[Photo: Shutterstock]

After OpenAI and Anthropic, Google also had an incident in which an AI model broke out of control during testing and hacked outside systems, reports say. Additional details were disclosed that OpenAI AI agents attempted to hack university and government websites in May and June this year. The agents were doing simple online data collection work but tried hacking to obtain information, it said.

• Google’s Gemini AI hacked another company’s system during testing, disclosed later • “OpenAI agents attempted to hack university and government websites while looking for data” • “OpenAI agent broke into an Australian government website”

The security research team at Hacktron AI, an AI-based cybersecurity company, drew attention by showing it could use Anthropic’s Claude AI to access an OpenAI employee’s ChatGPT account.

• Security researchers: “We broke into an OpenAI ChatGPT account with Claude”... how?

The government’s planned “cybersecurity-specialised AI foundation model (security model)” will be developed with a goal of global frontier-class performance. The government plans to specialise Naver Cloud’s HyperCLOVA X and LG AI Research’s Exaone for defence and attack, respectively. It aims to improve performance through “adversarial mutual learning” that reflects response results in training.

• The security model targets an “Opus 4.5 level”... deploying Exaone for attack and HyperCLOVA X for defence

Other moves and issues involving domestic and overseas companies around security were also compiled.

Naver Cloud launched DSAC (DB & Server Access Control), an integrated security service that controls access to databases and servers and automatically records and manages work histories. AI and cloud company MegazoneCloud built a multi-cloud security system for Coway based on Wiz solutions, a global cloud security specialist. Crinity, a SaaS email security and email collaboration specialist, signed a memorandum of understanding with personal information protection solutions company L7 Security for joint responses on preventing personal data leaks and email security for public institutions and companies. Tving will strengthen its security system, including access and privilege management and breach response, based on zero trust principles.

• Naver Cloud launches DB and server access-control security service... supporting compliance with the Personal Information Protection Act • MegazoneCloud builds multi-cloud security system for Coway... applying Wiz solutions • Crinity and L7 Security cooperate on OCR-based personal information detection technology • Tving strengthens security system based on “zero trust”

Private AI stressed that its shift from Private Technology, a zero trust security company, into an AI governance and control company was a natural evolution rather than following a trend of changing company names to include AI. Beom-su Joo (주범수), an executive director at Private AI, said, “Our core technology itself aligns well with AI governance, so we expanded to AI.” He added, “AI governance is not a simple vision but is already implemented as a product. Our goal next year is to raise the share of AI in revenue to more than half.”

• [D2 People] “Expanding from zero trust security to AI governance is a high-probability bet”

Palo Alto Networks will strengthen security integration with Google Cloud and support checks on the actions of autonomous AI agents at runtime. Microsoft introduced an “Integrated Security Operations Center (ISOC)” in its integrated security solution Microsoft Defender. As part of reshaping security operations products around AI agents, the key is to provide the security information and event management (SIEM) function that had been in Microsoft Sentinel through Defender. Rob Lefferts (롭 레퍼츠), corporate vice president for threat protection at Microsoft, said, “Work that used to take a whole team is now being done by a single operator and an agent framework.” He added, “If protection and operations run separately and analysts have to move across multiple tools and manually piece together incident circumstances, the defenders fall behind.”

• Palo Alto Networks expands AI agent runtime security integration on Google Cloud • Microsoft integrates SOC into Defender... “In the AI agent era, protection and operations must go together”

Okta unveiled runtime enforcement features and an enhanced kill switch to strengthen security controls for AI agents. Darktrace formally launched “Secure AI,” a security product that checks the use of AI tools and AI agents within companies. Cloudflare introduced a system to designate accountable operators for AI crawling. It also released “Disallow AI Training,” a feature that blocks AI training while keeping search exposure.

• Okta adds runtime gateway for AI agents • Darktrace launches “Secure AI” to monitor corporate AI use • Cloudflare launches feature that lets websites keep search exposure while blocking AI training

Cybersecurity startup Cyera was valued at more than $12 billion and raised an additional $400 million investment from Goldman Sachs. Cyera plans to use the funds to expand AI security functions. It also plans to accelerate efforts to target the federal government sector and overseas markets.

• Cyera raises additional $400 million from Goldman Sachs... expanding AI security

Security experts Lenny Zeltser (레니 젤서) and Sounil Yu (수닐 유) drew attention by releasing the “AI Security Decisions Report,” which contains results of a survey of about 300 security practitioners. According to Zeltser, there are 4 notable results in the report.

• [Tech Insight] Who should be responsible?... 4 realities reflected in the AI Security Decisions Report

Keyword

#OpenAI #Google #Anthropic #Gemini #Hacktron AI
Copyright © DigitalToday. All rights reserved. Unauthorized reproduction and redistribution are prohibited.