high-value users. Defence must assume public and hospitality Wi-Fi as hostile infrastructure. Prefer a mobile hotspot and cellular data, or a travel router. Never install software, certificates, “drivers", or browser updates offered by a captive portal. https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/
Privacy
Technology Policy
Other
Kimi K3 open weights model have some impressive cybersecurity capabilities. It reportedly found 16 previously unknown vulnerabilities, including two serious Linux kernel bugs. It can also help in chip design. "in our early experiments with container-based sandbox runtimes, we observed several kernel panics and deadlocks caused by unintended agent operations" https://github.com/MoonshotAI/Kimi-K3/blob/main/k3_tech_report.pdf
We have grown used to the idea that training AI requires enormous amounts of data, preferably everyone’s data, all of it, and without consent. But what about physically destroying books to train AI https://storage.courtlistener.com/recap/gov.uscourts.cand.434709/gov.uscourts.cand.434709.231.0_1.pdf https://arstechnica.com/ai/2025/06/anthropic-destroyed-millions-of-print-books-to-build-its-ai-models/
In case you feel it's worth it to forward this content further:
Subscribed
If you’d like to share:

