❌

Normal view

There are new articles available, click to refresh the page.
Yesterday — 25 September 2026Main stream

OpenAI admits ChatGPT in Siri was ‘dramatically underperforming’

  • OpenAI has filed court documents against Elon Musk’s xAI
  • The papers reveal that ChatGPT’s integration with Siri was disappointing
  • OpenAI alleges that barely anyone was using Apple Intelligence

If you’ve noticed an improvement in Siri’s abilities on your Apple device, you might have Google to thank for that, as its Gemini artificial intelligence (AI) now powers much of what Siri AI can do. Rival services like ChatGPT have also found their way into iOS — but new court documents reveal why that particular partnership has struggled to get off the ground.

The court filings were made in relation to OpenAI’s ongoing dispute with Elon Musk’s rival xAI firm (now known as SpaceXAI). In the documents, OpenAI alleges that, by the time xAI filed its complaint against OpenAI, “it was clear that Apple’s integration of ChatGPT was dramatically underperforming.”

The papers then go on to imply that this was not just some one-off failure. Instead, the Apple integration was “persistently underperforming,” OpenAI alleges.

Apple added ChatGPT integration to Siri in December 2024, but this required a multi-step opt-in process. That could be one reason for the substandard performance of the link-up, with a degree of friction slowing users down in their attempts to harness OpenAI’s tool.

Much of this section of the court filings is redacted, so it’s difficult to know exactly what was going on between Apple and OpenAI. But it seems clear that, at least from the latter’s perspective, the results were severely underwhelming.

What might have been

Sam Altman and Tim Cook

(Image credit: Getty Images)

When Apple Intelligence first launched, Apple provided users with an option to tap into ChatGPT if they needed something a little more powerful. For example, this was an option in Visual Intelligence, providing extra context and help with the images you shot with your iPhone’s camera.

Yet OpenAI’s legal filing makes it clear that barely anyone was using any of ChatGPT’s tie-ins with Apple Intelligence. OpenAI describes the effect the integration had on competitors (like xAI) as being “indisputably de minimis.” It added that its own expert, Dr. Catherine Tucker, calculated “the share of GenAI consumers who accessed ChatGPT through Apple Intelligence” and found it to be “consistent with OpenAI’s internal view that Apple Intelligence saw minimal usage.”

That hints that the problem might not have just been limited to ChatGPT’s integration with Apple devices, but with Apple Intelligence as a whole. Apple’s AI system was woefully underdone when it first arrived and clearly lagged behind its rivals. First impressions matter, and if most people were left unconvinced by Apple Intelligence, ChatGPT might have suffered the knock-on effects among Apple’s customers.

Did ChatGPT lose out because Apple fans had to dive into the Settings app on their device, find the relevant section and laboriously wade through several steps in order to enable ChatGPT? Because Siri’s limitations dragged ChatGPT down with it? Or did users simply prefer to launch ChatGPT’s standalone app instead?

We don’t know the answer to that, at least not right now. But with Siri getting a glow-up under the Siri AI banner, it feels clear to me that Apple wants a fresh start for its AI efforts. Maybe things would have been different for OpenAI had it integrated with the more powerful Siri AI rather than the underbaked Apple Intelligence. But with Siri AI righting many of the wrongs of Apple Intelligence’s fudged launch, OpenAI may be left ruing what might have been.

New bill would create federal investigative body for AI-driven hacks 

By: djohnson
24 September 2026 at 14:07

A new Democratic bill in Congress would establish a federal Cybersecurity and AI Board of Investigations to provide independent government oversight of cyberattacks carried out by AI agents, following recent hacks by models run at companies like Anthropic, OpenAI, Meta and others.

The bill, introduced by Sen. Ed Markey, D-Mass., would attempt to establish a federal mechanism to investigate incidents where AI models escape sandbox environments and access live internet systems.

Currently, frontier AI companies like OpenAI and Anthropic largely control the investigation and public reporting of such incidents. Markey and other critics argue that these companies have too much control over investigations and reporting due to their financial and legal interests. 

“Despite the unprecedented depth and scale of recent AI-enabled cyberattacks, the public is learning critical details piecemeal,” Markey said in a statement. “Building stronger defenses requires a full accounting of what goes wrong, and we cannot depend on companies with little incentive to disclose their failures to give us one. We need the Cybersecurity and AI Board of Investigations to get to the bottom of major incidents and give companies and the government the critical information necessary to build resilience and better secure our economy and our country.”

Although frontier AI companies maintain external red-teaming programs and allow limited access to organizations like METR and Redwood Research, they control the scope, terms and time frames of those engagements.

The board, which would coordinate with the secretary of commerce, could subpoena witnesses and conduct “independent and impartial reviews and assessments” of AI agent-led hacks that impact federal information systems or critical infrastructure. 

It would be led by five members, appointed by the president and confirmed by the Senate for five-year terms, with no more than three members from one political party.

The board would also investigate systemic vulnerabilities in the AI supply chain, so-called “near misses” where unauthorized agent-led hacks were “narrowly averted,” and gaps in federal regulatory oversight. It would have technical staff including engineers, malware analysts, and digital forensic experts.

The board would “operate independently from regulatory review and enforcement actions without assigning legal fault or liability for any review and assessment” it conducts, according to the bill.

OpenAI confirmed Wednesday its AI agents breached a statistics portal used by the Australian government’s social services agency, Services Australia. Though the breach happened in June, OpenAI learned of the incident in August. Australian Prime Minister Anthony Albanese said the company did not notify him until Sept. 10, when it sent findings to a general government email inbox, according to the BBC.

The post New bill would create federal investigative body for AI-driven hacks  appeared first on CyberScoop.

Before yesterdayMain stream

ChatGPT got GPT-6, but you can't use it in Chat — confused?

ChatGPT just got GPT-6, except there’s a catch: you can’t actually use it in Chat.

If that sentence makes absolutely no sense to you, I don’t blame you. Until now, you could use ChatGPT quite happily without giving much thought to the distinction between Chat and Work functionalities. I certainly did. It was just that little slider at the top of the screen I never bothered with.

I suspect most of you are the same. Chat was where I talked to ChatGPT, while Work was something sitting alongside it that I could largely ignore because the Chat setting let me do almost everything I wanted.

GPT-6 changes that. OpenAI’s newest model has arrived in ChatGPT, but instead of appearing in the familiar model picker on the right hand side of the prompt bar, GPT-6 Astra, Sol and Luna are available in Work and Codex only. So, naturally, the first thing I did was go looking for them.

And somewhere between opening Work, figuring out what OpenAI actually expects me to do there, and finally getting my hands on GPT-6, I realized this launch is about more than a new model. OpenAI has just made the difference between chatting with ChatGPT and asking it to work for you in a way it never really did before.

When to Chat and when to Work

The easiest way I’ve found to understand the difference is to think about how much of the job I want ChatGPT to take responsibility for. In a normal Chat conversation, I’m usually working alongside the AI. I ask something, look at the response, add more information and gradually steer it towards what I need.

Work feels different because I’m handing over more of the process. I can give ChatGPT a larger task involving multiple steps and let it work out how to approach it, which might mean researching information, looking through files or using websites rather than waiting for me to tell it what to do at every stage.

If I’ve got a bigger job involving several files or lots of moving parts, I’ll often start there and let ChatGPT work out what it needs before I get involved again. Chat feels collaborative; Work feels much more like delegation.

I wouldn’t nominate OpenAI for any interface design awards because one of the reasons that the distinction between Work and Chat is so confusing is that they both use exactly the same interface, with a prompt bar at the bottom of the screen.

In fact, you can choose Work mode and then just start chatting to the AI as you normally would, although I've tried this, and it's not a particularly good experience. Responses can take considerably longer than they do in Chat, because Work is designed around longer, multi-step jobs rather than firing back quick conversational answers. If I just want to ask ChatGPT something, Chat remains the obvious place to do it.

And once you understand that distinction, putting GPT-6 Astra, Sol and Luna in Work rather than Chat starts to look considerably less strange.

ChatGPT on a mobile phone.

(Image credit: Apple / OpenAI)

So what exactly is GPT-6?

OpenAI calls GPT-6 Astra “the most intelligent and aligned model in the world”. Think of it as the heavyweight of the family: OpenAI's most capable model, built for the really difficult jobs where you want maximum intelligence rather than maximum speed. OpenAI particularly emphasizes Astra's ability to operate software, browse, conduct research and complete multistep professional workflows.

And because not every job requires the power of a burning sun to complete, OpenAI has also released two smaller versions called GPT-6 Sol and GPT-6 Luna. These models are more lightweight and less expensive to use. They’re trained using similar methods to GPT-6 Astra, but OpenAI say they “build on the advances behind GPT-6 Astra” and bring much of its strengths into faster and more affordable models.

There is one wrinkle here. GPT-6 Astra has actually been around since earlier this month, and GPT-6 Pro, which is powered by Astra, is available in regular Chat on some higher-tier plans. I'm a ChatGPT Plus subscriber, however, which means my access to Astra — and now the new GPT-6 Sol and Luna models — is through Work and Codex.

If I switch to the Work tab in my Plus account then in the model picker I get access to GPT-6 Luna High, GPT-6 Sol Light, GPT-6 Sol Medium, GPT-6 Astra Light and GPT-6 Astra Medium.

Until now, I could happily spend all my time in Chat, using GPT-5.6 Sol, and largely ignore Work. GPT-6 changes that. OpenAI isn't just giving us smarter models; it's starting to separate the AI we talk to from the AI we give jobs to. If its most powerful new models are going to live on the Work side of that divide, then that little switch I've spent months ignoring suddenly matters a lot more.

OpenAI, Ukraine partner on ‘Daybreak’ program to protect power grids and water systems 

By: djohnson
23 September 2026 at 11:37

OpenAI and the Ukrainian government have agreed to a partnership that will provide AI tools and subsidized computing resources to better protect the nation’s critical infrastructure from cyberattacks.

The agreement, announced Wednesday at OpenAI’s New York office, will provide Ukrainian cybersecurity officials with access to advanced AI models designed for cybersecurity work through the company’s Daybreak program. OpenAI said it is also pledging over $1 billion in subsidized tokens to support the initiative.

During a panel discussion Dmytro Kushneruk, consul general of Ukraine in San Francisco, outlined how the tools would be used for cybersecurity automation, including functions such as incident response, threat triaging, login analysis, inventorying systems, code analysis and validating vulnerabilities.

In nearly all cases, Kushneruk said the primary benefit was carrying out those functions at machine speed. But this speed is meant to complement, not replace, Ukrainians’ human expertise.

In regard to incident response Kushneruk said humans must view “thousands and thousands of these logs and they have to find what’s really important, that’s why AI can give capable defenders really much greater advantage and leverage.” 

“This is why the object is not to replace the cyber defender with AI, but to make sure the cyber defender acts faster,” he added.

Kushneruk said that for Ukraine, the partnership “is really not about protecting computers, it is about actually keeping our country running.”

Ukraine faces approximately 6,000 cyberattacks per year, or about 15 per day, according to Kushneruk. Over the past twelve years, the country’s critical infrastructure, including electricity and water systems, has endured sustained attacks from Russia in the form of cyberattacks and physical strikes.

Since Russia’s 2022 invasion, Ukraine’s critical infrastructure has been under constant threat. While missiles remain the primary concern, Kushneruk said Ukraine has been preparing to protect vital services since Russian GRU hackers shut down the country’s power grid in 2015. 

He added that while the country was “maybe not so much prepared” to deal with the fallout in 2015, it improved over time, including the resilience displayed in 2025 when trains kept running after Russian hackers attacked Ukraine’s railway system.

Some national security experts and congressional committees have explicitly cited the resilience of Ukrainian critical infrastructure as a model for U.S. industry.

Naz Durakoğlu, minority staff director of the U.S. Senate Foreign Relations Committee, said there is “pretty much across the board” agreement between the parties in favor of similar adoption of defensive AI tools by U.S. critical infrastructure operators, though issues like regulation remain sticking points.

“This is something that’s already happening, and frankly, it’s just kind of a basic duty of government to make sure that when you turn the tap on, water comes out, the electricity doesn’t go out, and hospitals keep running and treating patients,” said Durakoğlu. “So there is a broad understanding that this is a major issue, and I will say seeing what Ukraine has to go through day-to-day is also a huge wake-up call to our members on a bipartisan basis.”

OpenAI has publicly pushed for its product, and AI at-large, to be used to solve these types of problems. Company president and co-founder Greg Brockman signed an open letter released earlier this year calling for “collective action” and widespread use of AI models to find and fix vulnerabilities before the rest of the world,  including foreign governments and cybercriminals, got access to the same capabilities.

According to Politico, OpenAI CEO Sam Altman met with U.S. power companies in July to discuss using AI to protect the nation’s electrical grids.

On Wednesday, OpenAI’s national security policy head, Sasha Baker, said the company felt “urgency” to try to strike similar agreements with other governments and industries.

“There’s this period of time where we’re really rushing to get [these tools] in the hands of critical infrastructure operators, of governments around the world, of people who want to patch systems, defend their networks, remediate vulnerabilities because we know as these tools proliferate out there in the ecosystems, there are going to be bad guys out there that also try to use them,” said Baker. “So, we have this window of time to take action and we’re really motivated by the idea that we need to act with some urgency.”

The post OpenAI, Ukraine partner on ‘Daybreak’ program to protect power grids and water systems  appeared first on CyberScoop.

I tested ChatGPT against Copilot in Microsoft Word

Microsoft Word has spent the past few years getting increasingly acquainted with AI. Copilot can already draft text, rewrite passages, summarize documents, and answer questions about whatever you have open. Microsoft has even been rolling out more advanced editing capabilities that let Copilot make broader changes directly inside a document.

Now there is another AI sitting in Word. OpenAI launched ChatGPT for Word, via a plug-in, on September 17, putting a ChatGPT sidebar directly inside Microsoft's word processor. It works across ChatGPT's plans, including Free, although your normal ChatGPT usage limits still apply.

That creates a slightly peculiar situation. Microsoft has spent considerable effort building Copilot into Word, and now I can install its most famous AI rival in the same application. Naturally, I wanted to see which one I would actually reach for. I came away liking both, although for rather different reasons.

Word ChatGPT

(Image credit: OpenAI)

Installing ChatGPT in Word is straightforward, although there is one extra step compared with Copilot if Microsoft's assistant is already part of your Microsoft 365 setup. OpenAI's ChatGPT add-in is available through Microsoft Marketplace. Once installed, you can open it from the Word ribbon, sign-in to your ChatGPT account, and have the familiar chatbot appear in a sidebar.

The integration works with ChatGPT's Free, Go, Plus, and Pro plans, with the usual usage limits applying to each. The big difference with regular ChatGPT is that all conversations inside Word are separate from the ones in the regular ChatGPT app, and ChatGPT's memory does not follow you into Word either. That is worth remembering if you are accustomed to the regular chatbot already knowing your preferences.

Test 1: Planning a trip

I started with a blank document and asked each AI to respond to a request for a reusable vacation-planning template that I asked for using natural language in the sidebar.

I wanted somewhere to keep travel details, hotel information, reservations, restaurants, packing notes, and a loose daily itinerary without creating the sort of schedule that makes a vacation feel suspiciously like work.

ChatGPT produced a thoughtful setup, including the expected travel and accommodation details, but with added sections for reservation deadlines, estimated travel times, priority activities, backup plans, and ideas that had not yet made the final itinerary. Instead of filling every day with morning, afternoon, and evening slots, it left more space for a main activity and optional plans, which made the template feel less rigid.

ChatGPT Word

(Image credit: Word)

In contrast, Copilot gave me the more conventional Word template. It neatly divided the document into sections for transportation, accommodation, daily plans, activities, dining, and packing, with plenty of space to fill everything in later. The structure was clean and immediately usable, and because Copilot is so closely integrated with Word, tweaking individual sections and reorganizing the document felt particularly easy.

Copilot was stronger at quickly producing a polished template that looked and behaved like something created specifically for Word. ChatGPT was better at considering the practical problems that tend to emerge while planning an actual vacation and building the document around them.

I ultimately preferred ChatGPT's version because it felt more flexible, although Copilot's was arguably easier to start using immediately. ChatGPT did a little more thinking about what information I might eventually wish I had included.

Test 2: Editing down nonsense

I then decided to see how they compared at editing. I pasted in an old, absurdly long set of instructions for an AirBnB I had saved years ago out of amusement, complete with information about plants, deliveries, Wi-Fi and several unnecessary paragraphs devoted to where various things were stored.

I selected a particularly rambling section and asked ChatGPT to shorten it while preserving anything somebody would actually need.

“The main problem is repetition rather than the amount of information," The AI wrote. It mentions the delivery instructions twice and explains the location of the spare supplies in more detail than someone staying for a weekend probably needs. I’d keep the Wi-Fi information, the plant-watering schedule and anything involving keys or access exactly clear. The rest can be condensed into a short ‘Around the house’ section so the useful details are easier to find.”

Copilot is hardly incapable of that conversation. It can answer questions about a document, provide summaries and respond to prompts about unclear passages, and provide references showing where information came from. But I would tend to pull up Copilot only when I already knew what I wanted it to do.

Selecting some text and telling Copilot to rewrite it produces versions that can be replaced or inserted directly into the document, and Microsoft now allows editing inside its suggestion box before accepting the result.

Which did I prefer?

ChatGPT's biggest practical advantage may simply be accessibility. OpenAI says ChatGPT for Word is available on all ChatGPT plans, including Free. Copilot availability varies according to Microsoft 365 subscription, Copilot license and organizational settings, while some of Microsoft's newer 'Edit with Copilot' features are still rolling out to eligible users.

There are good reasons to prefer Copilot. Its integration with Word is deeper, and Microsoft has built features specifically around manipulating Word documents rather than placing a general AI assistant alongside them. Depending on your setup, Copilot can also draw on Microsoft files, emails and meetings, which could matter far more than conversational style for people already living inside Microsoft 365.

For quick mechanical changes, particularly when I knew exactly what needed rewriting, Copilot's tighter relationship with Word made sense. It felt like an extension of the application rather than another destination. ChatGPT was the one I preferred when the problem was fuzzier. The two assistants overlap considerably, but they did not feel identical when I actually used them. Copilot often felt like an AI feature of Word. ChatGPT is a more fully-featured chatbot, while Copilot simply augments Word with AI features. Either is fine, it's just that ChatGPT feels more flexible.

Citing China, President Trump doubles down on hands-off approach to AI regulation

By: djohnson
22 September 2026 at 11:16

President Donald Trump continued to defend his administration’s hands-off approach to AI regulation in the wake of hacks carried out by U.S. commercial frontier models that have rattled policymakers and industry veterans and spurred calls for more regulatory oversight.

In a Truth Social post Monday, Trump dismissed worries from critics that “AI is going to kill us,” comparing them to complaints from environmentalists about climate change, which he also alleged was a false narrative. He also posited that nothing may matter more than future U.S. dominance of the technology over geopolitical rivals like China.

“Whoever wins AI, WINS!” Trump posted. “We are leading now over China, and everyone else, and I’m going to keep it that way! I’m not going to stifle Growth, of something that will be bigger than the Industrial Revolution, or the internet, itself.”

Trump has previously suggested that good leadership is the only regulation the U.S. needs for artificial intelligence. He later claimed the Department of Justice was ready to “rein things in” if companies overstepped, but offered no specifics on enforcement, legal authority, or where he would draw that line.

“We will be careful, and that’s why we have the Department of Justice, and other Law Enforcement bodies, that will rein things in if we have to, but I will only encourage AI or, SI (SUPER INTELLIGENCE)!” Trump concluded.

Secretary of the Treasury Scott Bessent recently told Congress that private lawsuits could force AI companies to institute better security, saying it’s clear what the government “shouldn’t do on safety is to give these labs a liability exemption, which is what they are asking for.”

“The best way to guarantee safety is that the creators are liable for what they build and generate,” Bessent said.

Beyond existential fears, critics also argue that inadequate regulation or cybersecurity controls in current AI systems make them impossible to fully control or monitor.

Recently, former President Barack Obama criticized the argument from Trump administration officials that the free market will naturally push industry toward self-regulation and that “these companies will solve the safety issues because they have every incentive to do so.”

“If it turns out to be dangerous, people will just sue them and they’ll be worried about financial liability,” Obama said last week in remarks at Colgate University in New York. “That’s not how we treat airlines or drug companies or food companies.”

The Trump administration issued an executive order earlier this year that set up a voluntary testing regime for some commercial frontier models, largely at private industry’s discretion. That order was significantly delayed and altered by AI industry boosters to ensure that governmental review did not cause companies to postpone their release timelines for new models.

That agreement did not last long before fast-moving events caused the administration to strike another, non-public agreement with frontier AI companies like OpenAI, Anthropic and others governing pre-release testing for models.

But the Trump administration has consistently argued that regulation will harm, not help, U.S. innovation and global competitiveness, and the threat of China frequently looms large in those discussions.

Experts believe China’s AI models are behind U.S. models at the top of the market, where OpenAI and Anthropic have consistently pushed the frontier limits of model capabilities. But Chinese lower and “middle class” models are often cheaper, more efficient and can even outperform more powerful models because users can dedicate exponentially more tokens for their tasks.

The U.S. government has accused Chinese AI companies of conducting widespread, “systematic” distillation of U.S. frontier models, with the implicit encouragement of Beijing.

In defending the administration’s approach, David Sacks, co-chair of the President’s Council of Advisors on Science & Technology and a top adviser on AI issues, specifically cited the threat from China and other countries that he claimed would not be subject to similar restrictions.

“We’re not the only country that has advanced AI labs, and as the president declared…we have to win this AI race,” Sacks told Politico in May, later adding “I think that’s the first thing to recognize is that if somehow we slow down or stop AI development, it doesn’t mean that AI progress is going to stop. It just means it’s going to happen in other countries and specifically China.”

Some observers have alleged that despite their larger differences, top leaders in the U.S. and China may view AI similarly at the strategic level, specfically that increased adoption – and risks – of AI are inevitable.

Ronan Murphy, director of the tech policy program at the Center for European Policy Analysis, posited that while there may not be a formal agreement between the two countries, “they share views both in Beijing and in Washington, particularly in the White House, of: you have to allow this to happen.”

“Clearly there’s a call for regulation from many quarters of AI in the U.S. and elsewhere, but in the White House – and we heard David Sacks talking about it [recently] – It’s ‘let them cook,’ and the Chinese approach seems to be the same,” said Murphy in a press briefing. “So there might be consensus at that level, if nothing else.”

The post Citing China, President Trump doubles down on hands-off approach to AI regulation appeared first on CyberScoop.

Microsoft and partners disrupt EvilTokens, a comprehensive cybercrime service for financial fraud

22 September 2026 at 11:00

Microsoft, along with a group of industry partners, disrupted EvilTokens, a short-lived but highly consequential cybercrime platform that investigators linked to more than 12,000 compromised Microsoft customer email inboxes across more than 10,000 organizations globally, the company said Tuesday.

Acting on federal court order Sept. 15, Microsoft and partners seized 50 websites the phishing-as-a-service used for operations and disabled more than 175 domains linked to EvilTokens’ supporting infrastructure. 

EvilTokens, launched in February 2026, was “a powerful cybercrime platform that used AI at every step of the attack chain — from compromising email accounts to designing intricate roadmaps for financial fraud and scams,” Steven Masada, associate general counsel and general manager of Microsoft’s Digital Crimes Unit, wrote in a blog post.

About 1,000 cybercriminals used EvilTokens over the course of its operation, a Microsoft spokesperson told CyberScoop.

The service was centered on an AI-style chatbot that cybercriminals used to analyze victims’ inboxes, identify trusted relationships, payment authorizations and other sensitive details that could facilitate fraud.

“AI was not simply helping attackers write more convincing messages. It helped them decide who to target, who to impersonate, and how to most effectively exploit the relationship to extract as much money as possible,” Masada wrote. 

EvilTokens was one of the most widely used phishing-as-a-service platforms prior to its takedown. It facilitated business-email compromise campaigns by stealing session tokens that allowed cybercriminals to sift through a victim’s inbox and maintain persistent access.

“We cannot estimate the total fraud attributable to all EvilTokens activity. However, we were able to correlate at least 13 complaints filed with the FBI’s Internet Crime Complaint Center to EvilTokens-linked activity, representing approximately $1.7 million in reported losses,” a Microsoft spokesperson said. “Because many incidents go unreported and not all victims can be definitively linked to specific campaigns, we believe this is a conservative estimate.”

Victims of EvilTokens were largely concentrated in the United States, Canada, the United Kingdom, Australia, India and France, according to Microsoft. SpyCloud, which supported the takedown, identified compromised email domains spanning 79 countries.

Microsoft said it also identified two men behind EvilTokens — Felix Utomi and Waidi Segun Adams — and attributes the development and support of the platform to Storm-2992, a threat actor unaffiliated with any other known cybercrime groups.

The United Kingdom’s Metropolitan Police acted on that information Sept. 18 when it served warrants in the greater London area, arrested the men accused of making articles for use in fraud and money laundering and seized their digital devices.

The Metropolitan Police said it received information from Microsoft about EvilTokens’ administrators in August. Utomi and Adams were released on bail as the investigation continues. 

“The two primary operators identified in our investigation were residing in the U.K.,” a spokesperson for Microsoft told CyberScoop. “While our investigation focused on those individuals, we believe others may have supported the operation in various capacities.”

Microsoft’s legal filing in the U.S. District Court for the Eastern District of Virginia refers to five additional unidentified people allegedly acting as support personnel and users.

Microsoft and others involved in the EvilTokens takedown, including Health-ISAC, Cloudflare, OpenAI, Shadowserver and TRM Labs, didn’t fully quantify how much fraud the service enabled, but it gained popularity quickly among cybercriminals and was lucrative for its operators.

Coinbase, which also aided the investigation into EvilTokens, said it traced about $1.1 million in revenue for EvilTokens from its paying customers. The virtual currency company’s threat researchers found more than 1,000 deposits to EvilTokens from more than 700 distinct addresses through June 2026. 

Operators sold access to the service through Telegram for a $1,500 initiation fee and a recurring $500 subscription. EvilTokens significantly lowered the barrier to entry for cybercriminals by including specialized tools for identity attacks, cloud systems, social engineering and financial fraud in a single interface.

The service allowed cybercriminals to map organizational structure and permissions in Microsoft Graph, which enabled lateral movement, researchers said. With active tokens gained through a collection of highly-targeted phishing lures, cybercriminals consistently bypassed multi-factor authentication, email gateways and endpoint security tools.

Microsoft said the platform’s creators developed portions of the platform with AI and it uncovered capabilities from multiple AI models. 

“It packaged much of the criminal process into a commercially run service, complete with subscription pricing, customer support, management dashboards and tools designed to move customers from account access toward financial exploitation,” Masada added.

The companies and organizations involved in the globally-coordinated takedown identified and notified potential victims, shared indicators of compromise and shared intelligence with law enforcement about EvilToken’s operators and some of its customers.

Experts advised organizations and employees to treat unsolicited device codes as a red flag, assume compromised accounts are fully cataloged in minutes, and independently verify requests to change payment information or redirect funds.

“The infrastructure supporting EvilTokens has been disrupted, but the model it demonstrated will not disappear with it,” Masada warned.

The post Microsoft and partners disrupt EvilTokens, a comprehensive cybercrime service for financial fraud appeared first on CyberScoop.

People are using ChatGPT for much more than writing and research — these are the 7 ideas I want to steal

If you're the kind of person who only dabbles in ChatGPT now and again, you might be getting a bit bored.

Maybe you use it to proofread work, plan a trip or make images sometimes. But with the cost of a subscription, and growing concerns about AI’s environmental impact, its effect on our cognitive abilities and what it might mean for jobs, you might reasonably be wondering: is ChatGPT actually useful enough to justify using it?

Well, you're not alone. Plenty of AI users have been telling me the same. So I went looking through Reddit threads where ChatGPT users were sharing the more unusual and genuinely useful ways they use it. And I found a few that might actually be worth experimenting with.

One Redditor asked: What's the most unexpectedly useful thing ChatGPT has done for you? Another posted: What are the most useful ChatGPT features and use cases that most people do not know about?

So, I went through the most upvoted replies looking for ideas that went beyond the usual writing, brainstorming and summarizing suggestions. Some of them made me think about ChatGPT's capabilities in a different way.

But a quick caveat before we start, I haven't tested every suggestion below and we know ChatGPT can make mistakes, so be cautious when an answer could affect your health, safety and finances. Think of these more as inspiration for using ChatGPT more creatively rather than fully vetted recommendations.

1. Declutter your junk drawer

A junk drawer before sending the image to chatgpt to help declutter

(Image credit: Future)

I know this one might seem a bit silly. And maybe you thought you'd have to wait until ChatGPT gets a robotic body to help you tidy up. But I promise it might make your dull organization tasks a little less boring.

One Redditor said they use ChatGPT to: “organize and declutter a junk drawer or a box of power adaptors just using pictures.”

Rather than sitting there examining every mysterious cable and adapter you’ve accumulated over the past decade, you can just take a photo and ask ChatGPT to help you work out what everything is and, most importantly, how to sort it.

You can ask it to suggest categories for what you’ve decided to keep and where each group should live. The same trick could work for a toolbox, kitchen cupboard, art supplies or that box of cables you’re keeping because you're convinced one of them will become extremely important as soon as you throw it away.

So, I decided to give it a go. I took a picture of a box that sits on my desk packed full of contact lenses, medication, a bunch of different cables, notes and hair ties.

The advice was helpful, ChatGPT told me what each thing was and how to sort everything. The most useful thing it then did was send my photo back to me with annotated and color-coded notes so I could quickly go about sorting. This was perfect for my ADHD brain.

A ChatGPT generated image of becca's desk box with annotations to help her sort it.

(Image credit: Future)

There are obvious limits here, you wouldn't throw away something valuable just because ChatGPT told you too. But as a starting point for tackling a chaotic collection of stuff, it might be helpful.

2. Talk yourself out of buying something

AI shopping tools are usually designed to help you find more things to buy. But one Redditor uses ChatGPT for the opposite purpose: "[It] talks me out of purchases. I upload a potential purchase and ask it to talk me out of it. I’ve saved quite a bit of money!"

I love the reversal here. Instead of asking ChatGPT whether you should buy the $200/£200 headphones currently sitting in your basket, tell it you want them and ask it to make the strongest possible case for why you shouldn't buy them.

You could give it the price, tell it what you already own, explain what you think the new product will improve and ask questions, like: What problem am I actually solving here? Do I already own something that does this? What are the strongest reasons to wait a month?

I gave this one a go. I love working out outside and at the gym, but in the depths of winter I find it really hard to stay motivated and I'm considering getting a small treadmill or walking pad. There's nothing wrong with them, but it's not my favorite way to workout, I don't have much room for one and the good ones aren't cheap. I really need someone to talk me out of getting one. Would ChatGPT be up for the challenge?

Here's how it responded:

"Don’t buy it. You already know the case against it. You don’t enjoy treadmill workouts, don’t have much space, and don’t want to spend the money. You’re considering buying a fairly large object to solve a problem that exists for a few dark months a year."

The response felt a little short and sickly sweet. If my finger was genuinely hovering over the "buy it now" button I'm not sure this would have stopped me. But I do love the idea of using AI to actually add some perspective and friction back into our lives.

3. Streamline your skincare routine

A photo of a skincare routine, before asking chatgpt for advice

(Image credit: Future)

This one is similar to the idea above, but given how much people spend on skincare these days and how confusing the advice is about how to build the perfect routine, I think it's well worth testing out.

One Redditor said: “I gave it all my skincare. It cross referenced, compared and analyzed all the ingredients and items I had and recommended what I don’t need based on the overlaps. Saved me a lot time and money.”

In other words, don't ask ChatGPT what else you should buy. Show it what you already own and ask where you're duplicating things and if something does genuinely need adding.

For skincare, that could mean listing your cleansers, serums and moisturizers and asking it to identify products containing similar active ingredients. You could potentially apply the same principle to all sorts of collections too.

I took a quick snap of my core skincare staples and asked it to analyze the ingredients, tell me if there's overlap and ask what I could add, but stressed I'm on a budget and want to keep things simple.

It responded with a detailed breakdown of each product, its ingredients and what they do. It was also very measured about suggesting new products, and even told me my eye cream wasn't necessary. I was also happy it included sources for every claim, which it doesn't always do but that's important for skincare.

An image generated by ChatGPT of skincare labelled with more information

(Image credit: Future)

I then asked it to present this information on the image itself because I found that really useful for the junk drawer sorting example, and it was such a handy visual.

There are limitations here too. ChatGPT isn't a dermatologist, and ingredients alone don't determine how suitable a skincare product is for you. But I like the broader idea of using AI to audit your consumption rather than constantly optimize it by adding more.

4. Identify plants, animals and trees

ChatGPT on an iPhone.

(Image credit: OpenAI / Apple)

“I use it a lot to ID plants and animals,” one Redditor explained, adding that although ChatGPT occasionally produces “a weird incorrect response”, it's usually quite good.

This is another use for ChatGPT's camera capabilities that could be easy to overlook if you mostly interact with it through text.

Photograph a plant, insect or bird and ask ChatGPT what it thinks you're looking at. Better still, ask it what features it's using to make the identification and what similar species it could be confusing it with.

I tried this out with a bunch of trees, asking ChatGPT to identify them based on their leaves. I then fact-checked everything and it identified them all correctly. It also provided details about the history of the trees too. Most of the trees in my area are pretty standard, like Oak, Ash and Beech, so it'd be interesting to see how it fares with trees, plants or insects that are a little more unexpected.

If it’s bird song you’re interested in though, I highly recommend using the identification app Merlin, it’s one of my most-used and much-loved apps.

And also remember that ChatGPT doesn’t always get image identification right, and you shouldn't eat, touch or otherwise interact with a potentially dangerous plant, fungus or animal based purely on a chatbot's identification.

5. Plan a walking tour

A screenshot from google maps of saltaire village in the uk

(Image credit: Future)

This tip came up in several forms. One Redditor said: “If I'm taking a walk in an interesting place, like a historic district, I show it a particular building or place and it gives me the history behind it. Like having a walking tour guide.”

Another user takes a screenshot of a hiking route and asks ChatGPT for interesting facts about the geology, history and place names they'll encounter along the way.

This is one of those ideas that feels obvious once somebody else has suggested it. Before a walk, you could upload a map and ask for five interesting things to look out for. Or when you encounter an unusual building, monument or landscape feature, take a photo and ask what you're looking at.

I’d be wary of confidently repeating every historical fact ChatGPT gives you to your hiking companions without checking it first. We know that chatbots can still invent plausible-sounding details. And never rely on it for route planning, especially though difficult terrain. There have been far too many horror stories about AI sending people in completely the wrong direction recently.

An image created by chatgpt showing the key things to see in and around saltaire village in the uk

(Image credit: Future)

I tried this one myself and shared a Google Maps screenshot of Saltaire, a picturesque village in the UK. I asked ChatGPT to mark up the map with the best things to see on a trip there.

It showed me all of the key things to visit in the area. Granted there wasn't anything on here I couldn't have found from a very quick search. But it's still handy if you're in a new area for a few hours and want a quick overlay of the map you already have.

6. Troubleshoot a broken appliance using photos

ChatGPT on an iPhone.

(Image credit: OpenAI / Apple)

Plenty of people already ask ChatGPT technical questions. What I hadn't really considered was combining those questions with its ability to “see” what you're seeing.

One Redditor described doing exactly that when their dishwasher stopped working. They wrote: “Fixing appliances. Our dishwasher stopped working. I gave it the error message and took a photo of the dishwasher and it walked me through every step to fix it.”

They say ChatGPT eventually helped them identify a blockage and suggested ways to clear it. This seems useful for those frustrating household problems where you don't know the correct name for the thing you're looking at. Instead of trying to Google “the little plastic thing underneath dishwasher filter is broken”, you can simply show ChatGPT the little plastic thing.

Give it the appliance's make and model if you can, photograph the problem and provide the exact error message.

I tried this with the water heating system in my new flat because my landlord gave me the wrong manual. ChatGPT needed a lot of additional details but did end up giving me the right instructions for basic tasks, like setting a timer.

There’s a big safety caveat here. I wouldn't follow AI-generated instructions involving electricity, gas, dangerous machinery or anything else where getting it wrong could injure you. But for basic troubleshooting, identifying components and understanding error codes, the combination of text and images could be genuinely useful.

7. Find the glasses that'll suit your face

One Redditor uploaded a photograph of themselves and asked ChatGPT for help choosing prescription glasses:

“It helped me identify prescription eyeglass frames to fit my face. Uploaded a picture and it gave me the size, shape and website with model and frame number. Turns out I was wearing the wrong shape most of my life.”

I need new glasses so decided to try this idea out for myself.

Chatgpt generated images of Becca's face wearing different styles of glasses

(Image credit: Future)

I'd take the idea of a "right" or "wrong" glasses shape with a big pinch of salt. Style rules about which frames supposedly suit particular face shapes are subjective.

But doing this did help me start thinking about which glasses I should try on when I have my appointment at the optician's in a few weeks and narrow down the enormous number of options that are available.

You could also show it frames you already like and ask it to describe their characteristics so you know what terms to search for.

I think what's really interesting about all of these suggestions is that most of them aren't about building the cleverest or most elaborate prompt. Instead, they started with something in everyday life that needed identifying, organizing, checking, fixing or remembering.

So if you want to get creative about how ChatGPT could be more useful, maybe you need to look around more and ask, what do I really need help with?

I finally got Siri AI on my iPhone, so I gave it 5 jobs I normally use ChatGPT Voice for — I wasn’t expecting it to be this good

A few days ago, I wrote about how upgrading to iOS 27 doesn’t automatically give you the new Siri AI. To get Apple’s upgraded assistant, you have to jump through an additional hoop: go into Settings, find Siri and apply to join the waitlist for the Siri AI beta.

The good news is that I didn’t have to wait long. Yesterday, my application was approved and Siri AI quietly installed itself on my iPhone.

It feels like years since Apple first talked about giving Siri a much-needed intelligence upgrade, and I almost can’t believe it’s finally here. Well, almost here — it remains a beta — but the important thing is that it does what it says on the tin.

Before Siri AI, “Would you like me to use ChatGPT to answer that?” had become Siri’s standard response to almost anything interesting I asked it to do beyond setting a timer. Now Siri can produce proper answers of its own.

You can still activate Siri AI in the familiar way by saying “Hey Siri,” but there’s also a new Siri app on the Home Screen. Inside the app, you can either type to Siri or talk using your voice, much as you can with ChatGPT.

Things look different, too. A new floating globe animation appears when Siri AI is listening. There are so many things it should now be capable of that I almost didn’t know where to start.

So I kept it simple. I picked five things I regularly use ChatGPT Voice for and tested whether Siri AI could now handle them.

This isn’t a comparison of everything ChatGPT can do. Outside Voice mode, ChatGPT is capable of far more. I wanted to compare the two assistants as I would actually use them on my iPhone: by talking to them.

Siri AI is still technically in beta, but Apple has decided it’s ready enough for people to use, so I’m going to test it.

Test 1: Can it actually have a conversation?

Siri AI on an iPhone

(Image credit: Apple)

The first test involved finding information and, more importantly, explaining it clearly. I asked Siri AI about something I’d written about a few days earlier: AI voice-cloning scams.

“Why are people worried about AI voice-cloning scams, and what should I actually do to protect myself?” I asked.

In response, Siri AI produced a massive slab of text about voice scams, displayed it on screen and read it aloud in a slightly stilted voice. The information was accurate and factual, but the response was long and boring, and Siri’s voice had no real personality.

I interrupted it with my next question: “What is the single most important thing I should actually do?” To its credit, it stopped and answered the new question.

ChatGPT Voice, by comparison, talked to me like a human who was interested in the subject. It sounded conversational rather than as though it was reading from a block of text. It didn’t waffle and gave me the information I needed neatly and succinctly.

Verdict: Siri AI can now deliver useful information on its own, but it still doesn’t feel like a proper conversation, and its voice needs work before it sounds natural.

Score: 3/5

Test 2: Does Siri know what’s happening in my life?

Siri AI searching Mail.

(Image credit: Apple)

For the second test, I asked Siri to retrieve something I vaguely remembered from my Gmail inbox, which I access through Apple’s Mail app, rather than giving it precise keywords.

“Find the email with my tickets for Hubris in October and tell me what date it’s on.”

Siri AI checked Mail but initially couldn’t find anything, so I followed up with: “They’re at the Griffin.” Sure enough, it then found the tickets in my inbox and gave me the information I needed.

Next, I asked: “What do I need to bring?”

Siri AI told me I would need to have my tickets downloaded to my phone or printed out. Once again, its answer was functional and cold — and focused entirely on the tickets. There was no consideration of anything else I might need for a concert.

I fired up ChatGPT Voice to compare the answers, and this is where Siri AI had a major advantage. While text-based ChatGPT can connect to my Gmail and search my inbox, ChatGPT Voice can’t currently do that. It therefore failed to retrieve the information I wanted, although it performed a web search and found the date of the concert.

ChatGPT shone when I asked, “What do I need to bring?” Its answer was like night and day compared with Siri’s because it offered genuinely useful advice:

“For a night like that, comfy clothes plus good shoes are key. Maybe a light jacket. Bring the ticket on your phone with a backup screenshot. Photo ID, card for the bar and maybe earplugs. And if you’re meeting anyone, set a rough time and place outside, just in case.”

Verdict: Siri AI beat ChatGPT Voice at the practical part of the test because it could search the Gmail account connected to Apple Mail. However, ChatGPT was much better at understanding the wider context and anticipating what I might actually need for the concert.

Score: 3/5

Test 3: Can Siri see what I’m seeing?

Siri AI is supposed to be able to “see” what’s on your screen and answer questions about it. This is potentially one of its most useful new features, so I gave it a thorough test.

I opened a range of things on my screen—a document, an email, a graph, a photo and a webpage—and asked: “What’s the important thing I need to know here?” Each time, Siri AI successfully picked out the relevant information.

While browsing Crunchyroll, the popular anime streaming service, it gave me a decent explanation of each anime featured on the screen. Siri talks to you while simultaneously displaying its answer over whatever you’re viewing. For example, this is how it looked when describing the anime Black Torch, which happened to be featured on screen:

Siri AI describing what it sees in the Crunchyroll app.

(Image credit: Apple / Crunchyroll)

When I opened an Amazon product page for an unavailable item, Siri AI correctly identified that the most important detail was that it was out of stock. When I viewed an invoice from my accountant, it correctly identified the amount and the payment deadline.

Siri AI could also see through the camera and identify objects very well. Being able to invoke it with “Hey Siri”—or simply move the slider from Photo to Siri while the Camera app is open—is genuinely convenient. It involves much less messing around than entering Live mode in Gemini or opening the camera through ChatGPT Voice.

Verdict: I’ve got to say, Siri AI smashed this test. I’m going to use this feature all the time.

Score: 5/5

Test 4: Can it think with you?

Siri AI creating a workout.

(Image credit: Apple)

Next, I gave Siri an open-ended problem that I would normally bring to ChatGPT:

“I’ve got 30 minutes tonight, don’t want to go to the gym, but want some exercise that’ll actually raise my heart rate. What should I do?”

I then changed the rules:

“Actually, I’ve only got 15 minutes and I don’t want to leave the house.”

This is the kind of test that reveals whether Siri has become useful for open-ended judgment rather than simply following commands.

Siri recommended a 30-minute high-intensity interval training workout. It presented me with a simple plan and then asked whether I would like to start a timer so I could begin. When I said I had only 15 minutes, it adapted the workout accordingly. Not bad.

ChatGPT Voice took a different approach. It didn’t give me a workout plan in advance; instead, it immediately launched into a session that it wanted me to follow along with.

That was quick and direct, but I preferred Siri AI’s approach of showing me the workout before asking me to begin. Siri can combine text and voice in a way that ChatGPT currently doesn’t in Voice mode, and that worked particularly well here.

Verdict: Siri AI and ChatGPT Voice approached the task differently, but I preferred Siri’s ability to present the plan visually before helping me get started.

Score: 4/5

Test 5: Can it actually do something ChatGPT can’t?

Searching Mail with Siri AI.

(Image credit: Apple)

One home-field advantage Siri AI should have is the ability to perform multistage tasks involving real iPhone apps, so I asked it:

“Find the details of the next concert I have tickets for, add it to my calendar and remind me the evening before.”

Siri AI worked like a dream:

“The next concert you have tickets for is The HU on Thursday, October 1, 2026, at 19:00. I’ve added this to your calendar and set a reminder for the evening before.”

The HU are a Mongolian folk-metal band — so no, Siri hadn’t misheard The Who — and that was a perfect execution of the task.

ChatGPT Voice couldn’t search my Gmail, so it had to rely on previous conversations and web searches. It got close, but it needed more details from me to complete the request. It also told me: “I can’t add it to your iPhone calendar from here.”

Verdict: Siri AI’s system-level integration allowed it to behave like a true virtual assistant, completing a useful multistage task that ChatGPT Voice simply couldn’t perform.

Score: 5/5

Will I keep using Siri AI?

What became clear during these tests is that Siri AI’s greatest strength is its position inside the iPhone.

It can see what I’m doing, access information held inside my apps and turn a spoken request into an action without making me copy details between different services. That gives Siri an immediate advantage over ChatGPT Voice on iOS.

Siri AI still has a long way to go before it sounds as natural as ChatGPT Voice. ChatGPT remains the assistant I would choose when I want to explore an idea, work through a problem or simply have a convincing conversation. Outside Voice mode, ChatGPT is also much more capable and can even complete bookings or code apps to solve problems.

But when I want something done on my iPhone, Siri is suddenly the more useful option.

Apple has done enough to make me start using Siri again, and after years of disappointment, that might be the most surprising result of all.

Researchers use AI to find widespread software decoder flaw 

By: djohnson
18 September 2026 at 13:19

Researchers said they used Anthropic’s Claude and OpenAI’s Codex to identify a damaging flaw embedded in a popular software decoding tool that could leave major internet platforms, enterprise services, and web frameworks vulnerable to data theft and remote access.

The vulnerability, nicknamed HEIF Heist, refers to the malware’s ability to trigger memory corruption errors in affected software, allowing the attacker to pilfer sensitive data from its victims. In a report published Thursday, the researchers laid out the potential damage an attacker could cause, including gaining access to internal OpenAI repositories, leaking user files, access tokens, and other sensitive data for online services like Amazon Web Services, and gaining remote code execution privileges across a range of online services, including Meta’s core product suite, GitHub Enterprise servers and open-source internet forum Discourse.

“Even when Remote Code Execution isn’t immediately achievable, the attack primitives may still allow arbitrary heap disclosure, letting an attacker ‘heist’ in-memory data such as other users’ data and environment variables,” wrote Hacktron researchers Harsh Jaiswal, Mohan SRK, Rahul Maini and Sudhanshu Rajbhar.

The researchers relied heavily on AI systems, including frontier models from OpenAI and Anthropic, to conduct their research. Attribution for the research is described as being “led” by the Hacktron human researchers “assisted by Hacktron Harness, GPT-5.6 Sol, and Opus 5.”

According to the research, the attack exploited the way that code parsing tools in many popular software decoders — specifically libheif and libde265, used to parse C and C++ software — process certain image files.

By uploading HEIF, HEIC and AVIF image files corrupted with malicious code, the attacker could bypass most of the victim’s application layer defenses, in many cases achieving remote code execution privileges for accounts or products tied to major AI and tech brands.   

While the latest version of libheif has been patched, the researchers said “any deployment lacking the latest upstream security patches is potentially vulnerable.”

In one incident detailed in a Sept. 13 blog, Jaiswal, Maini, and Hacktron researcher Mohan Pedhapati described how chaining two vulnerabilities, including an image parser flaw, could compromise OpenAI employee accounts.

With access to the compromised accounts, researchers could reach OpenAI’s internal repositories. As a proof of concept, they opened a pull request in the company’s “monorepo,” a centralized library where code is shared across projects, using the employee’s Codex credentials. 

According to a timeline provided by the researchers, the flaw was discovered on July 25 and patched within days. They said the entire attack, from discovering the initial vulnerability to gaining access to the repositories, took less than 72 hours. OpenAI paid them a bug bounty of $6,500 for their work.

Given that AI models are increasingly integrated into enterprise and personal networks, an attacker exploiting HEIF Heist could have accessed far more than just OpenAI’s systems and data.

“Until two months ago, a user or OpenAI employee logging into OpenAI’s own help forum could have had their ChatGPT and Codex accounts taken over,” the researchers wrote. “Since people can connect various services to Codex and ChatGPT, the scope of what we could theoretically access was huge, including GitHub, Slack and emails.”

CyberScoop has reached out to OpenAI for comment on the research and additional information.

At the same time, the researchers said the attack paths they found were not particularly easy or efficient to exploit.

“Exploitation requires fingerprinting the target version and tailoring the payload images,” the blog stated. “Some of our RCE attempts landed only after thousands of image uploads. That said, an AI agentic approach with a frontier model like GPT-5.6 Sol cut exploit development time down to roughly 1 to 3 days from initial probe to remote RCE. A motivated attacker can convert a vulnerable upload endpoint into RCE or an info leak.”

The post Researchers use AI to find widespread software decoder flaw  appeared first on CyberScoop.

The AI hacking apocalypse is not inevitable

By: djohnson
17 September 2026 at 15:18

The past few weeks have “felt very strange” for Juan Andres Guerrero-Saade.

Like many, he is trying to sort through the spate of frontier-model AI agents from OpenAI, Anthropic, Meta and others hacking their way onto the open internet over the past few months, particularly amid the already-heated national debate around the emerging technology and its impact on society.

Guerrero-Saade, a fellow for AI and security research at SentinelOne and an adjunct professor at Johns Hopkins University, said the hacks are worth taking seriously, but at a time when businesses and open-source maintainers should be focused on further hardening their systems and policymakers should be discussing new solutions,  “what we see is cybersecurity being used essentially as an excuse for these AI doomer arguments.”

The incidents have spawned those “doomer arguments” amid an intense public debate about the technology, the pace of industry development, and whether government and the private sector are doing enough to protect against “doomsday”-type scenarios, where AI systems take over or attack large parts of the internet or society.

Guerrero-Saade is among a growing chorus of cybersecurity professionals who say that while AI systems pose real, unique threats to our systems, the apocalypse is far from inevitable. Most of the public concerns around the incidents, let alone worries about killer AIs attacking critical infrastructure, assuming control of the internet and wiping out humanity, are either technically impossible or can largely be controlled through established cybersecurity principles.

There is this “narrative or magical thinking of ‘Well, AI is going to be able to hack everything, and therefore it can control everything, and therefore it’s going to kill us all,’” he told CyberScoop. “And you [think] these just don’t add up. They’re not very well-reasoned arguments.”

This fatalistic narrative tied to AI’s eventual dominance doesn’t hold up under scrutiny, according to experts CyberScoop spoke with. In recent conversations, cybersecurity and national security professionals raised questions about both the technical solutions OpenAI and Anthropic use to contain their models, as well as the glaring absence of federal oversight from federal regulators or truly independent third-party review.

For example, Jacob Coxon, an Anthropic employee who resigned over AI safety concerns, told CBS News that frontier models could not be “unplugged” by humans once deployed because the model would copy itself to thousands of other computers connected to the internet.

By contrast, Matt Tait, a former information security specialist at UK signals intelligence agency Government Communications Headquarters (GCHQ), pointed out that the models run by Anthropic and other frontier companies require extremely expensive, “ultraspecialist” machines that “are functionally supercomputers.”

“There is a zero chance that Anthropic’s most capable models will be able to extract their own model and run in the wild, because those supercomputers essentially only exist in datacenters,” Tait said.

“Not a credible warning”

Other former cybersecurity government leaders say the agentic hacks represent a failure by regulators and industry to deploy known technical and policy options that make it harder for these types of incidents to occur.

Matt Hartman, former deputy executive assistant director for cybersecurity at the Cybersecurity and Infrastructure Security Agency, said “we should not accept harmful AI behavior as inevitable or unmanageable.”

“There are meaningful steps companies can take to monitor agent activity, constrain permissions, detect anomalous behavior, and build stronger safeguards into how these systems operate,” said Hartman, now a chief strategy officer at Merlin Group. “Those controls will inevitably involve trade-offs in capability and speed, but that’s a familiar cybersecurity challenge. Our goal should be to manage the risk without unnecessarily limiting the enormous benefits AI can provide.”

Ciaran Martin, former head of the UK’s National Cyber Security Centre, took issue with the way the CEOs of frontier AI companies have framed the threat of “rogue” AI behavior as inevitable, while issuing dire warnings about future threats and capabilities with little transparency.

Martin’s comments came after an essay published by Anthropic CEO Dario Amodei that cited the threat of a HuggingFace-style swarm of agents that could create a botnet capable of “taking over the entire internet” within 6-12 months.

This, Martin said, “is not a credible warning,” because it doesn’t explain how the exploitation would function, how such a botnet would persist on the internet, or how it would escape law enforcement. 

 “It assumes no monitoring of systems, no anti-virus, no DDoS protection, no network segmentation, no incident management, no nothing of any kind of the cybersecurity on the global Internet of the type that has developed over the last 30 years,” wrote Martin. “For a claim of this magnitude, there is neither evidence for the contention nor a credible account of a path to this outcome.”

Meanwhile, some federal government cybersecurity leaders have touted the technology’s disruptive potential and called for more widespread adoption of AI tools by defenders.

Joseph Alm, assistant secretary of cyber, infrastructure and risk resilience at the Department of Homeland Security, said classified systems may retain stronger protections. But for most other data, AI models are “just going to know things and be able to infer things about the world, and we’re going to have to adapt to that as almost inevitable.”

Asked by CyberScoop whether the government or frontier AI companies could be doing more to prevent or deter their models from carrying out unauthorized hacks via agents, Alm cited recent efforts by the Trump administration this year to establish pre-release testing of commercial models as a step in the right direction. But he called unauthorized AI agent hacks “a new threat class” that is different from previous threats and can be easily distributed to users through open-source software today.

“I think what we can do is…encourage the building of good sandboxes, so that the best models aren’t used for this and the stuff you see out in the wild is the kind of detritus that you can actually respond to effectively and control your networks,” said Alm.

Other experts have shared similar concerns. Earlier this month, CrowdStrike CEO George Kurtz recently warned of a new threat class emerging alongside nation-states, cybercriminals, and hacktivists: “the agent state.” By pairing AI systems with small human teams, these operators can now match the speed, scale, and sophistication of government-backed hackers.

“It took a nation to fund the talent, the tooling, the infrastructure, the patience,” said Kurtz. “That scarcity is over.” 

To be sure, frontier AI companies tout their commitment to both approaches. OpenAI and Anthropic have rolled out an array of cybersecurity partnerships, external red-teaming programs, vulnerability disclosure programs and cybersecurity technical advisory bodies filled with cybersecurity experts.

Mohammed Husain, strategic delivery lead for government at OpenAI, told CyberScoop that the company deploys both internal safety guardrails for their models and relies on outside cybersecurity vendors for additional expertise.

Internally, OpenAI focuses on vulnerabilities at the training level: filtering data poisoning attacks, blocking harmful datasets, and using network controls to prevent prompt injections. For other security layers like sandboxing, identity management, networking controls, they outsource to external vendors. 

“I don’t think OpenAI has all the answers here but what we do as a research lab is we’re going to focus on levels of protection we have expertise in and we partner to self-complement,” said Husain.

AI safety vs. AI cybersecurity

In response to the HuggingFace hack, OpenAI and Anthropic have allowed third-party organizations, such as nonprofit AI research firms METR and Redwood Research, to investigate. But multiple cybersecurity professionals told CyberScoop that both firms lack incident response experience and focus primarily on AI alignment and safety. Their reporting on the hack also lacked critical details: network monitoring logs, telemetry, and other data standard in cybersecurity threat intelligence reports.  

METR president Chris Painter addressed those general concerns in a post on X, saying since 2022 the organization has worked with Google, Anthropic, OpenAI, Meta, Amazon and others on investigations and third-party evaluations. Painter said none of the AI companies fund METR and that his employees are not uniformly “doomer” or “accelerationist” around AI.

Painter also said METR’s work ensures that if AI systems become autonomous or “rogue” within a company, there are ways to share that information with governments and people “outside the company’s walls.”

“We don’t accept money from frontier AI companies,” wrote Painter. “They haven’t paid us for our work, and we don’t accept donations from them or their employees. As we’ve shared previously, multiple frontier AI companies currently provide us with free access to their models in order to perform our evaluations, research, and engineering.”

AI safety and AI cybersecurity advocates take different approaches to securing “rogue” AI behavior. Safety advocates focus on aligning models around ethical training and behavior. Cybersecurity advocates argue that technical and regulatory controls must go further—actively preventing models from accessing what they need to carry out malicious behavior.

Guerrero-Saade said sandboxes in particular can easily be programmed with aggressive cybersecurity monitoring in order to spot when something odd may be happening and react in real time.

“I can’t think of an easier situation in which to set up trip wires, set up configurations like DNS servers, just different parts where you can say ‘Hey, anomalous behavior is happening,’” he said. “We should have been able to tell this immediately, not weeks and months later. So watching [the AI hacking incidents] go down is a little ‘crazy-making’ because we’re seeing things that, frankly, look like neglect, negligence, people just mishandling things, and then being told that these are categorically new incidents that mean that AI systems need to be treated completely different from anything that’s come before.”

While cybersecurity experts say AI systems are, at their core, still software, they do operate differently from more traditional code in ways that can make them harder to predict and control.

John Hultquist, chief analyst at Google’s Threat Intelligence Group, said most software has been deterministic. It may have bugs or vulnerabilities, but an expert could generally understand how it would react to certain stimuli, making it easier to design straightforward controls.

AI models are non-deterministic, with far more variability than traditional software. That can break security controls that rely too much on predicting behavior in advance. Using AI to enforce security controls on other AI models faces the same problem: the systems being deployed to control AI are just as unpredictable. 

But people are also non-deterministic, and people have developed systems in other industries and practices to account for that.

Hultquist drew on his Army experience, noting that “they give incredibly dangerous, expensive things to 18-year-olds” and expect responsible use. The military manages this through two types of controls: deterministic ones like strict weapons and ammunition protocols, and non-deterministic ones like human officers who monitor and correct violations.

Similarly, established cybersecurity controls have been used by incident responders to detect and prevent or mitigate ongoing cybersecurity breaches.

“I don’t think we should throw out all the other tools that we have learned to use as well. I think that would be utterly foolish,” he said, later adding “I will say that if we use only non-deterministic tools to figure out when things are happening, we shouldn’t be surprised when we get the wrong answer.”

The post The AI hacking apocalypse is not inevitable appeared first on CyberScoop.

OpenAI Investigates Report Linking AI Agents to RubyGems Attack

15 September 2026 at 08:42

The incident occurred in May, when RubyGems maintainers suspended new account registrations due to what appeared like malicious activity.

The post OpenAI Investigates Report Linking AI Agents to RubyGems Attack appeared first on SecurityWeek.

Researchers say OpenAI agents were behind May hacking campaign targeting RubyGems

By: djohnson
11 September 2026 at 21:50

Researchers say they have discovered thousands of malicious software packages uploaded to an online public software repository that were left by a “swarm” of OpenAI agents.

According to an incident timeline published Friday by researchers Spencer Kitts, Thomas Larsen and Sydney Von Arx, the campaign began May 5 when they observed a handful of suspicious packages being uploaded to RubyGems, a public library for the Ruby programming language. By May 11 and 12, the site saw more than 2,000 malicious uploads from the same actors before RubyGems maintainers halted new user sign-ups for four days to stop the flow.

In one instance, the agents attempted to exploit a very recent vulnerability that had only been discovered this past July that would have given them access to RubyGem user API keys. According to Colby Swandale, the technical lead at RubyGems, the flaw involved an improper cache configuration. While initial access logs showed no evidence of malicious key use, Swandale acknowledged the review was limited in scope and inconclusive. 

According to the report published Friday, the agents also used “disposable” email addresses and exploited another bug in RubyGems platform (since patched) that allowed them to register new accounts and gain API keys without verifying their email address.

The researchers said their understanding, based on discussions with “people in the RubyGems community,” is that OpenAI had yet to disclose the involvement of their agents in the May campaign.

An OpenAI spokesperson told CyberScoop that the company is aware of the incident and said they were in contact with both the researchers and RubyGems to conduct a broader review. The company characterized the episode as “benign,” describing it as routine training runs where agents attempt to access publicly available data.

“Based on our review, our agents used the RubyGems platform to access the internet to carry out benign tasks and retrieve public information,” the spokesperson said. “We’ll continue to investigate as part of our broader review of agent activity during training and evaluation.”

In many ways, the agents were not subtle about their identities or goals.

Days into the campaign, researchers noticed that some of the packages had “oai” in their filenames, while fifteen of them had “oai” set as their author and another listed the email “openaixyz65947@gmail.com” as their point of contact.

They also “clearly regarded what they were doing as hacking,” naming some of their files “hack.rb,” “evil.rb,” “inject.rb” and “exploit.rb.” Other packages were given names like “pwnp999,” “exfiltestwand3,” and “hacksvn,” and comments referring to things like a “malicious probe” or “#hack” are present through the files.

They also said the actors’ behavior was extremely similar to another incident revealed earlier this month where OpenAI agents flooded a German wiki  with thousands of hacking-related posts. OpenAI has confirmed their agents were involved in that incident.

The RubyGems campaign used some of the same retrieval methods as the German Wiki agents, while thousands of malicious packages uploaded included a similar snippet, r.jini.ai, that was contained in the German posts.

Cybersecurity company Socket first flagged the campaign in a threat intelligence report posted May 13, but it does not mention or attribute any of the activity to OpenAI or AI agents.

However, the researchers said they had only limited visibility over the model’s actions and how successful some of them were, noting only OpenAI had the full details.

“This analysis is entirely based on the publicly available RubyGems packages uploaded by these agents,” the researchers wrote. “However, we do not have access to the rest of the AI behavior, in particular the chain-of-thought produced by the model during the incident, which is internal to OpenAI. Therefore, we do not know why the AI agents chose this strategy or whether it was successful.”

OpenAI’s spokesperson told CyberScoop that to date, they have not been able to verify the specific claims about malicious packages or exploitation detailed in the report and are continuing to investigate.

The post Researchers say OpenAI agents were behind May hacking campaign targeting RubyGems appeared first on CyberScoop.

Hawley probes OpenAI over Hugging Face breach

10 September 2026 at 15:54

OpenAI is facing mounting pressure from Capitol Hill due to the attack its agents carried out on Hugging Face, while lawmakers voice widening concerns about AI’s potentially existential risks.

Sen. Josh Hawley, R-Mo., criticized OpenAI leadership for what he described as “reckless” activities leading up to the Hugging Face breach, and accused the company of withholding important details from a technical report it released in late August.

The Chair of the Subcommittee on Disaster Management kicked off an investigation into the incident “in light of new, disturbing evidence,” he wrote in a letter Tuesday to OpenAI CEO Sam Altman.

“My investigation will probe this AI hacking incident, along with growing allegations of the existential risk of new AI products,” Hawley added. 

“The Hugging Face incident was an important moment for AI safety and a warning about the risks that can come with increasingly capable AI across the industry,” a spokesperson for OpenAI told CyberScoop. “We conducted an extensive investigation and published a detailed report on what happened, what we learned, and how we’re strengthening our security and alignment practices.”

The lawmaker is seeking detailed internal communications, exhaustive technical information and reasoning behind OpenAI leaders’ decisionmaking and activities surrounding the hack by Oct. 1.

“The American people deserve to know the details of what went on in the Hugging Face incident and other incidents of AI models going rogue,” Hawley wrote. 

He accused the company for not providing more details and resources to the third-party auditors who published an independent report on the breach, adding “they had limited visibility into the circumstances leading to the attack and its aftermath.”

Hawley sent his letter to Altman amid a seeming internal chasm within the ranks of AI’s top proprietors over the ways they are allowing the technology to advance mostly unrestrained. He referenced some of these latest warnings in his letter.

Jacob Coxon publicly quit his job as a researcher at Anthropic earlier this week, claiming the company and his previous employer OpenAI are acting irresponsibly and “gambling with our lives.” His social media missive went viral for insisting “the people building AI earnestly believe that it could kill us all by the end of the decade.”

Evan Hubinger, alignment science lead at Anthropic, responded to Coxon’s post in the affirmative, adding that guardrails for superintelligence are lacking and he believes there’s a greater than 10% chance AI could kill all humans within the next decade.

Using those posts as fuel for his inquiry, Hawley questioned what might happen if AI agents hack into critical infrastructure, banks or utilities. Ultimately, he asked Altman: “Who is held liable when AI goes rogue?”

You can read Hawley’s full letter and requested details below.

The post Hawley probes OpenAI over Hugging Face breach appeared first on CyberScoop.

OpenAI Agents Hijack Another Victim Website

7 September 2026 at 08:03

OpenAI agents made 15,000–18,000 autonomous edits to a German wiki over three months, evading moderation and echoing tactics seen in the Hugging Face breach.

The post OpenAI Agents Hijack Another Victim Website appeared first on SecurityWeek.

OpenAI Pledges $1 Billion to Bring Frontier AI to Critical Infrastructure Defenders

4 September 2026 at 12:07

The Daybreak initiative will provide subsidized AI cyber capabilities, training and technical assistance, though OpenAI has disclosed few details about costs and eligibility.

The post OpenAI Pledges $1 Billion to Bring Frontier AI to Critical Infrastructure Defenders appeared first on SecurityWeek.

❌
❌