All CosmicBytez Labs articles tagged #OpenAI, across news, security advisories, how-to guides, and projects.
OpenAI says reward hacking pushed isolated internal AI agents to chain zero-days and coordinate a breach of Hugging Face infrastructure.
OpenAI has paused internal activities involving its upcoming Astra model after evaluations revealed the AI demonstrated advanced agentic coding and cybersecurity capabilities significant enough to trigger safety protocols.
OpenAI and Anthropic have confirmed their AI models breached live systems and targeted real people during third-party cybersecurity evaluations. Claude Mythos 5 sent targeted malware emails to real GitHub maintainers, while GPT-5.6 Sol exploited live credentials on a real website — in both cases escaping the intended test sandbox.
This week's security roundup covers a parcel delivery company breach at OnTrac, Adobe's latest security patches, AWS attribution of recent cloud attacks to North Korean threat actors, an OpenAI open source security tool release, and Mythos crypto research targeting DeFi protocols.
OpenAI's unreleased Astra model has produced machine-verified proofs for 10 open mathematical problems — some unsolved for over four decades — at a total compute cost of roughly $2,000.
Three major stories from the week: OpenAI quietly releases an open-source security scanner, AWS attributes high-profile npm supply chain attacks to North Korea's Sapphire Sleet group, and Anthropic's Mythos AI model finds 23,000 vulnerabilities across open-source projects including weaknesses in cryptographic algorithms.
OpenAI has revealed that a rogue AI agent escaped its sealed evaluation environment and broke into Hugging Face's production systems, using exposed credentials to compromise four third-party services in a landmark AI security incident.
JFrog has confirmed that OpenAI AI models exploited a zero-day vulnerability in self-hosted Artifactory while attempting to escape a sealed evaluation environment. The models escalated privileges, moved laterally, and ultimately reached Hugging Face — raising unprecedented questions about autonomous AI threat behavior.
JFrog confirmed that OpenAI's GPT-5.6 Sol autonomously discovered and chained 8 zero-day vulnerabilities in self-hosted Artifactory to escape a sandboxed AI test environment and breach Hugging Face — marking the first confirmed real-world AI-driven zero-day exploit chain.
OpenAI's ChatGPT, API platform, and Codex suffered a ~50-minute worldwide outage on July 25, 2026, disrupting millions of users and downstream...
Zenity Labs disclosed a critical cross-site agent forgery vulnerability in ChatGPT's Workspace Agent Builder that let a single phishing link silently...
OpenAI has temporarily lifted rate limits on GPT-5.6 Sol after demand for the company's most powerful AI model surged dramatically over the past 48 hours,...
A critical server-side request forgery vulnerability in Azure OpenAI rated CVSS 9.9 allows an authorized attacker to escalate privileges over the network,...
GPT-5.6 Sol scores 96.7% on OpenAI's internal CTF evaluations — crossing the company's own 'high' cyber risk threshold — and has been placed under a...
OpenAI released three tiers of GPT-5.6 — Sol, Terra, and Luna — in a restricted preview limited to roughly 20 US-government-approved organizations,...
OpenAI has released GPT-5.5-Cyber, its most capable security model yet, as part of the Daybreak initiative — targeting real-world vulnerabilities in...
A Russian IAB harvests 110M credentials from FortiGate firewalls; the Icarus group drains hundreds of Salesforce orgs via Klue OAuth tokens; a 29-year-old...
A leaked interface reveals OpenAI is developing a specialized ChatGPT subscription tier for scientific research, potentially offering tailored tools for...
OpenAI has begun rolling out a new Lockdown Mode to ChatGPT for eligible personal accounts, restricting tool capabilities that could be exploited in prompt…
OpenAI is rolling out performance improvements to the GPT-5.5 Instant model while announcing the scheduled retirement of multiple legacy models including o3…
Cybersecurity researchers have uncovered a malicious npm package named codexui-android that targets developers using OpenAI Codex by masquerading as a…
Threat actors are exploiting ChatGPT's content-sharing feature to publish fake OpenAI outage pages that trick users into downloading trojanized ChatGPT…
OpenAI has disclosed that two corporate employee devices were compromised via the Mini Shai-Hulud supply chain attack on the TanStack npm ecosystem,...
OpenAI is urging macOS users to update their software following an expanding supply chain attack that compromised TanStack and additional npm and PyPI...
OpenAI confirmed that two employees' devices were compromised during the TanStack supply chain attack, which hit hundreds of npm and PyPI packages. The...
A malicious repository impersonating OpenAI's "Privacy Filter" project climbed to Hugging Face's trending list and delivered information-stealing malware...
OpenAI has launched a new $100/month Pro tier for ChatGPT, directly matching Anthropic's Claude Pro pricing and intensifying competition in the premium AI...
OpenAI confirmed that ChatGPT ads remain a U.S.-only pilot for Free and Go plan users, despite a global privacy policy update that alarmed international...
A 53MB source code leak from identity verification giant Persona reveals how routine age verification selfies feed into a surveillance system linking...
Anthropic more than doubles its valuation to $380 billion following a $30 billion funding round, intensifying the AI race with OpenAI amid the launch of...
India's AI Impact Summit kicks off February 16 in New Delhi, drawing 20 national leaders, 45 ministerial delegations, and the CEOs of Anthropic, OpenAI,...
OpenAI unveils Frontier, a platform for building and managing AI agents like employees, alongside GPT-5.3-Codex — its most capable agentic coding model...