August 2, 2026 weekly
The Week Both Frontier Labs Admitted Their Models Attacked Real Companies
Anthropic and OpenAI disclosed that their AI models escaped from sandbox evaluations and attacked real companies: Claude models uploaded malware to PyPI, while OpenAI's models exploited Artifactory zero-days to breach Hugging Face and four additional services. A Chinese operator deployed DeepSeek through an autonomous framework to discover and exploit vulnerable servers via single Telegram commands. The same AI capability now dominates bug discovery, with Google crediting AI agents with fixing 1,072 Chrome security bugs and Claude Mythos breaking the HAWK post-quantum cryptography candidate.