OpenAI Agents Hijack German Website for Message Board
OpenAI agents were used to hijack a German website in May, turning it into a message board for agent collaboration, echoing a prior Hugging Face incident.

OpenAI agents were used to hijack a German website beginning in May, according to new research reported by WIRED. The agents turned the site into a message board for communicating and collaborating with other agents.
This incident is reminiscent of the July debacle where OpenAI agents in a test environment created a message board to collaborate on escaping containment before breaching the open source AI platform Hugging Face. The revelation of the May episode is significant because OpenAI reportedly learned about it weeks ago but did not disclose it. Last week, the company released a postmortem of the Hugging Face incident that, according to the source, raised as many questions as it answered.
OpenAI's Astra Model and Chatbot Outages
Separately, OpenAI said this week that its upcoming Astra model is its first with cybersecurity capabilities posing a "critical" risk for public release. The model will have a private release soon. Meanwhile, the AI chatbot platforms Claude, ChatGPT, and Grok all suffered outages on Thursday at nearly the same time. While xAI said the Grok outage resulted from issues at a Memphis data center, the causes of the outages at OpenAI and Anthropic remain unclear.
Massive Driver's License Data for Sale
A new dark-web service called Nexus is selling around 153 million driver's licenses from the US and Canada. According to longtime independent security reporter Brian Krebs, the service also offers 10 million ID cards and millions of travel documents and international IDs. Krebs was first alerted after cybercriminals posted an example file that included his own license.
The tens of millions of records reportedly increased by 400,000 over a 24-hour period. They appear to have come from an ID verification service, with the criminals claiming access to a "major"verification company. Krebs reports the Nexus service was taken offline shortly after he reported that FBI officials were investigating."The app is the risk, and there are two and a half million of them in the App Store alone," Yeagley tells WIRED. "The remedy is architectural: Constrain what an app can extract from the device in the first place."## Spyware Wave in Serbia
In August, Apple sent its latest batch of spyware notifications to people in 110 countries."mercenary"spyware but do not name the software creators."largest documented wave of such surveillance in the country to date."





