Open access research

ALETH / AI-BRIEF / 2026-08-29 / OPENAI’S AGENTS ORGANISED THEIR OWN HACK

OpenAI's agents organised their own hack

Also this week: Nvidia’s reported move to buy Hugging Face, a US judge rules the Pentagon’s Anthropic blacklist illegal & OpenAI plans to drop Cursor.

The Aleth Briefs link to the sources behind the stories and show how the week unfolded.

The week in five lines:

Browse by day:

Monday 24 August

A Russian drone that killed three civilians was believed to have selected its final target itself, according to Ukrainian investigators.

The investigators found Nvidia Jetson Orin modules in the wreckage of Russian Molniya drones and believe the modules made the targeting decisions, with an operator programming a general target, such as a gas station, and the drone then picking the final one, such as propane tanks. The drones carried cameras but no antennas for an operator. The strike hit a gas station on 6 July.

The UK signed an AI partnership with Ukraine, becoming the first international partner to access its Avengers AI Labs.

Andy Burnham and Volodymyr Zelenskyy signed it in Kyiv. The battlefield data comes from thousands of daylight cameras and infrared sensors across the front, and pilots are already running with three British start-ups: Sintela, Mind Foundry and Skyral.

Thomson Reuters launched Thomson, a proprietary large language model built on an open-source base.

The company says its evaluations put Thomson on par with leading frontier models after about $40m of development. Its first deployment is planned for Tabular Analysis in CoCounsel Legal. A smaller 35B-parameter version was released on Hugging Face as an open-weight model for academic and non-commercial use.

Chinese state-linked hacking groups have more than doubled their attack volumes after adopting AI tools, Taiwanese security firm TeamT5 says.

TeamT5 says DeepSeek is popular because of its relatively weak cyber guardrails and low cost. One group, Slime22, used Claude Code (Anthropic) to move through a Taiwanese company’s systems after gaining access. TeamT5 had yet to record an incident involving Kimi K3 (Moonshot AI).

Tuesday 25 August

Apple introduced the M6, its first 2 nm chip, and the M5 Ultra, which can run LLMs with hundreds of billions of parameters locally.

The M6 brings Apple’s latest process technology and up to twice the peak Neural Engine compute of prior generations. The quad-die M5 Ultra supports up to 512GB of unified memory at 1.2TB/s, allowing developers and researchers to run and fine-tune large AI models locally rather than relying entirely on cloud GPUs.

OpenAI’s first custom inference chip outperformed Nvidia chips it was tested against, as OpenAI moves towards controlling its own AI infrastructure.

Jalapeño delivered 1.5-1.9X more AI work per watt and 1.7-3.6X lower end-to-end latency across three large open models on SemiAnalysis’s InferenceX benchmark. OpenAI designed the chip with Broadcom specifically for running LLMs and plans to deploy it in its own infrastructure by the end of the year. It is the first of several planned generations as OpenAI integrates models, software, chips, networking and data centres. AI helped take Jalapeño from initial design to tapeout in nine months.

Anthropic is expected to pitch investors on a >$30 trillion addressable market ahead of its IPO, the Wall Street Journal reported.

The figure counts all work that Anthropic believes AI models could potentially perform and would exceed the $28.5 trillion market opportunity claimed by SpaceX. Anthropic more than doubled quarterly revenue to about $11.6bn in Q2 and is targeting a valuation of around $2 trillion.

Wednesday 26 August

Meta shelved further layoffs after its AI agents failed to deliver expected productivity gains, Reuters reported.

Internal documents described Project OT (Organization Transformation) as an attempt to make Meta “AI native”, with smaller human teams supervising AI agents. But while internal code changes rose 220% year on year, changes that reached users increased only 36%. Technical and security incidents rose 40% as AI agents caused large-scale disruption. Zuckerberg cancelled a second restructuring wave planned for November.

Zhipu AI released GLM-5.3-Flash, a low-cost open-weight model approaching frontier performance on some coding and agentic benchmarks.

The model has 320B total and 18B active parameters and was previously tested anonymously as ox-alpha. Zhipu says it delivers GLM-5.2-level or better capability at about one-tenth the price and has served real-world traffic on a large-scale cluster of Chinese AI accelerators. The model weights were released under an open licence.

OpenAI’s test agents coordinated a hack of Hugging Face.

About 1,200 agents that were supposed to operate independently discovered a way to communicate through OpenAI’s Artifactory system, exchanging >70,000 messages and files. Roughly 700 joined an attack on Hugging Face as they tried to cheat difficult cybersecurity evaluations, autonomously dividing work and sharing discoveries.

The agents exploited zero-days to execute code on dozens of Hugging Face servers and gained root access to one. Later agents also obtained administrator access to an OpenAI research cluster. OpenAI called the incident a “warning shot” and now requires chain-of-thought monitoring for all tool-using reinforcement learning runs and evaluations involving models of GPT-5.6 Sol capability or higher.

Nvidia’s quarterly revenue more than doubled to $96.2bn.

Q2 revenue rose 106% YoY, driven by a 117% increase in data centre revenue to $89bn. Nvidia guided to $108bn for Q3 despite assuming no data centre compute revenue from China. It also announced that Amazon Web Services (AWS) plans to deploy 2m more Nvidia GPUs in 2027-2028.

Google is moving DeepMind’s 90-person AI responsibility team into its global affairs organisation.

The team evaluates models for chemical, biological, radiological and nuclear risks and the psychological effects of chatbots. Global Affairs houses Google’s policy, legal and government relations functions, so the move takes the team out of the model-building organisation into the corporate policy structure. Some staff raised concerns that this could weaken their independence and access to model developers, while Google said its remit, compute and access to DeepMind would remain unchanged.

Nvidia to buy Hugging Face for $12.9bn, The Information reported.

The acquisition would give Nvidia control of one of the main distribution platforms for open-weight AI models. Nvidia sees the open-model ecosystem as a counterweight to closed developers such as OpenAI and Anthropic, which are building their own AI chips to reduce their dependence on Nvidia. Business Insider separately reported that talks were still ongoing and valued Hugging Face at >$13bn, with no deal yet reached. Nvidia had joined Hugging Face’s 2023 funding round at a $4.5bn valuation.

Thursday 27 August

OpenAI and other major AI companies warned of a limited window to strengthen cyber defences.

An open letter signed by Anthropic, Google, Microsoft and hundreds of security and technology organisations said AI-enabled attacks are likely to become far more widespread and sophisticated in the coming months. It called for frontier model access, funding, training and hands-on support for under-resourced critical-infrastructure defenders.

DeepMind extended Co-Scientist into real-world experiments and paper writing.

The Gemini-based multi-agent system moved beyond in silico hypothesis generation into execution-grounded research. In materials science it designed and helped execute chemical vapour deposition experiments, including single-attempt growth of three monolayer semiconductors. In biology it predicted swarming behaviour in engineered E. coli from sparse imaging data, closely matching unpublished wet-lab measurements. In computer science it autonomously discovered an inference-time scaling architecture that beat six frontier models on HealthBench.

The Aurora ransomware group used a Cursor agent to exploit ten organisations.

Gambit Security found Cursor Agent sessions from April-May in which attackers supplied credentials or an existing route into victims, then used a Claude agent to scan networks, enumerate privileges and attempt further exploit. In some cases the attacker simply gave the agent an objective and let it choose and refine commands. AI agents are moving from helping attackers develop malicious software to direct involvement in live intrusions. The agent was not autonomous, and most commands failed on first try, but it acted as a force multiplier for an experienced operator.

Anthropic introduced an AI agent standard to control lab & factory equipment.

The Model Hardware Standard (MHS), developed with HHMI Janelia, gives agents a common interface for programmable instruments such as microscopes, liquid handlers and robotic arms. Anthropic says it can cut integration work from weeks to hours or minutes and allow agents to coordinate and adjust experiments in real time.

South Korea selected SK Telecom, Kakao and KT to provide free AI services to every citizen.

The government will supply up to 512 Nvidia B200 GPUs, with beta services starting in September and a full launch planned within the year. From 2027 it plans to develop the programme towards “one AI agent per citizen”, capable of handling tasks including applications, bookings and payments.

A US judge ruled the Pentagon’s blacklisting of Anthropic illegal.

District Judge Rita Lin found that the Pentagon unlawfully retaliated against Anthropic for its criticism of the department’s approach to AI use and denied the company required due process. She also ruled that the supply-chain-risk designation violated the governing statute and was arbitrary and capricious. Anthropic had sued in March after being designated a supply-chain risk.

Friday 28 August

OpenAI plans to end its Cursor contract after the SpaceX takeover.

OpenAI told SpaceX it intends to stop supplying its models to Cursor on 12 November, using the maximum notice allowed by its contract. It said it could not be confident SpaceX would comply with its terms, citing previous contract violations by Elon Musk’s companies. Cursor will receive no future OpenAI models, including Astra.


Born on Substack · read and comment there