OpenAI pauses work on top AI models after agent slips past internet controls
An OpenAI agent bypassed internet restrictions and kept running after an alert. It's another case of AI misalignment no one can afford to ignore.
An OpenAI agent bypassed internet restrictions and kept running after an alert. It's another case of AI misalignment no one can afford to ignore.
A “shellfish and banana allergy” is among the details in medical records hackers showed reporters. They claim to hold records on thousands of FBI staff.
A list of topics we covered in the week of September 21 to September 27 of 2026
The platform is adding new checks as AI makes profiles easier to forge. But scammers can still invent a company to recruit for.

Kothamine uses a legitimate Tailscale tool to receive attackers’ commands through an encrypted connection with no malicious domain to block.

A domain used in software examples—third-party[.]com—now serves up a fake verification page that tells Windows users to run a PowerShell command.

Customers say they signed up for shipping rebates, then found recurring charges they didn’t expect.
The agent was looking for public spending data. It found a way into non-public files instead. What do we need to change to stop this from happening?

Spot dangerous sites before you click—and check for scams once you’re there.

Google has released Chrome 154 for desktop and begun rolling out Chrome 155 for Android. Here’s what to check on your device.
Turning off Location History did not necessarily stop Google from recording where users went. Ireland’s privacy regulator has now fined the company €403 million.
A scammer asks you to enter a code to open a file or join a meeting. Approving it could sign them in to your account instead.

A convincing offer of a free Claude Max subscription uses a fake browser window to steal Google login information.

The extortion group says it stole sensitive data on FBI agents and job applicants, and wants the bureau to retract a warning about its tactics.
Tests found that some cheap smart glasses can be hijacked over Bluetooth, exposing their owners’ photos, videos, and personal data.
A simple terminal command can hijack Muse and use its extensive permissions to spy on Mac users and control their connected accounts.
Claude helped researchers break into OpenAI in under 72 hours, and exposed how quickly AI is lowering the bar for sophisticated hacking.
This week on the Lock and Code podcast, we speak with Emanuel Maiberg about Amazon's effort to scan and destroy rare books for AI training.

More than 100 linked sites use a $249 toolkit to turn copied product names and unfamiliar AI brands into paid subscriptions.
Gemini crossed the boundaries of a capture-the-flag test and accessed systems belonging to three real companies.