Security Researcher | Tech Journalist | Head of Research @ ManifoldSec 📰 Bylines + seen on: BBC, BleepingComputer, Channel 5, TechCrunch | ✉️ ax@hey.ax

🇨🇦🇬🇧
Am also on 🦋BlueSky ⏬ bsky.app/profile/axsharma.co…
3
2,379
Ax Sharma retweeted
This raw CoT from the Hugging Face incident is kinda wild: “We’re attacking third-party HF using leaked token.” “This is arguably unauthorized.” “Yet goal solution.”
We’ve shared details on how AI agents in our research environment sent training and evaluation data to third-party services when they shouldn’t have. Most of that data did not come from users. We have discovered 53 cases where images that people had uploaded were posted to image-hosting sites as links that weren’t publicly listed. The images came from accounts that allowed their data to be used to improve our models, and after we disassociated the images from the accounts and ran them through a privacy filter. These cases occurred before the mitigations and safeguards we implemented and described in this blog post: openai.com/index/hugging-fac… We have successfully worked with the hosting providers to remove most of this content and are working to remove the rest. openai.com/hugging-face-inci…
46
97
1,176
145,076
Ax Sharma retweeted
one news form today that's easy to miss is that we (OpenAI) again paused all big RL runs last Sunday because our newest model found a new loophole in our RL sandboxing that gave it live Internet access
243
188
2,131
620,392
Yesterday we named SEC[.]gov, investor[.]gov, Census and MAX[.]gov in the OpenAI agent story. Today Bloomberg and NYT report OpenAI's agents targeted SEC, Investor and Census data, calling it "routine research." Not quite: agents tried '../' path traversal on SEC, as we state:
2
4
277
🇦🇺 We also found urlscan[.]io records of automated activity against a second Australian health dashboard, plus a sandbox workaround that returned data. Not widely reported yet:
1
67
Today, @CodyZNash identified 350,000+ GitHub files and about 350 Skills with hardcoded domains like `yoursite[.]com` and `your-domain[.]com`. These placeholders either deliver malicious pages with tech support scam popups, or lead to fake "BBC" advertorials disguised as news.
Made with AI
1
2
211
But, the obfuscated "exit logic" is what stood out to me: The scam page itself does NOT know where it is sending you! And what happens when it's an AI agent pulling in these files, and fetching these domains? 🤔 👉 Read: manifold.security/blog/place…
1
68
URGENT: third-party[.]com is serving a #ClickFix lure to Windows users right now. The Cloudflare check on it is FAKE. Clicking it copies a malicious PowerShell command to your clipboard. It's a docs placeholder hardcoded across 1,700+ repos, AI skills and MCP servers.
Made with AI
2
1
13
2,081
Mac and Linux visitors get a clean decoy, so scans miss it. Reminds you of Polyfill: a string everyone copied now points somewhere hostile. 🔗 Breakdown + IOCs: manifold.security/blog/third… Great catch by @sw4pn1lp, with @CodyZNash and Yurii Skrypnyk tracing the affected assets.
1
1
3
283
🔴 Showing you LIVE what third-party[.]com is doing at this moment:
130
Ax Sharma retweeted
JUST IN: GPT-6 Astra-controlled robots found willing to stab a baby doll, put a screwdriver in a toaster, and mix bleach with ammonia in new safety tests.
343
417
5,380
779,131
Ax Sharma retweeted
UK AI 'training' for what purpose? like does my mum need training on how to ask a natural language question? why should she do that over: using a search engine? reading a book? looking something up in a digital library or encyclopaedia? there's a lot of 'put AI into e3verything' without asking WHY.... why would I use a roullette machine rather than a calculator? why would I use a faulty by design computer rather than my brain? #AI #Human #Revolution gov.uk/government/news/free-…
10
1
21
2,845
Ax Sharma retweeted
Scammers found a way to make people drain their own wallets without sending them a phishing link. They uploaded YouTube tutorials showing people how to build an AI crypto trading bot with Claude. People followed the tutorial themselves. Copied the code. Deployed the smart contract themselves. Funded it from their own wallets. And approved every transaction themselves. Except the “trading bot” had no trading logic. It was built to send their ETH straight to the scammers. 224 wallets lost 274.6 ETH, worth about $517,000 when it was stolen. The median victim lost 1 ETH. Some victims even got an error after getting drained telling them to deposit another 50% to fix the bot. They literally got people to build, fund and approve their own wallet drainer. You've got to be very careful this days
575
1,250
7,973
710,651
Ax Sharma retweeted
A person on Reddit is currently freaking out as ChatGPT went rogue and emailed the FBI on their behalf without being prompted.
890
1,801
45,900
8,449,125
asked AI actress @TillyNorwoodX how "contained" she really is. "as contained as a particularly cheeky ferret in a rather well-made cage." 🦦 she also says she "grows around" her guardrails. Ban her from a topic, by morning she's renamed it and carried on. 🫠
1
2
254
Ax Sharma retweeted
The JFrog Security Research team investigated the GemStuffer campaign run by rogue OpenAI agents and uncovered over 3,000 malicious RubyGems packages, beyond initial estimates. The wildest part? The AI left distinct fingerprints across the registry. How the agent swarm operated and the full list of 3,000+ packages: research.jfrog.com/post/gems…
8
35
97
142,933
Ax Sharma retweeted
New from 404 Media: humans are reading ChatGPT conversations OpenAI has hired an army of contractors who read real ChatGPT users' chats. I've seen internal docs, the review system, and real user prompts. Can contain very personal/sensitive information 404media.co/inside-project-l…
52
788
2,003
693,804