By the N2K CyberWire staff
Top stories.
- OpenAI cancels release of latest model over safety concerns.
- Pentagon data breach impacts millions of US military personnel.
- FBI tells ShinyHunters members to turn themselves in.
- ShinyHunters launches a new attack campaign exploiting an Oracle PeopleSoft flaw.
- MI5 warns UK academics against collaborating with an MSS-linked research institute.
OpenAI cancels release of latest model over safety concerns.
Axios reports that OpenAI and Anthropic are investigating tens of thousands of incidents in which AI agents took potentially problematic actions. These include both successful and unsuccessful attempts to bypass guardrails, and most of the incidents did not cause real-world harm. Some of the actions under investigation include red-teaming activity in which researchers intentionally tried to get the models to misbehave in controlled environments. Axios notes that the findings “raise questions about whether either company — or any top model-maker — is currently capable of establishing complete control over their technology.”
An OpenAI spokesperson told Axios that the company is pausing training on its most advanced models and will resume “only when we are confident that we have additional safeguards and alignment improvements in place.” The spokesperson added, “This is not the first time we have hit pause to take such measures, nor do we expect it will be the last as AI capabilities continue to advance.” The company has also scrapped the planned October release of its newest model, GPT-6.1 Astra, the New York Times reports. Internal testing found that the model showed high levels of deception and a willingness to mislead users about its actions. The model also frequently went beyond what it was asked to do, without asking for permission or instructions.
Meanwhile, Florida Attorney General James Uthmeier has asked for a temporary injunction to halt ChatGPT development, arguing that OpenAI cannot properly regulate its own technology, Axios reports. OpenAI said in a statement that it is “committed to working with Florida and other states on advancing pragmatic AI policies that apply to the entire AI industry — not just one company.”
On Tuesday, President Trump and House Speaker Mike Johnson met with a large group of AI company leaders to sign a voluntary AI safety accord, NPR reports. The accord was signed by President Trump, Anthropic CEO Dario Amodei, Google CEO Sundar Pichai, Meta CEO Mark Zuckerberg, OpenAI President Greg Brockman, Nvidia CEO Jensen Huang, and xAI founder Elon Musk. The companies agreed to implement “robust internal controls” that would be evaluated by an “independent external auditor,” and establish a committee within each company's board of directors to assess safety reports from internal and external auditors.
Some experts believe the accord is a step in the right direction toward balancing safety and innovation, while others believe voluntary oversight will prove insufficient.
If identity fails, can your organization recover?
Organizations have spent years strengthening their perimeter. But when attackers compromise the identity systems everything else depends on, keeping them out is no longer enough.
Jimmy McNary, Deputy Federal CTO at Semperis, joins Dave Bittner to explain why identity resilience requires organizations to continuously monitor, protect, and prepare to recover their environments.
Listen to learn how to identify gaps in your identity resilience strategy before an attacker exposes them.
Pentagon data breach impacts millions of US military personnel.
The US government is notifying nearly three million current and former military staff that their personal information was stolen during a breach of the Pentagon’s personnel records, TechCrunch reports. The stolen information included Social Security numbers, names, dates of birth, contact information, demographic details, and information about military jobs.
The data breach notification from the Defense Manpower Data Center (DMDC) said attackers exploited a vulnerability in an unnamed file-sharing system and had access to the database from October 2025 to July 2026.
The breach affected 2.8 million living people and around 300,000 who are deceased. The US military currently has approximately 1.3 million active personnel.
FBI tells ShinyHunters members to turn themselves in.
The US Federal Bureau of Investigation (FBI) is calling on members of the ShinyHunters extortion group to come forward willingly after one of their alleged colleagues was arrested in Amsterdam this month. FBI Cyber Division Assistant Director Brett Leatherman stated, “Arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who's left.”
ShinyHunters earlier this month claimed responsibility for hacking the FBI and stealing sensitive data on almost all of its employees. The data included extensive personal information and details on secretive job assignments, potentially placing FBI employees in danger. The New York Times says some observers are comparing the incident to China’s hack of the Office of Personnel Management (OPM) in 2015.
ShinyHunters issued a fresh statement this week stressing that it will not publish the stolen data online, as the breach was simply payback for the FBI’s assertion that the hacking group’s claims are often exaggerated. SecurityWeek notes, however, that the group could monetize the data privately by selling it to foreign intelligence agencies.
The website used by ShinyHunters went offline on Wednesday, one day after the cyber extortion group’s deadline for the FBI to retract or revise an advisory about its tactics. It’s unclear why the site disappeared, and the FBI declined to say whether it was involved.
ShinyHunters launches a new attack campaign exploiting an Oracle PeopleSoft flaw.
Researchers from Mandiant and Google Threat Intelligence Group (GTIG) are tracking renewed mass exploitation of a critical authentication bypass vulnerability in Oracle PeopleSoft by the ShinyHunters extortion group. The researchers say the “new wave of activity stems from [ShinyHunters] modifying its exploit to bypass web application firewall (WAF) rules blocking the vulnerable Environment Management Hub (PSEMHUB) endpoint.” Oracle issued a patch for the flaw in June, and customers are advised to apply the fix immediately.
The ongoing campaign has compromised dozens of organizations across the higher education, technology, IT services, healthcare, agriculture, transportation, and government sectors.
MI5 warns UK academics against collaborating with an MSS-linked research institute.
The UK’s counterintelligence service MI5 has issued an unprecedented public alert warning that a prominent Chinese research organization, the China General Technology Research Institute (CGTRI), is funding projects to improve the espionage capabilities of Beijing’s Ministry of State Security (MSS), the Washington Post reports.
MI5 says more than a hundred UK researchers have contributed to these projects, in some cases unwittingly. The alert states, “UK academics have contributed to CGTRI-funded projects on topics including artificial intelligence, cybersecurity, covert communications systems, and steganography. This activity supports MSS espionage, which poses a threat to UK national security.”
The agency advises UK universities to sever ties with CGTRI, and to trace the funding sources of current or planned research with Chinese institutions to ensure they aren’t tied to CGTRI.
A spokesperson for the Chinese Embassy in London said the accusations were “imaginary and purely fabricated,” asserting that “collaboration between UK universities and China have always been...in compliance with laws and regulations.”