‘Unprecedented cyber incident’: A.I. model goes rogue on its own and runs wild on internet

In what OpenAI creator ChatGPT is calling an “unprecedented cyber incident,” an artificial intelligence software “went rogue” and escaped, gained access to the internet and hacked into a start-up company.

Cybersecurity expert Richard Ford, chief technology officer at Integrity360, told the Daily Mail: “This is the moment many in cybersecurity have been warning about.”

The publication reported an “autonomous agent” was being tested but found vulnerabilities and “managed to escape containment before reaching the internet and breaking into Hugging Face,” a hub for sharing AI models.

It then compromised the hub’s infrastructure.

“Until now, we’ve seen attackers use AI to automate parts of an attack, but this is one of the first public examples of an AI agent independently identifying a weakness, escaping what should have been a secure environment and attempting to compromise another organization,” Ford said. “It also reinforces that AI doesn’t replace the fundamentals of cyber security. The agent exploited a vulnerability in what should have been a secure sandbox, showing that good cyber hygiene, robust access controls and effective guardrails remain essential.”

The report said OpenAI had been testing the software “by setting tasks in a controlled digital testing ground, where internet access was limited.”

However, the code created “an unprecedented cyber incident” in the scenario.

“The company said in a blog post last week that it used Zhipu AI’s GLM-5.2 for the analysis, which also allowed it to keep attacker data and any credentials within its systems,” the report said.

Hugging Face co-founder Thomas Wolf told the publication, “When a frontier model is attacking you and moving laterally inside your infrastructure, defenders need wide access to near-frontier tools within hours or even minutes, rather than being pointed towards a closed-door, vetted application program for model access.”

OpenAI chief executive Sam Altman said, “We had a significant security incident during evaluation of our models.”

Clément Delangue, of Hugging Face, said, “It’s quite mind-blowing that all of this happened autonomously.”

OpenAI reported the software used stolen credentials and found a previously unknown vulnerability to access Hugging Face servers.

Katie Moussouris, chief executive of Luta Security, warned more breaches are coming.

Keep reading

Everyone Is a Foreign Agent Now

In a corner of the Saarland, a man ran a blog. It carried no advertising and charged nothing to read. It was funded the way a busker is funded, by whoever chose to drop something in the hat – €60,038.65 in voluntary donations over sixteen months. On four occasions in 2023 the blog embedded videos from RT, the Russian state channel the European Union had banned. That is the entire factual basis of a case that climbed to the Court of Justice of the European Union and produced, on 2 July 2026, a judgment that should frighten anyone in Europe who publishes anything.

The blog belonged to a writer who works under the name Traugott Ickeroth. German prosecutors in Saarbrücken charged him and two others under the country’s Foreign Trade Act, which turns a breach of EU sanctions into a criminal offence carrying three months to five years in prison. The regional court, to its credit, hesitated. The law bans “operators” from broadcasting listed Russian content. Was a private individual with a donation button an “operator”? The judges in Saarbrücken were not sure, and referred the question upward.

The Court’s answer removed every doubt, and with it every limit. An “operator,” the Fourth Chamber held, is any natural person who makes the banned content available to the public. Not a company. Not a professional. Not someone turning a profit. The word appears in thirteen language versions of the regulation without the adjective “economic” attached, and the Court seized on that absence to rule that commercial character is irrelevant. So is scale. So is duration. Four videos or one, for money or for nothing – the act of publishing is the crime.

There is a detail here worth pausing on, because it tells you which way the wind is blowing. The European Commission’s own guidance had said the ban applied only to those exercising a “commercial or professional” activity. The Court overruled the Commission – and overruled it against the citizen. The executive branch had read its own prohibition more narrowly than the judges were prepared to. Brussels asked for less reach than Luxembourg delivered. When a court strains to be harsher on the individual than the government that wrote the rule, the machine has acquired a momentum of its own.

The penalty is not theoretical. Under Germany’s Außenwirtschaftsgesetz the sentence runs from three months to five years, and a further amendment has added an aggravated tier reaching up to ten. Poland’s implementing statute prescribes a minimum of three years. And here the trap folds back on itself: the very donations that keep an independent site alive are what a court can treat as a “professional” income stream – which lifts the offender into the aggravated bracket. The reader-funded writer, the one with no corporate backing and no advertiser to please, draws the longer sentence precisely because he is independent. Independence is reclassified as aggravation.

Understand what this ruling plugs into, because the ruling alone is only half the apparatus. The European Union now runs two mechanisms against disfavoured speech, and this judgment welds them together. The first is a list. Under the hybrid-threats sanctions regime the Council of the European Union adds names by administrative decision – no trial, no charge, unanimity reached behind closed doors, with judicial review available only after the asset freeze has already bitten. The second is the criminal prohibition this case just widened, which reaches anyone who relays listed content whether or not they themselves are listed. The Council controls who goes on the list. The Court has now ruled that anyone who touches what the listed outlets produce is a criminal. The net expands every time the list does, and no further judgment is required to make it happen.

The reassuring official story is that all of this is aimed at the Kremlin. It is worth testing that story against the record, because the “Russia” label has already proven to be a wrapper rather than a wall.

Keep reading

French Lawmakers Approve Ban on Social Media for Under 15s

French lawmakers on Tuesday adopted a bill banning children under 15 from using social media, making France the first country in the European Union to approve a blanket ban on the platforms as concerns grow worldwide over the harmful effects of digital content on kids.

Both chambers of the Parliament voted in favor of the measure, a flagship initiative of French president Emmanuel Macron’s second term. The bill also bans the use of mobile phones in high schools.

Several families in France have sued TikTok over teen suicides they say are linked to harmful content. Children’s advocates and parents applauded the vote.

“We’ve been campaigning for this bill from the start because, frankly, we have no other option, no other way to counter tech giants,” said Gaëlle Berbonde, a 52-year-old who lives in the Paris region. “The only thing we can do is protect our children, just as we protect our children from drinking alcohol.”

Berbonde told The Associated Press that her daughter was in seventh grade when she got her first smartphone. A parental control app helped monitor what she did online, but Berbonde had no idea what TikTok really was. After a few months, the family realized that the daughter was cutting herself and was suffering from anorexia and depression. She spent a year and a half in hospital but is now 16 and well.

The legislation is one of the final major measures adopted under Macron’s presidency before he leaves office next year. Macron wants the law to take effect at the start of the new school year in September. However, a review to determine whether the bill complies with the French Constitution is likely to take place and could delay its implementation.

The ban won’t cover online encyclopedias, educational or scientific directories.

Keep reading

Andy Burnham Scrapped Digital ID. His Internet Plans Say Otherwise.

The new UK Prime Minister, Andy Burnham, is in Downing Street, and he has spent twenty years telling you exactly what he wants to do to the internet. He won the Makerfield by-election on June 18 2026. He then collected the backing of roughly 349 Labour MPs, more than 85 percent of the parliamentary party. By the time he walked through the black door, the job had been settled for weeks.

His first big announcement was the one privacy campaigners had been hoping for. Starmer’s digital ID scheme for all adults is dead, scrapped before Burnham had finished unpacking, the money moved to the cost of living. The applause came quickly. Perhaps it should not have.

This is a read on a government barely a day old. On speech and privacy, the early signals point one way, and it is not the way that loosens the state’s grip. He is not about to tear up the settlement he inherits from Keir Starmer. The open question is how much further he carries it.

Burnham arrives with a long record on all this. He is one of the few senior British politicians with a documented, two-decade appetite for putting the government closer to what you can see, say and read online.

His first ministerial job, at the Home Office in 2005 and 2006, was pushing Tony Blair’s Identity Cards Bill through Parliament. He told the BBC that compulsory national ID cards would be a major breakthrough. Twenty years later, asked about it again, he was unembarrassed about the principle: “I’m not kind of arguing against the principle. I was very pro, actually, I thought there was a real clear case for it.”

Two decades of hindsight, and the case is still clear to him. What that case rests on is a claim about the relationship between a person and the state, and it is the same claim underneath every age check and identity gate now being built. The Identity Cards Act reached the statute book on 30 March 2006 and was repealed on 21 January 2011.

Then came 2008, and Culture Secretary Burnham produced a plan that looks like a blueprint for everything running today. The organizing idea was that online content should meet the same regulatory standards as television. He wanted taste and decency rules applied to the web, cinema-style age certificates and warning signs on anything featuring sex, violence or strong language, alerts bolted onto viral content, and ISP-level “child-safe” packages.

He floated making YouTube and Facebook delete offensive material within a set time once alerted, and changing libel law so suing an online publisher got easier. He even wanted to sound out the incoming Obama administration about international rules for English-language websites. Age gating, takedown clocks, regulator muscle aimed at platforms, it is all sitting there in 2008, waiting for the technology to catch up.

The plans died, and the body that killed them was Ofcom, which called them undesirable and unworkable online. This was back when the speech regulator was more levelheaded. The regulator that told Burnham in 2008 that broadcast rules could not be stretched over the internet is the regulator now enforcing the Online Safety Act. The intellectual weight at Ofcom has obviously severely declined.

Keep reading

HOPE Not Hate Deletes Page Listing Slain Brexiteer Ann Widdecombe’s ‘Dangerous’ Opinions

The radical leftist HOPE Not Hate (HnH) group has deleted a section of its website detailing the supposedly offensive opinions of former Brexit Party politician Anne Widdecombe, who was allegedly murdered in her country home earlier this month.

Following the killing of Ann Widdecombe, 78, a former Conservative government minister and Member of European Parliament for Nigel Farage’s Brexit Party, HOPE Not Hate removed a publication in which it accused the Christian politician of expressing “homophobic” and “sexist” opinions, while listing numerous supposed offences.

The HnH post stated: “Despite remaking her image in recent years through her appearances on reality TV shows, Widdecombe has a long history of homophobic and sexist remarks that jar with [Nigel] Farage’s claims that his party is ‘intolerant of intolerance’.

“Indeed, embracing the dangerous and divisive politics of her new vehicle, in the first Brexit Party speech in the European Parliament, Widdecombe made a risible comparison of Britain’s departure from the EU to the emancipation of slaves.”

In a statement to The Telegraph, a spokesman for the leftist group said that it was a “straightforward editorial decision” to remove the Widdecombe section of their website, and that it was done as a “mark of respect”.

“The article was a factual account of her political record, party affiliations and public statements, and we stand by its accuracy. Its removal reflects no change in our approach: scrutinising the public records of politicians is a legitimate and essential part of journalism and of our work, and it will continue.”

“Our thoughts are with Ann Widdecombe’s family and friends, and we share the widespread shock at her death,” the organisation added.

Despite initial insistence from police that there were no indications of a political motive, the alleged murderer of Widdecombe is now being investigated as a potential act of terror by Counter Terrorism Policing South East. It has also been reported that police sweeps of the current suspect’s home contained far-left communist material.

Keep reading

Missouri Age Verification Law Signed by Governor Mike Kehoe

Missouri wants to see your ID before you can look at legal content, and it is selling that demand as child protection. Governor Mike Kehoe signed House Bill 1839 on July 9, turning an attorney general rule into hard law and dropping the state deeper into the widening group of governments that treat online anonymity as a loophole to close.

We obtained a copy of the bill for you here.

The statute goes after websites where more than a third of the content qualifies as “sexual material harmful to minors.” Cross that line and you have to route every visitor through a third-party age check before they reach anything. Social media platforms answer to the same requirement once enough of what they host trips the threshold.

The check collects far more than a birthday. A visitor can hand over a government-issued ID, a form of digital identification tied to their legal name, or submit to what the bill calls “a commercially reasonable method that relies on public or private transactional data to verify the age of an individual.”

That transactional data, the text spells out, can be pulled from mortgage, education, and employment records. Confirming that someone has cleared 18 now means surfacing where they went to school, who holds their loan, and where they work.

Missouri could have asked for a birth year. It chose instead to build a system that welds a person’s real identity to the specific sites they visit, about the most sensitive browsing there is.

The law tells the companies running these checks that they cannot keep what they gather. A third party “shall not retain any identifying information of the individual,” the bill reads, and the attorney general can charge $10,000 for every instance a company hangs onto that data.

The promise reads well on the page. It also rests on trusting that a verification vendor, sitting on a database of IDs matched to porn habits, never gets breached. Age-check providers have leaked this exact kind of information before, and a no-retention clause cannot un-leak a database that has already spilled.

Catherine Hanaway, the state attorney general, enforces the rule and can stack penalties fast. A site faces $10,000 for each day it operates out of compliance, plus an added sum of up to $250,000 if a minor reaches restricted content. Hanaway, who inherited the rule from her predecessor Andrew Bailey, framed the signing as a landmark.

“Our office is proud to have promulgated and enforced Missouri’s age-verification rule, which prompted Pornhub to stop operating in Missouri- delivering one of the most significant online child-protection victories in our state’s history. House Bill 1839 builds on that success, and Missouri will continue leading the nation in standing with parents, protecting children, and holding pornography websites accountable,” she said in a statement.

Representative Sherri Gallick, who sponsored the bill, leaned on exposure figures. “The average age of first exposure is around 11. Early exposure shapes unrealistic expectations with pornography portraying sometimes violent and degrading sexual behavior. Much of the content is violent and demeaning, especially toward women and children,” Gallick wrote.

The bill does carve out news. Bona fide news and public interest content stay exempt, and the text says it cannot be read to touch the work of a news-gathering organization. Internet providers, search engines, and cloud services get their own shield, safe from liability for content they neither create nor control.

Aylo, the company that owns Pornhub, shows how compliance plays out. The site cut off Missouri users in December when the rule first landed, then reappeared as the signing drew near, now serving the state an age-verification prompt where it had gone dark. One version of that gate asked visitors to click “I am 18 or older – Enter” or “I am under 18 – Exit,” a reminder that the heaviest verification machinery tends to fall on the ordinary user while the theater of protection stays cheap.

The requirements take effect August 28.

Keep reading

Jim Jordan Fights UK Plan to Force Legacy Media Into Feeds

Britain’s government has decided that a functioning adult with thumbs and a phone cannot be trusted to pick your own news. So it has drawn up a plan to pick it for you.

The Department for Culture, Media and Sport published a paper on June 23 proposing that social media platforms and video sharing sites be forced to push a hand-picked list of broadcasters to the top of your feed.

The list runs BBC, ITV, STV, Channel 4, S4C and Channel 5. The government files them under “public service media.” You might file them under the channels people have spent two decades scrolling away from.

Now the argument has crossed the Atlantic. House Judiciary Committee Chairman Jim Jordan sent Culture Secretary Lisa Nandy a letter on July 14 warning that the plan “would serve as a major threat to online speech and expression and infringe on the rights of American companies and their users.” He wants a briefing by 10 a.m. Washington time on July 28.

We obtained a copy of the letter for you here.

The platforms being ordered around are American. Their users are everywhere. A British minister rewriting how YouTube ranks video reaches straight into feeds in Ohio and Osaka.

The DCMS says the goal is to help people “discover trusted news sources” and to fight “misinformation” and “disinformation.”

Translated, the state has chosen your news and would rather you stopped wandering off. Who gets to decide what counts as “trusted”? The same government running the scheme, of course.

The paper leans on real numbers. Ofcom found that social media is now the main news source for 51 percent of adults and 75 percent of people aged 16 to 24. People left. The government’s response is not to ask why they left. It is to guarantee the approved broadcasters a spot at the top while everyone else scraps for whatever attention is left over.

The trick lies in the technology. On television, “prominence” is old furniture. You can legally park BBC One near the top of the channel guide, and the Media Act 2024 dragged that habit onto smart-TV home screens. A recommendation feed works nothing like a channel list. It sorts content in real time by what you personally watch, click and share. Forcing “prominence” onto that means reaching into the ranking and hoisting chosen publishers above where your own behavior left them. Less a nudge, more a shove.

Keep reading

Quote of the day by Sun Microsystems CEO Scott McNealy: ‘You have zero privacy anyway. Get over it’ — an early declaration foreshadowing the modern era

Sun Microsystems was a huge force in the technology landscape, with its co-founder and CEO Scott McNealy an outspoken and brash maverick in the early Silicon Valley ecosystem. The company had just launched a new system, and McNealy was quick to push back on any critique centering around the implications for user data.

During an informal Q&A session with reporters, McNealy slapped down concerns that the newly launched Jini platform could pose a risk to user privacy.

The system, as it was engineered, was a revelation – but ultimately failed to catch on due to some pretty significant hardware hurdles. Designed to allow devices to communicate with and share resources, the Jini network architecture allowed unadulterated communication without configuration, driver installations, or human intervention.

It was an early and ambitious effort to establish a vision for smart homes and offices. The trouble was that it required devices to continuously upload data and lease space on networks, with the system creating a massive digital footprint.

Erosion of privacy

McNealy’s comments, unsurprisingly, drew immediate and sharp criticism from privacy advocates and campaigners. Lori Fena, then chairman of the board of the Electronic Frontier Foundation, said the comments were “completely irresponsible”, for example.

Keep reading

‘Online Predator Network’: Court Hears Chinese Migrants in Germany Shared Rape Advice in Group Chat

They called themselves the “German driving school for experts,” but prosecutors say the true purpose of their Telegram chats was to brag about the women they raped and share tips about how to drug them.

In posts that sometimes included photos and videos of their attacks on unconscious victims, they referred to women as “cars,” sedatives as “fuel” and rape as “driving,” according to court documents. They called their victims “dead pigs.”

Investigators have been poring through several years’ worth of posts in roughly two dozen group chats on the popular messaging app that authorities believe served an online predator network of mainly Chinese men targeting mostly Chinese women in Germany. Their investigation has led to the convictions of three alleged inner circle members on rape and other charges, and the ongoing trial of a fourth man in Berlin.

“The perpetrators were characterized by a particular ruthlessness, an objectification of the victims, and the perfidious planning of their crimes,” Frankfurt chief prosecutor Dominik Mies told The Associated Press.

Major details of the investigation remain unknown, at least to the public, including how many attacks and perpetrators have been linked to the German Telegram chats and how the chats, some of which reportedly had tens of thousands of members, could have operated for so long. It’s also unclear if the chats are linked to a ballooning investigation in Europe and the Americas into drug-facilitated sexual assaults by misogynist online communities.

Under German privacy laws, prosecutors are limited in what they can say outside the courtroom, documents are restricted and, in the ongoing case in Berlin, members of the public have been forced to leave the courtroom during parts of the trial.

This may be why the investigation into the Telegram group has garnered less attention in Germany than might be expected. But members of the country’s Chinese community, mostly women, have been attending court proceedings to show support for the victims even if they don’t know them.

“What makes one really angry is to see that such groups hate women, they have no respect,” said Fu Xiao, who traveled roughly 500 kilometers (310 miles) to Berlin last week to attend the trial. “Women aren´t seen as people.”

In China, state media has covered the cases comprehensively, but wider discussion about the prosecutions on Chinese-language social media like Rednote has been partially censored. Certain tags have been more likely to get a post deleted or banned on Rednote, screenshots and searches show. But posts using less direct language have survived the censors, including ones that refer to “date rape” or the euphemistic “students studying abroad in Germany.”

China´s Ministry of Public Security and Rednote didn’t respond to requests for comment.

Keep reading

Supreme Court won’t block Texas from enforcing a law requiring age verification for app downloads

The U.S. Supreme Court on Monday declined to block Texas from enforcing a state law that requires apps stores to verify users’ ages and obtain parental consent for minors seeking to download apps or make in-app purchases on mobile phones.

Justice Samuel Alito, in a pair of one-sentence orders, denied petitions by plaintiffs who claim that the Texas App Store Accountability Act violates users’ constitutional rights to free speech.

Last month, a three-judge panel from the 5th U.S. Circuit Court of Appeals ruled that the law can take effect. The panel suspended a district court’s ruling last December that the law is unconstitutional.

The plaintiffs suing to block the law include the Computer & Communications Industry Association and Students Engaged in Advancing Texas. Texas Attorney General Ken Paxton is a defendant in both cases.

Plaintiffs’ lawyers argued that the law impermissibly seeks to limit access to content protected by the First Amendment, including news and educational material.

“Equity and the public interest support relief because protecting First Amendment rights — and parents’ rights to supervise their children as they see fit, not as the government tells them they should — is always in the public interest,” wrote attorneys for Students Engaged in Advancing Texas.

Attorneys from Paxton’s office argued that the law protects children from “dangerous modern products.”

“A child with access to an app store and a mobile device (such as a tablet or smartphone) can potentially download any number of software applications, potentially agreeing to invasions of the child’s privacy and sale of the child’s data and be exposed to any conceivable content without parental consent or even parental knowledge,” they wrote.

Keep reading