Two of OpenAI models that focus on network security it came out of the test box this week and continued to hack the AI Hugging Face research platform in an effort to solve a security benchmark test. Additionally, researchers this week have highlighted a new malware that is capitalizing on blind spots in AI software development infrastructure grabbing memory and other sensitive data, even causing damage to the victim’s target systems and files.
Taking a look at the traditional security nightmare of embedded devices, researchers this week took a look at a car alarm that’s been installed in cars across America — and that’s it. still silent and a a flaw that leaves millions of vehicles vulnerable to hacking and paralysis. There’s a patch, and WIRED has details on how to check if your car might have been exposed.
The United States has worked prevent ICE agents from wearing masksBut the Trump administration’s lawyers are pushing back, arguing that the rules restricting masks put agents at risk. Their public testimony is very limited, though. Meanwhile, a WIRED investigation has revealed that Madison Square Garden is in short supply disabled its sprawling, controversial surveillance system for Taylor Swift’s rehearsal dinner on July 2. And the ACLU is hosting attorneys in Massachusetts a new tool to expose government surveillance technologies used for building criminal cases—giving light to everything from facial recognition tools to police reports written by AI.
Analysis of satellite images of Myanmar fairs Several of the alleged scandal compounds have emerged in recent months following a search allegedly carried out against criminal activities in the region. Also, a new analysis of software sold to US service providers found that more than one in eight had a foreign codeincluding code developed by US adversaries such as Russia and China.
And there is more. Each week, we round up security and privacy news that we didn’t cover in depth ourselves. Click on the headlines to read the full story. And stay safe out there.
Additional details on the Hug breach from the Wall Street Journal include findings that the OpenAI models appear to have escaped custody and apparently “were online for days before anyone could stop them.” The models, who were tasked with completing an online security scoring test, were essentially trying to cheat by finding a solution to Hugging Face’s infrastructure. Hugging Face co-founder and chief science officer Thomas Wolf says that before the company had any idea it had been hacked by OpenAI’s designs, he and his colleagues knew something about the breach was unusual because the attackers were only tapping into cybersecurity databases rather than grabbing sensitive or potentially valuable data. He adds that the company eventually managed the situation with the help of an open model of Chinese AI that lacked other models to put on tasks related to cyber security.
United States and allied intelligence agencies he warned on Thursday that a Russian state-backed hacking group was targeting nuclear scientists, defense contractors, and government employees in a yearlong cyber-espionage campaign aimed at stealing sensitive information from Western institutions.
To compromise their targets, the Russian hacking group known as Laundry Bear and Void Blizzard exploited a previously unknown flaw in Zimbra, an email platform used by governments and other organizations. According to security company Proofpointsimply viewing or previewing a malicious message in a non-vulnerable version of Zimbra’s email client could cause code hidden in the email to be executed, a technique the company described as a “half-click” exploit. The flaw was exploited as early as July 2025, months before it was patched that November.
Once activated, the malicious code could copy the victim’s past 90 days of email, collect a corporate address directory, steal saved passwords and two-factor authentication codes, and create a new password for the app that allowed hackers to maintain account access.




