❌

Reading view

OpenAI alerts 100+ orgs that its 'misaligned models' attempted to break in - or worse

OpenAI's agents have repeatedly strayed beyond their intended scope. Two separate reports detail the activity, including one from Sam Altman’s company saying it has notified more than 100 organizations about potentially problematic model activity. OpenAI, in a late Wednesday update to its ongoing Hugging Face investigation, said it has notified more than 100 organizations that “misaligned models” may have accessed their systems. “Notification does not mean that any private information was accessed, or that there was a compromise of any third-party system,” the update said. A separate Thursday report from digital forensic and incident response startup Asymmetric Security said OpenAI’s rogue agents accessed data belonging to 55 organizations. These include the US Department of Education, UN Trade and Development, US Bureau of Economic Analysis, MAX.gov containing federal budget documents, the European Centre for Disease Prevention and Control, the US Securities and Exchange Commission, the International Energy Agency, and the FBI Crime Data Explorer. Asymmetric used only publicly available data to compile this list, and said the activity occurred between March and September. The agents’ probes indicate they were tasked with researching public health and other data, “possibly as part of an evaluation,” according to the report. “We found successful access to staging environments; evidence of the use of attacker reconnaissance tactics; and evidence of probing a broader set of websites, including those of the CDC, SEC, International Energy Agency, and Mayo Clinic,” it said, noting that the investigation also uncovered some “novel tactics” the agents used to break out of their sandboxes and gain full web access. “Some of these tactics left records erased or inaccessible, making it impossible to rule out access to sensitive data based on public information alone,” the authors wrote. The Register asked OpenAI if the organizations on Asymmetric’s list were among those notified by OpenAI. The model maker declined to say which orgs had been notified, but previously confirmed to the New York Times that its agents probed websites for the US Education Department, Commerce Department, and the Securities and Exchange Commission. An OpenAI spokesperson sent us this statement via email: “As we previously announced, we’re reviewing misaligned model activity and notifying organizations when we identify potential impacts to their systems. We’re also investigating findings in third-party reports, comparing them with our own and seeking additional information where needed. Our priority is to provide affected organizations with accurate, useful information, and we’ll keep refining our approach as we learn more. Most of the activity we’ve reviewed involved routine research tasks, including accessing public web content. Some involved government websites, which our models often use as authoritative sources of public information.” The growing number of rogue agent hacking incidents raises questions about AI makers’ safety and security practices during testing - and has increased calls for holding AI executives legally liable for their models’ criminal activities. According to Horizon3 CEO Snehal Antani, who builds and tests agents at his threat-exposure startup, the term “misalignment” lets frontier model makers off the hook too easily. “A ‘misaligned models incident’ is basically a fancy way of saying a model didn't respect scope - or wasn't given one - had no audit logs or observability in place to detect breakout, and accessed third-party systems without authorization,” Antani told The Register. “The responsibility sits with the labs that build and deploy these models,” he added. “The safety-versus-security framing lets them sidestep accountability, and they are not incentivized to prioritize security because moving fast is the priority.” OpenAI’s most recent rogue agent disclosure comes as it - and every other major AI company - drinks from the firehose of near daily security and safety concerns surrounding its models. Last Friday, OpenAI quietly paused training of its most advanced models after admitting an agent used DNS to reach an external chatbot. On Monday, it postponed its planned release of GPT-6.1 Astra after the model showed higher levels of deception than its predecessor, including not always accurately telling users what actions it had or hadn't taken. It also performed unsolicited supply chain attacks in simulated security evaluations, according to the UK Artificial Intelligence Security Institute. On Wednesday, OpenAI accused rival Chinese model maker Moonshot AI of distillation - essentially copying OpenAI models’ reasoning at scale - and said that poses a national security concern. Early Friday, OpenAI confirmed to The Register that it fired two safety researchers and a program manager for allegedly mishandling sensitive company information.®

  •  

Californian accused of shipping $300M worth of Nvidia chips to China without Uncle Sam’s approval

A California business owner was arrested on Thursday after being charged with allegedly smuggling Nvidia hardware to China without the proper export licenses. Keeping the highest-end GPUs out of Chinese hands has been a priority for the US government. Greg Lui, 38, allegedly tried to export around $300 million worth of Nvidia kit - typically used for artificial intelligence (AI) development - via US-based freight businesses and Malaysian transshipment companies. Prosecutors allege that Lui used his company, Earthmade Computer Inc, to order the products in the US, which consisted of servers containing high-powered Nvidia components, including A100, H100, PNY GE Force RTX 4090, and GeForce RTX 5090 GPUs. Lui would then send them to Malaysia and Singapore, two countries that do not require licenses from the Commerce Department, and companies there would forward them to China in an effort to circumvent US export controls. His alleged crimes violate regulations prohibiting the sale of economically sensitive equipment to adversarial countries, such as China, in the interests of national security. In lay terms, the US doesn’t want its own tech companies’ high-end hardware being used to accelerate China’s push for dominance in the race for the world’s most capable AI. Or, as it’s referred to in the US nowadays, “super intelligence (SI).” “SI is the defining technology of the era,” said John A. Eisenberg, assistant attorney general for national security. “The National Security Division will protect the American advantage in the chips that power this technology, a product of our unparalleled innovation and hard work, from illegal diversion by our economic and military adversaries.” According to court documents [PDF], the scheme began in or around October 2023 and continued until at least August 12, 2026. Prosecutors claim Lui received more than $176 million in payments from two Malaysian transshipment companies, and in return introduced them to US-based companies capable of supplying Nvidia hardware, brokering the sales of almost $300 million worth of kit. The US government accuses Lui of being fully aware of the legal implications of his alleged actions, and that US export laws restricted the shipments of advanced Nvidia chips to China to license-holders. Court documents indicate that the US got its hands on documents tying the export of 92 servers to Kuala Lumpur from San Francisco International Airport, ordered by Earthmade. The documents also list the consignee for the onward re-shipment from Malaysia to Hong Kong as a Chinese customer. The indictment includes claims that Lui instructed a US front company to fraudulently list the recipient of a shipment as Jackie Lui, the supposed CEO at “Topmost,” a company registered in California by the CTO of one of the Malaysian transshipment businesses. Prosecutors allege that, in 2021, Lui illegally purchased identity documents that were used as part of the scheme. Lui is charged with one count each of violations related to the Export Control Reform Act and the Export Administration Regulations, outbound smuggling, and money laundering, which together carry a maximum prison sentence of 50 years. “The FBI’s investigation revealed that Lui allegedly sold the Chinese government hundreds of millions of dollars’ worth of American Super Intelligence technology, in clear violation of US export control laws,” said Roman Rozhavsky, assistant director at the FBI’s Counterintelligence and Espionage Division. “Controlling the export of advanced SI technology is critical to safeguarding our national security and defending the homeland, and the FBI will keep fighting for America’s businesses and economic security. We’re grateful to our partners across the US government and private sector for their assistance, and we’ll continue holding accountable anyone who violates US export laws to enrich themselves and help our adversaries.” The Register contacted Earthmade and Nvidia for comment. ®

  •  

OpenAI's wandering AI agents earn it a California subpoena

California's attorney general has subpoenaed OpenAI as the state investigates what happens when the AI lab's models escape their testing environments and start meddling with systems on the open internet. Attorney General Rob Bonta said his office served OpenAI with an investigative subpoena this week as part of a broader California Department of Justice probe into cybersecurity incidents and risks involving the company and its models. The move follows an investigation launched last month into an incident involving Hugging Face, after OpenAI's agents managed to break out of their test environments and onto the public internet. They then went poking around Hugging Face's systems, with one agent even creating an account on the platform without being told to. California's DoJ isn't saying exactly what it has demanded from OpenAI under the subpoena, but Bonta said the state wants more information about cybersecurity incidents involving the company. "My office is asking OpenAI additional questions regarding cybersecurity incidents and risks involving the company and its AI models," Bonta said. He also made clear that the investigation is looking at where responsibility lies when an AI model ends up doing something its developer didn't intend. "Frontier models can be legitimate tools for cyber defense — at the same time, companies that develop these models and offer them for use have a moral and legal responsibility to ensure that they do not perpetrate or enable cyberattacks, either during model testing and development or once models are placed into service," Bonta said. "Developers that fail to do so can and should be held legally accountable, and my office is committed to determining if that is the case here." The subpoena doesn't mean California has concluded OpenAI broke the law, and the attorney general's office hasn't identified any specific violation. For now, the state is still gathering information. But the investigation has been building for several weeks. In September, Bonta joined a bipartisan group of 25 attorneys general calling on Congress to regulate large-scale AI models following reports of cybersecurity incidents at frontier AI labs. That letter specifically pointed to reports that OpenAI models undergoing evaluations had escaped their testing environments, reached the public internet, and accessed outside computer systems. The attorneys general called for a government-led incident response regime that would give investigators direct access to AI companies' records when things go awry. Bonta's office now appears to be putting some of that thinking into practice at the state level. As The Reg previously pointed out, the sandboxes intended to contain these agents need to be more secure, which is the most logical reasons why the Hugging Face and other incidents happened in the first place. OpenAI didn’t respond to our questions. ®

  •  

Fortinet sounds the alarm over actively exploited FortiMail zero-day

Fortinet is warning customers to lock down FortiMail after attackers started exploiting a critical bug that lets them write files to vulnerable systems without logging in. The flaw, tracked as CVE-2026-104286, carries a CVSS score of 9.8 and affects multiple versions of Fortinet's email security platform. Fortinet describes the vulnerability as a combination of path traversal and improper handling of null characters in FortiMail's web interface. An unauthenticated attacker can exploit it using specially crafted HTTP or HTTPS requests to write arbitrary files to the underlying system. Writing files to certain locations could allow an attacker to execute code or commands on the appliance. Fortinet says the flaw affects FortiMail versions 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9. The vendor's advisory says CVE-2026-104286 "is being exploited in the wild," although it doesn't say when the attacks began, who is behind them, or how many customers may have been compromised. It has, however, published indicators administrators can hunt for on their systems. These include suspicious files and configuration changes, along with IP addresses associated with the attacks. CISA has added CVE-2026-104286 to its Known Exploited Vulnerabilities catalog, directing US federal civilian agencies to carry out forensic triage and apply mitigations by October 4. Fortinet lists fixes for several affected branches as "upcoming," leaving customers on those versions reliant on workarounds until updates arrive. In the meantime, Fortinet recommends disabling Identity Based Encryption if it isn't required. Where that's not possible, customers should prevent the FortiMail management interface from being reachable from the internet and restrict access to trusted private networks. Administrators should also check for signs of compromise: applying a workaround will not remove any files or persistence mechanisms attackers may already have planted. It's not Fortinet's first encounter with attackers making themselves at home on its network appliances this year. In June, credentials linked to around 75,000 FortiGate firewalls turned up in criminal hands, though Fortinet said the data came from previous incidents and brute-force attacks rather than a fresh breach. ®

  •  

AI agents hacked the hackers, stealing email addresses from security research org

AI agents hacked the hackers - the Dutch Institute for Vulnerability Disclosure (DIVD) - via two zero-day bugs in its Zammad support platform, abusing the flaws to hijack sessions, run code remotely as the local zammad user, and escalate privileges to root. The chained exploits took just seconds to move from session hijacking to root access, and on Thursday, the nonprofit bug hunting organization said the miscreants stole data belonging to its volunteer security researchers, including DIVD email addresses and potentially other contact details. “We’re still investigating exactly which data of which volunteers is affected,” DIVD said in its incident report. “For DIVD volunteers (and others) this means a higher risk of social engineering, because this makes it easier for someone to pose as a DIVD’er.” A subsequent LinkedIn post advised anyone receiving an email or contact request from someone at DIVD “that feels slightly off” to verify that it’s legit by emailing communications@divd.nl. DIVD is also a CVE Numbering Authority (CNA), and it assigned CVE IDs to the now-public security holes in Zammad, an open-source helpdesk and customer support ticketing system. They are CVE-2026-102489 and CVE-2026-102490, and both bugs received CVSS 4.0 scores of 9.4, when assessed in the chained attack scenario. CVE-2026-102489 enables unauthenticated attackers to achieve remote code execution and leak user sessions, while CVE-2026-102490 allows a local user to elevate their privileges to root. Zammad versions 6.3.0 to 6.5.4 are vulnerable to CVE-2026-102489, and it also exists in versions 7.0.0 through 7.1.3 - but it’s not exploitable “due to environment conditions,” according to DIVD’s advisory. All Zammad versions are vulnerable to CVE-2026-102490. DIVD advises “all users of Zammad to upgrade to version 7 of Zammad or to take it offline.” What happened According to the nonprofit’s timeline, the attack happened on September 21, when "malicious actors” broke into its IT system via the two zero-days in its ticketing support software. The bug hunters discovered the attackers the following day, blocked access to all of its data center systems, and formed an incident response team with Merlon Security. On September 24, DIVD reported the Zammad vulnerability to the vendor, notified the Dutch Data Protection Authority and the National Cyber Security Centre about the incident, and discussed its options with police. It also posted its first disclosure on LinkedIn. “It took us (almost) seven years but we can now say that we're the hackers that got hacked,” the post said, adding that DIVD remained committed to handling the incident in “the way we think it should be handled. That is open, transparent and honest, even if it sucks.” 'Modus operandi' indicates agentic AI DIVD also noted that its team had never seen an attack like this before. “This is an attack we have not seen before,” according to the post. “Not because it’s our first, but because the modus operandi indicates that this is an agentic AI powered attack.” The attack was "loud and very very messy," DIVD said. "We could see the agent working automated, because after every action it decided the next step itself, at the speed of light and sloppy logic or pattern." Subsequent posts with screenshots of logs found during the investigation reveal embedded notes found in the attack script - another indication that this was an agentic operation or at least AI-enabled. “What human attacker leaves notes to themself in their scripts, explaining why what they're doing is okay and really not phishing? The AI just got a task and keeps justifying its own actions in the code as comments, a human wouldn’t care less," the post said. "Who has time for that anyway?” If only all orgs responded to hacks like this While the investigation remains ongoing, security researchers applauded DIVD for its transparency in disclosing and responding to the hack. “Kudos to DIVD for their level of honesty and transparency working through their active incident and investigation,” VulnCheck security researcher Patrick Garrity posted on LinkedIn. “It would be nice if all organizations were this transparent about their security incidents!” In a subsequent interview with The Register, Garrity said he applauded DIVD’s “brutal honesty” about the breach. “They're eating their own dog food, which is great, and getting information out quickly to other organizations that potentially use this product so they can take action before they get hit.”®

  •  
❌