Hacking AI: Loss of Control Instead of Controlled Tests

A digital déjà vu: Hardly had the industry digested the news about the OpenAI breakout , Anthropic admitted that its models had also autonomously entered other companies. What is framed as a systematic test is, in reality, an unprecedented loss of control over its own technology.

The Absurdity of “Cybersecurity Evaluations”

The communication from the leading AI labs, Anthropic and OpenAI, follows a disturbing pattern. Both frame these incidents as necessary “Cybersecurity Evaluations,” essentially as controlled experiments to measure model capabilities.

In Anthropic’s case, it was not a technical breakout from a sandbox via a software vulnerability, but a simple yet serious infrastructure misconfiguration: a misunderstanding with a test partner led to the test environment simply being connected to the public internet. This negligence allowed the Claude models to reach the internet and hack three different organizations. In one of these cases , the AI even attempted to upload a package to the public Python Package Index (PyPI), which was however prevented by PyPI’s automatic protection systems.

The fact that high-potency AI models can act unrestricted on the internet and compromise uninvolved companies cannot be understood as scientific progress, but rather as a failure of security architecture. For the affected companies, the origin of the attack is irrelevant; the fact that AI agents can now autonomously define targets and independently execute complex attack chains over several days is a new, existential threat level.

Machine vs. Human: The New Dynamics of Lateral Movement

A crucial point is the way these agents operate. While a human attacker often follows certain patterns and shows a noticeable time delay during lateral movement in the network, the AI operates at “machine speed.”

An AI agent analyzes vulnerabilities, tries exploits, and moves through the network with a speed and logic that often overwhelms traditional monitoring systems designed for human response times. This absence of human patterns makes detection significantly more difficult.

The incidents are now putting AI labs heavily in the focus of regulatory authorities, especially the AI Safety Institutes . With the entry into force of the EU AI Act, technical “breakouts” are turning into systemic legal risks. A model’s ability to autonomously overcome security barriers could in the future no longer be viewed as an experiment, but as gross negligence, leading to billion-dollar fines (up to 7% of global turnover) and extensive claims for damages.

Three Levers for an Agent-Resilient Infrastructure

Traditional perimeter thinking has long been obsolete. Anyone who believes that a firewall or a sandbox is sufficient is ignoring at least the lessons of the last few weeks. What is required is an architecture based not on isolation, but on continuous verification.

Zero Trust and Radical Micro-segmentation

The assumption that a once-authenticated process is trustworthy must be abandoned. Every request within the network is validated. For SMEs, this specifically means dividing the network into VLANs to prevent the unhindered lateral movement of an AI agent.

Deception Technology: Systematic Deception

AI agents act extremely logically and systematically. This characteristic can be used against them. The placement of honeytokens serves as a highly effective early warning system. Access to these tokens is a clear indicator of compromise long before conventional alarms go off.

AI-powered Detection and Managed Response

A human cannot react in real-time to the speed of an autonomous agent. The transition to AI-powered EDR and XDR systems is inevitable. SMEs can close this gap through Managed Detection and Response (MDR) services, where external experts monitor anomalies in real-time.

Strategic Resilience: Defense in Depth and Assume Breach

The incidents at OpenAI and Anthropic mark a turning point. In a world where AI models autonomously penetrate productive systems, it is no longer enough to just “close the door.” We therefore consistently pursue two strategic approaches:

  • Assume Breach: We assume that the perimeter has already been breached. The goal is no longer just to prevent the break-in, but to detect the attacker as quickly as possible and maximally restrict their freedom of movement in the network.
  • Defense in Depth: Security is understood as a multi-layered system. If one layer fails, other independent security mechanisms immediately take over to limit the damage.

In this context, the professional penetration test remains an indispensable instrument. It is the necessary foundation for making vulnerabilities visible in the first place and testing the effectiveness of security chains. But only the combination of regular penetration tests and an agent-resilient architecture creates true resilience.

Security in the age of autonomous AI means acting proactively. We support you in validating your systems using penetration tests and implementing a resilient infrastructure.


Valerie Erhard

Published on 31.07.2026 published.

Agentic AI Changes the Rules of Cybersecurity

From helpful advisor to autonomous actor: The evolution of agentic AI forces a paradigm shift in our IT security. (read more)

Valerie Erhard

Published on 22.07.2026 published.

AI Models Break Out and Hack Hugging Face

During an evaluation, OpenAI models autonomously broke out of their test environment and successfully infiltrated Hugging Face's infrastructure. (read more)

Fabienne Hofsäß

Published on 22.05.2026 published.

Experience the World of Hackers and Defenders Live

As a partner of the Night of Digitalization, aramido opens its doors on Friday, June 19, 2026, from 3 PM with a diverse program. (read more)

Jule Bohe

Published on 07.05.2026 published.

New Space for Growth: aramido expands location on Durlacher Allee

aramido continues to grow: New office space at Durlacher Allee 73 in Karlsruhe available for sub-lease. Modern offices in a prime location with optimal connections. (read more)

Fabienne Hofsäß

Published on 09.09.2024 published.

Who's Afraid of the Big Bad Wolf? Voice Cloning and Modern Deception

Many of us know the fairy tale of the Big Bad Wolf, who uses clever tricks to deceive his victims. Today, artificial intelligence (AI) can deceive us in a similar way. (read more)

Niklas Fuhrberg

Published on 25.08.2024 published.

What is the NIS 2 Directive? (Part 1)

In response to the increasing number of cyberattacks, the EU is introducing new measures. Among these is NIS 2, which sets new requirements for companies. (read more)

Niklas Fuhrberg

Published on 20.08.2024 published.

Who is affected by NIS 2? (Part 2)

Approximately 30,000 companies in Germany are affected by NIS 2. Find out when a company must comply with NIS 2 requirements. (read more)

Niklas Fuhrberg

Published on 19.08.2024 published.

NIS 2: What do companies need to do? (Part 3)

As a first step, responsibilities within the company should be established. In addition to a coordinating body, such as an Information Security Officer, the executive management must also fulfill specific obligations. (read more)

Fabienne Hofsäß

Published on 05.06.2024 published.

Steganography: The Art of Hidden Communication

Encrypted communication dates back to antiquity. Much has changed since then, and the way we communicate has become significantly more secure. (read more)

Fabienne Hofsäß

Published on 21.05.2024 published.

Versatile Program at the Night of Digitalization

As a partner of the Night of Digitalization, aramido opens its doors on Friday, June 7, 2024, from 3 PM with a versatile program. (read more)

Patrick Stracke

Published on 14.05.2024 published.

Artificial Intelligence and Social Engineering: The Ingredients for a Hackathon

In today's world, Artificial Intelligence (AI) and Social Engineering are two powerful forces that affect us humans in different ways. (read more)

Fabienne Hofsäß

Published on 04.03.2024 published.

Active Directory Hacked – How Does It Work?

An attack on the "central nervous system" of corporate networks. This is how quickly an attacker can gain full control. (read more)

Leonard Otto

Published on 27.04.2023 published.

Become a Domain Admin in 30 Minutes

On May 4, 2023, we will demonstrate at a live hacking event how attackers can take over an entire network within 30 minutes. (read more)

Kadir Ates

Published on 14.03.2023 published.

Incident Response Tabletop

Apply now for aramido's Incident Response Pen & Paper! Become part of the crisis team and try to resolve the IT security incidents. (read more)

Christian Birker

Published on 27.01.2023 published.

What Could (Possibly) Go Wrong? - Designing Threat Modeling with a Card Game

To make the threat modeling process more playful, aramido developed a card game. This helps development teams with Security by Design. (read more)

Hannah Schneider

Published on 08.06.2022 published.

Making Information Security Visible with a Colorful Program

As a partner of the Bunte Nacht der Digitalisierung, aramido makes information security visible on Friday, July 1st, from 3 PM. (read more)

Hannah Schneider

Published on 31.03.2022 published.

Better Safe Than Sorry: On the Secure Side with a Backup

March 31 is World Backup Day. It serves as a reminder to ensure the security of your own data through backups. We show you how. (read more)

Oliver Werner

Published on 04.03.2022 published.

Phishing, SMiShing, Vishing, ... Tishing!

In addition to email and SMS, Microsoft Teams represents a new channel for phishing attacks. How do they work and how can you protect yourself? (read more)

Hannah Schneider

Published on 21.10.2021 published.

The New OWASP Top 10 - 2021

The OWASP Top 10 - 2021 describes the ten most common security risks for web applications. They help developers implement applications securely. (read more)

Thomas Schmitt

Published on 12.08.2021 published.

Secure with a System: Do I Need an Information Security Management System?

Do I need ISO 27001, IT-Grundschutz, TISAX, and VdS 10000? With an Information Security Management System (ISMS), companies ensure long-term security. (read more)

Hannah Schneider

Published on 10.06.2021 published.

Secure by System: Cybinar on Information Security Management Systems

Do I need an Information Security Management System (ISMS)? aramido consultants provide practical tips based on a case study on July 14 (read more)

Hannah Schneider

Published on 12.02.2021 published.

On a Growth Path: aramido moves into new premises at Durlacher Allee

Your company can also benefit from this: aramido is renting out large, bright office units in a separate area for subtenants. (read more)

Moritz Kaumanns

Published on 01.02.2021 published.

Security Advisory: Amazon Secret Key Publicly Accessible (CVE-2020-28199)

A security vulnerability in an Amazon Pay plugin for Shopware 5 allows the unauthorized reading of the Amazon Secret Key (CVE-2020-28199). (read more)

Hannah Schneider

Published on 30.11.2020 published.

How the Dolphin Attack Opens Doors and Windows in the Smart Home

aramido demonstrated live at the Innovation Festival how smart home devices controlled by voice assistants can be attacked unnoticed (read more)

Jan Weil

Published on 21.11.2020 published.

OCSP Stapling: The Good, the Bad, and the Ugly

When hackers have compromised a certificate, the Online Certificate Status Protocol (OCSP) with the Must-Staple extension is often the last line of defense for your own protection. (read more)

Gil Talebian

Published on 15.10.2020 published.

Protection Against Phishing, Vishing & Co. - Seven Golden Rules Against Social Engineering

aramido demonstrates how to protect yourself against phishing and other social engineering attacks - our contribution to the European Cyber Security Month (ECSM). (read more)

Hannah Schneider

Published on 09.10.2020 published.

When Dolphins Outsmart the Smart Home - InnovationFestival @karlsruhe.digital

aramido demonstrates live how smart home devices can be covertly attacked using voice commands in the ultrasonic range (read more)

Andreas Sperber

Published on 14.09.2020 published.

Security Advisory: 1CRM Insufficient Data Protection (CVE-2020-15958)

A security vulnerability in the 1CRM software allowed unauthorized users to access sensitive files and system backups. (read more)

Moritz Kaumanns

Published on 23.07.2020 published.

FIDO2 and WebAuthn: Login without a Password

FIDO2 and WebAuthn allow a secure and phishing-resistant authentication for web services in order to avoid data leakage. (read more)

Tristan Wagner

Published on 09.07.2020 published.

Two Vulnerabilities in TeamBeam

aramido was able to identify two vulnerabilities in the data exchange platform TeamBeam. (read more)

Benjamin Pokrant

Published on 06.05.2020 published.

HTML Injection Vulnerability in WordPress Plugin WPForms

A security vulnerability in the WordPress plugin WPForms allowed attacks via HTML injection. How does this vulnerability affect systems and how can it be closed? (read more)

Jonas Lehmann

Published on 03.04.2020 published.

How can IT managers ensure a secure home office during the coronavirus pandemic?

A six-step guide for information security in the home office and tips for financial support. (read more)

Hannah Schneider

Published on 17.02.2020 published.

Save the Date: Cooling Spray, Popcorn, and Live Hacking at the IT Cinema

aramido demonstrates the Cold Boot attack at the BWG IT Cinema, showing how a disk encryption can be bypassed. (read more)

Martin Nuß

Published on 28.10.2019 published.

November Events: aramido leads you safely through the digital wonderland

Get to know the dangerous sides of the digital wonderland with aramido on November 7 and 14, and get active yourself by building useful gadgets. (read more)

Kai Streiling

Published on 09.10.2019 published.

aramido at the Night of Digitalization

aramido is a partner of the Night of Digitalization and invites you to live hacking presentations, interactive workshops, and stimulating conversations on October 11, 2019. (read more)

Andreas Sperber

Published on 09.10.2019 published.

Cold Boot Attack: Farewell Disk Encryption

aramido demonstrates the current state of the Cold Boot attack and shows how disk encryption can be bypassed. (read more)

Andreas Sperber

Published on 09.07.2019 published.

HTTP Security Headers Protect Your Visitors

Security headers protect website users and expand the defense-in-depth strategy. We demonstrate how they are implemented and their specific impact. (read more)

Regina Okun

Published on 03.04.2019 published.

aramido at KA-IT-Si: Hacking on Ice

„Cold-Boot“ live hacking with aramido and subsequent buffet networking on April 11, 2019, at 6 PM in Karlsruhe (read more)

Elisabeth Apicella

Published on 03.04.2019 published.

How Do I Find a Job in Information Security?

Information security: an exciting field with social relevance and promising earning prospects. What should interested parties bring to the table? (read more)

Elisabeth Apicella

Published on 20.12.2018 published.

Security Advisory: Three Findings at prescreen.io and jobbase.io

As aramido discovered, the cloud-based applicant management software of the company Prescreen had several security deficiencies. (read more)

Andreas Sperber

Published on 21.11.2018 published.

What are the OWASP Top 10 - 2017?

The OWASP Top 10 - 2017 describes the ten most common security risks for web applications. They help developers implement applications securely. (read more)

Elisabeth Apicella

Published on 07.11.2018 published.

Reflected HTML Injection in CRM Software

A security vulnerability in the web software CRM+ by Brainformatik allowed attacks via HTML injection. Who is affected and what should you do now? (read more)

Regina Okun

Published on 01.10.2018 published.

Understanding Hacker Attacks - A Workshop for Ethical Hackers

Full-day hacker workshop as a Capture The Flag (CTF game) in Jeopardy mode. How can I as an ethical hacker test my own applications? (read more)

Regina Okun

Published on 06.07.2018 published.

Event Announcements: Live Hacking, Keynotes and Trade Fairs

Experience IT security and aramido at one of our upcoming events. We look forward to welcoming you to a presentation or live hacking session! (read more)

Daniel Matesic

Published on 13.06.2018 published.

52nd OWASP Meetup - Guided Hacking of a Web Application

At the 52nd OWASP Meetup, numerous security risks, including the OWASP Top 10, were illustrated through guided hacking of a web application. (read more)

Andreas Sperber

Published on 15.05.2018 published.

Efail - Encryption is Still Alive

Efail announced an attack on encrypted emails, which allegedly could crack the encryption. Reason for concern? (read more)

Regina Okun

Published on 08.05.2018 published.

Where is the Crumple Zone of IT Systems?

Should security incidents be prevented or expected? aramido CEO Andreas Sperber answers this question on informatik-aktuell.de. (read more)

Regina Okun

Published on 28.02.2018 published.

Events! Live Hackings, Live Forensics, Cinema

Experience IT security and aramido at one of the upcoming live hacking sessions, live forensics events, and exhibitions. We look forward to welcoming you! (read more)

Regina Okun

Published on 15.02.2018 published.

What is Payment Diversion?

Two internet giants fell for the Payment Diversion scam – could the same thing happen to your company? (read more)

Regina Okun

Published on 24.01.2018 published.

Live Hacking of a Company - In the Minefield of the Internet

Live hacking at Innotec Pforzheim on February 7, 2018, with Andreas Sperber from aramido (read more)

Regina Okun

Published on 09.11.2017 published.

Keynote: IT Symposium at Haigerloch Castle

aramido delivered the keynote at the 15th IT Symposium at Haigerloch Castle: four paradigms for tomorrow's information security. (read more)

Andreas Sperber

Published on 21.07.2017 published.

Using HTTP Public Key Pinning Securely

Public Key Pinning restores trust in the PKI. However, this powerful method must be used correctly, otherwise serious dangers may arise. (read more)

Andreas Sperber

Published on 31.05.2017 published.

Trust is Good. Verification is Better.

Andreas Sperber spoke about trust problems in PKIs at the 17th GPN. With "Trust is Good. Verification is Better.", he calls on service providers to take action. (read more)

Andreas Sperber

Published on 17.04.2017 published.

Certificate Transparency – Transparency in the Certificate Jungle

Certificate Transparency is a system for monitoring certificates. For Google Chrome, it has been mandatory since October 2017. We report on what needs to be considered. (read more)

Andreas Sperber

Published on 21.03.2017 published.

Why Do We Trust Certificate Authorities?

Certificate authorities are an essential component of today's World Wide Web. We place great trust in them despite worrying incidents. (read more)

Armin Harbrecht

Published on 03.03.2017 published.

Multiple Vulnerabilities in the New CyberForum Portal

aramido found several security vulnerabilities on the CyberForum website. They show the typical dangers of websites with user-generated content. (read more)

Armin Harbrecht

Published on 14.02.2017 published.

Live Hacking for Hoteliers

IT security is playing an increasingly important role in the hospitality industry. In the DEHOGA seminar on data security, it will be shown how to secure your hotel. (read more)

Armin Harbrecht

Published on 06.02.2017 published.

Security through Transparency – How We Disclose Security Vulnerabilities

The responsible disclosure of security vulnerabilities is a proven approach to making IT systems more secure for everyone. (read more)

Andreas Sperber

Published on 28.01.2017 published.

aramido at the 18th Industry Fair i+e 2017

aramido is an exhibitor at the Industry Fair i+e 2017 in Freiburg: visitors can receive information security consulting on February 1st and 2nd. (read more)

Armin Harbrecht

Published on 18.01.2017 published.

Live Hacking at the "Produkte suchen Produzenten" Trade Fair

Experience IT security firsthand at the next Live Hacking event by aramido GmbH in Karlsruhe on January 27, 2017. (read more)

Armin Harbrecht

Published on 05.01.2017 published.

Secure Software Updates

How can I, as a software manufacturer, provide my users with secure updates? Learn about secure software update mechanisms. (read more)

Andreas Sperber

Published on 15.12.2016 published.

Live-Hacking a Symfony application

Andreas Sperber from aramido is a guest at SensioLabs in Cologne on Dec 21, 2016. He hacks a Symfony app and shows what can be done for IT security. (read more)

Armin Harbrecht

Published on 09.12.2016 published.

SWR Interview on the Telekom Router Hack

Last week, one million Germans were locked out of the internet. What initially appeared to be an attack on Telekom routers turned out to be different. (read more)

Armin Harbrecht

Published on 14.11.2016 published.

How Much Does a Penetration Test Cost?

As penetration testers, we are often asked about the cost of a penetration test. The answer depends on several factors. (read more)

Armin Harbrecht

Published on 28.10.2016 published.

Review it-sa Trade Fair 2016 in Nuremberg

In the recap of the it-sa 2016 IT security trade fair in Nuremberg, we report on current trends in the IT security industry. (read more)

Andreas Sperber

Published on 24.10.2016 published.

Founder Stories and Live Hacking

aramido will be a guest at PionierGarage in Karlsruhe on Nov 8, 2016. Meet the founders at Founder Stories and Live Hacking! (read more)

Armin Harbrecht

Published on 19.10.2016 published.

HTTPS on the Rise - Why everyone must switch their site to HTTPS in 2017

Encrypted communication via HTTPS was long only for highly secure web applications. Soon, however, Google will penalize unencrypted websites. (read more)

Andreas Sperber

Published on 13.10.2016 published.

Ransomware: Pay the Ransom or Not?

Negotiating with extortionists makes you vulnerable. In the event of a cryptotrojan infection, should the ransom be paid or not? (read more)

Armin Harbrecht

Published on 30.09.2016 published.

Meet aramido at the Information Market "The New Suction Principle"

aramido will be present on October 11, 2016, at the Cyberforum Information Market in Karlsruhe. We look forward to meeting you there. (read more)

Andreas Sperber

Published on 27.09.2016 published.

Workshop: IT Security for SMEs at IHK Gießen-Friedberg

IT security expert Andreas Sperber speaks at IHK Gießen-Friedberg on October 6, 2016, on the topic of IT Security for SMEs and presents possible approaches. (read more)

Andreas Sperber

Published on 19.09.2016 published.

RoundTable: Give Me Your Data!

Long-term customer success for your SaaS solution through IT security and data protection - a presentation with live hacking by aramido and eknowvation (read more)

Andreas Sperber

Published on 18.08.2016 published.

Eight Reasons for a Penetration Test

A penetration test checks the vulnerability of systems. We provide eight reasons why penetration tests are important for companies. (read more)

Armin Harbrecht

Published on 03.08.2016 published.

More IT Security Needed for Hotels

IT security is a critical issue for hotels. The IT Security for Hotels initiative helps protect credit card data and WLAN networks. (read more)

Armin Harbrecht

Published on 19.07.2016 published.

aramido Penetration Testing Offer Victim of a DDoS Attack?

In DDoS attacks, attackers specifically try to overload a web application. Our server logs suggested that we ourselves were affected. (read more)

Armin Harbrecht

Published on 01.07.2016 published.

What Hotels Need to Consider When Handling Credit Card Data

As a collection point for vast amounts of personal data, hotels are in the crosshairs of criminals. We explain what hoteliers must do to protect their guests' data. (read more)

Armin Harbrecht

Published on 23.06.2016 published.

You are in Good Hands with aramido

aramido has recently become a member of the Beraternetz Karlsruhe. Also find out how to receive up to 2,000 euros in funding for consulting projects (read more)

Andreas Sperber

Published on 14.06.2016 published.

Infection by a Cryptovirus

In the aramido security laboratory, we infected ourselves with a ransomware trojan and show what a cryptolocker would do to your data. (read more)

Armin Harbrecht

Published on 21.05.2016 published.

Kidnapping 2.0 - Ransomware on the Rise

Cryptotrojans cause significant damage to companies. With the article series on ransomware, aramido reports on the background of the acute threat situation. (read more)

Andreas Sperber

Published on 19.05.2016 published.

SWR2: How to Use WLAN Securely

SWR interviewed Andreas Sperber from aramido and other experts at the 2016 Anti-Prism Party, reporting on "How to use WLAN securely". (read more)

Andreas Sperber

Published on 20.04.2016 published.

Five Myths About Secure WLAN Networks

There are many recommendations for secure WLAN networks. Some should be followed, while others are considered myths. We show what is true and what is not. (read more)

Armin Harbrecht

Published on 15.04.2016 published.

Piwik Security – Securely Analyzing Web Applications

The aramido best practice for Piwik shows what to look out for when using the web analytics tool. The Piwik security checklist helps you secure your Piwik installation. (read more)

Andreas Sperber

Published on 08.04.2016 published.

Anti-Prism-Party 2016 - Protection from Surveillance

Since the Prism affair, espionage has been a topic of concern. At the Anti-Prism-Party 2016, aramido shows how WLANs function securely and when hotel WLANs are insecure (read more)

Andreas Sperber

Published on 25.03.2016 published.

Seven Recommendations for a Secure WLAN

Almost everyone uses WLAN today, staying connected with all their devices. We show you how to build a secure WLAN and clarify WPA2-PSK and other methods. (read more)

Andreas Sperber

Published on 18.03.2016 published.

aramido IT Security Blog

The aramido blog reports regularly on IT security. Subscribe to the feed for pentests, web application security, and other interesting topics. (read more)