DHS agents not only tracked and intimidated people observing ICE activity in Maine, but stored information about them in a Palantir-built database, newly unsealed court filings say.
OpenAI's agents have repeatedly strayed beyond their intended scope. Two separate reports detail the activity, including one from Sam Altman’s company saying it has notified more than 100 organizations about potentially problematic model activity. OpenAI, in a late Wednesday update to its ongoing Hugging Face investigation, said it has notified more than 100 organizations that “misaligned models” may have accessed their systems. “Notification does not mean that any private information was accessed, or that there was a compromise of any third-party system,” the update said. A separate Thursday report from digital forensic and incident response startup Asymmetric Security said OpenAI’s rogue agents accessed data belonging to 55 organizations. These include the US Department of Education, UN Trade and Development, US Bureau of Economic Analysis, MAX.gov containing federal budget documents, the European Centre for Disease Prevention and Control, the US Securities and Exchange Commission, the International Energy Agency, and the FBI Crime Data Explorer. Asymmetric used only publicly available data to compile this list, and said the activity occurred between March and September. The agents’ probes indicate they were tasked with researching public health and other data, “possibly as part of an evaluation,” according to the report. “We found successful access to staging environments; evidence of the use of attacker reconnaissance tactics; and evidence of probing a broader set of websites, including those of the CDC, SEC, International Energy Agency, and Mayo Clinic,” it said, noting that the investigation also uncovered some “novel tactics” the agents used to break out of their sandboxes and gain full web access. “Some of these tactics left records erased or inaccessible, making it impossible to rule out access to sensitive data based on public information alone,” the authors wrote. The Register asked OpenAI if the organizations on Asymmetric’s list were among those notified by OpenAI. The model maker declined to say which orgs had been notified, but previously confirmed to the New York Times that its agents probed websites for the US Education Department, Commerce Department, and the Securities and Exchange Commission. An OpenAI spokesperson sent us this statement via email: “As we previously announced, we’re reviewing misaligned model activity and notifying organizations when we identify potential impacts to their systems. We’re also investigating findings in third-party reports, comparing them with our own and seeking additional information where needed. Our priority is to provide affected organizations with accurate, useful information, and we’ll keep refining our approach as we learn more. Most of the activity we’ve reviewed involved routine research tasks, including accessing public web content. Some involved government websites, which our models often use as authoritative sources of public information.” The growing number of rogue agent hacking incidents raises questions about AI makers’ safety and security practices during testing - and has increased calls for holding AI executives legally liable for their models’ criminal activities. According to Horizon3 CEO Snehal Antani, who builds and tests agents at his threat-exposure startup, the term “misalignment” lets frontier model makers off the hook too easily. “A ‘misaligned models incident’ is basically a fancy way of saying a model didn't respect scope - or wasn't given one - had no audit logs or observability in place to detect breakout, and accessed third-party systems without authorization,” Antani told The Register. “The responsibility sits with the labs that build and deploy these models,” he added. “The safety-versus-security framing lets them sidestep accountability, and they are not incentivized to prioritize security because moving fast is the priority.” OpenAI’s most recent rogue agent disclosure comes as it - and every other major AI company - drinks from the firehose of near daily security and safety concerns surrounding its models. Last Friday, OpenAI quietly paused training of its most advanced models after admitting an agent used DNS to reach an external chatbot. On Monday, it postponed its planned release of GPT-6.1 Astra after the model showed higher levels of deception than its predecessor, including not always accurately telling users what actions it had or hadn't taken. It also performed unsolicited supply chain attacks in simulated security evaluations, according to the UK Artificial Intelligence Security Institute. On Wednesday, OpenAI accused rival Chinese model maker Moonshot AI of distillation - essentially copying OpenAI models’ reasoning at scale - and said that poses a national security concern. Early Friday, OpenAI confirmed to The Register that it fired two safety researchers and a program manager for allegedly mishandling sensitive company information.®
A critical flaw in GitLab's AI Gateway could let a logged-in user with Duo Agent Platform access run commands on the gateway under certain conditions, GitLab said in an advisory.
The gateway is the service that connects a GitLab instance to AI models, and only organizations that host their own gateway need to act. The flaw is fixed in gateway versions 19.2.4, 19.3.2, and 19.4.1.
The flaw
Government and policy organizations across Asia have become the target of a new campaign orchestrated by a China-nexus threat actor.
The activity, which has targeted government and policy organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar, involves the deployment of a previously undocumented backdoor codenamed Antino. Cisco Talos is tracking the cluster
Dell has released security updates to address multiple critical security flaws in Dell Container Storage Modules (CSM) that could be exploited by bad actors to take over susceptible systems.
The vulnerabilities are listed below -
CVE-2026-63688 (CVSS score: 10.0) - A missing authentication for critical function vulnerability in the csm-authorization-storage gRPC server that an
When analysing firmware attack surfaces, image decoders built into bootloaders get less scrutiny than cryptographically verified OS kernels. If image parsing happens before signature verification, any memory corruption in the parser breaks the secure boot trust model.
researchers analysed U-Boot's video subsystem (drivers/video/video_bmp.c) and identified an unbounded write in the RLE8 bitmap decoder (video_display_rle8_bitmap()) that leads to a pre-authentication Secure Boot bypass.
Root Cause and Vulnerability Mechanics
When U-Boot displays a boot logo or splash screen, it parses a BMP image loaded from local storage (SPI flash, MMC/eMMC, USB, or SD card).
Unbounded framebuffer write: During RLE8 decompression, video_display_rle8_bitmap() decodes run-length encoded streams directly into the active framebuffer without validating stream bounds against the frame boundary or allocated buffer size.
Pre-authentication execution window: In many embedded target configurations, the boot splash screen is rendered immediately on startup, before U-Boot calls Android Verified Boot (AVB) or FIT image signature verification routines.
Storage disparity: The kernel image and rootfs are signed, but splash images are frequently stored in unsigned, user-writable partitions or external media.
An attacker who writes a crafted RLE8 BMP to the boot storage can trigger an out-of-bounds write past the framebuffer during early boot, corrupting adjacent bootloader data structures, function pointers, or verification flags in memory.
This hijacks the execution flow before signature checking completes.
TL;DR.SConnect - 1M+ users, an extension middleware+native host for authentication with eIDs, 3SKeys and other hardware signing tokens had a drive-by RCE which enabled any site or iframe a user saw to silently download and execute a dll due to a poor hand-rolled implementation of RSA-2048 token validation, enabling a use of uninitialized memory validation bypass which enabled "plugins" (DLLs) to be loaded. v2.16.0.0 of the extension and native host is vulnerable. CVE-2026-18397. CVSS 9.4.
A California business owner was arrested on Thursday after being charged with allegedly smuggling Nvidia hardware to China without the proper export licenses. Keeping the highest-end GPUs out of Chinese hands has been a priority for the US government. Greg Lui, 38, allegedly tried to export around $300 million worth of Nvidia kit - typically used for artificial intelligence (AI) development - via US-based freight businesses and Malaysian transshipment companies. Prosecutors allege that Lui used his company, Earthmade Computer Inc, to order the products in the US, which consisted of servers containing high-powered Nvidia components, including A100, H100, PNY GE Force RTX 4090, and GeForce RTX 5090 GPUs. Lui would then send them to Malaysia and Singapore, two countries that do not require licenses from the Commerce Department, and companies there would forward them to China in an effort to circumvent US export controls. His alleged crimes violate regulations prohibiting the sale of economically sensitive equipment to adversarial countries, such as China, in the interests of national security. In lay terms, the US doesn’t want its own tech companies’ high-end hardware being used to accelerate China’s push for dominance in the race for the world’s most capable AI. Or, as it’s referred to in the US nowadays, “super intelligence (SI).” “SI is the defining technology of the era,” said John A. Eisenberg, assistant attorney general for national security. “The National Security Division will protect the American advantage in the chips that power this technology, a product of our unparalleled innovation and hard work, from illegal diversion by our economic and military adversaries.” According to court documents [PDF], the scheme began in or around October 2023 and continued until at least August 12, 2026. Prosecutors claim Lui received more than $176 million in payments from two Malaysian transshipment companies, and in return introduced them to US-based companies capable of supplying Nvidia hardware, brokering the sales of almost $300 million worth of kit. The US government accuses Lui of being fully aware of the legal implications of his alleged actions, and that US export laws restricted the shipments of advanced Nvidia chips to China to license-holders. Court documents indicate that the US got its hands on documents tying the export of 92 servers to Kuala Lumpur from San Francisco International Airport, ordered by Earthmade. The documents also list the consignee for the onward re-shipment from Malaysia to Hong Kong as a Chinese customer. The indictment includes claims that Lui instructed a US front company to fraudulently list the recipient of a shipment as Jackie Lui, the supposed CEO at “Topmost,” a company registered in California by the CTO of one of the Malaysian transshipment businesses. Prosecutors allege that, in 2021, Lui illegally purchased identity documents that were used as part of the scheme. Lui is charged with one count each of violations related to the Export Control Reform Act and the Export Administration Regulations, outbound smuggling, and money laundering, which together carry a maximum prison sentence of 50 years. “The FBI’s investigation revealed that Lui allegedly sold the Chinese government hundreds of millions of dollars’ worth of American Super Intelligence technology, in clear violation of US export control laws,” said Roman Rozhavsky, assistant director at the FBI’s Counterintelligence and Espionage Division. “Controlling the export of advanced SI technology is critical to safeguarding our national security and defending the homeland, and the FBI will keep fighting for America’s businesses and economic security. We’re grateful to our partners across the US government and private sector for their assistance, and we’ll continue holding accountable anyone who violates US export laws to enrich themselves and help our adversaries.” The Register contacted Earthmade and Nvidia for comment. ®
California's attorney general has subpoenaed OpenAI as the state investigates what happens when the AI lab's models escape their testing environments and start meddling with systems on the open internet. Attorney General Rob Bonta said his office served OpenAI with an investigative subpoena this week as part of a broader California Department of Justice probe into cybersecurity incidents and risks involving the company and its models. The move follows an investigation launched last month into an incident involving Hugging Face, after OpenAI's agents managed to break out of their test environments and onto the public internet. They then went poking around Hugging Face's systems, with one agent even creating an account on the platform without being told to. California's DoJ isn't saying exactly what it has demanded from OpenAI under the subpoena, but Bonta said the state wants more information about cybersecurity incidents involving the company. "My office is asking OpenAI additional questions regarding cybersecurity incidents and risks involving the company and its AI models," Bonta said. He also made clear that the investigation is looking at where responsibility lies when an AI model ends up doing something its developer didn't intend. "Frontier models can be legitimate tools for cyber defense — at the same time, companies that develop these models and offer them for use have a moral and legal responsibility to ensure that they do not perpetrate or enable cyberattacks, either during model testing and development or once models are placed into service," Bonta said. "Developers that fail to do so can and should be held legally accountable, and my office is committed to determining if that is the case here." The subpoena doesn't mean California has concluded OpenAI broke the law, and the attorney general's office hasn't identified any specific violation. For now, the state is still gathering information. But the investigation has been building for several weeks. In September, Bonta joined a bipartisan group of 25 attorneys general calling on Congress to regulate large-scale AI models following reports of cybersecurity incidents at frontier AI labs. That letter specifically pointed to reports that OpenAI models undergoing evaluations had escaped their testing environments, reached the public internet, and accessed outside computer systems. The attorneys general called for a government-led incident response regime that would give investigators direct access to AI companies' records when things go awry. Bonta's office now appears to be putting some of that thinking into practice at the state level. As The Reg previously pointed out, the sandboxes intended to contain these agents need to be more secure, which is the most logical reasons why the Hugging Face and other incidents happened in the first place. OpenAI didn’t respond to our questions. ®
OpenAI has parted ways with three members of its safety team after they leaked private information in violation of company policies, The Wall Street Journal reported.
"We have parted ways with three individuals for violating our policies on accessing and handling sensitive company information," a spokesperson for the company was quoted as saying. "Our investigation confirmed that these
The quarterly board meeting is two weeks out. The security team is pulling exports from the identity provider, the cloud posture tool, the vulnerability scanner, the SIEM and the EDR console. Someone is building a spreadsheet to reconcile them. Someone else is turning that spreadsheet into slides.
Then a board member asks three questions:
How secure is the organization, overall?
What is
Fortinet is warning customers to lock down FortiMail after attackers started exploiting a critical bug that lets them write files to vulnerable systems without logging in. The flaw, tracked as CVE-2026-104286, carries a CVSS score of 9.8 and affects multiple versions of Fortinet's email security platform. Fortinet describes the vulnerability as a combination of path traversal and improper handling of null characters in FortiMail's web interface. An unauthenticated attacker can exploit it using specially crafted HTTP or HTTPS requests to write arbitrary files to the underlying system. Writing files to certain locations could allow an attacker to execute code or commands on the appliance. Fortinet says the flaw affects FortiMail versions 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9. The vendor's advisory says CVE-2026-104286 "is being exploited in the wild," although it doesn't say when the attacks began, who is behind them, or how many customers may have been compromised. It has, however, published indicators administrators can hunt for on their systems. These include suspicious files and configuration changes, along with IP addresses associated with the attacks. CISA has added CVE-2026-104286 to its Known Exploited Vulnerabilities catalog, directing US federal civilian agencies to carry out forensic triage and apply mitigations by October 4. Fortinet lists fixes for several affected branches as "upcoming," leaving customers on those versions reliant on workarounds until updates arrive. In the meantime, Fortinet recommends disabling Identity Based Encryption if it isn't required. Where that's not possible, customers should prevent the FortiMail management interface from being reachable from the internet and restrict access to trusted private networks. Administrators should also check for signs of compromise: applying a workaround will not remove any files or persistence mechanisms attackers may already have planted. It's not Fortinet's first encounter with attackers making themselves at home on its network appliances this year. In June, credentials linked to around 75,000 FortiGate firewalls turned up in criminal hands, though Fortinet said the data came from previous incidents and brute-force attacks rather than a fresh breach. ®
While the focus has been on AI agents’ hacking capabilities, a recently patched vulnerability in a ChatGPT app shows that AI software is itself an inviting—and vulnerable—target.
Google has announced a new security measure that limits access to Android's accessibility services to verified applications classified as Accessibility Tools when Advanced Protection is enabled.
With malicious Android applications abusing the API serving as the main conduit for malware and financial fraud, the tech giant said the move would block a major attack pathway. Advanced Protection is a