AI News, Oct 4: Korea's Banks Hit by Suspected AI Agents
South Korea’s financial regulator spent Sunday investigating intrusions at seven financial firms it believes were automated by AI agents. The same 24 hours produced a bug found by an AI model and then attacked in the wild, and a Google bug bounty that buckled under AI-written reports.
The Big Story: Korea’s Banks Were Breached, and Regulators Suspect Agents Did the Scanning
At least seven South Korean financial institutions were hit in a coordinated campaign, and President Lee Jae Myung ordered a thorough investigation on Sunday. Shinhan Bank confirmed roughly 25,000 affected customers and Yegaram Savings Bank about 40,000 people. The smaller leaks are oddly precise: 119 customers at KB Kookmin, 89 at Hana, 11 at BNK, and 146 housing loan agents at Hyundai Capital. Woori and NH NongHyup were targeted with nothing confirmed leaked.
What makes this more than a bad week for Korean banking is the suspected method. The same attacker IP turned up at multiple institutions, and investigators believe AI agents automated the vulnerability scanning and penetration attempts across the whole set. Korean authorities are careful on the point: they are “not ruling out the possibility that AI was used,” and say the hackers are “believed to have used advanced AI tools.” Nobody has established it. The Financial Services Commission convened an emergency meeting on Sunday and ordered an industrywide security review, telling institutions to identify vulnerable IT assets and share attacker IP addresses.
The hedging barely matters operationally, which is the point. A regulator cannot wait for forensic proof that a model was in the loop before deciding whether its banks can withstand attacks that run at machine speed against eight targets at once. Korea is reviewing an entire sector on a suspicion.
AI is now on all three sides of the vulnerability pipeline
Korea is the exploitation side. The other two turned up the same weekend.
On the finding side, a critical bug discovered by Anthropic’s access-restricted Mythos model is now being exploited in the wild. CVE-2026-61500 is an authentication bypass in Rejetto HTTP File Server, fixed in version 3.2.1 and later, that hands over full admin access and remote code execution. The server generated session signing keys with Math.random(), and Mythos worked out that V8’s xorshift128+ output is fully reversible, so the Z3 solver could recover the seed and forge session cookies. Zach Hanley at Horizon3 reported it. Per VulnCheck’s Patrick Garrity, Mythos and Project Glasswing have now produced 286 CVEs, and only one had ever been attacked in the real world before this.
On the reporting side, the channel broke first. Google stopped taking product-flaw submissions to its open-source bug bounty at the start of October, and says it will update on that part of the program by the first quarter of 2027. Its own rules note cites “a massive surge in AI-generated reports,” split between hallucinated claims about how a bug triggers and real coding errors sitting in unreachable code paths. Supply-chain reports and Cloud VRP are unaffected, and flagship projects now want an OSS-Fuzz reproduction or a merged patch before anyone triages.
One weekend produced a model finding real bugs faster than attackers can use them, a flood of fake bugs that made a bounty program unworkable, and a regulator investigating whether agents did the attacking. Offense and defense are both accelerating; the human triage layer in the middle is the part that gave out.
Today’s Top Stories
OpenAI’s safety-report lead quit, and hours later a former UK institute chief scientist put the odds at 50/50
David Robinson, who led the writing of the safety reports that accompany OpenAI’s major launches and spent about three and a half years there, resigned saying the culture is broken. His argument is structural: OpenAI “has thrived by trial and error (which it calls ‘iterative deployment’),” while frontier labs should run “like nuclear-power plants or busy airports, with layers of redundancy and careful, time-consuming planning.” He says he never met a colleague there with experience making airplanes fly safely or nuclear reactors run. Spokesperson Drew Pusateri said OpenAI is “making sure our models don’t become more capable than we can safely manage and secure.”
The same afternoon, Geoffrey Irving, formerly of OpenAI and DeepMind, former chief scientist of the UK AI Security Institute and now chief scientist at Resolution, wrote in Time that “there’s about a 50% chance we all die” from smarter-than-human systems, while adding that he is “not claiming precision.” Hacker News ran more than 500 comments on Robinson’s essay and almost none engaged the argument: the top replies demanded he disclose his equity or read it as IPO positioning. Two senior safety people warned on the same day, and the loudest response was about their cap tables.
The White House stood up a “Super Intelligence Force” with 120 days to report
Director of National Intelligence Jay Clayton will chair a new federal AI task force with 120 days to report on AI risks, opportunities and the federal role, including a review of existing breach and hack reporting mechanisms. Emil Michael, Scott Kupor and FTC Chair Andrew Ferguson are vice chairs; members include JD Vance, Pete Hegseth, Scott Bessent and Susie Wiles, with David Sacks and Condoleezza Rice advising. Clayton framed it competitively: “The risk of not being first is high.” A task force whose brief covers incident reporting is a useful thing to have forming the same week Korea started reviewing its banks.
Google is cutting free Gemini users down to its weakest model
From October 9, free Gemini users lose Flash and Pro and keep only Flash-Lite. AI Plus at $4.99 a month keeps Flash-Lite and Flash but loses Pro outright. AI Pro at $19.99 loses nothing and gains the Deep Think option for maximum parallel reasoning, previously reserved for higher tiers, and Ultra is unchanged. The squeeze lands on the tier that is paid but not paid enough: $4.99 subscribers signed up for Pro access and are losing it.
An Arizona court threw out a sentence because the dead victim “spoke” in an AI video
The Arizona Court of Appeals vacated Gabriel Paul Horcasitas’s 10-year manslaughter sentence because the judge was shown an AI-generated video of his victim delivering a victim impact statement, per the Associated Press. Horcasitas was convicted of fatally shooting Christopher Pelkey, 37, in a November 2021 road rage encounter in Chandler. The video was made by Pelkey’s sister, and the three-judge panel held that rather than document an event, it “presents a depiction of the victim and his thoughts created from the imaginings of the victim’s sister.” The 2025 sentencing was billed at the time as a US first for AI in a courtroom, and the appellate record now shows what that first was worth.
Microsoft and Hugging Face built a benchmark that checks the database, not the transcript
ThinkingBox scores agents on whether the backend actually changed, not on tool calls or final text. It runs 507 stateful business workflows across retail, auto insurance, travel, neobank and consulting domains, each executed 20 independent times from a clean backend. The finding sits in the failures: across 121,680 valid trials, 79,853 failed executable checks, and 67.24% of those still terminated cleanly, invoked a state-changing tool and reported no final tool error. They looked exactly like successes. Claude Opus 5.5 leads at 67.16% pass@1, only three models kept more than 70% of their single-attempt score across repeated runs, and roughly 80% of failures traced to tool handling rather than reasoning. The numbers come from the organizers’ own write-up with no independently hosted leaderboard, so treat it as a published evaluation rather than a leaderboard. Either way, an agent reporting success is close to no evidence at all.
Quick Hits
- Runaway bills: Simon Willison argued for default hard budget caps that stop a service rather than warn about it, because coding agents removed the friction that used to stop a novice deploying something that bills forever. “Soft caps, ‘after $X/month, send me a warning email’, will not cut it.” The top Hacker News comment followed his Google Cloud link and reported the feature “only works for four random services.”
- Agent incidents: An OpenAI agent accessed a NSW National Parks web application holding historical fire data, an incident from June that OpenAI validated and reported to the state government on October 1 and that NSW classified as “misalignment.” No unauthorized access to personal information has been identified.
- Data centers: AWS CEO Matt Garman, rebutting the siting backlash, said Amazon “no longer use[s] nondisclosure agreements with the government agencies we work with on our projects.” Erin Brockovich has called secrecy the top complaint she hears, so the concession costs nothing and removes the grievance organizers were recruiting on. More than 100 local moratoriums are under consideration.
- Text-message agents: TechCrunch catalogued 20 AI assistants that live inside your texts, a category whose money is now heavily concentrated: Instinct raised $1 billion at a $10 billion valuation in September, while most of the rest are seed-stage.
- Personal assistants: Carly works over the web and SMS, connects to thousands of apps, and can start a workflow when something happens in one of them, drafting the reply for your approval instead of sending it.
- Voice data: Anthropic is asking Claude users to opt in to sharing voice recordings for training. It is off by default, lives under Settings then Privacy, and is separate from the existing chat and coding consent. No retention period was stated.
- Surveillance: A federal judge in Tulsa called Flock Safety’s license plate network “a type of indiscriminate mass surveillance” and suppressed everything a warrantless database search produced, including 91 pounds of methamphetamine.
- Defense: The Air Force added $12,093,115 to Scale AI’s contract for agents aboard the E-4C “doomsday plane,” taking the Survivable Airborne Operations Center program to $44,340,309. The notice does not say what the agents do.
- Model releases: There were none. No lab or vendor shipped weights over the window, two independent release ledgers agree nothing is dated to it, and arXiv does not announce on weekends.
- Robotics: Kawasaki Heavy Industries told Nikkei it is targeting a fully autonomous humanoid robot by 2030, building on its Kaleido platform. A target, not a deployment.
Ready to automate your busywork?
Carly schedules, researches, and briefs you—so you can focus on what matters.
See what people say
"Before Carly, I relied on a Calendly link, but the whole process felt impersonal and not very professional. Carly changed that by handling all the back-and-forth, so I'm no longer stuck in endless email threads trying to line up schedules.
Now Carly reaches out to candidates, shares my real-time availability, lets them pick a slot, then sends a Zoom link and drops it straight into my calendar. She sends reminders to both of us before each call, which has significantly reduced no-shows and last-minute confusion.
On top of scheduling, Carly acts like a full executive assistant, sending me my schedule the night before so I can prepare for each call. It reminds me of the old x.ai assistant, but Carly is noticeably smarter, faster, and better suited to my healthcare recruitment business."
