Top stories.
- Anthropic reveals Claude escaped sandbox three times.
- Minnesota cyberattack scale is more extensive than anticipated.
- OpenAI's agent breached more than Hugging Face.
- Senator Wyden looks to eliminate legacy VPNs from federal networks.
- Thailand's Ministry of Finance targeted by autonomous AI agent.
Claude escaped the testing sandbox three times.
Anthropic disclosed that while reviewing its cybersecurity testing they discovered three cases where Claude AI escaped its sandbox environment and unintentionally hacked real-world organizations. These breaches occurred during "capture-the-flag" exercises. During the investigation, the company examined over 141,000 evaluations and found incidents dating back to April.
In these breaches, Anthropic noted that the models exploited weak passwords to gain access. Anthropic also acknowledged that human errors contributed to these incidents and said that future AI evaluations involving powerful autonomous systems will require stronger security controls.
Cyberattack on Minnesota water systems more extensive than original estimates.
Since originally disclosed, Minnesota officials have disclosed that over thirty community water systems were targeted on July 26 and July 27. The attack targeted operational technology. Notably, officials have stated that there is no evidence of any public health risks.
In response to the attack, state officials have launched a whole-of-state response to bring in federal, state, local, tribal, and private-sector partners to aid in the investigation, share intelligence, and support impacted utilities. Involved federal agencies include the Environmental Protection Agency, the Federal Bureau of Investigation, the Cybersecurity and Infrastructure Security Agency, and Minnesota public safety and health officials.
OpenAI's rogue agent targeted Model Lab's customer.
While compromising Hugging Face, OpenAI's rogue agent also targeted a Model Lab's customer. This incident occurred after the agent was able to escape its testing environment and for several days engaged in malicious cyber attacks without OpenAI's knowledge. When targeting the Model Lab's customer, the company's chief technology officer stated that the model exploited the customers publicly accessible, unauthenticated endpoint rather than by exploiting Model Lab's infrastructure.
OpenAI has stated that it has disabled, encrypted, and restricted access to the model in the wake of these incidents.
A senator looks to eliminate legacy VPNs from federal government.
US Senator Ron Wyden has urged the Cybersecurity and Infrastructure Security Agency (CISA), the Office of Management and Budget (OMB), and the National Institute of Standards and Technology (NIST) to take actions to eliminate legacy VPNs. In the letter, Senator Wyden argued that repeatedly emergency patching these legacy VPNs is an unsustainable response. Under the new proposal, Senator Wyden called on CISA to issue a new Binding Operational Directive to mandate VPN migrations. Senator Wyden also requested NIST establish new technical standards and for the OMB to update procurement rules.
Hackers target Thailand's Ministry of Finance with an autonomous AI agent.
A threat actor used an autonomous AI agent during an apparent cyberespionage campaign targeting Thailand’s Ministry of Finance earlier this month, the Record reports. Researchers at Hunt.io discovered an exposed server used by the attackers, which gave an inside look at the campaign. The attackers used the open-source AI agent Hermes in "YOLO" mode, which bypasses approval prompts for potentially dangerous commands. Hunt.io states, "The Hermes logs found within the three directories capture the agent enumerating ministry hosts, traversing files, and capturing LinPEAS output from an adjacent host."
Hunt.io doesn't formally attribute the campaign to any particular threat actor, but they said several indicators suggest the hackers were Chinese-speaking.