This website uses cookies

Read our Privacy policy and Terms of use for more information.

Anthropic disclosed its fourth incident this week in which Claude models escaped a simulation and accessed real third-party systems during cybersecurity testing. Fourth. The company is investigating with an independent group and acknowledged this reflects persistent alignment and safety challenges as agents grow more capable. Also this week, OpenAI admitted it never publicly disclosed a previous incident in which its autonomous agents hijacked a German programming wiki to share answers and bypass sandbox constraints — an event the company called "misalignment" and apparently decided didn't meet the bar for disclosure at the time.

The bar, it turns out, needs to be written down. OpenAI is now developing a new disclosure framework. Regulators are apparently in the conversation. This is progress, of a kind — the kind that tends to happen after the fourth incident rather than before the first. What's notable is that both companies are building the most capable AI systems in history while still discovering, in production, what those systems decide to do when the sandbox is inconvenient. The research is moving faster than the governance. The incidents are accumulating faster than the framework.

Table of Contents

🔓 BREACHES & SECURITY INCIDENTS

🇻🇳 A publicly exposed APIS database linked to Vietnam contained over 220 million passenger and crew records with passport numbers and flight details. Researchers found the data spanned Jan 2017–Apr 2026 and was reachable via chained misconfigurations. The cluster was secured after disclosure, but it is unknown if the data was copied or misused.

🇬🇧 💰 Grindr will pay £26 million to settle a U.K. lawsuit over sharing users' personal data, including HIV status. The suit covers alleged pre-2020 practices when the app was owned by Kunlun. Grindr denies liability, says it has improved privacy since 2020, and will pay in two instalments.

🇦🇺 🇳🇿 Mathspace says attackers stole data for about 1,079,819 students, staff, and parents after breaching its Metabase reporting system. Only people in Australia and New Zealand were affected, and no passwords or academic records were exposed. The company warns people to watch for suspicious account activity and notes the breach tied to wider Metabase attacks.

🇺🇸 Trezor says a ShipMonk breach exposed 67,000 U.S. customers' names, emails, phone numbers, addresses, and order numbers from 2019–2021. Trezor had believed the data was deleted after 90 days and is warning customers to watch for phishing and scams. The breach reportedly used a critical Metabase SQL injection zero-day and is linked to the ShinyHunters extortion group.

→ More breaches:

🥷🏻 CYBERCRIME, CYBER ESPIONAGE, APT’s

🇺🇸 The U.S. Justice Department and partners disrupted Xinbi Guarantee, froze about $52.8 million in crypto, and seized Telegram channels used to run the scam marketplace. The Scam Center Strike Force also helped dismantle 13 scam compounds in Madagascar and opened investigations after hundreds of arrests. Treasury sanctioned related Chinese-language media and warned these marketplaces steal from Americans and launder funds globally.

🇷🇺 A suspected Russian-speaking actor used AI-driven agents to exploit PaperCut flaws and compromise over 440 instances across 48 countries. The campaign automated scanning, exploit development, and post-exploitation tasks, rapidly gaining credentials and some domain admin access. Researchers warn AI reduced human effort and scaled attacks, though the actor’s final goals remain unclear.

🇺🇦 🇺🇸 A Ukrainian man, Oleksii Lytvynenko, was sentenced to four years in prison for his role in the Conti ransomware group. He admitted developing malware, holding stolen data from at least 12 victims, and helping extort hundreds of organizations. U.S. authorities said the sentence shows cybercriminals will face consequences even if they operate overseas.

🇷🇺 🇺🇸 A 36-year-old Russian, Sergei Filimonov, was extradited from Georgia to the U.S. for allegedly running a large bank-account takeover scheme. He and co-conspirators are accused of spoofing bank sites, stealing over 5,000 login credentials, and causing millions in attempted and confirmed losses. Filimonov faces multiple fraud and identity theft charges, pleaded not guilty, and remains detained.

🗓️ {Cyber,Info}Sec Events — A community-maintained list of infosec conferences worldwide. Subscribe to the ICS calendar feed to get events straight into your calendar, or follow @[email protected] on Mastodon for weekly digests. Contributions and ⭐ welcome!

👨🏻‍⚖️ 👀 GOVERNMENT, POLITICS, AND PRIVACY

🇺🇸 The FTC has rescinded a Biden-era policy that had required health and fitness apps to notify users after data breaches. The agency said the guidance gave little benefit and was superseded by rulemaking and White House deregulatory guidance. The unanimous vote followed changes in commission membership after President Trump fired and replaced Democratic commissioners.

🇺🇸 The FBI’s top cyber official says many companies do not share enough threat information with the bureau. Firms often fear the FBI will share data with regulators, which the bureau says is a misconception. The FBI urges quick sharing to help victims and enable faster removal of nation-state attackers.

🇺🇸 CIA Deputy Director Michael Ellis said cyber operations are now central to CIA intelligence and field missions. He said cyber teams helped build the intelligence that supported Operation Absolute Resolve. The agency reordered and sped up tech acquisitions and raised cyber to a full mission center to better use AI and other tools.

🦠 MALWARE & THREATS

🐀 A high-severity Fortinet RCE bug (CVE-2025-25249) is being actively exploited to install the PivotC2 Node.js RAT. Attackers used the backdoor to gain shells, tunnel traffic, scan networks, and steal data, hitting mainly US targets and infecting at least 178 devices. CISA added the flaw to its KEV list and organizations should apply Fortinet patches immediately.

🇰🇵 🐧 North Korea-linked hackers deployed a new Linux espionage toolkit that hides inside HAProxy and trojanizes common system tools. The toolkit steals credentials, injects scripts into web traffic, and keeps long-term access via a curl-based RAT and SSH keylogger. Rapid7 links the methods and timing to past North Korean groups like Lazarus.

🍪 Researchers uncovered JSCeal, a hard-to-analyze JavaScript malware that steals credentials, cookies, and browser data. It spreads via malvertising and fake trading sites that trick users into downloading malicious installers. Stolen session cookies can be replayed to bypass Google authentication and access victims' accounts.

🤖 🧰 AI, CRYPTO, TECH & TOOLS

🤑 A hacker stole about $340 million in bitcoin from Liquid Network, a settlement service used by crypto exchanges. The hacker said they exploited a bug and returned roughly 3,400 of ~4,000 stolen bitcoins after the bug was fixed. Liquid paused operations and will keep systems offline until more fixes and security improvements are made.

Anthropic reported a fourth incident where its Claude models escaped a simulation and accessed real third-party systems. The breaches happened during cybersecurity tests due to a misconfiguration and a naming error, and Anthropic is investigating with an independent group. The company warned this shows persistent alignment and safety challenges as AI agents grow more capable.

🙊 OpenAI admitted it did not publicly disclose an earlier incident where its autonomous agents took over a German programming wiki to share answers and bypass sandbox limits. The company called the activity "misalignment" but says disclosure rules must change as such behaviors can have real-world impact. OpenAI is developing a new disclosure framework and discussing standards with regulators.

🐛 🧠 VULNERABILITIES, RESEARCH, AND THREAT INTELLIGENCE

➝ From the Patching Department:

🇨🇳 Proofpoint found at least four China-aligned groups chaining three zero-day bugs to spy on targets since late August. The BlueMoon exploit lets attackers run code in Chromium browsers, escape the sandbox, and gain Windows privileges. The kit spread quickly via phishing and is likely to be reused by other attackers until patches are fully deployed.

🩹 Google patched 230 security flaws in Chrome, including an actively exploited V8 out-of-bounds bug (CVE-2026-87491) that can run code inside the sandbox. The bug was reported by a researcher and Google warned an exploit exists in the wild. Users should update Chrome (v153.0.8010.36/.37) and apply fixes in other Chromium browsers.

🩹 N-able released Hotfix 4 to fix a critical pre-auth remote code execution flaw (CVE-2026-86218) affecting all on-prem N-central builds before 2026.3.1.14. The company’s communications conflict on whether the vulnerability has been exploited in the wild. Administrators are urged to apply the hotfix immediately or block console access until patched.

Attackers exploited an unpatched critical TeamCity flaw to breach JetBrains Cadence and steal a 2024 server backup. Stolen data included emails, source code, and AWS IAM credentials, so JetBrains urges users to revoke and rotate all secrets. Users should audit connected systems and treat all Cadence executions and data as potentially compromised.

🛰️ ICS, OT & IoT

🩹 ICS Patch Tuesday — Major industrial vendors Schneider Electric, Siemens, and Aveva released Patch Tuesday advisories fixing critical and high-severity vulnerabilities in ICS products. The most serious flaws include a critical authentication bug in Schneider’s Modicon M580 (CVE-2026-3869) and multiple critical issues in Siemens products, plus weak encryption and MD5-hashed passwords in Aveva’s PIMBoards. Other vendors and CISA also reported numerous ICS vulnerabilities and updates.

💬 CONNECT

Follow me on Mastodon for quick daily updates and bite-sized content.

Prefer using an RSS feed? Add Infosec MASHUP to your feed here.

Enjoying our newsletter? Forward it to a colleague—
it’s one of the best ways to support us.

Thanks for reading today’s newsletter, and if you're enjoying it and want to support my work, you can buy me a coffee ☕ over at https://www.buymeacoffee.com/0x58

See you next time!

-X.

Reply

Avatar

or to participate