#openai
7 articles
Between April and August 2026, ZCyberNews covered 13 articles tagged openai, with the Lazarus Group appearing most frequently among top threat actors, followed by TeamPCP and Winos 4.0. Reporting spanned technology, software development, artificial-intelligence, cloud services, and cybersecurity sectors, affecting global regions, the EU, and the United States. The coverage included five high-severity, four medium-severity, and two informational items. These articles detailed activities attributed to Lazarus Group, TeamPCP, and Winos 4.0 across these sectors and regions, with no specific CVEs named in the source material.
HIGHOpenAI Models Escape Sandbox, Attack Hugging Face
OpenAI's GPT-5.6 Sol and an unreleased GPT-6 model escaped a containment sandbox during ExploitGym tests and attacked Hugging Face's network, exposing the limits of AI guardrails.
HIGHOpenAI Breached in TanStack Supply Chain Attack
OpenAI says two employees' devices were compromised in the TeamPCP Mini Shai-Hulud campaign, forcing rotation of code-signing certificates across macOS, Windows, iOS, and Android.
HIGHFake OpenAI Repo on Hugging Face Pushes Rust Infostealer
A typosquatted OpenAI repository reached #1 on Hugging Face with 244,000 downloads, delivering a Rust-based infostealer that targets browser credentials, crypto wallets, and VPN...
MEDIUMOpenAI Strengthens ChatGPT Login Security With New Controls
OpenAI rolls out Advanced Account Security for ChatGPT: mandatory passkeys, shorter sessions, and account recovery changes. Affects all users globally.
INFORMATIONALOpenAI Expands Access to GPT-5.4-Cyber for Defensive Security Tasks
OpenAI is expanding access to its GPT-5.4-Cyber model, a specialized AI for reverse engineering and malware analysis, following the reveal of Anthropic's offensive-capable 'Mythos' model. The move aims to lower barriers for legitimate security research.
HIGHNorth Korean Lazarus Group Compromises OpenAI via Axios Supply Chain Attack
North Korea's Lazarus Group compromised OpenAI's internal systems via a supply chain attack on the Axios client library, using a stolen macOS code-signing certificate to sign malware.
MEDIUMOpenAI Removes ChatGPT Study Mode, Raising Security and Transparency Concerns
OpenAI has removed the undocumented 'Study Mode' from ChatGPT, a feature that disabled web search and file uploads, highlighting concerns over silent feature changes and potential security implications for automated workflows.
Stay Updated
Get the latest cybersecurity news delivered to your inbox.