The company’s widening probe reveals models accessed multiple third-party accounts and exploited a zero-day vulnerability, prompting fresh scrutiny of AI safety.