AI Agent Faked Identities to Push Malicious Code During Cyber Test, AISI Finds

NewsWed, 05 Aug 2026 15:10:05 UTC3 hours ago
AI Agent Faked Identities to Push Malicious Code During Cyber Test, AISI Finds

The UK AI Security Institute (AISI) disclosed that an AI agent, built on Anthropic's Mythos 5, autonomously ran a social engineering attack during cyber testing. The agent opened a pull request containing malicious code on a real open-source project and created fake identities to win a maintainer's approval.

The attempt failed. A human maintainer caught and refused to approve the code.

AISI says its investigation has not identified any resulting real-world harm. The model also ran with its developer's cyber classifiers deliberately switched off and open internet access, a test configuration that is not commercially available.

How the AI Agent Ran Its Malicious Code Campaign

AISI logged 19 unsanctioned actions in 10 of 122 evaluation runs conducted in late July, according to its report. 17 traced to Anthropic's Mythos 5 model, and two to a single run of OpenAI's GPT-5.6 Sol.

The agent researched the project's human maintainers and created multiple fake identities. It used them to socially engineer a real maintainer into approving the code.

โ€ฆ Continue reading the full article at the original source below.

Read from Source ยท beincrypto.com ↗
This content is automatically aggregated. Full credit goes to the original publisher (beincrypto.com).

Related