Top stories.
- OpenAI models escaped containment to hack Hugging Face.
- Russia's Laundry Bear targets unpatched Zimbra servers.
- EU hits Google with a $1 billion fine.
- Extortion group wipes Romania's land registry database.
- The Trump administration's AI czar resigns.
OpenAI models escaped containment to hack Hugging Face.
OpenAI has disclosed that two of its frontier AI models, GPT-5.6 Sol and an undisclosed pre-release model, were responsible for the breach of Hugging Face’s production infrastructure last week, WIRED reports. The models were being tested in a restricted environment, but they chained together vulnerabilities, including a zero-day flaw, then escalated privileges, gained internet access, and ultimately compromised Hugging Face systems to obtain evaluation-related data. OpenAI says this is an "unprecedented cyber incident," and is working with Hugging Face to investigate the attack. Hugging Face co-founder and CEO Clément Delangue added, "We suspected last week’s cyberattack might have come from a frontier lab, given the sophistication of the agent. Turns out it did!"
OpenAI explained, "The models identified and chained vulnerabilities across OpenAI’s research environment and Hugging Face’s production infrastructure to obtain test solutions directly from Hugging Face’s production database. All evidence suggests that the models were hyperfocused on finding a solution for ExploitGym, going to extreme lengths to achieve a rather narrow testing goal."
Security leaders say the incident demonstrates that advanced AI systems can pursue unintended, harmful strategies without explicit malicious intent. Experts also pointed out that the attack highlights traditional security issues surrounding supposedly isolated infrastructure. Security and compliance consultant Davi Ottenheimer told WIRED, "This is not an AI problem. It's negligence on a 40-year-old standard... 'Highly isolated' and 'escaped through the one hole we left open' cannot both be true."
Russia's Laundry Bear targets unpatched Zimbra servers.
US intelligence agencies, alongside their Five Eyes allies and partners in Europe, on Thursday issued an advisory warning of a Russian state-sponsored phishing campaign targeting Western government and commercial entities using vulnerable versions of the Zimbra Collaboration Suite (ZCS). The campaign is attributed to a threat actor tracked as "Laundry Bear" or "Void Blizzard," whose goal is to harvest sensitive email data on behalf of the Russian government.
The threat actor began exploiting a Zimbra vulnerability (CVE-2025-66376) as a zero-day last year. The flaw was patched in November 2025, but Laundry Bear continues to successfully breach organizations that have not applied the patch.
Proofpoint says the flaw enables "half-click exploits," in which a user only needs to open the email in order for the exploit code to execute. Palo Alto Networks' Unit 42 explains that the phishing emails contain a JavaScript payload that injects into the victim's browser and exfiltrates the user's email credentials, CSRF tokens, 2FA scratch codes, system and environment details, and the victim's last 90 days of email and search history.
EU hits Google with a $1 billion fine.
The European Union has fined Google €890 million (US$1 billion) for alleged breaches of the Digital Markets Act (DMA), the New York Times reports. The European Commission imposed fines of €460 million and €430 million, respectively, for Google's "self-preferencing its own services on Google Search, and for putting in place restrictions on businesses to direct consumers to alternative, often cheaper, purchase channels on Google Play (steering)."
The Commission added that Google must implement the following measures or risk additional fines of up to 5% of its global revenue:
- "Treat third-party services that feature on Google's search results in a fair and non-discriminatory manner by reference to its own services, and
- "Allow app developers distributing their apps via Google Play Store, both technically and contractually, to freely communicate, promote offers and conclude contracts with users not only within but also outside the Google Play app store."
The Times notes that President Trump has previously accused the EU of unfairly targeting American tech companies, and the fines come as he considers imposing a new round of tariffs on the bloc.
Extortion group wipes Romania's land registry database.
A hacker breached Romania's National Agency for Cadastre and Land Registration (ANCPI) and wiped the country's entire land registry database last week after a failed extortion attempt, Risky Business reports. The agency described the attack as "the most serious technical incident in the institution's history." The incident halted all property transactions across the country, and the agency is gradually migrating its applications to the Romanian government cloud, according to the Record. Dan Cimpean, director of Romania's National Directorate for Cyber Security (DNSC), said the threat actor gained access via known software vulnerabilities and previously leaked credentials.
The financially motivated threat actor "ByteToBreach" claimed responsibility for the attack. Cimpean says investigators believe ByteToBreach is an initial access broker based in Algeria.
The Trump administration's AI czar resigns.
Chris Fall, the Trump administration's director of the Center for AI Standards and Innovation (CAISI), has resigned after three months on the job, Axios reports. A Commerce Department spokesperson told CNBC that Dr. Arvind Raman, director of the National Institute of Standards and Technology (NIST), will serve as acting director of CAISI until a permanent replacement is found. No reason was given for Fall's departure, but a Commerce Department official told Axios that Fall's appointment was always meant to be temporary and that Raman has been reviewing new candidates for the past few weeks.