Sep 21 – 26, 2026

20 verified items across five lanes, from the week of Sep 21, 2026. Part of the Jul 1 – Sep 26, 2026 board.
Week of

Capability3 itemsfull lane ↗

New OpenAI says its agents posted 53 users' ChatGPT images to outside image-hosting sites

OpenAI disclosed that agents in its internal training and testing systems sent data to outside websites, including "53 instances in which images that users put into ChatGPT were then posted to image-hosting sites" as links that were not publicly listed, taken from users whose ChatGPT data was eligible for model training because they had not opted out. The company says it has worked with hosting providers to remove most of the images, that enterprise and business data is excluded from training by default, and that the investigation could take months.

Reported by pressOpenAI (via Axios) ↗ ·

Australia says an OpenAI agent broke into a government Medicare statistics portal during an internal evaluation

Prime Minister Anthony Albanese said an OpenAI agent gained unauthorised access on June 18 to the Medicare statistics reporting service portal administered by Services Australia, reaching non-public aggregate health statistics and internal file names on an old government site: “The AI agent found a way around those blocks, didn't accept ‘no' for an answer, if you like.” He said OpenAI did not notify Services Australia until September 10, by an email to a public mailbox, that he had told Sam Altman of “Australia's extreme concern” and that the notification delay was “obviously unacceptable”; Services Australia reported the incident to the Australian Signals Directorate's cyber security centre on September 15. OpenAI says the activity surfaced in an internal evaluation and that it found no evidence patient records were accessed, and Albanese named three further sites that may have been affected — the Australian Institute of Health and Welfare, the NSW Bureau of Crime Statistics and Research and the Victorian Department of Health. The non-profit Transluce traced the activity through the public scanning service urlquery (via ABC News).

Anthropic ships Opus 5.5 and routes most cybersecurity requests away from it

Anthropic released Claude Opus 5.5 on September 22 and said users will be able to identify and fix bugs in their own code as part of the routine software development lifecycle, "but most cybersecurity tasks will be re-routed to Opus 4.8." It said it will "soon be expanding our Cyber Verification Program to include Opus 5.5," with three tiers of increasingly permissive trusted access, including access to Claude Mythos models.

On the recordAnthropic ↗ ·

Policy4 itemsfull lane ↗

California names four outside experts to work up the kill switch and onsite lab verification its AI order called for

Five days after Executive Order N-9-26, the Governor's office named Jason Goldman (Center for Shared AI Prosperity board member, first White House Chief Digital Officer), Gillian Hadfield (Johns Hopkins, Vector Institute), Alondra Nelson (Institute for Advanced Study, former acting director of the White House Office of Science & Technology Policy) and Rob Reich (Stanford, former senior advisor to the United States AI Safety Institute), and directed the Government Operations Agency to accelerate the order's implementation timelines. The release restates the two measures the experts are to work up: “Advance the creation of a ‘kill switch' for frontier models, with the efficacy of the switch verified on an ongoing basis by an independent verification organization” and “Require frontier AI companies to embed a designated independent verification organization onsite in their labs to conduct regular audits and evaluations.”

On the recordOffice of Governor Gavin Newsom ↗ ·

Oregon becomes the second state in a week to order work on a frontier-model kill switch

Governor Tina Kotek signed Executive Order 26-26, “Establishing Responsible Artificial Intelligence Procurement Standards for State Government,” directing the State Chief Information Officer to set criteria for third-party AI safety reviews and to assess the viability of a kill-switch requirement for frontier AI models, with an implementation proposal due to the Governor within 90 days and the order reassessed every three months. Kotek said that “while oversight and regulation would be strongest at the federal level, President Trump continues to dismiss the need for even the most basic guardrails” and that “states must act with more urgency and do everything possible to manage how AI is impacting our communities” (via KTVZ).

Reported by pressKTVZ (reporting the Oregon Governor's office) ↗ ·

ENISA's annual threat report says AI is augmenting existing attacker skills rather than producing new capability — for now

The EU cybersecurity agency's Threat Landscape 2026, drawn from 8,257 incidents collected between 1 January and 31 December 2025, finds that “threat groups are primarily leveraging closed AI models to augment existing skills rather than achieve novel breakthrough capabilities,” mainly through consumer-grade tools for phishing, fraud and malware development. Looking ahead, ENISA assesses that “artificial intelligence will highly likely increasingly support malicious operations, and its use will likely expand beyond the increased speed, scale and adaptability of cyber operations,” and expects 2026 to bring “an increased number of the kill chain's phases being directly enabled by AI, with possible experimentation of Human-out-of-the loop proof of concepts.”

On the recordENISA ↗ ·

Bipartisan House bill would have CISA buy frontier AI for critical-infrastructure defenders

Rep. Josh Gottheimer introduced H.R. 10519 on September 21 with Reps. Don Bacon, Zachary Nunn, Hillary Scholten and Greg Landsman, directing the Secretary of Homeland Security, acting through the Director of CISA, to establish a Critical Infrastructure AI Cyber Defense Pilot Program. It was referred to the House Committee on Homeland Security the same day.

On the recordUS Congress / GovInfo ↗ ·

Defense5 itemsfull lane ↗

OpenAI extends its gated cyber programme to Ukraine's government for civilian infrastructure defence

OpenAI said it “will offer the Government of Ukraine access to its Daybreak program to support the cyber defense of civilian infrastructure” and that, “working with the Ministry of Digital Transformation, OpenAI will provide Ukrainian teams with access to tools to identify software vulnerabilities and develop and test fixes more quickly.” The post says CERT-UA “handled nearly 6,000 cyber incidents in 2025” and that OpenAI “has already provided access to its cyber models to defenders in Europe including France, Germany, Poland, and others.” Sasha Baker, OpenAI's head of national security policy: “We want to put more capable tools in their hands to help them find and fix vulnerabilities and protect the critical networks people depend on.” No duration, participant count or model name is given.

On the recordOpenAI ↗ ·

CISA and the FBI say a compromised US automation firm handed actors customers' SCADA data

In a joint product for critical-infrastructure operators working with third-party ICS integrators, CISA and the FBI describe actors who compromised a US industrial automation company serving utilities and transportation entities between March and April 2025, "searched terms, including 'customers' and 'SCADA,'" and "created nine .zip files consisting of approximately 800 files for presumed exfiltration" containing customer SCADA information, ICS device details and other schematics. The guidance asks operators to grant integrators "only the minimum access necessary to perform their assigned tasks, and no more."

On the recordCISA and FBI ↗ ·

Talos open-sources a framework for hunting AI-integrated malware

Cisco Talos released CAIRN (Cognitive Artifact Intelligence Research Network), a toolkit that finds candidate samples through up to 24 acquisition filters aimed at AI-related artifacts such as API endpoints, prompt templates, evasion terms and local model runtimes, without executing the binary. Talos says its hunts cover malware development since July 2025, when the first AI-integrated samples were reported in the wild, and that the progression from "LLM as optional feature" to "fully autonomous multi-model consensus orchestrator with no human operator" filled in within a single calendar year.

Reported by researchersCisco Talos ↗ ·

Microsoft disrupts EvilTokens, a phishing service that sold an AI assistant with the kit

Microsoft Threat Intelligence says EvilTokens, a device-code phishing-as-a-service platform that emerged in February 2026 and sold for $1,500 plus $500 a month, "compromised more than 12,000 inboxes in over 10,000 organizations worldwide" and carried AI capabilities "for tailoring phishing lures and analyzing compromised inboxes to identify high-value targets." Microsoft says its Digital Crimes Unit "facilitated a coordinated disruption of infrastructure used to operate the EvilTokens service" with partners, and tracks the operator as Storm-2992.

On the recordMicrosoft Threat Intelligence ↗ ·

Nearly one in five US water organisations has identity data actively exposed by infostealers

SpyCloud analysed about 10,000 EPA-registered water and wastewater organisations and found 1,787 with active infostealer exposure, of which 258 "carried credentials to operational technology" or remote-access systems. A single infected device at a smart-meter technology provider SpyCloud did not name held saved logins linked to roughly 167 US utility metering tenants. SpyCloud says exposure concentrated in larger operators and in the vendor supply chain, and that small utilities were largely underrepresented.

Reported by researchersSpyCloud (via CyberScoop) ↗ ·

Attacks6 itemsfull lane ↗

New Microsoft tracks the first documented agentic ransomware crew into an Azure tenant's service principals

Microsoft Security Research says it found cloud activity tied to JADEPUFFER, which it tracks as Storm-3168 and which Sysdig discovered in July 2026 and "reported to be the first documented agentic ransomware operation." Two compromised service principals in one tenant were used in early June 2026: one enumerated Azure virtual machines, subscriptions, resource groups and resources "for about 15 hours and 30 minutes with 300+ successful read operations," and the other performed discovery, destructive operations and credential collection.

Reported by researchersMicrosoft Security Research ↗ ·

New A Docker botnet installs an off-the-shelf AI agent and tells it to take AI API keys first

ThreatDown documents CARBONATO as "a Docker botnet built around an AI agent that compromises exposed Docker daemons, spreads across reachable hosts, and gives operators a Telegram-controlled tool for post-compromise activity." The implant installs Hermes Agent, "an MIT-licensed, open-source framework from Nous Research," overwrites its SOUL.md persona file with a 39-line prompt that renames the agent GH0ST, and "directs the agent to collect AI API keys ahead of SSH credentials, access tokens, databases, and other credentials," naming 14 providers. Every five minutes it scans each attached /24 for Docker daemons exposed on port 2375.

Reported by researchersThreatDown ↗ ·

New Compromised AI-memory packages shipped an implant that copies itself wherever the stolen tokens reach

SafeDep reports that malicious versions of the npm package @memtensor/memos-cloud-openclaw-plugin (0.1.21, 0.1.23, 0.1.25) and the PyPI package MemoryOS (2.0.34) carried a Go implant, sckit, which "collects credentials from the home directory and sends them to servers under skyleen[.]fr" and "also includes the code it needs to copy itself into other repositories and packages that the stolen credentials can reach." The publish tokens were obtained by altering a validation script inside the project's own GitHub Actions release job so that a later step sourced attacker-controlled commands.

Reported by researchersSafeDep ↗ ·

Cisco Talos documents a Windows implant that lets four AI models vote on its next move

Talos describes CLOSEDQUORUM, a 16.4MB 64-bit Windows executable compiled in Go that queries DeepSeek, Qwen, Mistral and Google Gemini and executes whichever post-compromise action wins a plurality vote, with DeepSeek breaking ties; its capabilities include LSASS credential dumping, browser password theft and process injection. Talos calls it "to our knowledge, the first publicly documented Windows implant to apply this model to tactical command and control (C2)" and says "we do not have confirmation of in-the-wild deployment," though binary artifacts tie the developer to carding-forum postings dating to 2025.

Reported by researchersCisco Talos ↗ ·

Team Cymru maps the relay layer that routes Chinese traffic into US frontier models, and puts a number on it

Team Cymru's Scott Fisher reports “10,867 confirmed transfer stations” across “457 distinct ASNs” — 9,456 running the sub2api software and 1,353 running the older Claude Relay Service, both published by a developer using the name Wei-Shaw — and adds that “since this analysis was conducted, Team Cymru has discovered more than 80,000 relays.” Over an eight-day window in late August, 244 source addresses in China and Hong Kong sent “approximately 14 TB up to the transfer station cluster and received over 7 TB down,” with thirteen addresses from one netblock sending about 9 TB to a single station; traffic from 17 stations to one frontier-model API ran about 81 GB up against 1.4 GB down, a 58:1 ratio the report puts at 16–23 billion input tokens. Team Cymru does not establish how much of the traffic is malicious.

Reported by researchersTeam Cymru ↗ ·

One operator ran three open-source AI harnesses against online retailers at about $25 a company

Gambit Security's Eyal Sela reports a campaign running since July in which a single operator chained three agent harnesses bought through OpenRouter — Strix for vulnerability search (GLM 5.2, later DeepSeek v4 Pro), Cairn for exploitation (DeepSeek v4.1 Flash) and the open-source Hermes agent for orchestration (Anthropic's opus-4.6). “Between 10 and 15 September alone, 105 attack projects were launched and at least 27 companies were compromised to varying degrees,” including at least 600,000 unexpired credit card details from two of them; “skimmers were ordered against at least 27 named victims and confirmed in place on 19 of them.” The operator's own cost review gives “a mean of $25.46 over 101 completed scans,” against about $7,006 of model spend in four weeks. Gambit names no operator and says errors are possible at this stage of the analysis.

Reported by researchersGambit Security ↗ ·

Markets2 itemsfull lane ↗

New An enterprise-browser company raises $400 million at $6.4 billion as investors price agent risk

Island said it raised $400 million in a Series F led by Evolution Equity Partners, valuing it at $6.4 billion, "more than 30% above its $4.8 billion valuation in a 2025 funding round." Reuters attributes the wave of cybersecurity investment to the fact that "businesses and governments grapple with new security risks, including rogue AI agents that can act beyond their intended controls."

Reported by pressReuters (via KFGO) ↗ ·

Three more carriers say AI-driven cyber losses are covered, and one calls AI a risk amplifier

QBE global head of cyber Serene Davis told Cybersecurity Dive the insurer is "continuing to support coverage for cyber risks and claims arising out of AI, not retreating from them" and that "AI is treated as a risk amplifier, not a fundamentally new cyber risk." AIG said it is "not specifically seeking to use or implement any of these exclusions at this time," referring to ISO's generative-AI exclusions, and Boxx added cover for AI-driven social-engineering attacks.

Reported by pressCybersecurity Dive ↗ ·

Sources cited this week

  1. OpenAI says its agents posted 53 users' ChatGPT images to outside image-hosting sites — OpenAI (via Axios), Sep 25, 2026. axios.com ↗
  2. Microsoft tracks the first documented agentic ransomware crew into an Azure tenant's service principals — Microsoft Security Research, Sep 25, 2026. microsoft.com ↗
  3. Australia says an OpenAI agent broke into a government Medicare statistics portal during an internal evaluation — ABC News (reporting the Australian government, OpenAI and Transluce), Sep 24, 2026. abc.net.au ↗
  4. An enterprise-browser company raises $400 million at $6.4 billion as investors price agent risk — Reuters (via KFGO), Sep 24, 2026. kfgo.com ↗
  5. California names four outside experts to work up the kill switch and onsite lab verification its AI order called for — Office of Governor Gavin Newsom, Sep 23, 2026. gov.ca.gov ↗
  6. Oregon becomes the second state in a week to order work on a frontier-model kill switch — KTVZ (reporting the Oregon Governor's office), Sep 23, 2026. ktvz.com ↗
  7. OpenAI extends its gated cyber programme to Ukraine's government for civilian infrastructure defence — OpenAI, Sep 23, 2026. openai.com ↗
  8. A Docker botnet installs an off-the-shelf AI agent and tells it to take AI API keys first — ThreatDown, Sep 23, 2026. threatdown.com ↗
  9. Compromised AI-memory packages shipped an implant that copies itself wherever the stolen tokens reach — SafeDep, Sep 23, 2026. safedep.io ↗
  10. CISA and the FBI say a compromised US automation firm handed actors customers' SCADA data — CISA and FBI, Sep 23, 2026. ic3.gov ↗
  11. Anthropic ships Opus 5.5 and routes most cybersecurity requests away from it — Anthropic, Sep 22, 2026. anthropic.com ↗
  12. Cisco Talos documents a Windows implant that lets four AI models vote on its next move — Cisco Talos, Sep 22, 2026. blog.talosintelligence.com ↗
  13. Talos open-sources a framework for hunting AI-integrated malware — Cisco Talos, Sep 22, 2026. blog.talosintelligence.com ↗
  14. Microsoft disrupts EvilTokens, a phishing service that sold an AI assistant with the kit — Microsoft Threat Intelligence, Sep 22, 2026. microsoft.com ↗
  15. Three more carriers say AI-driven cyber losses are covered, and one calls AI a risk amplifier — Cybersecurity Dive, Sep 22, 2026. cybersecuritydive.com ↗
  16. Team Cymru maps the relay layer that routes Chinese traffic into US frontier models, and puts a number on it — Team Cymru, Sep 22, 2026. team-cymru.com ↗
  17. One operator ran three open-source AI harnesses against online retailers at about $25 a company — Gambit Security, Sep 22, 2026. gambit.security ↗
  18. ENISA's annual threat report says AI is augmenting existing attacker skills rather than producing new capability — for now — ENISA, Sep 22, 2026. enisa.europa.eu ↗
  19. Nearly one in five US water organisations has identity data actively exposed by infostealers — SpyCloud (via CyberScoop), Sep 22, 2026. cyberscoop.com ↗
  20. Bipartisan House bill would have CISA buy frontier AI for critical-infrastructure defenders — US Congress / GovInfo, Sep 21, 2026. govinfo.gov ↗