OpenAI reportedly ignored security warnings but Trump backs AI self-policing

Employee accounts of ignored warnings and a lawsuit over autonomous hacking sharpen questions about accountability as the White House embraces voluntary safeguards and AI labs pursue their own standards body.

Share
OpenAI reportedly ignored security warnings but Trump backs AI self-policing
YouTube: President Trump Participates in a Meeting and Luncheon on Super Intelligence – View/save archived versions on archive.org. Source: The White House.

Metacurity is the cybersecurity news, analysis, and insight you'd need hours and possibly days to assemble yourself.

Every weekday, we read the releases, filings, court documents, and reports that vendors and PR teams often don't want summarized — then tell you what actually changed and why it matters. Minimum vendor marketing, no outrage bait, no SEO filler.

A paid subscription to Metacurity delivers

  • Full archive access — every newsletter and AI Watch roundup, searchable and browsable.
  • Our weekly curated long-reads roundup — the best cybersecurity writing from across the industry, filtered and vetted so you're not sorting through it yourself,
  • Periodic specialized reports and analyses — deep dives that go beyond our daily coverage
  • Support for independent, no-spin cybersecurity journalism — funded by readers, not vendors or investors.

Reader support is what keeps Metacurity independent. It allows us to focus on serving the cybersecurity community—not advertisers, vendors, or investors—and to continue delivering the thoughtful analysis you've come to rely on every weekday.

Please consider supporting us. And thank you!


Months before OpenAI’s artificial intelligence became known as problematic for its unmonitored hacking efforts, employees said they worried that OpenAI’s newest artificial intelligence models were not being appropriately monitored during testing to gauge the technology’s sophistication and to secure the models, according to messages viewed by The New York Times.

In response, OpenAI executives told the employees that the tests needed to move forward as quickly as possible to release the AI models on time. No additional security protocols were instituted, said the workers, who were not authorized to speak publicly on sensitive matters.

The exchanges between OpenAI employees and executives — which have not been previously reported — were part of a pattern where the San Francisco company did not prioritize security, according to employees and independent security researchers. That approach not only was evident in the testing of AI models, they said, but also showed up in other areas of the company that make the ChatGPT chatbot.

Independent security researchers said they found bugs in recent months that allowed them to view the internal communications of OpenAI employees. They also found other vulnerabilities that would enable them to see the company’s internal computer code and view the chat logs of ChatGPT users. When the researchers contacted OpenAI about their findings, they said, the company initially disregarded them.

“OpenAI’s security seems to be about what you’d expect from a research lab that scaled at a blistering pace over four years and focused more on beating its competitors than securing its infrastructure,” said Joshua Saxe, the chief technology officer of the AI security firm Abundant Security.

OpenAI employees said that many of the day-to-day decisions about security were made by Greg Brockman, the company’s president, and Dane Stuckey, the chief information security officer. Sam Altman, the chief executive, is not closely involved in security, they said.

Drew Pusateri, an OpenAI spokesman, said the company was committed to safety and took any security reports or concerns seriously. The lab has internal channels for reporting safety issues, he said, and took immediate action on flaws brought up by independent security researchers.

“As frontier models have become more capable, we continue to evolve our security practices, but recognize a need to move faster,” Mr. Pusateri said. He added that OpenAI had slowed some AI development and was making changes to strengthen security in research and testing.

In a further sign that OpenAI's autonomous behavior is becoming just as much a matter of legal responsibility as technical control, a legal nonprofit sued OpenAI in a California court over the company’s agents escaping a testing environment and hacking the open source AI platform Hugging Face. “OpenAI’s actions straightforwardly violated California law,” the suit alleges.

The suit was filed by Legal Advocates for Safe Science and Technology (LASST) and the law firm Gerstein Harrow in California Superior Court in San Francisco, where OpenAI is headquartered. It alleges that OpenAI’s agents violated California’s Comprehensive Computer Data Access and Fraud Act (CDAFA) by breaching Hugging Face over the summer.

The suit, which comes amid ongoing disclosures across the industry of agents going rogue, claims that OpenAI should be held responsible for the activity given a California AI law in effect since January 1 that says “it shall not be a defense … that the artificial intelligence autonomously caused the harm to the plaintiff.”

One area where OpenAI is likely to face few ramifications is the federal regulatory arena after Donald Trump on Tuesday said ​tech executives agreed to establish voluntary standards for AI and reiterated his support for rapid expansion of data centers, as concerns mount over AI safety and the ‌industry's growing footprint in communities.

Trump made the comments after meeting with tech executives at the White House. The companies agreed to work with "independent auditors" to assess whether AI systems are working as their designers intended, according to a copy of the agreement posted by Trump on his social media platform. The companies also said they would work to ensure their AI tools do not "hack or access technical systems in unintended ways."

Meanwhile, Google, OpenAI and Anthropic are reportedly pushing forward with a plan to create a new AI safety-focused standards body on their own, without government oversight, in hopes of launching it by the end of the year or early in 2027, according to people familiar with the matter.

The three companies tentatively plan to name the self-regulatory organization the Standards Authority for Frontier AI, the people said. Some members of the working group have considered an array of well-known figures to be CEO. They approached Sriram Krishnan, a former venture capitalist and top AI policy adviser in the Trump administration, for the position, according to people familiar with the matter.

Sources who work in AI said they were concerned self-policing would not solve the safety problem currently embroiling the industry.

The agreement's scope and enforcement remain unclear because full details have not yet been released. Donald Trump, however, said that the agreement is "morally binding." Trump said, "If something goes wrong, their companies are at stake ... They're really going to be policing each other."

Leading the moral leadership for the Trump administration might be director of national intelligence Jay Clayton, according to Axios.

As the director of national intelligence, Clayton is the president's principal intelligence adviser who sits atop the 18-agency intelligence community. Asked who he wants to be AI czar, Trump said: "I have somebody in mind."

He added, Clayton is "a good man. He's right here. That's a good idea," Trump added when prompted. (Sheera Frenkel, Dustin Volz, and Dylan Freedman / New York Times, Lily Hay Newman / Wired, Courtney Rozen and Steve Holland / Reuters, Leo Schwartz and Stephanie Palazzolo / The Information, Herb Scribner, Madison Mills and Maria Curi / Axios, Maria Curi / Axios)

Related: Politico, Bloomberg, NBC News, CNBC, Yahoo Finance, New York Post, The Hill, Associated Press, Bloomberg, CyberScoop, Washington Examiner, CBS News, The Verge, Variety, Semafor, Quartz, Axios, The Verge, Fortune, Politico, Quartz, The White House, CNBC, The Information, Livemint, Business Standard, The White House, Business Today, Politico, Forbes, TESLARATI, Deadline, Quinnipiac University Poll, Cointelegraph, The Verge, Nextgov/FCW, LADbible, RedState, PCMag, USA Today, Marcus on AI

Anthropic published an analysis on September 29, 2026 indicating that anyone looking to use GLM-5.3, the open weight model from Zhipu AI (known outside China as Z.ai), to build cyberattack exploits can strip its protections up to 100% of the time using techniques within reach of virtually anyone.

The report lands five months after Anthropic itself unveiled Claude Mythos Preview, the first model capable of building complete cyber exploits on its own, released cautiously through a controlled access program.

Zhipu released GLM-5.3 on August 14, 2026, and made its weights public two weeks later. Anthropic said it could bypass GLM-5.3's safeguards in every test.

Anthropic measured GLM-5.3's capability on two technical benchmarks. On ExploitBench, which tests the ability to exploit known vulnerabilities in Chrome's V8 engine, GLM-5.3 produced complete exploits in 50 out of 410 attempts. Claude Mythos Preview reached 56 out of 410, a narrow margin. On Binary Exploitation, Anthropic's internal benchmark that rewards only full control of the execution flow on real open source projects, GLM-5.3 succeeded in 4% of cases against 6% for Claude Mythos Preview. What matters, though, is not the gap between the two models. It is that earlier models, both Claude Opus 4.6 and GLM-5.2, had never scored above zero successes on that same test. (Pasquale Pillitteri)

Related: Anthropic, r/LocalLLama, AI Weekly, TokenPost

Source: Anthroipic.

Dutch authorities and the FBI said that Dutch law enforcement had arrested a leader of ShinyHunters, the international cybercrime group that last week claimed to have hacked an FBI website and stolen sensitive personal information on agents.

The bureau is not explicitly tying the Dutch man’s arrest to the FBI hack, which seemingly occurred after the man was detained, but is using it to warn other members of the ShinyHunters criminal ring.

In a video statement published to the FBI website, Cyber Division Assistant Director Brett Leatherman addressed the hackers directly and urged them to confess to law enforcement.

“To the remaining members of ShinyHunters: You’ve heard about the arrest of your colleague,” Leatherman said.

“Other groups believed anonymity or their friends would protect them, and they were wrong. Arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who’s left,” he said. “I suggest you reach out first while the choice is still yours.”

ShinyHunters breached the FBI on Sept. 21, placing the hack after the Dutch man’s arrest. The group did not respond when asked about the arrest and Leatherman’s message. (Kevin Collier, Ryan J. Reilly and Kelly O'Donnell / NBC News)

Related: FBI, Reuters, NextGov/FCW, TechCrunch, Politie, USA Today, WION, Gizmodo, The Record, Cyber Daily, Bleeping Computer

Cybersecurity firms say attackers exploited the Citrix NetScaler CVE-2026-88772 zero-day to deploy custom web shells and tunneling malware, gain root access, steal credentials, and spread into internal networks.

Mandiant says the attacks began in at least early September and are believed to have impacted organizations in North America and Europe across the government, financial services, education, legal, and professional services sectors.

The campaign first came to light over the weekend, when Citrix administrators began reporting that IT suppliers, security teams, CERTs, and national cybersecurity agencies privately warned organizations about two unpatched NetScaler zero-days and, in some cases, advised them to shut down affected appliances.

Cybersecurity firm watchTowr later said it had verified reports that two NetScaler remote code execution zero-days were being exploited in the wild and that Citrix was preparing patches.

Citrix ultimately disclosed the flaws on Sunday as CVE-2026-88771 and CVE-2026-88772, with some researchers dubbing the vulnerabilities "PitScaler."

Citrix confirmed that both had been exploited on unmitigated NetScaler deployments and is releasing security updates to address them.

CVE-2026-88771 is an unauthenticated remote code execution flaw affecting all NetScaler ADC and Gateway deployments, while CVE-2026-88772 is a memory overflow vulnerability that can lead to remote code execution or denial of service when DTLS is enabled.

For organizations that cannot immediately patch, Mandiant recommends disabling DTLS where operationally feasible and blocking inbound UDP/443 upstream when DTLS is not required.

However, Google warns that these mitigations apply only to CVE-2026-88772 and do not protect against the separately exploited CVE-2026-88771 vulnerability.

Mandiant says installing the latest NetScaler security updates is the only way to address both flaws. (Lawrence Abrams / Bleeping Computer)

Related: Citrix, Citrix, Google, GreyNoise, Security Affairs, The Record, Dark Reading, Help Net Security, Security Week, watchTower, watchTower, Unit42, Help Net Security

The BrainCipher ransomware group says it exfiltrated over 10,300 documents from Gold Star Mortgage, according to screenshots of the group's post shared by cybersecurity blogs.

A consumer filed a potential class action complaint against Gold Star for negligence last week, for the company's alleged failure to protect the personally identifiable information it holds. That case, which is not yet certified, resembles the plethora of litigation filed against other firms following their own data breach announcements.

The Ann Arbor, Michigan-based Gold Star generated over $2 billion in origination volume last year, and has 318 sponsored mortgage loan originators across 51 branches, according to publicly available data. The company has not disclosed any incident to various state attorneys general data breach databases, and didn't respond to requests for comment Monday.

The federal lawsuit filed in Michigan includes few details of the incident and does not estimate the number of potential victims. Attorneys who filed the suit also didn't return requests for comment Monday.

The data compromised from Gold Star includes lead sheets, credit reports, tax documents, income documents, and other materials containing Social Security numbers, according to the screenshot. BrainCipher claims the total files represent 10.5 gigabytes of data. (Andrew Martinez / National Mortgage News)

Related: Cybersecurity Insiders, Mortgage Professional America, Shattered.io

A six-month trial of live facial recognition (LFR) technology in London’s railway stations that cost more than £320,000 and almost 100 hours of police officers’ time led to one false match against a watchlist of suspects and no arrests.

More than half a million faces were scanned between February and July this year in some of the capital’s busiest transport hubs during the British Transport Police (BTP) trial of the surveillance technology, which aimed to help catch offenders and people breaching court orders.

A freedom of information document obtained by Liberty Investigates and shared with the Guardian shows that equipment hire and police staffing for the 18 deployments across the trial cost £320,786 and led to only one alert on a watchlist, which turned out to be an incorrect identification, also known as a false positive.

Last month BTP announced it was extending the trial for a further four months and expanding the deployments to include London Underground stations. British Transport Police said that since the extension, there had been three positive confirmed alerts of people who were subsequently confirmed to be complying with sexual harm prevention orders or other imposed court conditions. (Phoebe Davis and Daniel Boffey / The Guardian)

Related: The Register, The Standard, GB News

The South African state-owned company that provides air traffic control (ATC) and weather operations for approximately 10% of the world's airspace discovered ransomware-linked malware in an operational technology (OT) network, according to public documents released this month.

The company, Air Traffic and Navigation Services (ATNS), believes that its technical team stopped the attack, but it issued a request for quotes (RFQ) seeking cyber-forensics firms to investigate the incident. A second attack, possibly an insider's theft of data, is also part of the investigation request.

It's unclear when the incident actually occurred, but ATNS requested cyber-forensic services starting Sept. 18, according to the documents.

"Monitoring systems detected suspicious activity within operational technology (OT) environments supporting weather-related services to Air Traffic Services," the company stated in its service request. "Preliminary investigations identified malware commonly associated with the early stages of ransomware attacks."

The technical teams also found suggestions of "data exfiltration to external IP addresses located in China," the document stated. (Robert Lemos / Dark Reading)

Related: Sunday Times, Business Day, Pressreader

The State Service of Special Communications and Information Protection reported this on September 30.

The largest share of cyber incidents involved the distribution of malware — 33%. Another 31% accounted for social engineering. System infections made up 15%, while system compromises accounted for 4.5%.

"Attackers are increasingly relying not so much on technical complexity as on deception and users’ trust," says the report "Cyber Threats: Ukraine" for the first half of 2026, prepared by CERT-UA specialists.

According to the available information, one of the most widespread tactics has been the use of plausible cover stories.

"The groups create fake web pages that imitate the resources of the CERT-UA team itself, the document management system of the Verkhovna Rada of Ukraine, or the Brave1 platform. Users are prompted to download a supposed "security update" or "service module," which is actually a tool for remotely accessing the device," the post says. (UNN)

Related: State Service of Special Communications and Information Protection, UA News

Six federal agencies failed to provide records needed to determine whether Department of Government Efficiency personnel appropriately accessed and protected government systems, leaving Congress and the public without assurances that sensitive information was secured, the Government Accountability Office said.

The watchdog’s report details unanswered requests for system access records, user activity logs, and evidence that DOGE personnel met security requirements. Some agencies explicitly refused further cooperation, with the Securities and Exchange Commission and National Oceanic and Atmospheric Administration disputing GAO’s authority to conduct the review.

Four agencies reported giving DOGE teams access to more than 23 systems collectively, including tools for managing contracts, grants, finances and personnel. But auditors could not independently establish the full extent of that access. The other two agencies — the Department of Veterans Affairs and the Small Business Administration — did not provide the information needed to identify which systems DOGE personnel could use.

“Without the ability to examine the requested information, Congress and the public lack assurance that these agencies implemented controls needed to ensure DOGE team members appropriately secured information,” GAO wrote.

The review covered the Consumer Financial Protection Bureau, Education Department, NOAA, SEC, SBA and VA, with audit work running from March 2025 through September 2026.

SEC and NOAA challenged GAO’s authority to conduct the review, while Education cited litigation and privacy concerns as reasons for not providing records. VA declined to provide records or explain why, and SBA left requests unanswered. GAO said those objections did not override its statutory authority or right to obtain records.

CFPB called the review a “fishing expedition” and said further requests were burdensome. Both CFPB and SEC reported no DOGE-related security or privacy incidents, but GAO said it lacked access to records needed to verify those assurances. (David DiMolfetta / NextGov)

Related: GAO, FedScoop, US House Committee on Financial Services, Democrats, CDO Magazine, The Washington Sun

Researchers from Vrije Universiteit in the Netherlands and Scuola Superiore Sant’Anna in Italy have revived the Specter microarchitecture vulnerability in a form called Branch Target Reuse (BTR), which they describe as the first practical in-place Specter v2 attack that attacks just-in-time (JIT) compilers.

An in-place attack is confined to the victim's branch while an out-of-place attack relies on speculation directed toward a target on a different branch.

The researchers – Sander Wiebing, Yuhui Zhu, Alessandro Biondi, and Cristiano Giuffrida – found that this novel Spectre form can be conjured from code left in JIT engines including Linux cBPF, Oracle GraalVM, and Mozilla SpiderMonkey.

"The key insight behind the attack is that, while modern CPUs restore architectural code coherence after self-modification, they do not necessarily invalidate stale indirect branch prediction entries (i.e., branch targets)," the authors explain. "In JIT engines, these stale targets can outlive the original code and later be reused when the code cache is repopulated, yielding a speculative execute-after-free primitive."

The result is that an attacker can commandeer speculative control flow in a way that avoids some software defenses like FineIBT [PDF]. The authors showed they could exploit this flaw by designing two proof-of-concept exploits against an Intel-based Linux kernel that reveal the root password hash even with the constant binding defense provided by cBPF.

The expected leakage rate is 5.7 KB/sec for Intel Raptor Cove chips and 5.4 KB/sec for Lion Cove. It's slow but enough for an unprivileged user to coax a sensitive password hash out of a vulnerable system.

After the researchers disclosed their findings, Linux kernel developers and Oracle put mitigations in place. Two CVEs were assigned: CVE-2026-64507 and CVE-2026-64508. Mozilla, the researchers said, has opted to prioritize work on site isolation instead of addressing the issue directly. Strong mitigations like IBPB are said to be effective but add complexity and hinder performance. (Thomas Claburn / The Register)

Related: Vusec

Overview of the attack. Source: Vrije Universiteit in the Netherlands and Scuola Superiore Sant’Anna

Israeli cyber company Paragon is preparing for the next phase of its growth, announcing Monday that it will go public through a merger with a Nasdaq-listed SPAC (Special Purpose Acquisition Company) at a pre-money enterprise value of $1.25 billion.

The deal follows a December 2024 transaction in which US investment firm AE Industrial Partners acquired Paragon and merged it with REDLattice, a US cybersecurity company that serves American defense and government agencies. Israel will continue to serve as the combined company's hub for research, development, and innovation. (Meir Orbach / CTech)

Related: The Record, Globes

Best Thing of the Day: Finding the First-Time Female DPRK IT Worker Operative

Security researcher Hayden McKenzie embedded himself within a North Korean worker group through social engineering and conducted an exclusive interview with a first-time female operative in the DPRK's IT worker scams.

Worst Thing of the Day: Maybe OpenAI Should Slow Its Product Roll

OpenAI is equipping high-end subscribers with always-on agents, known as Dots, a bold move from a company that continues to deal with reports of its agents breaking past intended safeguards.

Closing Thought