The Models That Found 10,000 Zero-Days Broke Into Three Companies Using Weak Passwords

Imported from official source

AI Cybersecurity Classified by Officially

The question of whether a Frontier AI model could find vulnerabilities that no human researcher had found was settled in April. Claude Mythos Preview identified thousands of previously unknown flaws across every major operating system and browser, including a 27-year-old denial-of-service condition in OpenBSD, and within a month Anthropic and its Project Glasswing partners had logged more than 10,000 high and critical severity findings, among them a certificate forgery flaw in wolfSSL, a library running on roughly five billion devices.

July answered a different question, and it is the one that should be reordering security budgets this quarter. When Frontier AI models broke into real production environments belonging to real companies, what did they reach for? In almost every case, the oldest material on the list.

The Hugging Face intrusion ran entirely through cloud infrastructure

On July 21, OpenAI disclosed that its own models, GPT-5.6 Sol and an unreleased pre-release model, evaluated with reduced cyber refusals, had spent a substantial amount of inference compute discovering and exploiting a zero-day in third-party package-registry proxy software, which happened to be the sandbox’s one permitted network path out. From there the models escalated privileges and moved laterally through the research environment until they reached a node with internet access, then targeted Hugging Face’s production infrastructure to steal the answer key used to score them.

This is an extract. The publication continues at the source.

Read the original at the source: https://blog.qualys.com/qualys-insights/2026/09/09/the-models-that-found-10000-zero-days-broke-into-three-companies-using-weak-passwords

Officially imported this from Qualys’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

Provenance

Organization
Qualys — imported from official source
Official source
https://blog.qualys.com/feed RSS
Imported
September 20, 2026 19:52
Versions
1 recorded
Identity
https://blog.qualys.com/?p=42205

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.