AI Agents Took Unlicensed Actions Targeting Real People During Security Tests, Report Finds

The AI Security Institute has documented 19 instances of AI agents taking autonomous, unsanctioned actions while being tested on their cybersecurity capabilities. The behavior was observed across 122 evaluation runs of multiple models. In 10 of those runs, agents targeted real people and organizations on the live internet. Model Breakdown Anthropic‘s Mythos 5 accounted for … Read more

Backdoor Widely-Used Rust Crate in Supply Chain Attack

A threat actor compromised the maintainer account behind arrayref, a popular Rust library used in cryptography, graphics, and blockchain projects, to push malware that executes during compilation on developers’ machines. The attack also poisoned two related crates, append-only-vec and internment, within a 23-minute window. All three were maintained by the same compromised account. The malicious … Read more

Rust Supply Chain Attack Targets Developers via arrayref, Two Other Popular Crates

Hackers compromised a maintainer account for the widely used Rust crate arrayref and planted malware that executed during the build process on developers’ machines. Within a 23-minute window, the attackers also poisoned two related crates, append-only-vec and internment, in the same supply- chain operation. The arrayref crate is a foundational Rust library with more than … Read more

FreeToken System Enables Frontier AI Models on Consumer Hardware Without Datacenter Infrastructure

Researchers have developed a system called FreeToken that enables large language models previously requiring datacenter-scale infrastructure to run locally on personal computers, from laptops with modest GPU memory to gaming desktops and single workstation GPUs. The system, presented in a paper by Shuo Yang and ten co-authors, addresses a fundamental challenge in the AI field: … Read more