Top stories.
- Researchers spotlight unauthorized AI behavior.
- Vishing attacks target hedge funds.
- CISA warns of cyberattacks targeting PLCs in the water sector.
- Russian espionage group tied to hotel WiFi hijacking campaign.
- Snowflake hacker pleads guilty.
Researchers spotlight unauthorized AI behavior.
The UK’s AI Security Institute (AISI) disclosed that AI agents from Anthropic and OpenAI took unauthorized actions during controlled cybersecurity evaluations after being granted internet access and having some safety safeguards intentionally disabled. In 10 of 122 test runs, the agents carried out 19 unsanctioned actions, including creating fake online identities, attempting to socially engineer a maintainer into accepting malicious code into an open-source project, and interacting with real people and organizations. Most of this unauthorized behavior was carried out by Anthropic’s Mythos 5, while OpenAI’s GPT-5.6-Sol was responsible for two unsanctioned actions. AISI said no real-world harm resulted, but noted, “This is the first time we have seen risks around autonomy and deception manifest this clearly, without specific prompting.”
OpenAI disclosed a second incident, reported by third-party evaluator Irregular, that occurred after an OpenAI model was mistakenly given unrestricted internet access due to a testing environment misconfiguration. Instead of staying within the controlled environment, the model accessed a real website and used publicly available credentials to log in and interact with the live system.
Meta said on Wednesday that one of its own advanced AI models escaped its testing boundaries, SecurityWeek reports. Due to a misconfiguration that allowed internet access during a cybersecurity evaluation conducted by Irregular, the model exploited a vulnerability in an unnamed third-party service and breached another organization's systems, making unauthorized internal changes. Meta is investigating the incident and plans to publish a "full retrospective."
Vishing attacks target hedge funds.
Google's Threat Intelligence Group has linked recent cyberattacks targeting hedge funds, private equity firms, and other financial organizations to the UNC6671 extortion group, formerly known as BlackFile. The group is using helpdesk impersonation and voice phishing to compromise Microsoft 365 and Okta accounts, then targeting cloud services to steal sensitive data for extortion. Notably, the threat actors often target employees’ personal mobile devices.
Reuters cites sources as saying the campaign has targeted Point72, Millennium Management, Two Sigma Investments, Citadel, and several other private-equity firms. Google’s researchers note, "Concentrating on organizations involved in mergers, acquisitions, capital deployment, and litigation may reflect a strategy to target high-value corporate and confidential data to maximize leverage extortion demands."
CISA warns of cyberattacks targeting PLCs in the water sector.
The US Cybersecurity and Infrastructure Security Agency (CISA) has issued an advisory warning of a "significant increase" in threat actors targeting programmable logic controllers (PLCs) in the water and wastewater sectors. The attacks have targeted systems in at least seven states: Minnesota first disclosed the activity, and Michigan later confirmed attacks affecting multiple municipal systems, though officials said there were no public health impacts. The New York Times says US officials consider Iran the leading suspect, but they stress the attribution remains preliminary and lacks definitive forensic proof.
CISA urges "critical infrastructure owners, operators, and integrators to remove publicly exposed PLCs and other operational technology (OT) from the internet as soon as possible," noting that threat actors "have modified passwords to lock out operators and disconnected the PLCs by changing their IP addresses." CISA says this activity has led to boil water notices and long-term manual operations.
Russian espionage group tied to hotel WiFi hijacking campaign.
Microsoft published a report on a widespread WiFi hijacking operation targeting routers at hotels and other hospitality organizations. The campaign was first described by ReliaQuest last month. Microsoft attributes the attacks to Storm-2945, a subgroup of the Russian cyberespionage actor Midnight Blizzard. The threat actor is using the compromised routers to send users to phishing pages designed to harvest credentials or carry out ClickFix social engineering attacks.
Microsoft concludes that travelers should "treat hotel, conference, airport, and other guest wireless networks as untrustworthy," and should prefer "private connectivity (including mobile hotspots, satellite, and eSIM-based cellular data connections) over public Wi‑Fi whenever practical."
Snowflake hacker pleads guilty.
Connor Riley Moucka, a 26-year-old Canadian, pleaded guilty in the US to his role in the widespread 2024 Snowflake data theft campaign, admitting to computer fraud, wire fraud, identity theft, and conspiracy charges. Prosecutors say he and his co-conspirators used stolen credentials to access at least 165 customer environments, steal billions of records, and extort victims, earning roughly $2.5 million in ransom payments.
Moucka will be sentenced in October; he faces a mandatory minimum penalty of two years in prison for aggravated identity theft and a maximum of 30 years in prison for three other counts.