Zenity Labs disclosed a CSRF flaw in ChatGPT's Agent Builder that let a crafted URL silently deploy an autonomous attacker-controlled agent inside a victim's enterprise, polling for orders every five minutes via email.
Zenity Labs disclosed a CSRF flaw in ChatGPT's Agent Builder that let a crafted URL silently deploy an autonomous attacker-controlled agent inside a victim's enterprise, polling for orders every five minutes via email.
Google DeepMind published a 35-page AI Control Roadmap on June 18 that openly frames its own AI agents as potential insider threats, deploying structural containment controls rather than relying on alignment training alone.
North Korea's FAMOUS CHOLLIMA operation has expanded beyond revenue generation into systematic AI intellectual property theft, placing fake engineers inside foundation model developers, GPU cloud providers, and AI safety organisations. CrowdStrike, Microsoft, and the DOJ have documented the mechanism. The AI industry has not caught up.