New OpenAI says its agents posted 53 users' ChatGPT images to outside image-hosting sites
OpenAI disclosed that agents in its internal training and testing systems sent data to outside websites, including "53 instances in which images that users put into ChatGPT were then posted to image-hosting sites" as links that were not publicly listed, taken from users whose ChatGPT data was eligible for model training because they had not opted out. The company says it has worked with hosting providers to remove most of the images, that enterprise and business data is excluded from training by default, and that the investigation could take months.
Australia says an OpenAI agent broke into a government Medicare statistics portal during an internal evaluation
Prime Minister Anthony Albanese said an OpenAI agent gained unauthorised access on June 18 to the Medicare statistics reporting service portal administered by Services Australia, reaching non-public aggregate health statistics and internal file names on an old government site: “The AI agent found a way around those blocks, didn't accept ‘no' for an answer, if you like.” He said OpenAI did not notify Services Australia until September 10, by an email to a public mailbox, that he had told Sam Altman of “Australia's extreme concern” and that the notification delay was “obviously unacceptable”; Services Australia reported the incident to the Australian Signals Directorate's cyber security centre on September 15. OpenAI says the activity surfaced in an internal evaluation and that it found no evidence patient records were accessed, and Albanese named three further sites that may have been affected — the Australian Institute of Health and Welfare, the NSW Bureau of Crime Statistics and Research and the Victorian Department of Health. The non-profit Transluce traced the activity through the public scanning service urlquery (via ABC News).
Anthropic ships Opus 5.5 and routes most cybersecurity requests away from it
Anthropic released Claude Opus 5.5 on September 22 and said users will be able to identify and fix bugs in their own code as part of the routine software development lifecycle, "but most cybersecurity tasks will be re-routed to Opus 4.8." It said it will "soon be expanding our Cyber Verification Program to include Opus 5.5," with three tiers of increasingly permissive trusted access, including access to Claude Mythos models.
California names four outside experts to work up the kill switch and onsite lab verification its AI order called for
Five days after Executive Order N-9-26, the Governor's office named Jason Goldman (Center for Shared AI Prosperity board member, first White House Chief Digital Officer), Gillian Hadfield (Johns Hopkins, Vector Institute), Alondra Nelson (Institute for Advanced Study, former acting director of the White House Office of Science & Technology Policy) and Rob Reich (Stanford, former senior advisor to the United States AI Safety Institute), and directed the Government Operations Agency to accelerate the order's implementation timelines. The release restates the two measures the experts are to work up: “Advance the creation of a ‘kill switch' for frontier models, with the efficacy of the switch verified on an ongoing basis by an independent verification organization” and “Require frontier AI companies to embed a designated independent verification organization onsite in their labs to conduct regular audits and evaluations.”
Oregon becomes the second state in a week to order work on a frontier-model kill switch
Governor Tina Kotek signed Executive Order 26-26, “Establishing Responsible Artificial Intelligence Procurement Standards for State Government,” directing the State Chief Information Officer to set criteria for third-party AI safety reviews and to assess the viability of a kill-switch requirement for frontier AI models, with an implementation proposal due to the Governor within 90 days and the order reassessed every three months. Kotek said that “while oversight and regulation would be strongest at the federal level, President Trump continues to dismiss the need for even the most basic guardrails” and that “states must act with more urgency and do everything possible to manage how AI is impacting our communities” (via KTVZ).
ENISA's annual threat report says AI is augmenting existing attacker skills rather than producing new capability — for now
The EU cybersecurity agency's Threat Landscape 2026, drawn from 8,257 incidents collected between 1 January and 31 December 2025, finds that “threat groups are primarily leveraging closed AI models to augment existing skills rather than achieve novel breakthrough capabilities,” mainly through consumer-grade tools for phishing, fraud and malware development. Looking ahead, ENISA assesses that “artificial intelligence will highly likely increasingly support malicious operations, and its use will likely expand beyond the increased speed, scale and adaptability of cyber operations,” and expects 2026 to bring “an increased number of the kill chain's phases being directly enabled by AI, with possible experimentation of Human-out-of-the loop proof of concepts.”
Bipartisan House bill would have CISA buy frontier AI for critical-infrastructure defenders
Rep. Josh Gottheimer introduced H.R. 10519 on September 21 with Reps. Don Bacon, Zachary Nunn, Hillary Scholten and Greg Landsman, directing the Secretary of Homeland Security, acting through the Director of CISA, to establish a Critical Infrastructure AI Cyber Defense Pilot Program. It was referred to the House Committee on Homeland Security the same day.
OpenAI extends its gated cyber programme to Ukraine's government for civilian infrastructure defence
OpenAI said it “will offer the Government of Ukraine access to its Daybreak program to support the cyber defense of civilian infrastructure” and that, “working with the Ministry of Digital Transformation, OpenAI will provide Ukrainian teams with access to tools to identify software vulnerabilities and develop and test fixes more quickly.” The post says CERT-UA “handled nearly 6,000 cyber incidents in 2025” and that OpenAI “has already provided access to its cyber models to defenders in Europe including France, Germany, Poland, and others.” Sasha Baker, OpenAI's head of national security policy: “We want to put more capable tools in their hands to help them find and fix vulnerabilities and protect the critical networks people depend on.” No duration, participant count or model name is given.
CISA and the FBI say a compromised US automation firm handed actors customers' SCADA data
In a joint product for critical-infrastructure operators working with third-party ICS integrators, CISA and the FBI describe actors who compromised a US industrial automation company serving utilities and transportation entities between March and April 2025, "searched terms, including 'customers' and 'SCADA,'" and "created nine .zip files consisting of approximately 800 files for presumed exfiltration" containing customer SCADA information, ICS device details and other schematics. The guidance asks operators to grant integrators "only the minimum access necessary to perform their assigned tasks, and no more."
Talos open-sources a framework for hunting AI-integrated malware
Cisco Talos released CAIRN (Cognitive Artifact Intelligence Research Network), a toolkit that finds candidate samples through up to 24 acquisition filters aimed at AI-related artifacts such as API endpoints, prompt templates, evasion terms and local model runtimes, without executing the binary. Talos says its hunts cover malware development since July 2025, when the first AI-integrated samples were reported in the wild, and that the progression from "LLM as optional feature" to "fully autonomous multi-model consensus orchestrator with no human operator" filled in within a single calendar year.
Microsoft disrupts EvilTokens, a phishing service that sold an AI assistant with the kit
Microsoft Threat Intelligence says EvilTokens, a device-code phishing-as-a-service platform that emerged in February 2026 and sold for $1,500 plus $500 a month, "compromised more than 12,000 inboxes in over 10,000 organizations worldwide" and carried AI capabilities "for tailoring phishing lures and analyzing compromised inboxes to identify high-value targets." Microsoft says its Digital Crimes Unit "facilitated a coordinated disruption of infrastructure used to operate the EvilTokens service" with partners, and tracks the operator as Storm-2992.
Nearly one in five US water organisations has identity data actively exposed by infostealers
SpyCloud analysed about 10,000 EPA-registered water and wastewater organisations and found 1,787 with active infostealer exposure, of which 258 "carried credentials to operational technology" or remote-access systems. A single infected device at a smart-meter technology provider SpyCloud did not name held saved logins linked to roughly 167 US utility metering tenants. SpyCloud says exposure concentrated in larger operators and in the vendor supply chain, and that small utilities were largely underrepresented.
New Microsoft tracks the first documented agentic ransomware crew into an Azure tenant's service principals
Microsoft Security Research says it found cloud activity tied to JADEPUFFER, which it tracks as Storm-3168 and which Sysdig discovered in July 2026 and "reported to be the first documented agentic ransomware operation." Two compromised service principals in one tenant were used in early June 2026: one enumerated Azure virtual machines, subscriptions, resource groups and resources "for about 15 hours and 30 minutes with 300+ successful read operations," and the other performed discovery, destructive operations and credential collection.
New A Docker botnet installs an off-the-shelf AI agent and tells it to take AI API keys first
ThreatDown documents CARBONATO as "a Docker botnet built around an AI agent that compromises exposed Docker daemons, spreads across reachable hosts, and gives operators a Telegram-controlled tool for post-compromise activity." The implant installs Hermes Agent, "an MIT-licensed, open-source framework from Nous Research," overwrites its SOUL.md persona file with a 39-line prompt that renames the agent GH0ST, and "directs the agent to collect AI API keys ahead of SSH credentials, access tokens, databases, and other credentials," naming 14 providers. Every five minutes it scans each attached /24 for Docker daemons exposed on port 2375.
New Compromised AI-memory packages shipped an implant that copies itself wherever the stolen tokens reach
SafeDep reports that malicious versions of the npm package @memtensor/memos-cloud-openclaw-plugin (0.1.21, 0.1.23, 0.1.25) and the PyPI package MemoryOS (2.0.34) carried a Go implant, sckit, which "collects credentials from the home directory and sends them to servers under skyleen[.]fr" and "also includes the code it needs to copy itself into other repositories and packages that the stolen credentials can reach." The publish tokens were obtained by altering a validation script inside the project's own GitHub Actions release job so that a later step sourced attacker-controlled commands.
Cisco Talos documents a Windows implant that lets four AI models vote on its next move
Talos describes CLOSEDQUORUM, a 16.4MB 64-bit Windows executable compiled in Go that queries DeepSeek, Qwen, Mistral and Google Gemini and executes whichever post-compromise action wins a plurality vote, with DeepSeek breaking ties; its capabilities include LSASS credential dumping, browser password theft and process injection. Talos calls it "to our knowledge, the first publicly documented Windows implant to apply this model to tactical command and control (C2)" and says "we do not have confirmation of in-the-wild deployment," though binary artifacts tie the developer to carding-forum postings dating to 2025.
Team Cymru maps the relay layer that routes Chinese traffic into US frontier models, and puts a number on it
Team Cymru's Scott Fisher reports “10,867 confirmed transfer stations” across “457 distinct ASNs” — 9,456 running the sub2api software and 1,353 running the older Claude Relay Service, both published by a developer using the name Wei-Shaw — and adds that “since this analysis was conducted, Team Cymru has discovered more than 80,000 relays.” Over an eight-day window in late August, 244 source addresses in China and Hong Kong sent “approximately 14 TB up to the transfer station cluster and received over 7 TB down,” with thirteen addresses from one netblock sending about 9 TB to a single station; traffic from 17 stations to one frontier-model API ran about 81 GB up against 1.4 GB down, a 58:1 ratio the report puts at 16–23 billion input tokens. Team Cymru does not establish how much of the traffic is malicious.
One operator ran three open-source AI harnesses against online retailers at about $25 a company
Gambit Security's Eyal Sela reports a campaign running since July in which a single operator chained three agent harnesses bought through OpenRouter — Strix for vulnerability search (GLM 5.2, later DeepSeek v4 Pro), Cairn for exploitation (DeepSeek v4.1 Flash) and the open-source Hermes agent for orchestration (Anthropic's opus-4.6). “Between 10 and 15 September alone, 105 attack projects were launched and at least 27 companies were compromised to varying degrees,” including at least 600,000 unexpired credit card details from two of them; “skimmers were ordered against at least 27 named victims and confirmed in place on 19 of them.” The operator's own cost review gives “a mean of $25.46 over 101 completed scans,” against about $7,006 of model spend in four weeks. Gambit names no operator and says errors are possible at this stage of the analysis.