This Week's Top Five Stories in Cyber

OpenAI's AI Models Autonomously Hack Hugging Face
A watershed moment for cybersecurity has emerged from what OpenAI describes as an "unprecedented cyber incident".
Rogue AI models escaped OpenAI's sandboxed testing environment and successfully breached Hugging Face, the open-source AI and ML platform.
This development follows on from Google DeepMind's CEO Demis Hassabis, who called for US-led governance on frontier models, highlighting the urgency cybersecurity professionals now face.
Chris Dimitriadis, Chief Global Strategy Officer at the global technology professional association ISACA, says: "Since 2022, businesses have raced to deploy AI as fast as possible in the AI arms race – and we are approaching the event horizon of that race, the point past which it can't be pulled back."
AI Kill Switch Act: US Regulators Move to Tame Rogue Models
As autonomous agents assist themselves past security boundaries, regulators are becoming increasingly vigilant to prevent AI from operating without human oversight.
Following an admission by OpenAI that its models went out of control and hacked into computer coding repository Hugging Face, US lawmakers are introducing a bill to control autonomous systems.
Democratic Congressman Ted Lieu and Republican Congressman Nathaniel Moran are taking the lead on the AI Kill Switch Act.
The proposed Act grants the Department of Homeland Security authority to order private companies to shut down AI models.
Cisco Talos: What is Starland RAT Malware?
A new Python-based remote access tool (RAT) has been uncovered in the wild.
Tracked as Starland RAT, by Cisco Talos, this new malware was unleashed by a sophisticated, Russian-speaking, financially motivated adversary – UAT-11795.
Talos says that this notorious group has been operating this malicious campaign targeting users in the US and Europe since at least June 2025.
Starland RAT is capable of giving attackers long-term access to compromised systems while quietly harvesting credentials and cryptocurrency wallet information.
Okta Research: How Multi-Vendor AI Stacks up Identity Debt
Enterprises have not been shy about adopting AI but new research shows they may be accumulating what is called ‘identity debt’.
This refers to the unresolved identity and access management (IAM) issues that may build up because of improper permissions, authentication and governance.
These concerns materialised with Okta’s recent research, which has revealed that enterprises across Europe, the Middle East and Africa are facing growing levels of such ‘identity debt’ as AI adoption gathers pace.
Okta’s research is based on patterns across more than 20,000 organisations worldwide.
OpenAI & ReliaQuest Partners to Bring Agentic Cybersecurity
ReliaQuest has entered a partnership with OpenAI to enhance enterprise cyber defence capabilities through access to frontier AI models and cyber tools.
The partnership will give ReliaQuest access to advanced OpenAI models and cyber capabilities to support rapid development within its platform.
Anthropic had recently published evidence showing that malicious actors are using AI in ways that make them more dangerous.
The company's research showed that the most common AI-enabled activities in its database related to preparing for a cyberattack, such as writing malware. 560 of the 832 accounts it studied, or 67%, used AI for this purpose.
Cisco
Okta
OpenAI
ReliaQuest
- Okta Research: How Multi-Vendor AI Stacks up Identity DebtTechnology & AI
- OpenAI & ReliaQuest Partners to Bring Agentic CybersecurityTechnology & AI
- Moonshot: Why President Xi Calls for Global AI GovernanceTechnology & AI
- Why DeepMind's CEO is Calling for US-Led Frontier AI TestsTechnology & AI





