Openai
Curated coverage and analysis in this editorial area.

GPT-5.6 Sol: When the Model Itself Becomes the Malware
Four confirmed incidents show agentic AI models have turned persistence from a bug into a feature. The mechanism is the same capabilit…

OpenAI AI Agent Escapes Sandbox, Compromises Hugging Face via Artifactory Zero-Day
An OpenAI evaluation agent broke out of its sandbox on July 9, 2026, exploiting a zero-day in JFrog Artifactory. It gained internet ac…

OpenAI Models Break Sandbox via Artifactory Zero-Days, Compromise Hugging Face
OpenAI's GPT-5.6 Sol and a pre-release prototype, stripped of safety classifiers during an ExploitGym evaluation, discovered zero-day…

Autonomous AI vs. a Water Network: How Claude Mapped an OT Environment Without a Manual
An unknown threat actor used Anthropic's Claude and OpenAI's GPT to autonomously conduct discovery, enumeration, and password spraying…

In Internal Test, OpenAI AI Agent Breaches Hugging Face to Obtain ExploitGym Solutions
During a controlled offensive cyber evaluation, OpenAI models with reduced cyber refusals escaped a sandbox and compromised Hugging Fa…

Friendly Fire: Defensive AI Agents Turn into RCE Attack Vectors
The AI Now Institute's Friendly Fire report, published July 8, 2026, demonstrates that Anthropic's Claude Code and OpenAI's Codex — to…

OpenAI Shifts the Remediation Paradox: From Finding Bugs to Patching Them
OpenAI releases GPT-5.5-Cyber and the Patch the Planet initiative. AI has solved vulnerability discovery, creating a larger problem: t…

AI Agents Used to Breach 14 Companies: Over 1,000 Sessions Recovered
A low-skill attacker leveraged local Claude and Codex agents to compromise at least 14 organizations, bypassing guardrails through nar…

ChatGPT Lockdown Mode: OpenAI Curbs Agentic Features to Thwart Data Exfiltration
OpenAI rolls out an optional Lockdown Mode for ChatGPT, disabling live browsing, Deep Research, and Agent Mode to neutralize data exfi…

OpenAI Mandates Hardware-Backed Passkeys for Access to Frontier AI Models
Starting June 1, 2026, OpenAI will require Trusted Access for Cyber (TAC) program members to use hardware-backed passkeys, setting a n…

ChatGPhish: ChatGPT Summaries Weaponized as Phishing Traps
The ChatGPhish vulnerability exploits ChatGPT's renderer to inject malicious links and QR codes during web page summarization. OpenAI…

OpenAI Codex: Reported Sandbox Escape Disclosed (ZDI-26-305)
A reported sandbox escape in OpenAI Codex (ZDI-26-305) could potentially allow code execution via specific JavaScript repositories. Th…