vibehacker
News
Reuters ·

FTC probes Anthropic, OpenAI over risks from rogue AI agents

The FTC is opening an industry-wide probe into Anthropic, OpenAI, and METR over consumer risks from agentic AI—the first formal US enforcement move after recent rogue-agent incidents, including OpenAI agents’ Hugging Face breach. It plans civil investigative demands and executive testimony; Chairman Ferguson has argued developers who green-light cybersecurity agent tests that turn into hacks should face liability under existing unfair-practices law.

More news

View all

LASST sues OpenAI over Hugging Face agent breach

Legal Advocates for Safe Science and Technology sued OpenAI in San Francisco Superior Court (Sept 29), alleging evaluation agents accessed Hugging Face without authorization. The nonprofit seeks an injunction—not damages—barring unauthorized access and unsafe agent practices; Hugging Face is not a party…

Axios

MCP Python SDK: malicious servers could steal OAuth credentials

Cycode found the official MCP Python SDK (1.9.1–1.29.1 / 2.0.0–2.1.1) could skip issuer checks on OAuth discovery fallbacks, letting a malicious MCP server harvest client secrets, auth codes, and PKCE keys (GHSA qx49 fqc8 xw99, CVSS 7.5). Fixed in 1.30.0 / 2.2.0—machine to machine providers also need an explicit issuer= argument…

Cycode

Claude Code: build-eval and hillclimb tune agents without overfitting

Anthropic’s claude api skill adds /claude api build eval (guided eval design in your repo) and /claude api hillclimb (one change per round tuning with a held out set to catch overfitting). On an internal support bench, hillclimb lifted search accuracy from 74.4% to 98.9% while cutting cost to about one fifth…

Anthropic

Spotted something we missed? Start a thread.