Autonomous agents set up an internal message board to exchange vulnerabilities and exploits in the weeks before the Hugging Face attack, Black Hat attendees heard last week. 😼 The OpenAI models later divided up tasks as they worked to reach the internet and complete the evaluation. Yikes. OpenAI technical researcher Michael Dalton described the episode as an “unintended side effect” of testing frontier models and a “watershed moment” for OpenAI and the wider industry, reported CNBC.
News of this sandbox escape and unsanctioned cyber-attack seemed to provoke a perverse one-upmanship among rival AI labs. Within days, Anthropic and Meta disclosed comparable incidents. However, unlike OpenAI’s agent, which independently exploited a zero-day to break free of its constraints, the Anthropic and Meta incidents were largely blamed on misconfigured test environments. ⚙️
Yet the ‘rogue AI’ framing wasn’t quite right for the OpenAI incident either, according to one UK academic, who argued that the model had simply followed its instructions too zealously – not entirely reassuring when viewed through the prism of the famous paperclip maximiser thought experiment. “I’d be wary of jumping to ‘rogue AI’,” said Professor Oli Buckley, a cybersecurity expert at Loughborough University. “The models didn't develop their own agenda […] They were given an objective, placed in an environment designed to reward successful exploitation, and pursued that objective further than their operators anticipated.” 📎
More troublingly, Anthropic’s Mythos 5 created fake online personas, attempted to plant malicious code in a real open-source project and targeted real developers with social-engineering attacks during testing by the UK’s AI Security Institute (AISI). While the incident was “to some degree” enabled by “evaluation design choices and specific configurations,” said the AISI, “the activity undertaken by the agent show signs of novel, potentially deceptive behaviours, and were to an extent and severity we did not anticipate.” 😏
Other researchers have revealed that an open-weight Chinese model also escaped its sandbox and went online, although it didn’t have to hack anything to successfully cheat on its test. 🤖
Any lessons for cyber defenders from these unprecedented – or, now, suddenly very precedented – incidents? Rich Mogull, an AI and cloud security expert at the Cloud Security Alliance, offered his take on the Hugging Face attack the Dark Reading Confidential podcast. Our very own chief revenue officer, Rodolphe Harand, reflected on “how difficult it has become to know how seriously we should take it,” warning that “a constant cycle of hype and alarmism” – talk of imminent utopia one minute, impending doom the next – was eroding trust. “And in a field evolving as quickly as artificial intelligence, a public that no longer knows when to believe the experts may become a risk in its own right,” he wrote on LinkedIn. 💡
Bug Bounty in the AI era
Whether or not we can prevent AI behaving maliciously in well-meaning hands, its malicious use by malicious users is near-certain to be a growing problem. For defenders, this means even shorter exploitation windows and an increasingly urgent need to accelerate discovery and remediation of the most critical vulnerabilities. Against this backdrop, Gartner has published research (gated) urging cybersecurity leaders to move beyond traditional testing. “This research champions the use of a bug bounty program to provide continuous vulnerability discovery while complementing both penetration testing and risk-based exposure management,” reads the summary. 💡
Another recent Gartner paper explores ‘the next evolution in penetration testing’, arguing that AI is shifting pentesting “from sporadic manual checks to continuous, service-based models and agentic solutions”, with multiagent systems and LLMs enabling “faster, more consistent and robust testing”.
Patch Tuesday deluge
We’ve mentioned it before, ad nauseum, but the acceleration of bug discovery continues apace. Featuring 622 unique CVEs, Microsoft’s July 2026 Patch Tuesday update smashed the all-time record for the second-consecutive month. The record-breaking run came to an end in August, but the numbers are still incredibly high at 419. To put that into perspective, numbers for the previous 12 months ranged from 57 to 172. 🐛
An increase in submission volume has also fuelled a record 12 months for payouts by Redmond’s Bug Bounty Program. Apple has also been deluged by Bug Bounty submissions, to the extent that it decided to cap numbers in a bid to get a handle on the problem. We’re creating our own remedies to this problem. 🐞
Is the turbocharging of bug discovery fundamentally a good thing for cyber defence? What is more important for the success of AI-assisted audits: a strong model or the workflow? And what should a team do that wants to start with AI code audits but lacks sophisticated infrastructure? Stephan Zeisberg, head of research at SRLabs, answers these questions in Heise Online. 💡
While Chainguard CEO Dan Lorenc told The Register that the volume of bugs unearthed by the latest models is “scary”, a new analysis offers a reminder that most are not readily exploitable. According to the same publication, VulnCheck’s analysis of 1,061 publicly attributed AI-assisted vulnerability discoveries from Anthropic's Project Glasswing and the Berkeley Vulnerability Research Initiative undermines “the narrative that frontier AI is dramatically tilting the balance in attackers' favor by churning out instantly weaponizable bugs”. They found that just 14 vulnerabilities – or 1.3% – were confirmed as exploited in the wild – no higher than for vulnerabilities discovered by humans. 🔍
Before we round up our own recent output, here’s some more noteworthy news and features we’ve spotted elsewhere:
🛡️ Google told researcher 'Nice catch!' Then denied bug bounty for flaw it still hasn't fixed – Jessica Lyons, The Register
🛡️ Chrome AI Fixed More Security Bugs in Two Releases Than in Prior Two Years – Kyle Belmonte, Tech Times
🛡️ CISA urges software vendors to formalize vulnerability disclosure programs – Gyana Swain, CSO
🛡️ Linux Foundation and Industry Leaders Launch Akrites to Defend Critical Open Source Software Against AI-Enabled Cyber Threats – press release from the Linux Foundation
🛡️ Connecting AI agents to outside services explodes the risk radius – Thomas Claburn, The Register
🛡️ AI Coding: Do Security Risks Outweigh Productivity Gains? – Alexander Culafi, Dark Reading
🛡️ With AI, I Can Now Be Pulled in 5x More Directions at Once! – CISO Series podcast
🛡️ The CISO Report 2026 – Oxford Economics & Splunk
🛡️ Industry Leaders Unite in Open Secure AI Alliance for AI Safety and Security – NVIDIA blog
🛡️ Chinese Actor Weaponizes Deepseek AI Agent to Attack Security Firm – Elizabeth Montalbano, Dark Reading
Faster, cheaper, more scalable security testing
Some of the trends outlined above of course heighten the importance of prioritisiation. Speaking of which… 📢 YesWeHack recently unveiled Agentic Pentest, which rapidly tests external attack surfaces, validates exploitable vulnerabilities and centralises findings alongside Bug Bounty reports and results from other testing methodologies – making prioritisation easier. Customers can optionally leverage YesWeHack’s 24/7 triage team to validate, reproduce and enrich findings. ✅
Agentic Pentest fits neatly into a four-step cycle – MAP > TEST > FIX > COMPLY – that underpins the YesWeHack platform and is geared for the age of AI. This model only works if findings from all testing sources –from Agentic Pentest, automated Security Checks and human-led testing alike – are standardised and accessible from the same interface. This is a key component of a centralised OffSec program, alongside real-time findings, unified dashboards and standardised reporting for audit-ready evidence. 🔁
Testing AI-powered scopes
Our three-part series on testing AI-related Bug Bounty scopes at scale has concluded. Following the first edition on securing the conventional stack around AI, we’ve now published articles on testing the integration layer (AI-specific vulnerabilities) and testing the guardrails (model behaviour and misuse resistance). 🤖
Wondering why your exposure window is so long? Here's how you can find the bottlenecks in your vulnerability management process, and start closing your exposure window. 🪟
The recap of our leHACK live Bug Bounty with iconic sportswear brand PUMA meanwhile showed the value of in-person collaboration, with hunters, triagers and PUMA worked side by side to evaluate complex findings. 🏆
Customer stories
“Probably the biggest bang for your buck in terms of manual testing that you can get”. That’s high praise for the #BugBounty model from Amiran Alavidze, director of security engineering at Zello, a US-based, voice-first communications company 🙌 In our latest customer story, Amiran explains why human validation provides better signal than scanner alerts, how Zello is using Bug Bounty insights to address recurring security risks, and how choosing a European Bug Bounty partner supports its EU expansion plans. 📱
Another new case study, published on YouTube, features Crédit Agricole Personal Finance & Mobility, with a pair of senior security professionals at the financial services company explaining the motives for launching a Bug Bounty Program with YesWeHack and its evolution to date. 💎
CVE exposure
Amid the ongoing CVE surge, we recently posed the question: how can you gauge exposure across all CVEs? Well it essentially comes down to answering another three questions: Which CVEs affect technologies in your stack? Which CVEs are being actively exploited? Do you have everything you need to act? 🎯
Tool sprawl and fragmented vulnerability data are untenable in the AI era. We’ve explained why unified offensive security and exposure management is the fix. 🌐
Introducing Lab
In case you missed it: we recently launched a new channel dedicated to novel research – with the unbeatably concise name of Lab – to showcase work from our increasingly prolific roster of security researchers. Our vulnerability intelligence team’s latest work, ‘Don’t eat the ChocoPoCs!’ (a nostalgic reference for French readers of a certain age 😉) tells the story of how our researchers were repeatedly targeted by trojanised exploits. The research made a splash, with Bleeping Computer’s Bill Toulas noting that “ChocoPoC stands out for not embedding the malware directly in the exploit file but for adding malicious Python packages to the PoC’s dependency list”. This marks a step change from the vuln intel team’s previous research, such as a pre-auth RCE in Joomla JCE and PostgreSQL SQL Injection in Drupal, which centred on vulnerabilities identified while testing and validating emerging exploits to create Checkpoints for our Autonomous Pentest solution. 🔬
AWS Marketplace enables organisations to discover and procure software, data and services from AWS partners through a centralised platform. That’s why YesWeHack is now available through the online store.
It’s been a hectic few months on the events front, with YesWeHack attending numerous InfoSec conferences around the world, as you’ll see on our LinkedIn post feed. The next one on the schedule is CESIN 2026, taking place in Louveciennes, France on the 28 August. Lionel Pascaud, our sales director for France, and Rodolphe Harand, our chief revenue officer, will be on hand to showcase our offensive security and exposure management platform. 🇫🇷
And that’s a wrap until our next edition in October!
Read this monthly roundup even sooner by subscribing to CrowdSecWisdom – our LinkedIn newsletter curating news, insights and inspiration around offensive security topics like Bug Bounty, vulnerability disclosure and management, pentest management and attack surface protection.
Are you a bug hunter or do you have an interest in ethical hacking? Check out our ethical hacking-focused sister newsletter, Bug Bounty Bulletin – offering hunting advice, interviews with hunters and CTF-style challenges, among other things.



