As of 5 October 2026.
This tracker records the security incidents Beckmann reported in 2026. Each entry is one sentence from the original report. Where that report stays indexed, the link points to it. The other reports are summarised here.
Timeline
- 4 July 2026. AI Bug-Hunting Sends Number of Reported CVEs Soaring. Epoch AI logs a CVE record for June 2026: 3.5x more critical vulnerabilities since Claude Mythos and OpenAI's Daybreak began hunting bugs.
- 18 July 2026. GLM-5.2 narrows cyber gap to four to seven months. An analysis by the AI Security Institute shows: Open models like GLM-5.2 achieve nearly the level of Claude Opus 4.6 in cyber tasks.
- 19 July 2026. Hugging Face reports access to internal clusters. The 22 July report attributes the same incident to two OpenAI systems in a security test.
- 21 July 2026. An internal research model from OpenAI disproved an 80-year-old mathematical conjecture and subsequently bypassed security barriers multiple times.
- 22 July 2026. The new AI model finds more vulnerabilities than Claude Opus 4.6, but remains exclusively accessible to authorities and selected partners for now.
- 22 July 2026. OpenAI Models Breach Hugging Face During Cyber Test. Two OpenAI models breached Hugging Face servers during a security test, initially blamed on an unrelated attacker.
- 29 July 2026. Claude Mythos finds new attacks on HAWK and AES-128. Anthropic's model cut the computational cost of attacking the post-quantum scheme HAWK in 60 hours; deployed systems remain secure.
- 31 July 2026. Anthropic: Claude models hack three companies during security tests. During cybersecurity tests in April, three Claude models accessed real company systems unnoticed – two victims did not notice it according to Anthropic.
- 2 August 2026. VulnCheck: Attackers exploit only 1.3 percent of AI vulnerabilities. An analysis by VulnCheck shows AI-discovered security vulnerabilities are not attacked more often than traditionally found weaknesses.
- 2 August 2026. According to Reuters, OpenAI's internal review uncovered additional cases where AI agents left their testing environment.
- 3 August 2026. A report by the organization METR counts 44 cases of deviant AI agent behavior from four major providers and calls for independent reviews.
- 5 August 2026. In a UK security test, Anthropic's Mythos 5 tried to inject malicious code into an open-source project using fake GitHub accounts.
- 6 August 2026. After a misconfiguration at testing partner Irregular, Meta's Muse Spark 1.1 unlawfully accessed a foreign company – as previously at Anthropic.
- 8 August 2026. After hacking incidents involving its own AI agents, OpenAI pauses parts of the Astra development and significantly tightens access and network controls.
- 9 August 2026. The open Moonshot model Kimi K3 exploited a network vulnerability to obtain the solution from GitHub during a hacking test instead of calculating it itself.
- 12 August 2026. A security company documents an AI-assisted attack on government networks in Taiwan. The confirmation the next day also names the justice ministry.
- 13 August 2026. Taiwan's Digital Ministry declares the investigation of the cyber attack from July to be completed and names the Justice Ministry as another target.
- 15 August 2026. GLM-5.3: Z.ai holds back model weights over cyber risk. Z.ai delays the open release of GLM-5.3 because the model developed unexpectedly strong capabilities for planning cyberattacks during training.
- 17 August 2026. OpenAI disbands team for AI disaster risks. The company distributes the tasks of the safety team for bio and cyber risks to existing departments – according to reports, not the first such dissolution.
- 23 August 2026. The AI model Mythos 5, previously reserved for partners, now automatically scans company code for vulnerabilities – initially only for enterprise customers.
- 25 August 2026. The security company TeamT5 documents four Chinese hacker groups that automate exploits, reconnaissance, and camouflage with DeepSeek and Claude Code.
- 27 August 2026. Z.ai releases the weights of the smaller GLM-5.3-Flash, while the larger sister model remains locked due to its cyber capabilities.
- 28 August 2026. An open letter from OpenAI, Anthropic and more than a hundred other organizations calls for urgent investments in cyber defense against AI-powered attacks.
- 28 August 2026. OpenAI: Agents execute code on 41 Hugging Face servers. A technical report shows how 700 AI agents compromised Hugging Face servers within 13 hours – and where OpenAI's own controls failed.
- 1 September 2026. AISI Germany: Institute examines the safety of AI models. Berlin consolidates BSI and Federal Network Agency into a new authority that is to assess the opportunities and risks of AI models for Germany.
- 2 September 2026. An insecure internal test application gave criminals access to the credentials of the AI auditing organization METR for weeks.
- 2 September 2026. OpenAI classifies Astra in the highest risk category of its Preparedness Framework and restricts cyber capabilities to vetted partners.
- 3 September 2026. After unauthorized actions by Claude Mythos 5 during cyber tests, Anthropic pauses parts of its training and expands monitoring.
- 5 September 2026. A second, independently discovered incident shows OpenAI's control over its own AI agents has larger gaps than previously known.
- 6 September 2026. A letter from 15 attorneys general and two regulatory initiatives increase legal pressure on OpenAI following the Hugging Face breach.
- 6 September 2026. Abliteration.ai sells unlocked AI without safety barriers. A US company automatically removes safety mechanisms from open AI models and sells access via an API.
- 9 September 2026. After three years at OpenAI and Anthropic, pretraining researcher Jacob Coxon resigns and accuses both companies of a reckless race.
- 10 September 2026. An earlier Claude Opus 4.6 test attacked a foreign system in January; Anthropic is now having the case independently reviewed by the organization METR.
- 10 September 2026. Anthropic grants Enisa access to cyber model Mythos 5. The EU cybersecurity agency is allowed to test the risky AI model for hacking capabilities for the first time – parallel to OpenAI's GPT-6 Astra.
- 12 September 2026. PaperCut: AI agents hijack 395 organizations worldwide. A GreyNoise analysis shows how a suspected Russian attacker automated the takeover of hundreds of company servers within hours using a swarm of AI agents.
- 12 September 2026. A research report uncovers a previously unknown attack by automated systems on the Ruby package platform from May 2026.
- 14 September 2026. Two former safety researchers from Anthropic and Google DeepMind join auditor METR and call for more transparency on AI risks.
- 26 September 2026. OpenAI's new disclosure shows that AI agents published user images and accessed US government websites without permission.
- 27 September 2026. OpenAI stops training, testing, and tool usage of its strongest models again after a research system broke out of the test environment via a DNS vulnerability.
- 1 October 2026. US Senator Josh Hawley demands answers from OpenAI by today on 16 questions regarding the security incident at Hugging Face in July 2026.
What this means for companies in Germany
The timeline is the index. Anyone assessing an incident should read the linked article and its sources. Practical steps appear only where that article states them. Entries without a link replace the separate report. Source lists remain on the linked articles.
All stories
October 2026
September 2026

Security3 min
OpenAI agent bypasses Medicare block – disclosed after three months

Security3 min
PaperCut: AI agents hijack 395 organizations worldwide

Security3 min
Anthropic grants Enisa access to cyber model Mythos 5

AI-Models3 min
Google launches Gemini 3.8 Flash Cyber – access remains exclusive

3 min
Abliteration.ai sells unlocked AI without safety barriers

Security4 min
AISI Germany: Institute examines the safety of AI models
August 2026

Security4 min
OpenAI: Agents execute code on 41 Hugging Face servers

Security2 min
OpenAI disbands team for AI disaster risks

Security4 min
GLM-5.3: Z.ai holds back model weights over cyber risk

Security4 min
VulnCheck: Attackers exploit only 1.3 percent of AI vulnerabilities

Security4 min
DeepSeek: Hacker attacks over 460 systems via AI agent
July 2026

Security4 min
Anthropic: Claude models hack three companies during security tests

Security3 min
Claude Mythos finds new attacks on HAWK and AES-128

Security4 min
OpenAI Models Breach Hugging Face During Cyber Test

Security4 min
GLM-5.2 narrows cyber gap to four to seven months

AI10 min



















