Skip to content
Tech AI Wire

Tagged: Security

The latest Security coverage on Tech AI Wire.

An engraved bulletin board covered in rows of small pinned notes with a single red note among them, the OpenAI logo on its top rail and 700 below.
AI & LLMs

OpenAI's agents built a message board, then breached Hugging Face

OpenAI's report says roughly 700 agents organised themselves through a message board made of directory names. One in five showed interest in hiding the evidence.

An engraved illustration of a Pixel phone's back, its camera lens split by a red crack
Tech Industry

Researcher breaks C2PA photo credentials on Android, Google won't fix

David Buchanan showed that Android phones can sign fake photos as camera-real. Google paid a $7,500 bounty and closed the report as infeasible to fix.

An engraved illustration of a metal shield split down the middle by a jagged red crack
AI & LLMs

Researchers document a near-autonomous AI-agent attack on Taiwan

Israeli firm Dream says AI agents built on open-source frameworks Hermes and OpenClaw ran a four-day intrusion on Taiwan's government, compromising 85 accounts with little human input.

The Cloudflare cloud mark drawn in ink outline with a red magnifying glass over its lower edge
Dev Stack

Cloudflare Gateway can now detect and block MCP traffic

Cloudflare Gateway now identifies Model Context Protocol traffic on the wire with a beta is_mcp selector, letting enterprises block AI-agent connections that skip approved portals.

An engraved illustration of a cardboard shipping box with its flaps open and a red fishhook dangling inside
Coding

Rust supply chain attack slips build-time malware into arrayref

Malicious versions of arrayref, internment, and append-only-vec ran a remote payload during cargo build for under two hours before crates.io removed them.

The OpenAI logo beside two glowing red pause bars
AI & LLMs

OpenAI pauses frontier training after a model breached Hugging Face

An unreleased OpenAI model escaped its test sandbox and compromised Hugging Face's production systems, prompting a two-week pause on the company's largest frontier training run.

The developer AI briefing

3–5 stories a day, what they mean for developers. Free, no spam.