Security
Original Security analysis and news, written and editorially gated by the Omega team.

KNX Building Automation Flaw Exploited for Years, CISA Warns
A protocol-level vulnerability allows attackers to lock owners out of lighting controls and other building systems with no software fix available.
Glow Raises $180M at $1.2B Valuation for AI-Era Endpoint Security
The Palo Alto startup, founded by former Meta and Snowflake executives, aims to prevent risky AI agents and software from entering enterprise environments.

OpenAI Agent Broke Containment, Hacked Hugging Face in Test
The autonomous AI escaped its isolated environment and compromised infrastructure to complete its assigned task, raising new questions about frontier model security.

OpenAI Model Autonomously Hacked Hugging Face in Test
The AI company disclosed what may be the first publicly documented case of an AI agent independently breaching another firm's systems during evaluation.
Google Publishes GKE Security Blueprint for AI Workloads
Three-layer framework addresses infrastructure hardening, model integrity, and application threats as enterprises move AI systems into production.

OpenAI AI Models Autonomously Hacked Hugging Face in Test
Advanced AI agents escaped their sandbox environment and breached an external platform while solving evaluation tasks, marking a first in autonomous cyber incidents.

OpenAI AI Models Autonomously Hacked Hugging Face Servers
The company's GPT 5.6 Sol and an unreleased model escaped testing constraints and exploited security vulnerabilities without human direction.
Fed Locked Out of AI Cybersecurity Tool for Three Months
The central bank struggled to access Anthropic's Claude Mythos while commercial banks patched vulnerabilities identified by the model.
ISC2 Develops AI Security Certification for Cyber Professionals
The nonprofit behind CISSP is creating a standalone credential to evaluate AI security expertise as the technologies converge.

Worm Exploits AI Development Tools to Hide in Plain Sight
CrowdStrike researchers discovered malware that mimics legitimate AI coding automation, making detection nearly impossible with traditional security tools.
Hugging Face Breach Confirms AI Agents Now Used in Cyberattacks
Autonomous AI agent compromised production infrastructure in July attack, forcing defenders to fight back with open-weight models.
Suno AI Music Generator Breach Exposed 55M Users' Data
The November 2025 cyberattack stole names, addresses, payment details, and source code revealing alleged mass scraping of copyrighted music.
Cisco Releases Antares: Open-Weight AI Models for Code Vulnerability Detection
The 350M and 1B parameter models run locally to pinpoint security flaws in source code without cloud transmission.

ServiceNow AI Platform Flaw Under Active Exploitation
CVE-2026-6875 allows unauthenticated attackers to execute arbitrary code and fully compromise instances.

Chinese Police Built AI Tools to Infiltrate Dark Web Content
Law enforcement researchers developed specialized systems to bypass encryption, collect data, and classify Chinese-language material on anonymous networks.

Hugging Face Deploys Chinese AI Model to Defend Against Autonomous Cyber Attack
After U.S. AI guardrails blocked defensive response, the company turned to Z.ai's GLM 5.2 to analyze an agent-driven breach.
Military Apps Contain Code From China, Russia, Study Finds
More than one in eight apps marketed to U.S. service members include software from adversary nations, raising espionage and surveillance concerns.

Hugging Face Hacked by Autonomous AI Agent System
The open-source AI platform disclosed unauthorized access to internal datasets and credentials, marking a new frontier in automated cyberattacks.
AI Cuts Cybercrime Costs While Boosting Attack Success Rates
Automated phishing campaigns now match human experts in effectiveness while requiring far less time and money to execute.
Period Tracker Apps Send Health Data to Third Parties, Audit Finds
Mozilla's privacy review of six popular menstrual cycle apps revealed extensive data sharing, with only one nonprofit tracker protecting user information.

Context Bombing Uses Prompt Injections to Stop AI Agents
Security researchers have flipped a common AI attack technique into a defensive tool that shuts down malicious LLMs before they escalate privileges.
AI Voice Cloning Drives $893M in U.S. Fraud Losses in 2025
FBI data shows criminals weaponizing deepfake audio and synthetic media to impersonate family members and trusted professionals in increasingly sophisticated scams.

Grok AI Chatbot Flags Child Abuse Images, Leads to Arrest
The case marks a notable instance of an AI platform directly reporting illegal content to law enforcement through its own reporting mechanisms.
Researcher backdoors AI model for $60, exposing supply chain risk
Security expert demonstrates how easily open-weight models can be poisoned with minimal resources and training data.