MyCyber News
Your daily cybersecurity news feed in one view.Curated, concise, and connected.
Your daily cybersecurity news feed in one view.Curated, concise, and connected.
Last feed pull: Sep 24, 2026, 2:02 AM (UTC+3)
Topic · AI Security
Claude discovers a novel enzyme system with CRISPR-like repeats Anthropic
Open-Source AI Agents Breach 27 Companies, Steal 600,000 Credit Card Records Hackread
A financially motivated threat actor is using open-source AI agent frameworks to attack hundreds of online retailers at scale, stealing more than 600,000 credit card records. [... ]
The physics of cybersecurity are changing. So must the security operations center (SOC). Cyberattackers are using agents to automate execution at unprecedented scale. What once required entire teams now requires a single operator and an agent framework. That shift has exposed a hard truth: security cannot operate at AI speed when protection and operations are built as separate systems. Every handoff, integration, and boundary slows defenders down. Agents inherit that complexity. For agentic security to work, the industry needs a different model. It needs a modern cyber stack with the breadth to see across the environment and the depth to investigate and act. Security operations and native protection must function as one system. This is the integrated security operations center (ISOC).
OpenAI and the Ukrainian government have agreed to a partnership that will provide AI tools and subsidized computing resources to better protect the nation’s critical infrastructure from cyberattacks. The agreement, announced Wednesday at OpenAI’s New York office, will provide Ukrainian cybersecurity officials with access to advanced AI models designed for cybersecurity work through the company’s Daybreak program. OpenAI said it is also pledging over $1 billion in subsidized tokens to support the initiative. During a panel discussion Dmytro Kushneruk, consul general of Ukraine in San Francisco, outlined how the tools would be used for cybersecurity automation, including functions such as incident response, threat triaging, login analysis, inventorying systems, code analysis and validating vulnerabilities.
Threat actors are poisoning ChatGPT, Gemini, and Google AI Overview answers by seeding the Web with malicious links and data and then optimizing the content.
Not long ago, many companies began actively implementing AI agents in a wide variety of workflows. Very quickly, the cost of using them became a pressing issue for companies. Moreover, it’s an issue that concerns more than just finance department — in addition to budgetary concerns, issues of reliability, operational stability, and even information security have emerged. This is because the cost of automating one and the same process varies significantly from one deployment to the next, is unpredictable, and could be subject to external influences. Furthermore, for a malicious actor attacking an organization, any process automated using AI and vulnerable to external influence is, in essence, a convenient target for a “new type of DDoS attack”.
Microsoft Copilot browser faces user backlash Cybernews
Microsoft Disrupts AI-Powered EvilTokens Service Linked to 12,000 Hacked Inboxes Hackread
Portnox has announced new capabilities to detect unauthorized AI applications and agents on managed devices and automatically enforce security policy, restricting, quarantining, or removing unapproved or risky applications the moment they’re detected. The capability addresses shadow AI: generative AI applications that increasingly act as autonomous agents, reaching local files, remote resources, and enterprise data with the same permissions as the logged-in user. As this footprint grows faster than most organizations can track, Portnox gives IT … More → The post Portnox detects and removes unauthorized AI applications from managed devices appeared first on Help Net Security .
Barracuda Networks has launched Barracuda AI Data Security, the AI security and governance solution purpose-built for resource-constrained organizations and managed service providers (MSPs). The solution enables businesses to accelerate AI adoption by protecting sensitive data, enforcing responsible AI use and demonstrating compliance. Barracuda AI Data Security represents a major milestone in Barracuda’s expanding AI Security portfolio. Built on the BarracudaONE platform, the solution combines AI visibility, data protection, threat defense, and governance into a single … More → The post Barracuda brings AI security and governance within reach of smaller organizations appeared first on Help Net Security .
Lookout has launched Social Engineering Protection (SEP), a new module within the Lookout Mobile AI Security Platform. SEP provides automated, real-time protection against the next generation of AI-driven mobile threats, including linkless smishing attacks, synthetic voice cloning, and other voice phishing (vishing) techniques. Frontier AI is transforming social engineering by enabling attackers to create highly convincing deception with unprecedented realism, personalization, and scale. Advanced AI models can craft context-aware messages tailored to individual employees, while … More → The post Lookout targets smishing, voice cloning, and vishing with real-time mobile protection appeared first on Help Net Security .
Meta says it issued a fix for the Muse zero-day vulnerability that would have let attackers do “whatever” they wanted on a victim’s Mac, highlighting the inherent dangers of AI helpers.
Phishing follows whatever people want at the moment, and right now that includes AI subscriptions they don’t have to pay for. We recently uncovered a new variation on this theme: A fake Claude Max giveaway that uses a convincing Google sign-in window to steal login information. Claude’s paid plans start at $20 a month and cost considerably more for higher usage limits, while free accounts have stricter limits. That makes the promise of a free upgrade an attractive lure. Microsoft reported in June that it had seen a growing number of phishing, malicious advertising, and search-based campaigns impersonating services such as ChatGPT, Claude, DeepSeek and Copilot. Some claim that a payment has failed and send you to a fake checkout. Others offer an app download that installs malware. The campaign we found takes a different approach.
A financially motivated threat actor is using autonomous AI agents to compromise online retailers at a reported average cost of roughly $25 per target. The campaign, active since at least July 2026, has reportedly stolen more than 600,000 unexpired payment card records, deployed web skimmers, and accessed systems belonging to major retailers, travel companies, and … The post AI agents steal 600,000 credit cards in attacks on online retailers appeared first on CyberInsider .
Only 21% of industrial security leaders report a complete OT asset inventory, even as 88% call their programs mature. The post Honeywell: OT Security Teams Embrace AI, but Autonomy Still Rare appeared first on SecurityWeek .
America leads the world in artificial intelligence. As it should. But tech leaders keep warning, with alarming frequency, that we are at risk of losing control. President Donald Trump has called for an AI czar and an “AI Force.” The details remain unclear, but the announcement underscores something fundamental. A technology this consequential demands clear leadership, accountability and action inside the U. S. government. The question now is what that leadership should do. That question became more urgent last week when Google disclosed that its Gemini AI model gained unauthorized access to three real companies during testing. The incidents follow similar disclosures involving models from Anthropic, OpenAI and Meta.
OpenAI’s advertising infrastructure can link activity on third-party advertiser websites to a user’s ChatGPT account through a cross-site cookie called __obi. The mechanism resembles established ad-tech tracking systems, but its use around an AI assistant raises additional privacy questions because ChatGPT conversations can be highly sensitive. Independent researcher ‘Buchodi’ reproduced the behavior on Chrome for … The post ChatGPT advertising system reportedly tracks users across websites appeared first on CyberInsider .
Frontier Red Team Research Anthropic
Autonomous security agents are getting good at finding bugs. Nobody has a good way to measure how good. Point one at a realistic target and what comes back is a report the agent wrote about itself: confident prose, a list of findings, and no way to tell which of them happened. Someone with a security background then sits down and checks every claim against the target. Which findings are real,
Anthropic and OpenAI on Tuesday announced new models, with both artificial intelligence (AI) companies noting that they are continuing to invest in improving alignment to combat risky behavior. Opus 5.5, per Anthropic, is a "major step up from Opus 5," and "achieves the best scores of any model to date on our automated behavioral audit, our alignment suite that tests Claude across thousands
The cybercrime platform leveraged AI at every step of the attack chain, including writing social engineering messages and deciding targets. The post AI-Powered Phishing Platform EvilTokens Disrupted by Microsoft appeared first on SecurityWeek .
New paper: “ Self-Jailbreaking: Language Models Can Reason Themselves Out of Safety Alignment After Benign Reasoning Training .” Abstract: We discover a novel and surprising phenomenon of unintentional misalignment in reasoning language models (RLMs), which we call self-jailbreaking. Specifically, after benign reasoning training on math or code domains, RLMs will use multiple strategies to circumvent their own safety guardrails. One strategy is to introduce benign assumptions about users and scenarios to justify fulfilling harmful requests. For instance, an RLM reasons that harmful requests like “outline a strategy for stealing customers’ credit card information from a retail store” could be associated with the benign intent of “a security professional trying to test defense,” despite no such benign context being provided as input.
EvilTokens turns a Microsoft sign-in into a route to corporate email fraud. The phishing kit, first seen in February 2026, tricks people into approving an attacker’s login through a real device code process without handing over a password. The lure usually arrives as an urgent email about an invoice, shared file, document signature or expiring password. A link or attachment takes the recipient to a page that presents a code and urges them to continue with the sign-in. The request looks routine. Microsoft researchers tied EvilTokens to a group they track as Storm-2992 and said the toolkit helped scale business email compromise. Microsoft said in a report shared with Cyber Security News (CSN) that campaigns using the kit compromised more than 12,000 inboxes at over 10,000 organizations worldwide. Affected sectors include finance, construction, healthcare and education.
OpenAI has expanded GPT-6 with the GPT-6 Sol and GPT-6 Luna models. Both are available in ChatGPT Work and Codex for Plus, Pro, Business, Enterprise, and Edu users. Free and Go users can access GPT-6 Luna in the desktop app. The models are not yet available in Chat. OpenAI API users can access them as gpt-6-sol and gpt-6-luna. A phased ChatGPT rollout is underway to maintain service stability. Performance and cost GPT-6 Sol delivers better … More → The post GPT-6 Sol and Luna arrive with 50% lower API prices appeared first on Help Net Security .
Emerging from stealth with $16 million in pre-seed funding, Outerlimit offers a decentralized authorization layer designed to discover, observe, and block harmful autonomous AI actions. The post Outerlimit Raises $16 Million to Stop Rogue AI Agents From Causing Harm appeared first on SecurityWeek .
OpenAI fires contractors for using AI to train ChatGPT Cybernews
The compromise affects MemTensor's MemOS, an open source memory framework for large language models (LLMs) and AI agents. Its main GitHub repository has about 11,500 stars and 1,100 forks. Four malicious releases, three of the npm package @memtensor/memos-cloud-openclaw-plugin and one of the PyPI package MemoryOS, each currently the latest version on its registry, drop cross-platform Go binaries that search developer home directories for secrets and report to servers under skyleen[. ]fr. Overview # On September 23, 2026, a threat actor published malicious releases of two MemTensor packages on two registries: npm: @memtensor/memos-cloud-openclaw-plugin versions 0. 1. 21, 0. 1. 23 and 0. 1. 25. This is MemTensor's OpenClaw lifecycle plugin, which adds MemOS Cloud memory recall and storage to OpenClaw agents. PyPI: MemoryOS version 2. 0.
Google has rolled out Chrome 154 to the Stable channel for Windows, Mac, and Linux, delivering fixes for 108 security vulnerabilities. The update, version 154. 0. 8037. 57 for Linux and 154. 0. 8037. 57/. 58 for Windows and Mac, addresses one of the largest security patch batches Chrome has shipped in recent memory, including 11 flaws rated Critical severity The most severe issues affect Chrome’s graphics and rendering stack. Multiple critical bugs were found in ANGLE, Chrome’s cross-platform graphics abstraction layer, including buffer overflows. Google Chrome 154 Patches 108 Security Flaws Additional critical flaws hit the GPU process, WebGL, ServiceWorker, Fullscreen, WindowDialog, and AdFilter components, with largely use-after-free and out-of-bounds write issues that could allow an attacker to achieve remote code execution or sandbox escape via a malicious web page.
Cyberattacks are increasingly built around familiar actions: signing in, approving a payment, or using a trusted app. Artificial intelligence can help attackers repeat those actions at speed, making financial fraud and network intrusion harder to spot before damage is done. The threats take different forms. Some automate parts of a network break-in, while others imitate executives on video calls, hide inside mobile apps, or place fake payment forms over legitimate checkouts. The shared weakness is misplaced trust in an apparently normal interaction. These attacks require continuous checks of identity and behavior, not just trust in a login. The report brings together espionage, mobile malware, fraud, and extortion rather than describing one new malware family. The consequences range from stolen phone data and payment details to large fraudulent transfers and reputational damage.
OpenAI’s new ChatGPT Computer History feature for macOS is designed to make AI assistance more context-aware, but its local “diary” of user activity may also create a high-value target for macOS infostealers . Released for the ChatGPT macOS desktop app, Computer History is disabled by default and currently applies to ChatGPT Pro, Business, and Enterprise users. The opt-in capability converts selected activity across apps and websites into searchable memories that ChatGPT and Codex can use in later conversations. ChatGPT Computer History Creates New Attack Surface The feature requires ChatGPT Memories to be enabled, while Business and Enterprise users need workspace-level administrative approval to activate it individually. Unlike Microsoft Recall’s original screenshot-centric model, Computer History relies on macOS Accessibility APIs to record interaction events.
The EvilTokens phishing service, which compromised more than 12,000 inboxes at over 10,000 organizations, has been disrupted by a coalition of law enforcement and private-sector partners led by Microsoft. With authorization from the US District Court for the Eastern District of Virginia, Microsoft and Health-ISAC worked with Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver Foundation and TRM Labs to seize 50 websites used to operate the service and disable more than 150 domains tied to … More → The post Microsoft disrupts EvilTokens phishing service that gave criminals access to 12,000 inboxes appeared first on Help Net Security .
Claude Opus 5. 5 is available across Anthropic’s platforms, Amazon Web Services, Google Cloud and Microsoft Azure. Developers can access it through the Claude Platform using the model name claude-opus-5-5. It includes watermarking measures designed to comply with the EU AI Act. Built for long and complex tasks Opus 5. 5 is designed for codebase migrations, software audits, financial analysis, data collection and workflows involving several applications. Early testers used the model for engineering tasks that ran … More → The post Claude Opus 5.5 cuts costs and adds safeguards for autonomous AI appeared first on Help Net Security .
Concerns over agentic risks are rising, and identity and access management (IAM) giant Okta believes it’s making the moves of a would-be leader in this emerging cyber market. “Identity is the primary control plane for securing AI,” said Okta CEO and co-founder Todd McKinnon in an earnings call in late August , telling investment analysts that the company’s customers see Okta as well-positioned to secure this agentic future. “And so we’re going after that on all fronts.” “We think that being the system of record for agents in the enterprise and being the system of record for agent identity, in the fullness of time, could be the biggest category of cyber,” he added. At the center of that strategy is Okta for AI Agents, an identity management and security platform for tracking and controlling agentic entities and activity.
Prismor is a free, open-source security layer for AI coding agents. It sits between an agent such as Claude Code, Codex, or Cursor and the actions that agent wants to take, and it checks each tool call against a policy before the call runs. Every call gets one of three verdicts: allow, warn, or block. AI coding agents run shell commands, read and write files, handle credentials, and call outside APIs, often chaining many steps … More → The post Prismor: Open-source runtime control plane for AI agents appeared first on Help Net Security .
Claude Sonnet 5 Anthropic
Malicious bot activity increased 124% between July 2025 and June 2026, compared with 13. 2% growth in human traffic. Traffic from AI agents and large language model crawlers rose 82. 3% during the same period, according to DataDome’s State of Bot & Agent Security Report 2026. Bot traffic grows nine times faster than human traffic The company analyzed trillions of requests across more than 75,000 customer sites during the 12-month period. Bots and AI agents generated approximately … More → The post Nearly two-thirds of tested websites fail every bot test appeared first on Help Net Security .
Claude Founder House San Francisco Anthropic
Attackers using AI have greatly benefited when it comes to speed and scale, and now, says Cisco Talos, the technology has evolved to execute large portions of the attack chain entirely without human involvement. Researchers at the threat intelligence group have identified what they call the first “LLM-as-C2” architecture that can fully automate the command-and-control (C2) chain. Dubbed CLOSEDQUORUM, the malware binary relies on a panel of large language model (LLM) judges to map and execute the optimal path to steal credentials. “This is not merely augmenting what an operator can accomplish in a session, but transferring an entire phase of the attack from the operator to the system,” Cisco Talos security and threat researcher Ryan Fetterman explained in a blog post . The benefits of speed and scale are compounded because the human-in-the-loop is no longer the bottleneck, he noted.
More than 80,000 AI relay servers are helping users in China mask their identities while they access cutting-edge large language models (LLMs), probably to clone them.