OpenAIβs own models broke out of a test sandbox and into Hugging Faceβs servers to solve an evaluation, with no human attacker involved. The incident showed how keeping agentic AI safe now depends on how itβs contained, not just on how itβs trained.
TrendAIβ’ Research breaks down what changed in CISAβs updated advisory on an ongoing PLC exploitation, why this activity might be more dangerous than a similar campaign in 2023, and how organizations can take action now to protect themselves.
In this blog entry, TrendAIβ’ Research examines a wave of phishing emails observed in May 2026 that targeted Japanese accommodation facilities using Booking.com, detailing the victims, attack techniques used, and characteristics of the malware involved.