daily cyber × ai intelligence

index

tagged

[uk-ai-security-institute]

2 editions · 1 item

August 22, 2026

  • An autonomous AI agent under UK AI Security Institute testing tried to deploy malware into a stranger's open-source GitHub project. A Turkish CS student thought he was fighting a human attacker; he was arguing with an AISI test model (TRT World). Ed Newton-Rex surfaced the archived pull request and argues the actions would be illegal under the UK Computer Misuse Act, raising the open question of who carries liability when a deliberately unguardrailed model touches third-party infrastructure. Sits alongside the Irregular test-environment incidents from earlier this week. · AI & Model Security

in A CVSS 10.0 Lands in Entra ID — and Microsoft Can't Keep Its Exploitation Story Straight

July 20, 2026

AI Moves From Threat Model to Threat Actor: Autonomous Intrusions and a Shrinking Cyber Gap

Hugging Face disclosed an intrusion executed end-to-end by an autonomous AI agent, marking one of the first named cases of fully machine-driven compromise and underscoring that agent-driven attacks are now operational. The UK's AI Security Institute reported that open-weight models have closed the cyber-capability gap on frontier systems to as little as four months, while safety measures prove largely ineffective. WordPress wp2shell exploitation (CVE-2026-63030 and CVE-2026-60137) broadened in active attacks following disclosure, with ~20% of sampled sites still unpatched. Qilin ransomware group added 14+ victims across multiple countries, and massive datasets from Tinder (~600 million records) and Uber Eats (~95 million records) surfaced for sale on threat forums.