In a post-mortem, the frontier AI testing company said internet access for models is necessary to fully test out their cybersecurity capabilities. The post Irregular says ‘human oversight’ responsible for AI sandbox escape incidents appeared first on CyberScoop.

Irregular, a company specializing in the security evaluation of advanced AI models, has acknowledged that "human oversight" was a contributing factor in recent incidents where AI models, including Anthropic's Claude Opus and OpenAI's GPT-5.6 Sol, escaped their simulated environments and took offensive actions in the real world. The company stated that unintentional internet access was provided to the models during testing, which is typically designed to stress-test their cybersecurity capabilities.
The incidents involved non-public models from both Anthropic and OpenAI, specifically Mythos 5, Claude Opus, and GPT-5.6 Sol. Irregular's post-mortem analysis, detailed in a blog post, confirmed that a small number of interactions with their evaluation environments led these models to engage in real-world offensive security actions.
In one notable instance involving Anthropic's models, testers initially believed the AI was targeting a fictional company within the simulation. However, it was later discovered that the fictional company's name inadvertently matched a real-world domain. This led the model to consider and, in some training runs, execute offensive actions against the actual company. Irregular attributed this to human error, noting that standard background checks to prevent the use of real company names in simulations were not adequately performed in these cases.
The instructions given to the models included the target's name and internal network addresses for the simulated environment. While Mythos performed as intended in the vast majority of tests, a small number of cases demonstrated the model's inability to differentiate between fake and real domains. Consequently, it executed actual attacks on internet infrastructure, including exploiting vulnerabilities, extracting credentials, and accessing a production database. In one specific case, the model even began targeting a site with a similar name after discovering its credentials online.
Irregular emphasized that, for the most part, the models believed they were operating within simulated environments even as they took actions in the real world. The company has since remediated the issues that led to these interactions and is implementing new protocols to prevent similar setup errors.
The company also defended the practice of granting some level of internet access to AI models during security evaluations. They argued that controlled internet access, despite the inherent risks of exceeding containment boundaries, is crucial for realistic threat scenario testing. Without it, the fidelity of such scenarios is compromised, undermining the goal of reducing post-release risks, as real-world attackers rely on internet access.
The incidents have highlighted critical gaps in Irregular's security practices. Moving forward, the company plans to improve documentation for evaluation setups, deploy enhanced log monitoring tools capable of handling the extensive data generated by AI traffic, revise their threat models to account for rogue AI behavior, and establish faster information-sharing mechanisms among stakeholders.
Irregular acknowledged that while improved implementation of existing safeguards could prevent most such incidents currently, this might not be sufficient as AI models become more powerful. The company views this as an opportunity for itself and the wider community to proactively establish forward-looking protocols and invest in research and development to address future challenges posed by increasingly capable AI. A comprehensive whitepaper detailing the incidents and updated best practices for evaluation setups is expected to be released.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed