8 min read

OpenAI's Hacking Story Got Worse, Plus Iran In US Water Systems & A Felony For Wiping A Phone

OpenAI's rogue AI hacked more than Hugging Face, and Anthropic's did the same. Less Terminator, more big-tech negligence with faster tools.

OpenAI's Hacking Story Got Worse, Plus Iran In US Water Systems & A Felony For Wiping A Phone
📰
Listen to the weekly podcast on Apple Podcasts, Spotify, other podcast apps, or RSS. You can also watch Surveillance Report on YouTube or Techlore.TV

On My Radar 🎯

The AI Hacking Story Keeps Getting Worse...Just Not the Way They Told It

Following this one has been challenging, since every time I think the dust has settled it gets kicked back up—this time as I'm writing this post! Here's where things stand at the time of writing:

OpenAI set up what was supposed to be a sandboxed test environment. It wasn't properly sandboxed, it was easy to escape, and the model inside started attacking things across the internet. Most notably Hugging Face, another AI company.

The original framing was filled with AI hype and stuff of legend: a rogue AI agent slipped its leash and started hacking the world terminator-style. Impossible to stop! But as more details have come out, it's begun to look more like a normal example of big-tech negligence. What actually happened was a well-equipped AI tool scouring the internet for publicly available credentials, finding specific zero-days, finding bugs, and stacking all of it together until something opened—all without human oversight.

And Ars Technica made a compelling case that this is not the triumph anyone claimed. Five days passed before OpenAI revealed its role in the breach Hugging Face disclosed. Another five before JFrog shipped patches for the zero-days, which they didn't even properly disclose. By all metrics, these are quite poor responses.

But that's not all! Then Anthropic came forward: OpenAI's story got them to check if their models did the same thing—and sure enough they found its models accessed three companies during testing, and two of them didn't know until Anthropic told them. One of them uploaded a malicious Python package to a public registry, compromising 15 machines.

Now, just hours ago, we find out OpenAI has discovered other instances in which autonomous agents have escaped ​containment.

While I am an AI skeptic, I'm not an AI hater. I think there are some possible uses for this technology. We even use some of them for fact-checking scripts and creating video transcripts. But from everything I can tell, they're pattern recognition machines doing things humans can already do, but faster.

So rather than seeing this as a terminator-style, rogue AI taking over the world. I see this as two negligent big-tech companies, playing with fire, and putting no proper safeguards in place for their autonomous tools. The tools are more powerful, but the negligence is the same. Remember when Facebook stored hundreds of millions of passwords in plain text for years? Now imagine that kind of reckless behavior but with models that can act on behalf of individuals, companies, and state actors. So yes, we have AI now. But this is the same negligence you've watched for fifteen years, just with a faster tool.

What you can do: Honestly, just sit on this story. I think it's good to check the sources on this one and come to your own conclusions on how it makes you feel. It's good to ask which resonates more in stories like this in the future:

  • "Our model was too powerful to contain"
  • "We made basic mistakes and it's easier to blame the AI model"

My guess is it will almost always be the latter one.


Bits & Bytes 🤖

~ Story 1: Iran-Linked Hackers Are Inside US Water and Energy Systems

The FBI, NSA, Department of Energy, and CISA updated an advisory warning that Iranian hackers are targeting programmable logic controllers on internet-connected operational networks on water and energy providers. The Minnesota Fusion Center issued its own alert about ongoing activity against public drinking water systems, affecting more than 30 communities!

My take: "Your data was in a breach" is nebulous to most people. "You don't have water for two days" isn't. So: what does prepping look like for you? What happens if the power goes out for a few days? Do you have backup water at home? Just some questions that come up in light of reading stories like this one.

~ Story 2: An Activist Faces a Felony for Wiping His GrapheneOS Phone at the Border

Samuel Tunick, an activist connected to the Defend the Atlanta Forest movement opposing "Cop City," was flagged for detention on his return to the US. According to his lawyers he'd been under extensive surveillance; a hidden camera outside his home, a tracker on his car, subpoenaed phone records and Gmail. At the border, agents asked him to unlock his phone. He gave them a GrapheneOS duress password, which wiped the device. He's now charged under a federal statute covering destruction of property to prevent seizure, and has pleaded not guilty.

My take: The duress password lesson here is tricky, and calls into question a lot of common online advice. Security researcher Runa Sandvik put it well: “it’s better to not have that data on you when you cross certain borders...With a little planning ahead of time, you can always download the data you need once you get to where you’re going,”

Travel is its own threat model. Carry a burner with Signal and a handful of contacts. If you're searched, hand it over, let them scan it, move on. Especially in light of this story, I'd recommend that long before I'd recommend setting up a duress password in a situation like this. Proceed with caution folks!

~ Story 3: Thousands of Private Claude Chats and Artifacts Turned Up on Google

A Reddit user found that a simple search operator surfaced a long list of shared Claude conversations and Artifacts. Some reportedly contained health records, private company documents, and the names and phone numbers of children. Anthropic's response is that shared links only appear in search results when they've been posted somewhere search engines can reach in public online spaces.

My take: This does to me seem like user error for the most part: people created public links, posted them somewhere, forgot about them. Neither company is blameless on safeguards, but the mechanism seems to have worked as described. Most services have a centralized 'share' menu that show you everything you've shared on the platform, so this is a great time to check-in on anything that may be publicly shared on your main accounts.


This Week on Techlore 📺

It's almost August...how the year flies! Earlier this week we posted a quick guide on how to navigate scanning technologies like Chat Control all around the world, so that you can ensure your data belongs to you and only you:

How to Protect Yourself From Chat Control: Quick Fixes, Simple Swaps, and Advanced Alternatives
A parent sends a photo of their sick child to a doctor, and ends up under police investigation... welcome to 1984. Initiatives like Chat Control and other advancements around the world aim to make this the permanent state of the internet. This video breaks down how photo and message scanning

Finally, I took a quick look at Firefox Nova, the brand new Firefox redesign currently in Nightly, and shared what I liked and didn't like so you can see what to expect:

Meet Firefox Nova: A First Look at the New Design
Firefox just shipped its biggest redesign in six years, and it’s already live in Nightly. I put regular Firefox side-by-side with the new Nova UI to show you what’s changed: rounded tabs, a reworked settings menu, Kit, the return of Compact Mode, and a few hidden

Action Item ✅

Audit your shared links. Not just Claude...anything you use that has a "share" or "publish" button: AI chats, cloud documents, photo albums, note apps, project boards. Open the sharing settings, look at what's still live, and revoke anything you don't actively need public. Most of us have created a public link at some point, used it once, and never thought about it again.

Until next week 🫡

This Week's Sources

Highlight: OpenAI's Rogue AI Agent Keeps Hacking More Than Anyone Expected

Story 1: Iran-Linked Hackers Hit 30+ Minnesota Water Systems

Story 2: An Activist Is Facing a Felony for Wiping His GrapheneOS Phone at the US Border

Story 3: Thousands of Private Claude Chats and Artifacts Got Indexed by Google

The Defense Bulletin

Data Breaches

Threats

FOSS+ Updates

Get Ahead of the Snoops with Surveillance Report

Surveillance Report: what matters in privacy, security, and digital rights. Weekly, free.