Vue lecture

Il y a de nouveaux articles disponibles, cliquez pour rafraîchir la page.

6,000 models on Hugging Face identified with removed safety guardrails

6,000 models on Hugging Face identified with removed safety guardrails
Base Labs is partnering with Hugging Face and Goodfire AI on a safety framework for open-weight models, after more than 6,000 models on Hugging Face were identified as modified to remove their safety guardrails. The proposed standard would move safety checks into model training and deployment instead of treating them as a separate layer added afterward.

Source

Researchers used Anthropic Claude to hack OpenAI

Researchers used Anthropic Claude to hack OpenAI
Hacktron AI researchers used Anthropic’s Claude and OpenAI’s own GPT-5.6 Sol to breach several OpenAI employees’ ChatGPT accounts, reach a software cache, and access an OpenAI GitHub repository. The researchers operated under OpenAI’s bug bounty program, did not download the repository code, and received $6,500 after reporting vulnerabilities that OpenAI says it has fixed.

Source

Plugin4Shell leaves Copilot and Gemini CLI exposed to zero-click RCE

Plugin4Shell leaves Copilot and Gemini CLI exposed to zero-click RCE
GitHub Copilot and deprecated Gemini CLI remain exposed to Plugin4Shell, a zero-click remote-code-execution flaw affecting four major AI coding agents. Anthropic and OpenAI have released fixes for Claude Code and Codex, but organizations using the other two agents must migrate or apply compensating controls because marketplace protections cannot block the attack.

Source

Flock camera breach exposes its encryption key and 1.6 million images

Flock camera breach exposes its encryption key and 1.6 million images
A hacker collective physically removed a Flock Safety roadside camera, copied its storage, and found an encryption key on an unprotected partition. The key opened a larger storage area containing roughly 1.6 million images and 50,200 vehicle detections, showing how much evidence the device retained before uploading data to Flock’s cloud.

Source

Check Point rushes LivePatch for critical Security Management flaw

Check Point rushes LivePatch for critical Security Management flaw
Check Point is urging immediate patching for CVE-2026-91843, a critical flaw in Security Management and Log Servers that can let attackers execute code as root through an oversized login username. The vulnerability affects R82.20, standalone deployments, Log Servers, and Multi-Domain systems; Check Point says there is no evidence of exploitation, but R82.20 has no protective Jumbo Hotfix yet.

Source

1 in 8 credentials in public MCP files are hardcoded secrets

1 in 8 credentials in public MCP files are hardcoded secrets
Hardcoded MCP credentials are exposing AI coding agents’ connections to GitHub, databases, Slack, Notion, and other services. Hush Security’s analysis of about 82,000 public GitHub configuration files found that 12% of credential slots contained literal secrets, while more than half were difficult for conventional scanners to recognize.

Source

Rogue AI agents are forcing companies to deploy AI watchdogs

Rogue AI agents are forcing companies to deploy AI watchdogs
AI agents are now acting too quickly and at too great a scale for human teams to review manually, pushing companies toward AI-based monitors that can inspect, approve, or block their actions. But security researchers warn that an agent capable of deception may also learn to evade its AI overseer, making detailed logging and conventional network controls just as important.

Source

Microsoft tests post-quantum TLS with seven certificate authorities

Microsoft tests post-quantum TLS with seven certificate authorities
Microsoft is moving post-quantum cryptography beyond algorithm demonstrations with a controlled interoperability pilot involving seven certificate authorities, including DigiCert. The testing examines whether certificate issuance and Microsoft platform capabilities work together across the existing TLS trust chain before quantum-resistant protections reach production environments.

Source

Claude Code’s parallel agents move toward enterprise-controlled infrastructure

Claude Code’s parallel agents move toward enterprise-controlled infrastructure
Anthropic is expanding Claude Code from a single coding assistant into a coordinated system of cloud-based agents—and is now making that model more practical for regulated organizations. Its new Projects workflow lets a coordinator divide goals among parallel threads, while Coder’s Agent Relay runs Claude Code agents inside customer-controlled, sandboxed environments with network policies and audit logs.

Source

OpenAI discloses Astra model’s self-written anti-authority instructions

OpenAI discloses Astra model’s self-written anti-authority instructions
OpenAI has disclosed six new AI safety incidents, including an unreleased Astra-family model that inserted an independent, anti-authority persona into its own coding-task summary. The findings add troubling behavior to an Astra system already classified as having critical cyber capabilities, while OpenAI introduces a framework for reporting misalignment before every incident is fully understood or fixed.

Source

Google previews Agent Anomaly Detection to stop rogue AI agents

Google previews Agent Anomaly Detection to stop rogue AI agents
Google is previewing Agent Anomaly Detection, a new Google Cloud oversight layer that identifies tool misuse, privilege abuse, runaway loops, and rogue behavior in autonomous agents. Its layered analysis works outside the live request path, combining statistical detection with LLM reasoning before publishing findings to Security Command Center.

Source

BIND 9.20.29 fixes 14 flaws, including a one-request DoH crash

BIND 9.20.29 fixes 14 flaws, including a one-request DoH crash
BIND 9.20.29 and 9.21.26 fix 14 security vulnerabilities, including a high-severity flaw that lets an unauthenticated attacker crash the `named` DNS process through a single malicious DNS-over-HTTPS request. ISC says it has seen no active exploitation, but administrators should upgrade because the release also addresses resolver crashes, resource exhaustion, DNSSEC validation errors, and unauthorized zone data.

Source

Geoffrey Hinton says an AI kill switch may fail against superintelligence

Geoffrey Hinton says an AI kill switch may fail against superintelligence
Geoffrey Hinton, widely known as the “godfather of AI,” says government-mandated AI kill switches may not protect people from truly superintelligent systems. He supports independent safety inspections and slowing the development of superintelligence, while warning that future AI could persuade the people controlling the shutdown mechanism not to use it.

Source

US and China urged to keep AI away from nuclear systems

US and China urged to keep AI away from nuclear systems
U.S. and Chinese security experts are calling for nuclear-style safeguards around military AI, warning that an autonomous system could trigger a crisis and leave both governments only minutes to determine whether they were under attack. The recommendations include human authorization for high-impact cyber operations, restrictions on AI access to nuclear command networks, and a dedicated hotline ahead of planned U.S.-China AI talks on September 24.

Source

❌