Researchers demonstrated that OpenAI's Codex AI model successfully identified and exploited a security flaw in Samsung televisions, highlighting potential risks in automated code generation systems.
A security researcher used Codex, OpenAI's code-generation AI, to discover and execute an exploit against a Samsung TV. The exercise revealed how large language models trained on public code repositories can identify known vulnerabilities and generate working attacks without explicit instruction.
Codex analyzed the TV's firmware and generated functional exploit code, bypassing security mechanisms. The vulnerability itself was not novel, but the demonstration showed that AI models can autonomously recognize and weaponize security gaps.
The findings raise concerns about the dual-use nature of code-generation tools. While Codex and similar models provide legitimate development benefits, their ability to identify and exploit weaknesses could enable malicious actors to automate vulnerability discovery at scale.
Security researchers emphasized the need for improved safeguards in AI model deployment and stricter access controls for systems with vulnerability-discovery capabilities. Samsung has not issued a statement regarding the specific TV model or exploit details.
Manchester Airports Group disclosed a breach affecting Manchester, Stansted, and East Midlands airports. Hackers accessed data from approximately 8.7 million customers.
A lawsuit alleges that Elon Musk's xAI trained its Grok language models using child sexual abuse material, including both real and AI-generated imagery.
The ShinyHunters extortion group has published sensitive data from nearly 13 million Carhartt customer accounts stolen earlier this month, according to data breach notification service Have I Been Pwned.
A Russian-speaking ransomware gang called Aur0ra exploited SpaceX's Cursor AI coding assistant to breach at least seven companies between mid-April and late May, according to security firm Gambit Security.