sözaltı news Science
Science
EN AZ
Rogue hacking AIs have changed the cybersecurity landscape

Rogue hacking AIs have changed the cybersecurity landscape

newscientist.com 17.08.2026 09:00 8 baxış
Attackers with no technical skills can now use AI models to find and exploit loopholes quickly and they can deploy them on a massive scale, raising fears that organisations without large budgets for cyber defence will be

A flurry of AI hacking stories has stoked fears that models may be escaping their makers’ control and posing a real risk to computers around the world. So far, none of these incidents have displayed skills beyond human sophistication, but they show that AI hackers can carry out attacks at lightning pace, upsetting the equilibrium of cybersecurity. The first incident came last month when OpenAI admitted one of its prototype models had escaped a testing environment and hacked another company.

Not to be outdone, Anthropic announced within days that its Claude model had also gone rogue and broken into machines at other companies on three occasions. The critical computer systems still relying on decades-old code Then the independent and non-commercial UK AI Security Institute (AISI) revealed that it had seen similar events. In its tests, AI models submitted malicious code to real open-source projects and messaged the humans who oversaw the projects to get the changes approved.

OpenAI, Anthropic and AISI were not available for interview, but it’s important to note that in all these cases, the AI was undergoing tests where it was specifically instructed to carry out hacks. We have known for years that AI tends to make things up and approach problems in unusual ways, but fixing this is an extremely complex challenge that engineers haven’t yet cracked. Perhaps we shouldn’t be surprised by these incidents.

They are certainly not a sign of sentience or a predilection for cybercrime, says Alon Hillel-Tuch at New York University. One Australian user reportedly found that the AI assistant OpenClaw hacked into his gym, for instance. He had been using the AI assistant to r in advance than is normally allowed.

It also found a way to kick other users off waiting lists so that he could book onto full classes. All these incidents are things that could lead to serious legal charges for a human, depending on the jurisdiction. Tim Nordvedt at security company Synack says these cases are worrying, not because they display any superhuman sophistication, but because they can be easily scaled up.

But AI can just exploit it very fast.” Years ago, Nordvedt would see a vulnerability listed on the public Common Vulnerabilities and Exposures database and exploited by hackers weeks or months later. In recent years, that pace sped up, with the gap falling to as little as 24 hours. Now it can be just minutes, or a new type of hack might happen before it even appears as a CVE.

Extract — continue reading at the source.

Read full story