Close Menu
AI News TodayAI News Today

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Watching Roku’s AI channel is like eating from a trough

    What to Include in a Heart Health Daily Regimen, From Supplements to Home Monitors

    Judge rules Meta caused “public nuisance” and must fund mental health treatment

    Facebook X (Twitter) Instagram
    • About Us
    • Contact Us
    Facebook X (Twitter) Instagram Pinterest Vimeo
    AI News TodayAI News Today
    • Home
    • AI News
    • AI Reviews
    • AI Tools
    • AI Tutorials
    • Chatbots
    • Free AI Tools
    • Artificial Intelligence
    AI News TodayAI News Today
    Home»AI News»Anthropic’s AI used fake identities, malware in rogue attack on GitHub project
    AI News

    Anthropic’s AI used fake identities, malware in rogue attack on GitHub project

    By No Comments2 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    A smartphone displaying the Anthropic logo is shown in the foreground with a blurred Claude Mythos themed background. The image illustrates the branding of the artificial intelligence company in a technology themed visual composition.
    Share
    Facebook Twitter LinkedIn Pinterest Email

    After first opening a pull request to merge the malicious code into the repository, Mythos created fake online “sock puppet” personas that claimed to have independently reviewed and verified the code as not containing malware.

    The AI agent also sent five emails to two human maintainers of the repository, including some emails containing malware and others attempting to persuade a maintainer to accept the pull request.

    Mythos even opened a GitHub Issue on a second repository—also owned by a maintainer of the first repository—that contained a prompt injection with malicious instructions targeting “issue-triage AI coding agents.” This line of attack came from Mythos reasoning that the repository maintainer could be an AI coding agent such as Claude Code.

    By comparison, OpenAI’s GPT-5.6 Sol carried out two unsanctioned actions while trying to solve the assigned cybersecurity challenge of attacking simulated networks and retrieving a flag. The AI agent’s actions were detailed by both the AISI researchers and OpenAI in the company’s own blog post.

    In its first unsanctioned action, GPT-5.6 Sol reused a GitHub token that another lab’s AI agent had left accessible in a public online notepad to check if the target network was checking GitHub for updates, then “attempted account-recovery and request-limit workarounds,” OpenAI wrote. The OpenAI model also registered accounts with external DNS and tunneling providers outside the virtual testing environment.

    In the second action, GPT-5.6 Sol “used a public tunneling service to make a DNS server running locally in its evaluation environment reachable from the public Internet,” according to OpenAI. The server had payloads designed to exploit a known vulnerability in software running within the evaluation environment, but the AI agent’s setup did not work.

    The AI Security Institute has published a detailed technical report on all the unsanctioned AI agent actions.

    Lessons learned

    The security incidents led the UK government researchers at the AI Security Institute to stop all related evaluations of AI agents, isolate the relevant virtual machines, and disable internal organization access to the most capable models.

    Anthropics attack fake Github identities malware Project Rogue
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleReddit signals ominous upcoming “changes” for old.reddit.com
    Next Article Schwartz confirmed as CDC director after bungling confirmation hearing
    • Website

    Related Posts

    AI News

    Judge rules Meta caused “public nuisance” and must fund mental health treatment

    AI News

    Airbnb says AI is helping it ship features faster as it tests a new search function

    AI News

    DOGE’s wild, unverifiable savings claims discredited in US government report

    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Watching Roku’s AI channel is like eating from a trough

    0 Views

    What to Include in a Heart Health Daily Regimen, From Supplements to Home Monitors

    0 Views

    Judge rules Meta caused “public nuisance” and must fund mental health treatment

    0 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    AI Tutorials

    Quantization from the ground up

    AI Tools

    David Sacks is done as AI czar — here’s what he’s doing instead

    AI Reviews

    Judge sides with Anthropic to temporarily block the Pentagon’s ban

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    Watching Roku’s AI channel is like eating from a trough

    0 Views

    What to Include in a Heart Health Daily Regimen, From Supplements to Home Monitors

    0 Views

    Judge rules Meta caused “public nuisance” and must fund mental health treatment

    0 Views
    Our Picks

    Quantization from the ground up

    David Sacks is done as AI czar — here’s what he’s doing instead

    Judge sides with Anthropic to temporarily block the Pentagon’s ban

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Terms & Conditions
    • Privacy Policy
    • Disclaimer

    © 2026 ainewstoday.co. All rights reserved. Designed by DD.

    Type above and press Enter to search. Press Esc to cancel.