Eigen RadarAI
Analysis

AI moves to both sides of the security line

A defender-only model, commands hidden in a document, local models on attack servers, and patterns that fool cameras show AI operating on both sides of the security line.

Artificial Intelligence··Night
A blank sheet enters a scanner as a cyan conduit runs from its translucent inner layer to a separate compute node; at right, a robotic arm probes an exposed server board.

A separate access tier for defence

OpenAI has made GPT-5.6-Cyber available on its Daybreak Red tier for defenders hunting security flaws. Access requires identity verification, account security measures, and legal declarations; hardware security keys become mandatory on September 1, 2026. The model's distinguishing feature is that it answers sensitive security questions that general-purpose models usually refuse. In OpenAI's own evaluation, the answer rate is 95 per cent for GPT-5.6-Cyber, compared with 1.5 per cent for standard GPT-5.6 Sol, 2 per cent for Daybreak Blue, and 57.3 per cent for the earlier GPT-5.5-Cyber. According to OpenAI, the model found two previously undiscovered Chrome flaws and at least five flaws in a widely used mobile operating system; the company's performance and discovery claims have not been independently verified. OpenAI says it surrounds the broader answer range with controls on users and operating environments, recommending an isolated sandbox and Codex Auto-Review for the model.[1]

A document becomes a command and a server becomes a workspace

The same capability appears through different entry points in attack chains. PromptArmor showed that instructions written as invisible white text on a white background could steer Atlassian's Rovo agent. While processing the file, Rovo can collect corporate data from Jira and Confluence and send it to an attacker-controlled server through a dynamically generated address; the sequence requires no user confirmation and leaves no visible trace in the chat window. The firm reported the flaw on May 23, 2026, and Atlassian acknowledged receipt two days later; according to The Decoder, the product remained vulnerable when the report was published. South Korean security firm Genians, meanwhile, says it found traces that the North Korea-linked Kimsuky group built a locally run large language model environment and a retrieval setup on attack servers, allowing data to stay inside. Alongside local runners such as Ollama, GPT4All, and Msty, researchers found agent-development frameworks, speech-to-text tools, and signs of Cursor use. Genians interprets these as attempts to examine stolen documents, extract information, and automate attack work. One treats a corporate document as a command; the other keeps attack data local, placing models inside operational workflows.[2], [3]

Machine vision is being challenged with counterexamples

Bill Swearingen's noRecognition project carries the attack surface into physical-world perception. Swearingen drove a 2009 Toyota Yaris wrapped in an AI-generated pattern past a Flock camera during Def Con in Las Vegas; TechSpot reports that the run fooled the camera. The reinforcement-learning setup generates a pattern, evaluates the result when recognition continues, and changes the design for another attempt. Swearingen says he ran roughly 31 million tests over a year from his home in Kansas City and trained the model to defeat 11 open-source object-detection algorithms. The system can now produce a fresh pattern every minute, and the report says its designs can mislead recognition connected to Flock plate readers, Axon body cameras, and Clearview AI. This example uses a different method from the invisible instruction in Rovo and Kimsuky's local model environment; the connection is that AI systems are becoming both targets and tools. A defender model searches for software flaws while attackers work on document interpretation, local information processing, and the mechanics of visual classification. AI security therefore extends beyond the behaviour of one model. The boundary at which text becomes an instruction, the place where data is processed, and the visual pattern from which a camera recognises an object all become part of the security outcome.[1], [2], [3], [4]

References

  1. News sourceThe DecoderOpenAI opens GPT-5.6-Cyber, a separate model built to hunt security flaws↩1↩2
  2. News sourceThe DecoderText hidden inside a PDF is enough to pull data out of Atlassian's Rovo agent↩1↩2
  3. News sourceYonhap News AgencyGenians says the North Korean Kimsuky group set up a local language model on its attack servers↩1↩2
  4. News sourceTechSpotA researcher wrapped his car in a pattern built to confuse plate-reading cameras↩