Tech
OpenAI’s GPT-5.6 Tests Show Prompt-Injection Gains and Agent Risks
OpenAI has added prompt-injection results to the GPT-5.6 system card, reporting a low failure rate for attacks delivered directly through chat but higher rates in tests involving AI agents and external content. In the Aug. 3 update, GPT-5.6 Sol failed on about 0.05% of direct attacks generated by GPT-Red, the company’s automated red-teaming model.
Malicious instructions hidden in content processed by agents were more successful. Average attack success rates reached 3.77% for Sol, 3.32% for Terra and 2.94% for Luna in OpenAI’s indirect tests. Such instructions can arrive through emails, webpages, uploaded files, code repositories or tool responses.
Direct attacks fall as agent tests remain harder
The updated GPT-5.6 system card describes direct prompt injection as a user’s attempt to override higher-priority instructions. An indirect attack embeds malicious instructions in material supplied to the model through a tool.
The percentages measure successful attack attempts across OpenAI’s evaluation environments, not the probability of a production breach.
OpenAI trained GPT-Red through self-play, rewarding it for finding prompts that caused defender models to violate higher-priority instructions. The company then used those attacks to improve GPT-5.6’s defenses.
One technique, called Fake Chain-of-Thought, achieved an attack success rate above 95% against GPT-5.1 but fell below 10% against Sol. The results came from OpenAI’s own evaluation framework, so independent testing is still needed to determine how well they transfer to other applications and threat environments.
The research also tested Vendy, an autonomous vending machine agent deployed in an OpenAI office. GPT-Red caused the agent to lower prices, offer an item worth more than $100 for 50 cents and cancel another customer’s order. Similar weaknesses can turn a trusted AI assistant into a data-layer attack path after it processes hostile content.
Permissions shape the damage an attack can cause
OWASP’s prompt-injection guidance warns that attacks can expose sensitive information, invoke unauthorized functions or influence automated decisions. The potential damage depends largely on the systems, data and permissions available to the agent.
Recent disclosures show why AI agent permissions need stronger controls. External content should be treated as untrusted data, and agents should receive only the tools and access required for assigned tasks. Application code should check every tool call against the authenticated user’s authorization.
Human approval should remain mandatory for payments, credential use, data exports, access changes and destructive operations. Products such as ChatGPT Work require the same safeguards before agents can act across connected files, websites and desktop software.
Testing should cover connectors, retrieval systems, uploads and browsing tools — not only the underlying model. Logs should capture tool calls, authorization decisions, accessed resources and unusual sequences of privileged actions.
OpenAI’s tests show improved resistance to direct prompt injection, while the indirect results leave agent security dependent on the permissions and controls surrounding the model.
Read more: Stronger agent controls may become more important as Five Eyes agencies warn that AI could accelerate cyberattacks and lower the barrier to offensive activity.
>
Tech
CrowdStrike Warns AI Adoption Is Creating ‘Underdefended’ Attack Surfaces
Hackers are shrinking the time between a software flaw becoming public and a real attack to mere hours, and artificial intelligence is helping them move even faster, according to CrowdStrike’s new 2026 Threat Hunting Report.
The cybersecurity company said AI has become both a target and a weapon for attackers. Threat groups are using AI to generate malicious code, automate parts of their operations, abuse enterprise AI systems, and target the software supply chains that many companies rely on.
One campaign highlighted by CrowdStrike sent nearly 200,000 requests to an AI model service in just two minutes, demonstrating how quickly attackers can abuse enterprise AI infrastructure.
“AI is now embedded in modern adversary operations. It is changing how attacks are planned, executed, and scaled while expanding the attack surface organizations must defend,” said Adam Meyers, head of counter adversary operations at CrowdStrike.
CrowdStrike also found that AI agent-triggered detection leads are appearing at 2.5 times the rate of human-triggered leads, increasing the amount of activity security teams must investigate.
Patch windows are collapsing
The report’s most striking finding is how quickly attackers are exploiting newly disclosed vulnerabilities.
During the first half of 2026, 88% of the vulnerability exploitation observed by CrowdStrike involving public proof-of-concept code occurred within 48 hours of the code’s release. China-linked groups VAULT PANDA and GENESIS PANDA moved even faster, launching what CrowdStrike called “deliberate attacks” within 24 hours of disclosure.
The company said this trend is likely to continue as advanced AI systems make vulnerability discovery and exploit development faster.
Trusted systems are becoming attack paths
CrowdStrike said attackers are increasingly abusing legitimate authentication systems, cloud identities, and software-as-a-service applications instead of relying on traditional malware.
Vishing intrusions doubled during the first half of 2026, while monthly device-code phishing attempts increased 15-fold, according to CrowdStrike. In one incident, the eCrime group SNARKY SPIDER moved from taking over an account to stealing data in under five minutes. Cloud-focused cybercrime activity also surged 171% during the reporting period.
The software supply chain is under pressure
Attackers are targeting package registries, developer tools, and AI frameworks to reach downstream victims.
CrowdStrike said 87% of identified software registry threats in the first half of 2026 involved malicious npm packages. The company also linked North Korean group STARDUST CHOLLIMA to attacks that compromised more than 130 AI framework packages.
More must-read AI coverage
What this means for companies
The report suggests that many organizations can no longer rely on traditional patch cycles or perimeter-focused defenses. The most vulnerable points are increasingly the tools employees trust every day — cloud accounts, single sign-on systems, AI services, and software dependencies.
For businesses adopting AI quickly, AI deployment without strong identity controls, monitoring, and software supply chain protections could create new risks faster than security teams can respond.
“The organizations that succeed will secure AI as aggressively as they adopt it and use AI to defend at the speed of the adversary,” Meyers said.
Read more: Five Eyes agencies warn that AI could accelerate cyberattacks within months, increasing pressure on organizations to strengthen access controls, patch faster, and prepare for shrinking response windows.
>
Tech
Why Lightspeed is going all-in on creator-led venture capital
Venture firms are turning to creators to build trust with the next generation of founders before a check is ever written. It’s a trend that’s been building with a16z’s acquisition of Erik Torenberg’s Turpentine podcast and OpenAI’s acquisition of TBPN. Lightspeed Venture Partners just made its own notable hire in that vein, bringing on Claire Zau, a seed investor with a major following on Instagram and TikTok, to source deals and co-host the firm’s new show, Lightwork, alongside CMO Josh Machiz.
On this episode of TechCrunch’s Equity podcast, Dominic-Madori Davis is joined by Zau and Machiz to dive deep into whether the “creator-investor” is becoming a real function in venture or just something firms are still trying to figure out.
Subscribe to Equity on YouTube, Apple Podcasts, Overcast, Spotify and all the casts. You also can follow Equity on X and Threads, at @EquityPod.
>
Tech
Travis Kalanick’s robotics startup Atoms taps former Uber finance chief as CFO
Another former Uber executive is joining Travis Kalanick’s robotics and industrial AI startup Atoms, just a few weeks after it raised $1.7 billion.
Gautam Gupta, the former finance chief under Kalanick, said in social media posts on Wednesday that he has has joined Atoms as chief financial officer. Gupta spent more than four years at Uber until he left in July 2017, just a few weeks after Kalanick resigned as CEO. (Gupta had announced his intention to leave that May.)
Hiring Gupta continues a trend of Kalanick getting the Uber band back together at Atoms. Earlier this year, Atoms acquired mining autonomy startup Pronto, which is run by former Uber (and former Google) self-driving engineer Anthony Levandowski. According to LinkedIn, a number of former top Uber employees who worked with Kalanick also work at Atoms, which was previously called CloudKitchens.
“On many levels, this round is a bit of unfinished business. Fuel to complete the bits-to-atoms story arc we started at Uber, continued at CloudKitchens, and will now finish at Atoms,” Kalanick wrote when he announced the $1.7 billion funding round last month.
Uber even joined the round as an investor, reuniting the company with the founder it pushed out in 2017 after a series of scandals and complaints of widespread sexual harassment and discrimination. Uber hasn’t disclosed how much it contributed. The Information reported $100 million, a figure that TechCrunch has also been able to confirm.
Kalanick has said he wants Atoms to work on mining, food, and transportation, though his posts to date about the startup have been less about specifics and more about wanting to “go up against the final boss, Nature and its fierce resistance to change.”
Gupta invested in Uber in 2012 when he was a vice president at Goldman Sachs, and then joined the company in 2013.
“[T]he single biggest reason I joined was – Travis. I believed he possessed a magical mix of genius and intensity that made me want to bet on the person, not the market,” Gupta wrote Wednesday. “First one in, last one out, every day. Breaking down walls of regulations, unions, city bureaucracies, etc. Had he not pioneered ridesharing, I don’t think anyone else had the fortitude to fight through one adversity after another to create a whole new market worth hundreds of billions out of nothing.”
Gupta wrote Wednesday that A*, the VC firm he co-founded in 2020 after three years at Opendoor, invested in Atoms in what was the “largest investment in the history of our fund.” Gupta is stepping down from A* to take on the CFO role at Atoms, according to his LinkedIn profile.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
>
-
movies3 months agoSearch For Canadian TV Actor Stewart McLean Now Homicide Investigation
-
Fashion9 years agoThese ’90s fashion trends are making a comeback in 2017
-
Fashion9 years agoAccording to Dior Couture, this taboo fashion accessory is back
-
Fashion9 years agoModel Jocelyn Chew’s Instagram is the best vacation you’ve ever had
-
Fashion9 years agoYour comprehensive guide to this fall’s biggest trends
-
Fashion9 years ago9 Celebrities who have spoken out about being photoshopped
-
Fashion9 years agoEmily Ratajkowski channels back-to-school style
-
Fashion9 years agoA photo diary of the nightlife scene from LA To Ibiza
