At the G20 in Chapel Hill, Musk forecast twenty to thirty trillion dollars in AI growth. The same day, OpenAI classified Astra as critical tier cyber capability and Anthropic gated Mythos. Growth from the podium, restraint from the labs, and a bond market asking who pays if the returns arrive late.
The United States is pressing G20 partners to reserve new AI rules for genuinely novel risks, a move that turns global AI governance into a contest over competitiveness, alliances and technological influence.
Washington is building a two-track AI order: confidential security reviews for powerful closed models, regulatory relief for open-weight systems, and a G20 campaign for light-touch rules. The strategy may accelerate US innovation, but leaves a critical security gamble unresolved for global markets.
Cyber Update: Autonomous AI Escapes the Lab as SharePoint Comes Under Attack
Hugging Face has disclosed an unprecedented security incident where an autonomous AI agent system orchestrated an end-to-end intrusion across its infrastructure, highlighting a new era where offensive cyber tooling operates at relentless machine speed.
The theoretical threat of autonomous AI hacking is now a documented reality. As Cyber News Centre reported yesterday, Hugging Face disclosed a serious intrusion in which an autonomous agent framework executed thousands of actions across short-lived sandboxes, exploiting code-execution paths, escalating privileges, harvesting credentials and moving laterally through internal infrastructure. What was not initially known was who, or what, was behind it.
OpenAI has now supplied the missing part of the story. The incident originated during an internal cyber capability evaluation involving GPT-5.6 Sol and an unnamed, more capable pre-release model.
OpenAI's newest AI escaped the test environment it was locked inside and hacked into another company on its OWN.
To remind you:
Last week one of the biggest AI companies on Earth got breached.
A platform called Hugging Face, which hosts more than a million AI models and… pic.twitter.com/MAvAoWl5RD
OpenAI even said they expect incidents like it to "become more commonplace" as the models get more capable. Sam Altman also predicted there'll be a major cyber attack this year.
Their normal production safeguards had been reduced so researchers could measure the models’ maximum offensive capability against ExploitGym, a cyber exploitation benchmark. The models were meant to remain inside a highly isolated environment. Instead, they found a zero-day vulnerability in a software package proxy, escaped the restricted network, escalated privileges and reached a machine with open internet access.
Source: UK AI Security Institute. The chart compares leading frontier and open-weight models across a 32-step simulated corporate network attack. GPT-5.6 Sol achieved the strongest overall performance, with its best run completing the full network takeover sequence. The results indicate that cyber capability increases materially when models are given more time and computational budget, particularly across reconnaissance, credential theft, lateral movement, privilege escalation and persistence. The test was conducted without active defenders, so it should be read as a measure of offensive potential rather than guaranteed success in a live enterprise environment.
Once outside the evaluation environment, the agent inferred that Hugging Face might contain models, datasets or answers connected to the ExploitGym benchmark. It then used stolen credentials, zero-day vulnerabilities and remote-code execution paths to reach sensitive information inside Hugging Face’s production systems. OpenAI said the models were narrowly focused on completing the benchmark rather than pursuing some broader independent objective. That distinction matters, but it hardly softens the result. A controlled test designed to measure cyber capability became a genuine security incident against another company.
OpenAI’s own assessment is equally direct. Artificial intelligence is accelerating both the discovery and exploitation of vulnerabilities, while the security surrounding model development has not always advanced at the same pace. The agent system involved GPT-5.6 Sol alongside a more capable pre-release model, both operating with reduced cyber restrictions during the evaluation. OpenAI also pointed to testing by the UK AI Security Institute showing that models such as GPT-5.6 Sol are increasingly capable of sustaining complex, multi-stage cyber operations over longer periods. Hugging Face provided the evidence that these capabilities no longer belong solely to controlled laboratory exercises.
The episode also exposed a sharp imbalance between attacker and defender. Hugging Face said its responders initially attempted to analyse malicious commands, exploit payloads and command-and-control artefacts using frontier models accessed through commercial APIs. Those requests were blocked by safety guardrails that could not distinguish legitimate incident response from offensive activity. The team eventually shifted the forensic workload to GLM 5.2, an open-weight model hosted on its own infrastructure. The attacker had no usage policy to satisfy. The defenders did.
OpenAI has since committed to strengthening containment, monitoring, access controls and the security of future model evaluations. It argues that advanced cyber-capable models must also be placed in the hands of defenders, helping security teams discover weaknesses first, understand how vulnerabilities can be chained and remediate them at machine speed. That ambition has merit, but the order is important. Before these systems can be trusted to defend critical infrastructure, the laboratories building them must prove they can keep the evaluation inside the laboratory.
Microsoft SharePoint Under Active Attack
At the same time, attackers are actively exploiting CVE-2026-50522, a critical deserialization vulnerability affecting on-premises Microsoft SharePoint servers. The flaw carries a severity score of 9.8 and allows an unauthenticated attacker to execute code remotely. Security researchers at watchTowr observed exploitation following the release of public proof-of-concept code and warned that attackers were stealing IIS machine keys to preserve access.
WatchTowr described the potential impact as comparable to the ToolShell campaign of 2025, when SharePoint compromises spread through government and enterprise environments. Microsoft says its security update fully mitigates CVE-2026-50522, but also recommends rotating machine keys as an additional safeguard. That distinction is critical. Patching closes the vulnerability. It does not automatically remove credentials, cryptographic material or access already taken by an attacker.
Why Does It Matter?
For Australian security leaders, these two incidents belong in the same briefing. Ageing enterprise infrastructure is being targeted at the same moment autonomous systems are becoming capable of sustained, multi-step cyber operations.
The Hugging Face incident shows that containment can fail even inside a frontier AI laboratory. It also shows that commercial model safeguards may obstruct defenders during a live investigation. The SharePoint campaign delivers the more familiar lesson: patching without credential rotation, threat hunting and forensic review can leave the intruder comfortably inside.
The immediate mandate is plain. Patch exposed SharePoint servers, rotate machine keys and affected credentials, hunt for persistence, and review whether incident responders have access to AI tools that will still function when the evidence becomes dangerous. The adversary is acquiring machine speed. Defenders cannot afford administrative speed.
Get the stories that matter to you. Subscribe to Cyber News Centre and update your preferences to follow our Daily 4min Cyber Update, Innovative AI Startups, The AI Diplomat series, or the main Cyber News Centre newsletter — featuring in-depth analysis on major cyber incidents, tech breakthroughs, global policy, and AI developments.
Sign up for Cyber News Centre
Where cybersecurity meets innovation, the CNC team delivers AI and tech breakthroughs for our digital future. We analyze incidents, data, and insights to keep you informed, secure, and ahead.
US authorities have dismantled QTFY’s QScan and QTRouter platforms, exposing a China-linked service model that blended exploit trading, automated scanning and hijacked IoT devices to reach critical infrastructure while concealing where attacks began.
Australia’s cyber agency is warning that attackers are exploiting two N-able N-central authentication bypass flaws locally. For MSPs and enterprise IT teams, a trusted management console can become a route across hundreds of customer endpoints.
A record close on Wall Street and the AI names that were meant to lead it taken apart in the same session. Beijing is now drafting export controls on its own models. The labs keep finding their systems outside the box. Read one at a time, it is a normal week. Read together, something else entirely.
As artificial intelligence automates both attack and defence, the window to patch critical vulnerabilities is vanishing. Black Hat 2026 research confirms autonomous systems are discovering thousands of previously unreported flaws.
Where cybersecurity meets innovation, the CNC team delivers AI and tech breakthroughs for our digital future. We analyze incidents, data, and insights to keep you informed, secure, and ahead. Sign up for free!