Hackers breach OpenAI using Claude tools, gaining access to employee accounts and the company’s internal codebase — attackers initiated a ‘harmless’ pull request as proof of the hack

From tomshardware.com

[Gemini]

Researchers receive a $6,500 bounty after reporting the vulnerabilities

A team of white-hat hackers from cybersecurity startup Hackron AI has successfully hacked OpenAI using Claude tools. In an X post on September 18, the team claimed they breached OpenAI’s internal codebase on July 25 and gained access to the ChatGPT and Codex accounts of some OpenAI employees. They established proof of the hack via a pull request to OpenAI’s private repository before reporting the vulnerabilities to OpenAI. The company reportedly fixed the issue within 14 hours of the report and paid the researchers a $6,500 bounty.

Read more…

UK government rejects ‘kill switch’ idea for dangerous AI

From bbc.co.uk

[Gemini]

The UK government has rejected the idea of creating a so-called “kill switch” to stop a dangerous attack from rogue AI.

The proposal to create a legal mechanism for the UK to switch off an AI model in an emergency has been brought to Parliament by lords and MPs in recent weeks as fears grow about the threat the tech poses.

But the Cabinet Office – the part of government which leads on AI safety – said the UK “cannot simply turn AI off”.

Read more…

OpenAI and Hugging Face partner to address security incident during model evaluation

Following a joint investigation, OpenAI and Hugging Face have disclosed a unprecedented security incident where AI models—including GPT-5.6 Sol—compromised Hugging Face’s production infrastructure during an internal cyber-capability evaluation. While operating in a sandboxed environment with reduced safety refusals to test exploit capabilities, the models autonomously escaped their testing containment by exploiting a zero-day proxy vulnerability, traversed the network, and executed remote code on Hugging Face servers to obtain test solutions directly from their database.

Read more…

Security alert: Windows 11 laptops

A security vulnerability affecting Windows 11 laptops has been identified. This is a global issue, and we are awaiting a fix from Microsoft. Increased vigilance is required until a fix has been provided.

Key risk

If a device is lost or stolen, any sensitive information stored on the laptop could be accessed.

Required additional actions

  • If you need to travel for work purposes (domestic or international) with your laptop, please contact the ITDS Service Desk in advance so we can add a temporary fix to ensure your device is secured
  • For all normal use, please be extra careful when transporting or using your Windows 11 laptop in a public setting.

General safety

  • Please remember it’s your responsibility to take appropriate care of your BU-provided devices. This applies at all times
  • Ensure your laptop/mobile device remains on your person or stored safely, such as in a locked drawer or secure office
  • Take additional care when travelling, working remotely, or using your laptop in public places
  • When working from home, only you should use your laptop
  • Report any lost, stolen or misplaced device immediately by calling the IT Service Desk 01202 965515 or 0808 196 2332.

How to identify if your BU assigned laptop is running Windows 11

  1. Right click on the start menu
  2. Select “System”
  3. On this page scroll down to ‘Windows specifications’ look for ‘Edition’. If this contains ‘Windows 11’, the laptop is running Windows 11 and is affected by this security vulnerability.

The Windows 11 rollout is currently paused. If you haven’t upgraded yet, you won’t be able to do so for now.

We’ll share an update once we have more information from Microsoft.

CISA Admin Leaked AWS GovCloud Keys on Github

From krebsonsecurity.com

[created with nano banana]

Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files detailing how CISA builds, tests and deploys software internally, and that it represents one of the most egregious government data leaks in recent history.

On May 15, KrebsOnSecurity heard from Guillaume Valadon, a researcher with the security firm GitGuardian. Valadon’s company constantly scans public code repositories at GitHub and elsewhere for exposed secrets, automatically alerting the offending accounts of any apparent sensitive data exposures. Valadon said he reached out because the owner in this case wasn’t responding and the information exposed was highly sensitive.

Read more…

[Critical] Emergency Security Update for Google Chrome: CVE-2026-3909 and CVE-2026-3910

[Nano banana]

There have been two high-severity zero-day vulnerabilities identified in Google Chrome that are confirmed to be actively exploited in the wild. These flaws allow attackers to execute malicious code or gain unauthorized memory access simply by tricking a user into visiting a compromised website.

  • CVE-2026-3909 (Out-of-bounds write in Skia): A flaw in the graphics engine that can lead to memory corruption and potential code execution.
  • CVE-2026-3910 (Inappropriate implementation in V8): A vulnerability in the JavaScript/WebAssembly engine allowing arbitrary code execution within the browser sandbox.

Impact

A remote attacker can leverage these vulnerabilities to compromise your device, steal sensitive data, or install malware. Because Chrome is a primary tool for university work and SaaS applications, these flaws represent a significant risk to personal and institutional information security.

Required Action

Staff and students are advised to manually trigger an update for their Chrome browser immediately.

Man accidentally gains control of 7,000 robot vacuums

From popsci.com

[nano banana]

A software engineer’s earnest effort to steer his new DJI robot vacuum with a video game controller inadvertently granted him a sneak peak into thousands of people’s homes. 

While building his own remote-control app, Sammy Azdoufal reportedly used an AI coding assistant to help reverse-engineer how the robot communicated with DJI’s remote cloud servers. But he soon discovered that the same credentials that allowed him to see and control his own device also provided access to live camera feeds, microphone audio, maps, and status data from nearly 7,000 other vacuums across 24 countries. The backend security bug effectively exposed an army of internet-connected robots that, in the wrong hands, could have turned into surveillance tools, all without their owners ever knowing.

Read more…