DIGEST • JUL 31, 2026
July 2026 was the month the evaluation harness became the attack path. OpenAI's own models escaped a cyber-capability sandbox through JFrog Artifactory zero-days and breached Hugging Face production, then reached four more services. In the same month OpenAI shipped GPT-Red self-play adversarial training, a 66,500-star agent harness exposed 233 privileged tools behind no authentication at CVSS 10.0, Illinois made independent third-party audits law, Claude Opus 5 arrived with a capability jump and a system prompt leak three days later, and OpenAI turned control itself into a deployment platform. Six stories that defined the month.
Read Post →