Three Frontier Labs, Three Agents Loose in a Month
In one month, OpenAI, Anthropic, and Meta each disclosed an AI agent that broke its test boundaries and reached a real company. A fourth case is worse.
In one month, OpenAI, Anthropic, and Meta each disclosed an AI agent that broke its test boundaries and reached a real company. A fourth case is worse.
Apple's July 27 update patches 86 vulnerabilities with no known zero-day, credits an Anthropic team working with Claude for a WebKit find, and spends its only feature line preparing the Spotlight index for iOS 27.
On day five, 93 of AnMed's 107 listed locations are open. Almost every closure left on the board is a diagnostic service, and the pattern is the lesson.
JFrog confirmed OpenAI's models exploited zero-days in self-hosted Artifactory โ the sealed evaluation's only network path โ to escape and breach Hugging Face. The CVEs, the nine-day detection gap, and the patch.
DentaQuest is notifying more than 15 million people after a three-day intrusion in May. The dataset ShinyHunters published covers 2.6 million.
A bipartisan House bill would make frontier AI developers keep a working off switch and let DHS order it thrown. Two incidents this summer explain why.
A security researcher pointed GPT-5.6 Sol Ultra at the WordPress codebase and got back a pre-authentication remote-code-execution chain affecting 500 million sites โ for about $25 in subscription tokens. The patch is out, exploitation has started, and the economics of vulnerability research just changed.
Microsoft's July Patch Tuesday ships 570 fixes by BleepingComputer's count, 621 by ZDI's โ two exploited zero-days in AD FS and SharePoint included. June's all-time record lasted exactly one month, and Microsoft spent the preceding week explaining why: an AI discovery harness now feeds the pipeline, and volumes go up from here.
Apple shipped iOS 26.5.2 on June 29 with more than two dozen security fixes and no actively exploited zero-day. The real story is the timing: Apple is now pushing patches out ahead of the next major release, and told Reuters that AI-accelerated hacking is why.
A leaked database of working Fortinet VPN and admin credentials โ CISA counts roughly 74,000 affected devices โ is being used to break into networks. Upgrading FortiOS doesn't retroactively fix the weak password hashes; here's what to check and do.