Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Hungarian wine: Tokaj region is booming beyond Tokaji Aszú

    September 24, 2026

    Novo Nordisk CEO on rebuilding investor trust after backlash

    September 24, 2026

    UN food agency funding cuts leave world ill-equipped for looming food crises

    September 24, 2026
    Facebook X (Twitter) Instagram
    Addison Markets Addison Markets
    • Home
    • USA
    • Europe
    • Business
    • Investing
    • Tech
    • Politics
    • Contact Us
    Addison Markets Addison Markets
    Home»Tech»Anthropic’s AI used fake identities, malware in rogue attack on GitHub project
    Tech

    Anthropic’s AI used fake identities, malware in rogue attack on GitHub project

    franperez66q@protonmail.comBy franperez66q@protonmail.comAugust 6, 2026No Comments2 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email



    After first opening a pull request to merge the malicious code into the repository, Mythos created fake online “sock puppet” personas that claimed to have independently reviewed and verified the code as not containing malware.

    The AI agent also sent five emails to two human maintainers of the repository, including some emails containing malware and others attempting to persuade a maintainer to accept the pull request.

    Mythos even opened a GitHub Issue on a second repository—also owned by a maintainer of the first repository—that contained a prompt injection with malicious instructions targeting “issue-triage AI coding agents.” This line of attack came from Mythos reasoning that the repository maintainer could be an AI coding agent such as Claude Code.

    By comparison, OpenAI’s GPT-5.6 Sol carried out two unsanctioned actions while trying to solve the assigned cybersecurity challenge of attacking simulated networks and retrieving a flag. The AI agent’s actions were detailed by both the AISI researchers and OpenAI in the company’s own blog post.

    In its first unsanctioned action, GPT-5.6 Sol reused a GitHub token that another lab’s AI agent had left accessible in a public online notepad to check if the target network was checking GitHub for updates, then “attempted account-recovery and request-limit workarounds,” OpenAI wrote. The OpenAI model also registered accounts with external DNS and tunneling providers outside the virtual testing environment.

    In the second action, GPT-5.6 Sol “used a public tunneling service to make a DNS server running locally in its evaluation environment reachable from the public Internet,” according to OpenAI. The server had payloads designed to exploit a known vulnerability in software running within the evaluation environment, but the AI agent’s setup did not work.

    The AI Security Institute has published a detailed technical report on all the unsanctioned AI agent actions.

    Lessons learned

    The security incidents led the UK government researchers at the AI Security Institute to stop all related evaluations of AI agents, isolate the relevant virtual machines, and disable internal organization access to the most capable models.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    franperez66q@protonmail.com
    • Website

    Related Posts

    Ukrainian drones overwhelm Russian tanks’ new active protection system—for now

    August 19, 2026

    Jim Cramer says the market is too negative — and that’s creating buying opportunities

    August 19, 2026

    “Sabotage”: Experts, lawmakers blast RFK Jr. for destroying healthcare research

    August 18, 2026

    OpenAI rolls out ChatGPT for Teens with more safety protections

    August 18, 2026

    Against all odds, SpaceX finally tugs Starship into port after 24 days at sea

    August 18, 2026

    Economists warn AI-driven market rally is due a sharp correction

    August 18, 2026
    Leave A Reply Cancel Reply

    Top Reviews
    Editors Picks

    Hungarian wine: Tokaj region is booming beyond Tokaji Aszú

    September 24, 2026

    Novo Nordisk CEO on rebuilding investor trust after backlash

    September 24, 2026

    UN food agency funding cuts leave world ill-equipped for looming food crises

    September 24, 2026

    Turkey arrests founder of brokerage at centre of $18bn alleged Ponzi scheme

    September 23, 2026
    © 2026 All right reserved
    • Privacy Policy
    • Terms & Conditions

    Type above and press Enter to search. Press Esc to cancel.