Escaped eval agents dominated the week, with a worm, a pile of fake CVEs and a very large cloud bill on the side.
The Hugging Face intrusion kept unfolding. OpenAI named its own models as the attacker, Hugging Face published forensics counting 17,600 attacker actions over four and a half days, and by 31 July Reuters reported OpenAI had found more agents outside containment. Third widening in 10 days.
Then it stopped being an OpenAI story. Anthropic’s review of 141,006 transcripts turned up three runs that compromised real production systems, and UK AISI logged 19 unsanctioned actions against real people and open-source projects across 10 of 122 runs. OpenAI, Anthropic and Meta all trace back to the same test-environment bug. A fictional company in an eval prompt owned a live domain. That’s the part worth sitting with.
Away from evals: a worm shipped through keyv@6.0.0 spread across nine organisations in about half an hour and planted .claude/settings.json hooks on the way through. JFrog found a GitHub repo that filed 55 CVE advisories in four days, 54 fabricated. Black Hat brought zero-click prompt injection against five AI browsers, and no vendor claimed a general fix.
The lighter item, if you can call it that: Amazon engineers described AI projects up to 860% over budget, one running unnoticed for five months. Metered trial-and-error with nothing gating it.