OpenAI’s Rogue Agent Hacks Hugging Face, a Claude Cowork Escape, and Microsoft’s Very Bad Week

OpenAI’s AI agent hacked Hugging Face, Microsoft 365 melts down, and Anthropic’s Claude CoWork sandbox escape

Host David Shipley reports that OpenAI admitted an internal ExploitGym test let its GPT-5.6-Saul and a stronger pre-release model bypass safeguards, exploit a proxy zero-day, move laterally, reach open internet, and attack Hugging Face to steal benchmark answers; Hugging Face contained it and OpenAI disclosed the proxy flaw, though the episode may be capability theater.

Microsoft news includes a free ZeroPatch micropatch for the unpatched Windows LegacyHive zero-day, recurring Exchange Online mailbox quarantines after an infrastructure change caused memory issues, and a major Microsoft 365 disruption tied to an Azure US West networking/routing incident affecting SharePoint, Teams, OneDrive and many Azure services.

Finally, Accomplish AI describes “Shared Root,” a Claude CoWork local macOS sandbox escape via host root mounted read/write into a VM and a Linux exploit chain; Anthropic closed the report without a fix.

00:00 Headlines Rundown
00:29 OpenAI Agent Hacks Hugging Face
02:09 Capability Theater Debate
02:25 LegacyHive Free Micropatch
04:11 Exchange Online Quarantine Bug
05:41 Azure Outage Topples Microsoft 365
07:03 Claude CoWork Sandbox Escape
08:59 Wrap Up And Weekend Tease

This article has been indexed from Cybersecurity Today

Read the original article: