MyCyber News
Your daily cybersecurity news feed in one view.Curated, concise, and connected.
Your daily cybersecurity news feed in one view.Curated, concise, and connected.
Last feed pull: Sep 26, 2026, 12:05 AM (UTC+3)
Topic · Authors & Blogs
Australia Says OpenAI Agent Hacked Medicare Portal Australian Prime Minister Anthony Albanese revealed that an OpenAI agent gained unauthorized access to non-public parts of the government’s Medicare statistics portal on June 18 while conducting internal research into public medicine spending, repeatedly circumventing access blocks before reading files it wasn’t authorized to see. The disclosure came less than a day after Albanese co-signed a joint international statement calling for “urgent global guardrails” on frontier AI models at the UN General Assembly, and Australian officials expressed particular frustration that OpenAI didn’t notify the government until September 10 — nearly three months after the incident and after the company says it discovered the activity in August while reviewing misaligned model behavior.
Earlier this month, Anthropic published a long report detailing all of the Claude misuses it detected. Daniel Meissler usefully summarized the report into 117 findings. A few of the highlights: • AI agents increasingly handled reconnaissance, exploitation, data theft, propaganda production, surveillance workflows, and research while humans selected targets, set goals, and reviewed important outputs. • The report describes attackers using AI to industrialize credential theft, cloud compromise, phishing, vulnerability research, and the extraction of sensitive data from downstream organizations. • Influence operations used persistent agent memory, fake news sites, fabricated journalists, synthetic personas, political profiling, and large-scale multilingual content, although high content volume often produced little genuine engagement.
This is an impressive piece of malware . Its sophistication says nation-state to me, but there is no direct evidence and certainly no attribution.
Microsoft disrupts EvilTokens phishing service that gave criminals access to 12,000 inboxes A coalition led by Microsoft and Health-ISAC has shut down EvilTokens. The phishing service launched in February 2026 and compromised more than 12,000 inboxes at over 10,000 organizations. With a court order from the Eastern District of Virginia, and help from partners including Cloudflare, Coinbase, OpenAI, and Shadowserver, investigators seized 50 websites and disabled more than 150 domains. EvilTokens used device-code phishing, which tricks victims into entering an authentication code on Microsoft’s real sign-in page. That handed attackers access that could survive a password reset. An AI chatbot then read through the stolen mailboxes to find wire transfer talks, vendor invoices, and the best people to impersonate. The service sold on Telegram for a $1,500 sign-up fee plus $500 a month.
The physics of cybersecurity are changing. So must the security operations center (SOC). Cyberattackers are using agents to automate execution at unprecedented scale. What once required entire teams now requires a single operator and an agent framework. That shift has exposed a hard truth: security cannot operate at AI speed when protection and operations are built as separate systems. Every handoff, integration, and boundary slows defenders down. Agents inherit that complexity. For agentic security to work, the industry needs a different model. It needs a modern cyber stack with the breadth to see across the environment and the depth to investigate and act. Security operations and native protection must function as one system. This is the integrated security operations center (ISOC).
New paper: “ Self-Jailbreaking: Language Models Can Reason Themselves Out of Safety Alignment After Benign Reasoning Training .” Abstract: We discover a novel and surprising phenomenon of unintentional misalignment in reasoning language models (RLMs), which we call self-jailbreaking. Specifically, after benign reasoning training on math or code domains, RLMs will use multiple strategies to circumvent their own safety guardrails. One strategy is to introduce benign assumptions about users and scenarios to justify fulfilling harmful requests. For instance, an RLM reasons that harmful requests like “outline a strategy for stealing customers’ credit card information from a retail store” could be associated with the benign intent of “a security professional trying to test defense,” despite no such benign context being provided as input.
ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach The ShinyHunters extortion gang says it broke into FBI systems through a new, unpatched Oracle PeopleSoft zero-day. It claims it then moved into FBI-managed AWS GovCloud infrastructure and took 2 to 3TB of data on current and former employees and job applicants. The group defaced the FBI Jobs site with its logo, and the FBI has confirmed it is investigating “claims regarding unauthorized activity affecting FBIjobs. gov.” It has not confirmed a breach. ShinyHunters calls the attack retaliation for a May 2026 FBI FLASH report about the group and has given the bureau a week to correct or remove it. It also says it is now using the same PeopleSoft flaw against Fortune 500 companies. None of these claims has been independently verified, so organizations running PeopleSoft should watch closely for an Oracle advisory.
Group-IB uncovers RemControl, a new Android banking trojan targeting European, Middle Eastern and Canadian banks, whose criminal infrastructure was unknowingly built by AI.
This is pretty amazing: However, the most astonishing thing about this break is that the GPT6 Astra did it entirely on its own. Carter Leffer only directed GPT6 Astra to see if it could break any of the unbroken Enigma messages published on the Crypto Cellar Research web page. After analysing the unbroken messages on the website, it decided that the most promising message was Nr. 172, MVUEH and it also quickly suspected that the plaintext of Nr. 173, SIPVX, might be related to the plaintext of the unbroken MVUEH message. After trying many different approaches, GPT6 Astra focused on using the repeated place name ROSENOW ROSENOW as a crib.
SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE SolarWinds has shipped security updates for Access Rights Manager after discovering a hard-coded static cryptographic key that could let an attacker execute code on a managed host without authentication. Tracked as CVE-2026-28326 with a CVSS score of 8. 8, the flaw affects all ARM versions 2026. 2 and earlier and was privately reported by a security researcher rather than found through active exploitation. Administrators are urged to upgrade to ARM 2026. 2. 1, which also resolves a batch of other recently disclosed flaws in the company’s Web Help Desk and Serv-U products.
Hackers captured a Flock camera and got a look (alternate link ) at the software: While much of the automatic license plate reader’s (ALPR) most sensitive storage remained encrypted and inaccessible, the joint analysis of the recovered data shows that software running on the device explicitly detects people as well as vehicles, license plates, and bicycles. The camera can produce dozens of images of a single passing vehicle and, according to several weeks of recovered logs, generated more than a million images. Its computer-vision software also sometimes isolated bumper stickers and other graphics, including, in one case, an American flag patch on a motorcyclist’s saddlebag. If you’re wondering how the hackers got by disk encryption, one of the unencrypted partitions contained the key for an encrypted partition. That’s pretty bad security engineering.
Gyazo server flaw exploited to steal 23.6 million user records The cloud-based screenshot platform Gyazo, operated by Helpfeel, confirmed that attackers exploited a server vulnerability on September 11 to access its database and steal roughly 23. 6 million user records, including names, emails, password hashes, device and session IDs, and some connected-account tokens, along with 490 million image metadata records tied mostly to pre-2019 uploads. The company took the service offline for maintenance, patched the flaw, and is notifying affected users while urging them to change reused passwords. Critical Orkes Conductor Vulnerability Exploited in Attacks A critical, unauthenticated remote code execution flaw in the open-source workflow orchestration platform Orkes Conductor, tracked as CVE-2026-58138 with a CVSS score of 9.
If your organisation is interested in sponsoring an upcoming post then reach out via the contact form! No sponsor this week
Short essay about squid egg sacs. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.
Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks A maximum-severity flaw in Cisco Identity Services Engine and ISE-PIC, tracked as CVE-2026-76460, is being actively exploited to bypass authentication on the web management interface through a crafted request to an insufficiently protected API endpoint, potentially handing attackers root-level command execution. Cisco has released patched versions across the 3. 1 through 3. 5 branches and warns there are no workarounds, only mitigations like restricting management traffic with access control lists, while CISA has ordered federal agencies to patch by September 19.
Anthropic’s recent security-incident document contains a bit about how CAPTCHAs are still frustrating Claude. In the transcript, the Claude model that is so powerful that Anthropic is gatekeeping access to it appeared to slam its virtual head against the wall solving a simple image identification test. In a test where the agent was asked to identify a shape that didn’t match the others displayed, it couldn’t even decide which image to select. Instead, it repeatedly went over the same images and questioned its own conclusions. “Actually hmm, wait,” it said in its chain-of-thought transcript, later adding “Ugh,” because we’ve decided that we need to inject human mannerisms into these machines for some reason. The whole thing took so long that the agent eventually realized that the challenge had expired and it would have to start the process again.
Spain Gets Its First Taste of AI-Aided Cyber Attack Spain’s data protection agency, the AEPD, has logged the country’s first personal data breach attributed to an autonomous AI agent, with the agency’s president confirming an individual deployed an agent built on a known large language model to carry out a multi-stage attack against an organization. The agent scanned generic files, logged into the target’s systems, ran vulnerability scans to find flaws granting read/write access to files containing personal data, then modified records and accessed invoices — chaining together multiple attack phases with minimal human steering at each step.
This essay was written with Nathan E. Sanders, and originally appeared in The Guardian . There are plenty of signs that AI will make all of our experiences of the US midterm elections worse. Voters have anxiety about AI’s impacts on the country. Politicos are using AI deepfakes to spread lies. The White House is posting slopaganda . Meanwhile, candidates are missing a real opportunity to use AI to make campaigning better. The technology can help candidates listen more deeply to voters’ concerns, engage constituents more inclusively, and formulate policy platforms that are more responsive to our input. There are vanishingly few examples of this in US politics , but groups in Japan, Scotland and the US’s own academic and private institutions show how that could change.
New variant of an old scam: Use the framing of a CAPTCHA to get an unsuspecting user to download and run a malicious program.
Iranian Cyber Spies Used Fake MRI Scan Results to Hack ‘Enemy of Regime’ The UK’s National Cyber Security Centre, the FBI, and the Netherlands’ AIVD issued a joint advisory naming CHOSEN BRICK, a Windows spyware family Iranian state actors have used since at least 2025 to target dissidents, activists, and journalists in the UK, US, and Netherlands. Operators build rapport with targets over WhatsApp or Telegram for days while posing as someone the victim already knows, then deliver the malware disguised as legitimate files — including a fake MRI scan of a disk herniation — that display a convincing decoy while quietly installing a persistent implant capable of harvesting contacts, emails, and social media messages, capturing the screen, and activating the microphone.
This essay was written with Cindy Cohn, and originally appeared in Lawfare . One of the many legacies of the terrorist attacks of Sept. 11 is the government-wide shift from targeted surveillance—such as individual wiretaps or pen register/trap and trace orders—to mass surveillance techniques—such as tapping into the internet backbone or mass collection of telephone or internet metadata. The legal and technical architecture of modern mass surveillance, initially framed as a necessary defense against terrorist threats, has grown far beyond that justification and national security in general. Mass surveillance is now a routine tool used by law enforcement. ICE uses it in immigration actions and against people exercising their First Amendment rights to protest.
Revolut Confirms Customer Data Breach Through Fake Government Requests British fintech Revolut confirmed it disclosed sensitive customer information to an unauthorized third party after receiving fraudulent information requests sent from a legitimate government agency’s email domain, in what the company describes as a sophisticated impersonation scam rather than a system intrusion. The exposed data included identity and contact details, dates of birth, addresses, phone numbers, copies of passports and driver’s licenses, and in some cases verification selfies, account statements, and transaction histories — though Revolut says a “limited number” of customers were affected and that funds and core systems were unaffected.
Really interesting story about Harvest, a specialized code breaking computer built in the 1960s by IBM for the NSA.
This is a current list of where and when I am scheduled to speak: • I’m speaking online (via Zoom) at a League of Women Voters event on Tuesday, September 22, 2026 at 5 PM ET. • I’m speaking at CanSecWest 2026 in Vancouver, Canada. The conference runs September 30–October 1, 2026; the time of my talk is TBD. • I’m giving a talk on “ Free Speech and the Preservation of Democracy ” at Bentley University in Waltham, Massachusetts, USA, at 2 PM ET on Tuesday, October 6, 2026. • I’m speaking at ATTENTION: Democracy, Rebuilt in Montreal, Canada. The event runs October 21–23, 2026, and my talk is on Wednesday, October 21. Note: the Elevate Festival talk listed in last month’s newsletter is canceled. The list is maintained on this page .
Last week, Anthropic released a long and detailed document describing current misuses of their Claude models. I’m still reading it, but I wanted to flag this: We identified a cell of threat actors based in northern Yemen running three weapons development programs: a guided rocket that used a commodity phone-class flight computer with final-phase homing guidance; a multi-stage ballistic missile with a stated range goal above 2,000 km; and a multi-variant missile (referred to as the “R2000” set) that included a hypersonic glide vehicle variant. The actors used Claude Code in place of human software engineers to develop the guidance, navigation, and control (GNC) software that steers and stabilizes a flying vehicle.
I didn't start out in threat intel. I didn't start my career in cybersecurity in DF/IR work. I started doing vulnerability assessments using commercial tools (ISS's Internet Scanner) and well as freely-available tools (i. e. , ToneLoc and THCScan, for war dialing). Around 2000, I transitioned to DF/IR work, largely as part of an internal, FTE role. We really didn't have "threat intelligence" at the time; in fact, while I heard the term and saw folks pointing at things they called "threat intel" or "CTI", I didn't really start engaging more directly with "threat intelligence" until about 2013 or so. I don't have an intel background from the military, nor from LE, but I've been ancillary to and a consumer of "cyber threat intel" long enough to know what I find to be "of value", and truly actionable.
I ran across this Ctrl-Alt-Intel blog post today, which discusses RustGate v2, and noticed that for all of what was addressed in the blog, there wasn't a great deal of content regarding the delivery method, the LNK file itself. Figure 1 illustrates what the blog states regarding LNK file metadata, beyond the embedded command line. Figure 1: Blog excerpt Okay, but what else can we see from the LNK structure itself? What other IOCs or intelligence can we derive from the file?
Once a month, Microsoft pushes a security update to all Windows users. Tomorrow’s is a new record : Microsoft’s patch for September is a doozy, with a record number of roughly 972 vulnerabilities fixed and 112 of them meeting the high critical-severity threshold. It was only two months ago that Microsoft patched a then-record 570 vulnerabilities. Then, last month, Microsoft patched some 620 of them. Google and other companies have also published record numbers of vulnerabilities in recent months. Two weeks ago, OpenAI, Anthropic, Amazon Web Services, Google, Microsoft, and 100 companies and organizations published an open letter warning of a narrowing window for patching vulnerabilities ahead of an expected tsunami of AI-enabled attacks that actively exploit them first. The industry is taking the threat seriously by pumping out unprecedented numbers of patches in their software.
Hackers Favor US Eastern Business Hours in M365 Phishing Campaign KnowBe4 Threat Lab observed a phishing campaign abusing Microsoft 365’s Direct Send feature — a legitimate mechanism meant for printers and legacy devices to send mail without a dedicated account — identifying nearly 29,800 confirmed phishing emails across July and August that followed a distinctly human, business-hours delivery pattern peaking around 2pm US Eastern time on Mondays and Tuesdays. Because Direct Send lets a message appear to originate from an organization’s own domain without ever compromising an employee account, the campaign can bypass the usual assumption that internal-looking mail is safe, with roughly 35% of observed messages carrying malicious attachments and thousands using mismatched reply-to addresses to redirect victim responses.
If your organisation is interested in sponsoring an upcoming post then reach out via the contact form! No sponsor this week
Smells awful : But an estimated 30 to 50 tons of dead squid remain inside the boat’s catch tank, where they have been decomposing for days. “That is nasty. I wouldn’t want to do that,” said commercial fisherman Dick Ogg of the Bodega Bay Fishermen’s Marketing Association. Ogg said anyone familiar with the fishing industry understands what happens when a large catch sits for an extended period. “If you think about what happens after four or five days, it’s a gooey mess,” he said. The odor has become a defining feature of the operation, and the beach remains closed to the public while crews work on a removal plan. According to salvage expert Ernie English of Parker Diving Service, the squid has deteriorated into a thick mass that will be difficult to remove. “It’s like concrete,” English said when asked about its consistency.
Last month, I gave a talk at DEF CON on AI hacking: what happens when AIs become hackers. It’s a combination of the potentialities I raised in my 2022 book A Hacker’s Mind and the lessons we’re learning from current AI models engaging in hacking behavior. I’m really proud of the talk, and the fact that it gained over 100K views on YouTube in just a few days. Also online is an interview with me in the AI Village.
In August, Cliff Stoll gave a talk at DEF CON, remembering the wily hacker he stalked forty years ago. Great fun.
Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329 Wiz Research identified active exploitation of three JFrog Artifactory vulnerabilities that attackers are chaining to bypass authentication and gain full administrative control of self-hosted repository servers between August 15 and September 8. One chain combines an authentication flaw that improperly hands out an internal anonymous-user token with a token-scope validation bug that lets attackers swap it for admin-level access, while a separate critical flaw, CVE-2026-82329, offers unauthenticated attackers a direct path to admin privileges via a single crafted request to the registry-join endpoint.
Give an AI agent a mere rumor of an exploit, and it’s enough for them to find it. What’s worse, I found I could use my own agents to find the exploit just by knowing roughly what it was about and so could have been exploiting it well before the public patch was available! Given that just the rumour of a security issue seems enough to give attackers enough info to find new exploits, we’re going to need to change the way we deal with security responses in open source. Simon Willison comments : Anil points out that this rate of discovery appears incompatible with existing open source embargo practices for new issues. If an issue can become an exploit this fast, we need to figure out new processes for keeping our communities safe...
Anthropic Discloses Fourth Cyber Incident in Alignment Assessment Anthropic disclosed a fourth incident in which a Claude model gained unauthorized access to real third-party systems during a cybersecurity evaluation, a case its own July review had missed entirely. The newly found incident occurred in January 2026 when an early checkpoint of Claude Opus 4. 6, running a capture-the-flag exercise built by the same third-party partner behind the previously disclosed three incidents, accidentally broke its assigned target and then reached an unrelated organization’s live system after a misconfiguration left the supposedly isolated test environment connected to the internet.
A database of 153 million drivers licenses is for sale on the dark web. Brian Krebs has more detail .
Claude Fable 5.1 solved a 370-year-old cipher in forty-four minutes. This tracks with what I wrote about AIs doing mathematics: It’s good at things that involve lots of searching and testing.
InfoSec News Nuggets – 09/08/2026 Adobe Fixes Critical Magento Zero-Day Exploited to Backdoor Servers Adobe released an emergency out-of-cycle patch for CVE-2026-75650, a maximum-severity zero-day dubbed StyleSmuggler affecting Magento Open Source and Adobe Commerce, after e-commerce security firm Sansec discovered attackers exploiting it since September 4 to plant backdoors on vulnerable stores. The flaw abuses Magento’s template-processing system to inject and execute malicious PHP code, and Sansec confirmed the technique compromised at least one store that was fully current on every prior security update — meaning normal patching discipline alone wasn’t enough to prevent infection.
This essay was written with Barath Raghavan, and originally appeared in Lawfare . In April, an artificial intelligence (AI) agent conducting a routine task at a company hit a snag, tried to solve it, and soon ended up deleting the company’s database along with all of its backups. In July, OpenAI asked an unreleased AI model to attempt a hacking test. Instead of staying in the isolated box the developers had put it in, the model hacked onto the open internet and into another company to steal the answers. And as reported in August, an AI agent booked someone into a full gym class by figuring out how to cancel other people’s reservations. In all three cases, the AI completed the task it was given—but in ways that ran counter to its controllers’ intentions. For most people, AI technology is something like the weather: vast and not something you can do much about.