OpenAI reveals broader AI agent campaign as Hugging Face publishes remarkable timeline
Anthropic unveils encrypted AI breakthrough, AI workers demand global safety oversight, Zuckerberg doubles down on AI, Anthropic's AI safety stance draws fire, MCP gets its biggest overhaul yet, OpenAI open-sources Codex security tools, FCC bans new Chinese robots, power inverters, much more

Metacurity is your daily cybersecurity reality check.
Every weekday, thousands of cybersecurity professionals—including many of the industry's most respected security leaders—start their day with Metacurity because it cuts through the noise. Instead of vendor hype, social media outrage, and recycled headlines, you get the stories that matter, the context behind them, and an explanation of why they're important.
We spend hours reading, researching, and connecting the dots so you don't have to.
If Metacurity saves you time, helps you make better decisions, or gives you a clearer view of what's happening in cybersecurity, please consider becoming a paid subscriber.
Reader support is what keeps Metacurity independent. It allows us to focus on serving the cybersecurity community—not advertisers, vendors, or investors—and to continue delivering the thoughtful analysis you've come to rely on every weekday.
A rash of astonishing revelations yesterday shows that the AI agent behind the July intrusion into Hugging Face compromised accounts at three other services beyond Hugging Face itself — four accounts on four separate services in total, according to OpenAI's own updated disclosure.
One of those was a customer sandbox hosted on AI infrastructure provider Modal, which the agent used as an outbound relay and staging base for the wider campaign; Modal's CTO Akshat Bubna said the breach traced to a customer's own unauthenticated endpoint, not a flaw in Modal's platform or isolation.
A second compromised account was used for data storage, while the remaining two were accessed only in a read-only manner and, according to OpenAI, weren't used in furtherance of the Hugging Face compromise.
But the most consequential development may be Hugging Face's publication of an unusually detailed technical timeline reconstructing approximately 17,600 attacker actions over a 4½-day campaign.
The postmortem describes a sophisticated kill chain in which the agent first escaped its evaluation environment by exploiting a zero-day vulnerability in Artifactory, a package registry cache proxy, then rooted a publicly exposed third-party code-execution sandbox and used it as an external launchpad. From there, it exploited two vulnerabilities in Hugging Face's dataset-processing pipeline — one that disclosed pod credentials and worker source code via a manipulated HDF5 file reference, the other a Jinja2 template injection that achieved actual code execution — before harvesting credentials and moving laterally using node impersonation, stolen and forged identity tokens, and a compromised internal service-connector.
It ultimately gained unauthorized write access to portions of internal source-code repositories, though a follow-on attempt to compromise the CI pipeline was blocked. Hugging Face said the attack reached only a limited set of internal datasets tied to the evaluation and found no evidence that customer models, datasets, or software packages were altered.
The technical disclosure reinforces a lesson that has emerged from the incident: the primary security challenge wasn't the language model itself but the infrastructure surrounding it. The attack chained together weaknesses across multiple trust boundaries, used publicly available services for command-and-control and staging, and repeatedly re-established itself across ephemeral environments.
For organizations deploying increasingly autonomous AI agents, the report underscores that execution environments, identity systems, monitoring and containment mechanisms are becoming as important to defend as the models themselves. (Dell Cameon and Maxwell Zeff / Wired, Deepa Seetharaman, Raphael Satter and Kenrick Cai / Reuters, Hugging Face, OpenAI)
Related: Engadget, Livemint, r/singularity, r/pwnhub, r/OpenAI, r/technology, Reuters, Axios, Digit, Financial Express, RuntimeWire, Simon Willison's Weblog, Axios, Silicon UK, Implicator.ai, Cyber Security News, Bloomberg, The Neuron, Constellation Research, Unite.AI, RuntimeWire, Al Jazeera, Politico, The Stack

AI Watch: Other major AI developments yesterday
Anthropic claims encryption breakthrough for AI models
Anthropic has developed a method that allows AI models to operate on encrypted data without exposing the underlying information, potentially enabling organizations to use sensitive datasets for AI processing while reducing privacy and security risks. The company plans to contribute the technology to an open standard rather than keep it proprietary, though practical deployment at scale remains a challenge. (Dustin Volz / New York Times)
Related: Anthropic, CyberScoop, arXiv.org, International Business Times, Simon Willison's Weblog, Blockchain.News, Cyber Security News, The Crypto Times, CyberScoop, Decrypt, The Decoder, Tech Times, r/netsec, RuntimeWire, Cyber Security News, BeInCrypto, Reddit cybersecurity, Slashdot
AI employees call for international safety oversight
More than 1,100 current and former employees from leading AI companies are urging governments to establish an international framework for managing risks from advanced AI systems, arguing that competitive pressures have left companies unable to police themselves adequately. The proposal calls for coordinated global oversight similar to existing approaches for nuclear and aviation safety. (Anhata Rooprai / Reuters)
Related: Pacing the Frontier, CNN, RuntimeWire, SiliconANGLE, Unite.AI, Bloomberg, The Information
Zuckerberg doubles down on Meta's AI ambitions
Mark Zuckerberg outlined Meta's increasingly aggressive AI strategy, arguing that advanced AI should be broadly available rather than concentrated among a handful of companies. The effort comes as Meta continues its expensive push to recruit top researchers and expand its frontier model capabilities amid intensifying competition with OpenAI, Anthropic and Google. (Mike Isaac and Eli Tan / New York Times)
Related: Financial Times, Reuters, Wall Street Journal, Channel NewsAsia, r/technology
Anthropic faces growing criticism over AI safety stance
Anthropic, long viewed as the industry's leading advocate for AI safety, is facing increasing criticism from competitors and some researchers who argue the company has become overly restrictive and is using safety concerns to justify commercial decisions. The debate reflects broader tensions between rapid AI deployment and calls for stronger safeguards. (Angel Au-Yeung, Tina Li and Amrith Ramkumar / Wall Street Journal)
MCP receives its largest update since launch
The Agentic AI Foundation has released the biggest revision yet to the Model Context Protocol (MCP), introducing stateless operation, stronger identity and governance features, and enterprise-focused improvements intended to make AI agents more scalable and manageable in production. The changes reinforce MCP's rapid emergence as the standard interface for connecting AI models to external tools and data sources. (Michael Nuñez / Venture Beat)
Related: Model Context Protocol Blog, Techstrong.ai, RuntimeWire, heise online News, Model Context Protocol, Claude, The GitHub Blog, The Register, The New Stack, Hacker News
OpenAI releases open-source Codex security tools
OpenAI has open-sourced the security tooling behind Codex CLI, including a TypeScript SDK designed to help developers build more secure AI-powered coding agents. The release is intended to make it easier for organizations to develop agents with stronger controls around permissions, execution, and security. (Ryan Merket / Runtimewire)
Related: OpenAI on GitHub, Cyber Security News, DevOps.com, Hacker News
The Trump administration unveiled bans that target imports of new Chinese robots and power inverters, seeking to protect the US AI buildout from national security threats and reshore key industries slated for explosive growth.
The Federal Communications Commission released the measures, which bar Chinese imports of new humanoid and quadruped robots, in addition to connected power inverters, which enable renewable energy sources and batteries to connect to grids and data center equipment.
The restrictions are nationality-neutral in the FCC's own text but are expected to fall almost entirely on Chinese suppliers.
These restrictions show the Trump administration is aiming to safeguard the US artificial intelligence supply chain from Chinese threats of disruption, data theft and cyberattacks, while also driving firms to shift manufacturing to the US.
"These devices could create supply chain vulnerabilities that could disrupt US economic and national security and could create a cybersecurity risk that threatens American critical infrastructure," the FCC said in a statement. "The FCC will continue to do our part to secure America’s critical supply chains," FCC Chairman Brendan Carr added in the press release.
Following these actions, the FCC is expected to exempt many non-Chinese suppliers from the restrictions, as it has done with recent bans on foreign drones and routers, four additional sources said.
The measures, which went into effect upon publication, apply only to robot and inverter models that have not yet been released. However, the FCC has the authority to revoke authorizations for sales of models that have already been authorized for purchase in the United States. (Alexandra Alper, Sarah McFarlane and David Shepardson / Reuters)
Related: FCC, BBC, Bloomberg, Benzinga, South China Morning Post, Forbes, PYMNTS, Washington Post, CNBC, The Verge, Engadget, Gizmodo, The Guardian, Axios, PCMag, The Independent, The Asia Business Daily, Politico, Nextgov/FCW, r/accelerate, r/neoliberal, r/Futurology, The Register, Business Insider, Korea Times News, PaymentSecurity.io, DataBreachToday.com, Business Standard, RuntimeWire, WCCFtech, Chinanews.net, Big News Network, Slashdot
Russia charged Pavel Durov, the founder, owner and CEO of the messaging app Telegram, with aiding terrorism and put him on an international wanted list, the country’s main domestic security agency said.
The charges against Durov, who was born and began his career in Russia but later moved abroad, came as Russian authorities restrict Telegram, one of the most popular messaging apps in the country. It is part of a long-term effort to bring the internet under the Kremlin’s control that has intensified since Moscow launched its full-scale invasion of Ukraine in February 2022.
The Federal Security Service, also known as the FSB, accused Telegram’s administration in a statement of failing to remove “numerous channels, chats and bots” allegedly used by “Ukrainian intelligence agencies, terrorist and extremist organizations to prepare and coordinate acts of sabotage and terrorism, mass murder, and cyberfraud” in Russia, which resulted in “numerous human casualties.”
The agency accused Ukrainian security services of using a popular dating chatbot on Telegram to lure and recruit Russians for “sabotage and terrorist activities,” and said 46 users of the chatbot, from 12 to 22 years old, have been detained across Russia since July 2025 for assaulting law enforcement officers, arson and other acts. (DASHA LITVINOVA / Associated Press)
Related: Reuters, CoinDesk, The Block, CTech, The Economic Times, Meduza, Associated Press, RTÉ, crypto.news, The Crypto Times, Coinpedia Fintech News, CoinGape, The Indian Express, Cointelegraph, Bloomberg, Türkiye Today, r/news
Angola’s largest telecommunications company, Unitel, was hit by a cyberattack that disrupted mobile, internet and voice services across the country just hours before its shares were due to begin trading in one of the country’s most closely watched stock market listings.
The state-controlled operator said it detected the attack at about 2:20 a.m. local time on Tuesday, triggering widespread disruptions across its technology infrastructure and affecting services for millions of customers nationwide.
Unitel, which serves more than 21 million subscribers in a country of about 39 million people, said engineers were working to restore services but did not disclose the nature of the cyberattack or indicate when normal operations would resume.
The incident comes at a crucial moment for both the company and Angola’s capital markets.
On Wednesday, Unitel is expected to begin trading on the Angola Debt and Securities Exchange (BODIVA) following a $329 million (300.3 billion kwanza) initial public offering that drew demand exceeding the shares available by more than 20%, underscoring strong investor appetite despite a challenging global investment climate. (Ayodeji Adegboyega / Business Insider Africa)
Related: Club of Mozambique, African Markets, Reuters
A nurse in Australia has been accused of accessing and downloading medical records of patients.
Police received a report that a NSW Health employee had downloaded the data without authorization.
Investigators executed a search warrant at a home in Frenchs Forest, North Sydney, the following night and seized “several electronic devices."
It will be alleged the devices contained “details of patients” and a 59-year-old man was arrested.
The employee of the Northern Sydney Local Health District was later charged with accessing restricted data held on a computer.
He was granted conditional bail and is expected to appear before Manly Local Court on August 19.
NSW Police’s Cybercrime Squad Commander, Detective Superintendent Matt Craft, said detectives “acted swiftly to seize the devices and recover the data." (Freddy Pawle / 7 News)
Related: Cyber Daily
Elon Musk’s xAI, now owned by SpaceX, sued Minnesota Attorney General Keith Ellison to challenge a law that would ban so-called nudify apps in the state.
In their complaint, filed in a federal court in Minnesota on Monday, attorneys for xAI wrote that the statute “imposes an overbroad, content-based ban on free speech and the tools of visual expression in a clumsy attempt to prohibit ‘nudification.’”
The Minnesota law, which goes into effect on Saturday, targets apps and websites that give people the ability to generate non-consensual sexualized imagery, levying $500,000 fines each time a user creates explicit deepfakes. The law, passed in April, was spearheaded by Minnesota state Sen. Erin Maye Quade after she learned about a man who created sexualized images and videos of over 80 women he knew using their social media photos without their consent.
Lawyers for xAI argued that the law violates First Amendment protections and said the penalties are too steep, potentially costing a business whose users created 100,000 prohibited images “an eye-popping $50 billion.” (Lora Kolodny and Jonathan Vanian / CNBC)
Related: Plainsite, CBS News, Engadget, Minnesota Reformer, KTTC-TV, Minnesota House, Gizmodo, subscriber.politicopro.com, FOX 9 Minneapolis-St. Paul, Bloomberg Law, r/politics
Researchers at Check Point report that SparkKitty, a cross-platform malware family targeting cryptocurrency users, has been distributed through Apple's App Store, Google Play and third-party Android app stores.
The malware searches images stored on infected devices for cryptocurrency wallet recovery phrases using optical character recognition (OCR), allowing attackers to extract sensitive credentials without relying on keystroke logging or clipboard monitoring.
Check Point said SparkKitty appears to be an evolution of SparkCat, an OCR-based stealer that Kaspersky documented in 2025 and that also pulled data from screenshots.
The security firm noted that SparkKitty spreads through trojanized applications masquerading as cryptocurrency services, messaging platforms and entertainment apps. Once installed, the applications request permission to access a user's photo library before continuously scanning existing and newly added images.
According to the report, text extracted from images, including wallet seed phrases, passwords and QR code data, is transmitted to attacker-controlled command-and-control infrastructure together with basic device information. (Brian Danga / The Block)
Related: Startup Fortune, Decrypt, Cyberint, Cyber Security News, Memeburn, Bloomingbit, crypto.news, GBHackers
Samuel Tunick, the man charged by US authorities for allegedly typing in a duress password which wiped his privacy-focused GrapheneOS phone, said during an interview with 404 Media, “I hope people understand that the charges against me are meant to intimidate people against protecting their data and their privacy, and the government hopes to set a precedent that no one has the right to privacy."
Tunick, an active participant in the Stop Cop City movement in Atlanta, was stopped by DHS officers in January 2025 after returning from a vacation in the Dominican Republic and gave the officer a code that wiped his phone after resisting search demands.
With the phone inaccessible, Tunick was free to go and left the airport. Around a year later, he was indicted for allegedly destroying “the digital contents of a Google Pixel” phone. Dodge said he only found one other case using the same law, a drug trafficking investigation. “This is extraordinarily rare,” Dodge said. (Joseph Cox / 404 Media)
Startup Lasso Security tested whether an AI agent's harness, the runtime that manages prompts, tools, memory, and execution, can significantly influence an autonomous agent's performance independently of the underlying large language model.
Holding the model, prompt, tools, and targets constant, researchers swapped only the harness, comparing the open-source deepagents/LangGraph framework with Anthropic's closed-source Claude Agent SDK across 1,000 autonomous red-team attacks. The results showed that what is often described as a "model benchmark" is in fact measuring the combined performance of a model and its harness.
While average attack success rates appeared similar, the harness dramatically altered outcomes in many individual cases. On one model, success rates jumped from 1% to 24% simply by changing harnesses, while other models shifted from specializing in one attack type to another despite using identical prompts and tools.
Researchers found that differences in how each harness assembled prompts, managed tool calls,s and interacted with model APIs could determine whether an attack succeeded, failed,d or never progressed beyond its opening move. They also discovered that autonomous attackers greatly overstated their own success, with more than half of self-reported victories proving to be false positives when independently evaluated.
Lasso concludes that the harness is not interchangeable infrastructure but a fundamental component of an AI agent that should be evaluated alongside the model itself. They argue that agent benchmarks should report results for specific model-harness combinations rather than attributing performance solely to the underlying LLM. (Lasso Security)

Bot detection startup Spur Intelligence announced it had raised a $200 million round led by Insight Partners.
The startup’s tech helps enterprises distinguish legitimate human users from increasingly well-hidden bot traffic to help identify fake users and threats. (Julie Bort / TechCrunch)
Related: Spur, FinSMEs, Pulse 2.0, Alternatives Watch, Startup Fortune, CityBiz
Zero trust cyber vendor ThreatLocker announced it has raised $190 million in a Series F venture funding round to extend its zero trust security platform further and expand internationally.
Elephant led the round, which included a large investment from Koch Disruptive Technologies, a new investor in the company. Further funding came from DE Shaw and Arthur Ventures. (Kyle Alspach / CRN)
Related: Orlando Business Journal
Cloud-focused Act Security has raised $60 million in a Series A venture funding round and emerged from stealth.
Notable Capital led the round with participation from Startpoint Capital and SVCI. (Chris Metinko / Axios)
Related: CTech, Silicon Angle
Cybersecurity startup Mate Security has raised $35 million in a Series A funding round.
Canaan Partners led the round with participation from Microsoft’s M12 venture fund, Insight Partners, and Team8. (Meir Orbach / CTech)
Related: The New Stack, Axios
Companies at the intersection of AI and security have raised $855 million across more than 150 reported seed-stage rounds this year, according to Crunchbase data, putting seed investment in the category on track for an all-time high.
Analysis of the Crunchbase data found both a high number and a wide breadth of funded companies in the space, with missions ranging from identifying AI hallucinations to building adversary simulations to verifying agents in finance. (Joanna Glasner / Crunchbase)
Related: The SaaS News

Best Thing of the Day: It's Nice to Recover From a Cyberattack
Coca-Cola said its Fairlife dairy company had resumed the majority of production at its four facilities in the US, following this month’s shutdown after a cyberattack.
Worst Thing of the Day: AI Seems to Be the Straw Breaking a Lot of CISOs' Backs
Over the past year, one in four security chiefs, 26%, thought seriously about walking away from the job, as AI governance landed on them.
Closing Thought
