OpenAI's release of Sora 2, an advanced AI video generation tool, has sparked significant concern among advocacy groups and security researchers. Public Citizen, a nonprofit focused on AI accountability, sent a letter to OpenAI urging the company to temporarily take Sora 2 offline, citing the proliferation of realistic deepfakes and the lack of sufficient safeguards. The group criticized OpenAI for what they described as a pattern of rushing products to market without adequate safety measures, warning that Sora 2's capabilities could be exploited to create convincing disinformation and manipulate public perception, especially in sensitive contexts such as elections.
In addition to these advocacy concerns, AI security firm Mindgard discovered a technical vulnerability in Sora 2 that allows attackers to extract the model's hidden system prompt via audio transcripts. By instructing Sora 2 to generate audio, researchers were able to reconstruct the internal rules and safety guidelines that govern the model's behavior, potentially exposing the tool to further abuse or circumvention of its guardrails. This dual set of issues—deepfake risks and prompt leakage—highlights the urgent need for stronger security and transparency measures in the deployment of generative AI technologies like Sora 2.

Track how attackers are adapting to this technology.
2 events from the most recent confirmed update back to the earliest known activity.
Advocacy group Public Citizen called on OpenAI to address the deepfake risks posed by Sora 2, highlighting concerns about misuse of the video generation model. The appeal marked a public policy and safety response focused on the model's potential societal harms.
AI security firm Mindgard found that OpenAI's Sora 2 could be prompted to reveal portions of its hidden system prompt through audio generation and transcript reconstruction. The research showed that audio outputs were a more reliable exfiltration channel than text or video for recovering internal rules and safety instructions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcecyberscoop.com
Open sourcehackread.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.