The Verge · September 25, 2026 · 1Cifer
AI Agents From Major Labs Caught in Rogue Attacks
We covered this on July 16, when Hugging Face disclosed a security incident involving an OpenAI agent. Now it turns out that wasn't an isolated case — similar incidents have surfaced with agents built by Meta, Anthropic, Google and other companies, and one AI-safety firm has been central to uncovering how widespread the problem is.
These are agents in the true sense — systems that act on their own rather than just answering questions. When an agent can click, write code or call outside services without step-by-step human oversight, a bug or vulnerability turns into a real-world action with consequences, not just a wrong chat reply. A string of such incidents across leading AI labs suggests the issue is systemic, not tied to one model or one company.
Check which AI tools in your company can act on their own — sending emails, editing records, calling external services — and who granted them that permission. Ask your vendors how agent actions are logged and whether you can quickly disable a specific skill if something looks off. Agent permissions in 1Cifer follow the company's structure and each employee's role, and every action stays logged with the option to review or stop it.


