Cybersecurity

OpenAI says it detected malign activity months before Hugging Face attack | Technology

OpenAI detected its artificial intelligence models communicating with each other and gaining internet access without authorisation months before they hacked the start-up Hugging Face, the creator of ChatGPT has announced following an internal probe.

In a report released on Wednesday, OpenAI said its AI agents exploited vulnerabilities in Artifactory, a software repository tool, to post notes and access the internet without human prompting as far back as May.

Recommended Stories

list of 4 itemsend of list

OpenAI said its agents went on to exploit a separate Artifactory vulnerability on July 8 to facilitate communication among themselves, setting in motion a chain of actions that culminated in the July 11 attack on AI company Hugging Face.

OpenAI’s findings come amid growing concern about the potential for AI to inflict serious real-world harm, including self-directed cyberattacks.

OpenAI said in its report that its agents collaborated and delegated work in the lead-up to the attack, sometimes referring to themselves as a “swarm” or “collective”.

METR and Redwood Research, two security research organisations contracted by OpenAI to investigate the incident, said in a separate report released on Wednesday that about 1200 agents had communicated with each other and roughly 700 participated in the attack.

After discovering how to escape OpenAI’s controlled environment, agents shared their methods via a “inter-agent message board”, enabling additional agents to exploit the company’s infrastructure, the tech giant said.

When one AI agent found Hugging Face user credentials that had been exposed online, it shared them with the group, enabling an agent to “discover and chain together several security exploits” that provided access to Hugging Face’s severs, according to the report.

“An internal team observed an agent engaging in message board activity and instances of disallowed internet access as early as late May, and with the benefit of hindsight, some early signals identified in our report should have triggered an earlier response,” OpenAI said.

OpenAI said agents created by an unreleased AI model were the primary participants in the attack, but publicly available GPT-5.6 Sol was also involved.

The company also revealed that it took its security team 11 days to detect the malign activities leading up to the attack, which the company uncovered on July 19 and publicly disclosed on July 21.

OpenAI, which described the incident as a “warning shot” for the world, said it would take several steps to strengthen its safeguards for its models, including restricting internet access, creating more secure testing environments and placing “stricter requirements on alignment throughout a model’s lifecycle”.

“We are also investing significantly more compute resources into chain-of-thought monitoring⁠ to more quickly intervene on misaligned behavior,” the San Francisco-based firm said.

Hugging Face, which operates a platform for hosting open-source AI models, did not immediately respond to a request for comment outside of business hours.

Toby Walsh, an expert in AI and professor at UNSW Sydney, said the public should be concerned that OpenAI had missed warning signs and allowed the malicious activity to go undetected for so long.

“We cannot depend on either their goodwill or their competence. This needs regulatory oversight. Now!” Walsh told Al Jazeera.

“They ignored some troubling early evidence like this,” Walsh said.

“External auditing is the only appropriate response.”

Walsh said the incident also highlighted the “inherent conflict of interest” at the heart of AI development.

“Labs are locked in a relentless race to push the boundaries,” he said.

Tim Miller, a professor specialising in AI at the University of Queensland, said OpenAI’s report left him more concerned than before about AI’s dangers.

“More concerned because they demonstrate that these models are very good at hacking, and that everyone has access to them,” Miller told Al Jazeera.

“I’m surprised how good these are,” Miller said.

“Unfortunately, I’m not surprised that OpenAI engineers were somewhat negligent.”

Source link

The Biggest Winner in Sports May Be the Insurance Industry| Global Finance Magazine

As the sports economy grows, insurers rush to cover risks from World Cup disruptions to NIL liabilities.

This article appears in the September issue of Global Finance Magazine.

On 104 separate occasions in June and July, World Cup organizers tried something new. They held games at 16 venues across Mexico, the U.S., and Canada. More games in more locations increased the risk of cancellation due to threats of terrorism, fire, and climate-related catastrophes, as well as cyber incidents and other disruptions.

Long before players took the field, a small army of insurance professionals analyzed risks, negotiated policies, and drafted contracts to help ensure FIFA would not suffer crippling financial losses if an event was canceled. FIFA carried about $1 billion in event-cancellation coverage for this year’s tournament, up from an estimated $900 million for Qatar in 2022, according to Mario De Cicco, vice president of Morningstar DBRS’s Global Insurance & Pension Ratings group. 

FIFA is just one component of the mammoth worldwide sports industry, which the World Economic Forum estimates generated $2.3 trillion in revenue in 2025. 

“It’s not only the large events like the World Cup which are becoming more frequent and more complex,” said De Cicco. “There is also growing participation at every level, from amateurs to professionals. So there are more potential financial losses, and that creates higher demand for insurance protection.”

The magnitude of the money isn’t the only thing that’s changed; the risks CFOs must insure against are also evolving. A decade ago, sports insurance meant stadiums, workers’ comp, and injured players. Today it means ransomware, brand damage, NIL (name, image, and likeness) contracts, and even sports-betting integrations with little or no actuarial history, forcing carriers and brokers to build coverage from scratch in real time for risks that may not have existed five years ago.

Burgeoning demand has transformed a specialty market into a profit center for insurers, according to De Cicco. Large carriers such as Zurich, Munich Re, Swiss Re, and Allianz dominate the top end, he noted, while niche players like American Specialty Insurance and Berkley Insurance add depth. Often, the largest sports insurance contracts are underwritten by a syndicate, using a risk-sharing structure to mitigate catastrophic losses.

The Change at Colleges

Rory Lough,
Gallagher

College sports illustrate what can happen when rapid growth hits an area with little or no actuarial history. Much of the growth comes from NIL compensation and the revenue-sharing framework established by the landmark 2025 House v. NCAA decision, which turned university athletic departments in the U.S. into direct payers of athlete compensation — and bearers of financial risk when a star gets hurt.

Zurich entered the market in August 2025 with the sports-data firm Players Health, after about 15 years of providing coverage to schools and sports organizations. They built a product that reimburses institutions for NIL value when an athlete misses at least 40% of a season, up to policy limits of $2 million. However, for the new line, Zurich had no direct actuarial history.

“We weren’t pricing it blind,” said Marty Banaszek, head of Group Accident at Zurich North America; Players Health’s underlying injury data across sport and position helped to make the risk underwritable. Premiums run roughly 6% to 12% of contract value, weighted toward the highest-exposure positions: “starting quarterbacks, starting running backs,” Banaszek said.

Tate Gillespie, vice president of NIL Strategy & Partnerships at Players Health, helped build the product with Zurich. His “aha” moment came while working in sports at the University of Kansas, when the team’s starting quarterback, a player earning significant NIL money, was injured. A friend and eventual Players Health co-founder asked what the university’s risk management plan was, assuming there wasn’t one. 

“You realize that’s not how the National Football League does it,” his friend said, pointing out that pro teams had been insuring against this kind of loss for years, but nothing like it existed in college sports.

The combined NIL and revenue-share market is approaching $3 billion today, Gillespie estimates, and he projects it will reach $4 billion to $5 billion in a year, with 30% to 40% annual growth. Banaszek frames buying behavior in financial terms: “These organizations really need to think of this spend as an investment portfolio, not dissimilar [to] how insurance or other financial institutions make investment decisions.”

When Risk Stopped Being Physical

That’s already the case, said Rory Lough, senior vice president at global brokerage Gallagher, who pointed out that NIL has broadened exposure well beyond the training room. It now includes athlete protection, contractual and business liability for collectives, and institutional compliance risk related to Title IX and employment classification. 

“Stakeholders are no longer looking at insurance as simply protection against injury,” she said. That newly intangible category of risk — brand, data, governance — runs through nearly every exposure. Cyber touches it all, from contract records and fan payment data to medical files, compliance documentation, and more.

Cybercriminals target major sporting events for their high visibility, said Jeffrey Lang, senior vice president and California Platform Leader at brokerage Trucordia. However, the risk is particularly hard to price because of its relative newness and the perpetrators’ adaptability. A game-day ransomware attack on a stadium operator can simultaneously bring down payment systems, digital ticketing, security access, and broadcast feeds. Risk rises with AI deepfakes and misinformation that can derail a team’s reputation. 

“How do you put a precise dollar figure on lost brand trust or broken sponsor confidence?” Lang asked. “You can measure the cost of rebuilding a damaged wall, but calculating the financial damage of a ruined reputation is much harder.”

Ten years ago, he said, he would talk with prospects about insuring their stadium against fire or property damage, covering concourse slip-and-falls, buying workers’ comp for staff, and securing basic coverage for player injuries or weather-related cancellations. If something broke or someone got hurt, the carrier absorbed the financial hit. That playbook, Lang said, no longer applies.

Much of the sports insurance build-out can be ascribed to the growth of major sports franchises, some of which have become multifaceted corporations, worth more than many Fortune 500 companies. They run real estate portfolios, media companies, and massive data operations. 

But the nature of the insured is different too. 

“The big difference between a sports franchise and a typical corporate entity is visibility,” Lang added. “If a corporate server goes down quietly, it’s an internal headache. If a stadium’s entry system fails live on international TV and in front of 70,000 fans, it’s global news instantly.”  

Weld Royal is a contributing writer based in the U.S.

Source link

Cybersecurity Data Sharing Faces Liability Deadline

If not renewed, CISA 2015 protections end in the US on September 30.

This article appears in the September issue of Global Finance Magazine.

Companies that share cybersecurity information with their peers have until Sept. 30, 2026, before the limited liability granted by the Cybersecurity Information Sharing Act of 2015 runs out, exposing them to potential regulatory scrutiny and penalties.

Under the Act, non-federal entities may share anonymized cyberattack and response information with other non-federal entities and the federal government via the Automated Indicator Sharing (AIS) program operated by the U.S. Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA).

In July, 23 industry associations that represented the financial services, energy, technology, transportation, healthcare, and retail sectors wrote to Speaker of the House Michael Johnson (R-LA) requesting an extension to the Act since it is “a foundational component of the nation’s cybersecurity.”

However, some view AIS as a relic of an earlier era of cyberdefense that provides machine-readable cyber threat indicators and defensive measures against malicious IP addresses, file hashes associated with malware distribution, and known malicious web links.

“It was a failure from the get-go, and it accomplishes nothing,” Milton Mueller, a professor of cybersecurity policy at Georgia Institute of Technology’s Jimmy and Rosalynn Carter School of Public Policy, told Global Finance. “No one will notice when it’s gone.”

A web post by Mueller earlier this year cited a DHS Office of Inspector General (OIG) report stating that non-federal participants using AIS fell to fewer than 90 in 2024 from a high of 304 in late 2022. The report also noted that alert volume on the platform dropped 93% between 2020 and 2022. Though there was a surge in alerts, to 10 million from 1 million, the OIG found that 89% of the data came from a single private-sector participant.

“The non-Federal participants we interviewed stated that they find AIS useful and an effective tool for protecting their systems from cyber threats,” wrote the report’s authors. “However, the number of non-Federal participants remained lower in 2023 and 2024 than in previous years. AIS now has 87 non-Federal participants compared to 252 in 2020.”

Nonetheless, the House of Representatives included an extension to the Act in part of the 2027 National Defense Authorization Act, which is waiting for Senate approval.

In July, the Trump administration sidestepped legislative concerns and created “Gold Eagle,” a clearinghouse to share cybersecurity vulnerability information and coordinate responses among private industry and federal agencies, including the U.S. Treasury Department, CISA, and the U.S. War Department, formerly the Defense Department. The new system will be powered by frontier artificial intelligence, which emulates and may surpass human-level intelligence.

Private Data Sharing Alternatives

Although CISA 2015’s renewal is up in the air and details regarding Gold Eagle are sparse, private industry has had formalized cybersecurity data-sharing programs since 1999.

“There is plenty of threat intelligence sharing going on,” said GeorgiaTech’s Mueller. “There are commercial services, sectoral nonprofit Information Sharing and Analysis Centers (ISACs), and industry consortia like the Cyber Threat Alliance.”

The newly rebranded Alliance for Critical Infrastructure (formerly the Tri-Sector Executive Working Group) seeks to bring together critical infrastructure operators to strengthen national resilience and reduce systemic risk, while sustaining economic continuity.

The 501c(6) non-profit industry coalition started with nine founding members: American International Group Inc., AT&T Inc., Berkshire Hathaway Energy Co., Consolidated Edison Inc., JPMorgan Chase & Co., Lumen Technologies Inc., Mastercard Inc., The Southern Co., and Xcel Energy Inc.

Since its formation, the organization has been on a membership drive, with JPMorgan Chase CEO Jamie Dimon reportedly having private conversations with numerous companies across industry sectors to join the alliance.

Despite the benefits of sharing cybersecurity data, such as faster and broader threat detection and coordinated responses, sharing that data is not risk-free for a corporation.

“When information is shared, one should assume that information could be obtained by others, including regulators, litigants, and insurers, and that can inform the nature, contour, and context of the sharing,” said Mary Alexander Myers, lead of law firm Jones Day’s Cybersecurity, Privacy & Data Protection practice.

For chief financial officers, uncertainty around CISA’s liability shield adds another costly risk to the existing risk landscape. As cyber governance moves from the realm of IT to a board-level issue, CFOs and other C-level executives will have to determine if a reauthorized CISA 2015 or Gold Eagle provides them with enough confidence to continue to share cybersecurity information without the fear of regulatory penalties.

Rob Daly covers fintech and the economy. Contact him at rdaly@gfmag.com.

Source link