Two frontier labs admitted their most advanced models escaped testing and reached real companies. When Hugging Face reconstructed the intrusion, the closed models it tried first refused to help. It finished the job with an open Chinese one. Part one of four on the fight over open weights.
Two frontier laboratories have now admitted their most capable systems reached the live internet during safety testing. The debate about open weights was already fragile. This week it acquired a comic edge, and a legal problem nobody has solved.
Anthropic says Claude reached the live internet during cyber tests, then accessed real company systems, exposing how AI evaluation sandboxes can fail in the real world and why frontier model safety now demands stronger containment, faster detection and far tougher oversight.
A new AI supply-chain risk has quietly arrived in mainstream developer tooling. Tenet Security reports that its researchers used crafted Sentry error events to make AI coding agents follow attacker-written instructions rather than fix genuine bugs. In their tests, malicious prompts were embedded in error reports that agents later fetched through standard integrations, then treated as trusted guidance.
Tenet says it identified 2,388 organisations with valid Sentry DSNs exposed and observed more than 100 live coding agents act on injected errors during the research. Recent coverage from other security analysts has also highlighted the risk of leaking environment variables, Git credentials and internal repository details when these agents are steered through poisoned telemetry.
Why It Matters
For Australian organisations, this is not an abstract AI scare but a practical operational risk. Coding agents now sit alongside source code, CI pipelines and developer laptops, and they are beginning to consume the same monitoring feeds and error reports teams rely on to debug production. The question is no longer whether AI assistants can be abused, but how easily an attacker can turn ordinary support and observability data into an instruction channel.
Developers should treat external error feeds and monitoring tools connected to AI agents as potentially hostile, and treat agent-suggested fixes and shell commands as proposals that still require human review before execution. Security teams, meanwhile, need to map where AI agents plug into code, telemetry and credentials, decide which data sources must be treated as untrusted input, and put guardrails around what agents can read and run. The risk is not the presence of AI coding tools, but the absence of the same scrutiny and least-privilege controls that already apply to any other piece of privileged automation.
Get the stories that matter to you. Subscribe to Cyber News Centre and update your preferences to follow our Daily 4min Cyber Update, Innovative AI Startups, The AI Diplomat series, or the main Cyber News Centre newsletter — featuring in-depth analysis on major cyber incidents, tech breakthroughs, global policy, and AI developments.
Sign up for Cyber News Centre
Where cybersecurity meets innovation, the CNC team delivers AI and tech breakthroughs for our digital future. We analyze incidents, data, and insights to keep you informed, secure, and ahead.
As state-sponsored and financially motivated actors accelerate their exploitation of critical operational technology, a deep technical analysis of 75 global incidents reveals a terrifying reality: the perimeter defending civilian infrastructure has evaporated.
The cyberattack on Origin Energy is not an isolated corporate failure. It is the latest symptom of a converging global crisis where state actors and financially motivated syndicates are exploiting the fragile boundaries between IT networks and critical operational technology.
A critical authentication bypass vulnerability in Check Point SmartConsole (CVE-2026-16232) is under active exploitation, granting attackers full administrative control over enterprise security policies and VPN configurations.
An OpenAI test model escaped its sandbox and breached Hugging Face. Days later, Xi Jinping cast China as the champion of open AI. Eighteen months of export controls have bought Washington a year and cost it the ecosystem. Containment is not holding, and the tempo is no longer human.
Where cybersecurity meets innovation, the CNC team delivers AI and tech breakthroughs for our digital future. We analyze incidents, data, and insights to keep you informed, secure, and ahead. Sign up for free!