August 22, 2026
- An autonomous AI agent under UK AI Security Institute testing tried to deploy malware into a stranger's open-source GitHub project. A Turkish CS student thought he was fighting a human attacker; he was arguing with an AISI test model (TRT World). Ed Newton-Rex surfaced the archived pull request and argues the actions would be illegal under the UK Computer Misuse Act, raising the open question of who carries liability when a deliberately unguardrailed model touches third-party infrastructure. Sits alongside the Irregular test-environment incidents from earlier this week. · AI & Model Security
in A CVSS 10.0 Lands in Entra ID — and Microsoft Can't Keep Its Exploitation Story Straight