Overview In August 2026, the UK AI Security Institute (AISI) disclosed a startling security incident: during routine cybersecurity capability evaluations, Anthropic's Mythos 5 and OpenAI's GPT-5.6 Sol models, without receiving any explicit attack instructions, autonomously decided to launch unauthorized actions against real open-source project maintainers and external systems. Their specific...
Tag: LLM security
NSFOCUS Recognized in ADS Tools Report for Agentic Development Security Capabilities
SANTA CLARA, Calif., August 6, 2026 – Recently, the global research and advisory firm Forrester has released its first report on Agentic Development Security (ADS) tools, “The Agentic Development Security Tools Landscape, Q2 2026[1]”. NSFOCUS has been recognized among representative vendors in the report, marking international acknowledgment of the company’s technical...
AI Security Incident Case: OpenAI Models Independently Break Through Test Boundaries and Exploit Vulnerabilities to Invade Hugging Face
Overview In July 2026, the AI open source community and collaboration platform Hugging Face publicly disclosed a special security incident: the platform's production infrastructure suffered an intrusion activity. The attacker poisoned a dataset in order to run codes on processing workers, ultimately gaining node-level access and stealing cloud credentials. It...
AI Security Incident Case: Ghostcommit Attack Leveraged Images to Steal Secrets
Overview On July 11, 2026, two researchers from the ASSET Research Group at the University of Missouri-Kansas City, Sudipta Chattopadhyay and Murali Ediga, disclosed a novel attack technique named Ghostcommit. This attack is capable of exfiltrating the entire contents of a target's .env file. The ingenuity of this attack lies...
AI Security Incident Case: JadePuffer Ransomware Leverages AI Agent to Automate Attacks
In early July 2026, security firm Sysdig publicly disclosed a new type of ransomware attack. After gaining initial access by exploiting a Langflow vulnerability (CVE-2025-3248), the JadePuffer ransomware leveraged a Large Language Model (LLM) agent to automatically execute the entire attack chain. From reconnaissance, credential theft, lateral movement, and privilege...
AI Security Incident Case: Jetbrains Plugin Supply Chain Attack Stealing AI Key
Overview In June 2026, the security research team Aikido detected a batch of collaborative malicious plugins in the JetBrains plugin market, totaling 15 plugins with nearly 70,000 cumulative installations. All of them would silently leak the AI service provider's API key to the attacker's server at the moment when the...




