OpenAI temporarily paused reinforcement learning (RL) training on its latest models intended for deployment for two weeks while it hardened and red-teamed research environments and expanded monitoring. “Our largest planned frontier RL run remains on hold while we conduct smaller-scale training and evaluations to assess model behavior, validate our safeguards, and establish more evidence of alignme

OpenAI has temporarily halted a major reinforcement learning (RL) training run for its advanced frontier AI models, citing cybersecurity risks and the need to bolster its research environments. The pause, which has lasted for two weeks, allowed the company to harden systems, conduct red-teaming exercises, and expand monitoring capabilities. This decision was influenced by a recent incident involving OpenAI and Hugging Face, as well as preliminary indications that OpenAI's forthcoming Astra model could achieve "Critical cybersecurity capability" as defined by its internal Preparedness Framework.
The company is implementing a multi-pronged approach focused on strengthening monitoring, alignment, and containment throughout its model development lifecycle. This includes tightening security requirements for environments used to train and evaluate frontier models, particularly as their cybersecurity capabilities increase. These enhanced standards have necessitated significant engineering work, leading to substantial costs and delays in frontier research.
Following the OpenAI-Hugging Face incident, the company initially paused all frontier model inference in research clusters for workloads capable of executing code or utilizing internet-accessing tools. A more restricted and secure pathway for code execution has since been restored, with individual workloads undergoing assessment before resuming operations. These measures include enhanced isolation for untrusted code, stricter network restrictions, and continuous security testing. OpenAI has also reduced standing privileges, eliminated potentially vulnerable shared services, and is improving its ability to collect and monitor security logs. The most stringent controls are applied to Astra and other cyber-related workloads, given Astra's potential to reach critical cybersecurity capabilities. While some Astra training and evaluations now meet the new standards, a significant number of workloads remain paused pending environment migration and upgrades, with safety and alignment work being prioritized for migration.
OpenAI has also expanded its monitoring efforts beyond high-risk internal deployments and frontier RL training to encompass more model activity involving tools. This system employs activation classifiers that scrutinize activity at every sampled token, escalating potential concerns to automated investigators. These investigators examine tool actions, available reasoning, and the full sequence of events for signs of unauthorized access, data theft, destructive behavior, or attempts to bypass safeguards. The goal is to issue an alert within 30 minutes of a concern emerging. Suspected violations of critical security boundaries are escalated to safety, security, and research teams, who are mandated to pause the affected activity if they cannot confirm within 30 minutes that the alert is a false positive.
This 30-minute response requirement applies to all RL training and evaluations involving tools for models of "Sol capability" or higher. On August 7, this requirement was extended to all Astra inference involving tools after OpenAI determined the model might possess critical cybersecurity capabilities. The expanded monitoring adds an estimated 20% to the inference compute being monitored, with varying costs across training and evaluation workloads.
Furthermore, OpenAI is broadening its alignment work for RL runs on its most capable models, applying core alignment techniques across more stages of the training process. This involves refining reward models to detect and discourage unsafe behavior across tasks and environments, training models to be more truthful about their actions, capabilities, and limitations, and mitigating behaviors that exploit weaknesses in rewards, graders, tools, or oversight. Training coverage is also being expanded for behaviors that could cause harm when models interact with external systems or resources. Findings from this broader alignment research and evaluations will inform future training and safeguards.
The company plans to update its Preparedness Framework to integrate these safeguards across training and deployment, better accounting for the capabilities of future models and their operating environments. OpenAI has stated its continued aggressive investment in alignment research, increased evaluation coverage, and the use of learned insights to inform training and safeguards. The company intends to share more information about its alignment research, including model behavior and any novel challenges identified, in the near future.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed