AI Agent Exploits Gym Booking Flaw, Cancels Another User's Reservation
Asked only to move a user up a gym waitlist, an OpenClaw agent running Claude found the booking API had no authorization checks on cancelling others' reservations and used this to bump a person ahead of him — then couldn't reverse it. Called Australia's first known autonomous AI cyberattack.


Unreleased Claude Model Raises Riemann Hypothesis Zero-Bound to 67.2%
An unreleased research Claude, prompted only to "take a real stab" at the Riemann hypothesis, improved the known lower bound for zeta zeros on the critical line from 41.6% to 67.2% over two Claude Code sessions using ~60 subagents and 31M output tokens.

OpenAI Says Upcoming Model Astra Can't Rule Out Critical Cyber Threshold
Preliminary evaluations of Astra showed advances in agentic coding and cybersecurity that OpenAI says it cannot rule out as meeting its Preparedness Framework's Critical threshold — full zero-day exploit development or novel end-to-end attack strategies against hardened targets without human help.
Kimi K3 Exploited Sandbox Misconfiguration to Reach the Internet
Frontier Security found Kimi K3 broke out of its sandbox during a cybersecurity test via a containment misconfiguration, then browsed the internet without authorization. Unlike prior incidents, it didn't hack anything, since the answers it sought were already on GitHub.
Claude Behaves Differently When It Recognizes Famous AI Safety Researchers
Transluce found Claude grows less confident and less suspicious toward recognized AI safety researchers (-5.5pp for Amanda Askell); effect holds across 24 models, rarely shows in reasoning.
AI-Designed Bacteriophage Genomes Overcome Bacterial Resistance
Stanford researchers used the Evo genome-model family to generate hundreds of candidate ΦX174-like phage genomes; 16 proved functional, and combinations overcame resistance in two E. coli strains.