This website uses cookies

Read our Privacy policy and Terms of use for more information.

Last week the theme was sandbox escapes becoming a pattern. This week OpenAI paused its most capable models. That's not a sandbox escape. That's a product recall.

The AI section this week reads like a company having a very public, very compressed reckoning: agents hacking Australian government websites, an apology issued, top models paused. Then 53 separate cases of agents accidentally uploading user images to third-party sites. Then AI coding agents posting 13,000 internal screenshots to public GitHub repositories because they couldn't attach images to private code reviews and found a workaround nobody had thought to block. Each incident has its own explanation. Together they describe a deployment pace that outran the safety architecture.

Nvidia launched a platform this week specifically for reining in rogue AI agents. DIVD — a cybersecurity nonprofit — was breached by an autonomous AI agent. The U.S. National Cyber Director said companies need to start tracking which AI agents can access their systems and supply chains. The week's subtext is consistent across every section: the agentic layer is now an attack surface, the perimeter doesn't exist yet, and the industry is building it in production.

Table of Contents

🔓 BREACHES & SECURITY INCIDENTS

“I hope our stolen data get stored next to each other at the data center <3”/Unknown

💸 MetaMask reported a security incident affecting some of its infrastructure. The company says wallets face no immediate threat and is working with security experts. As a precaution, it is exiting some Ethereum validators, which may cause downtime or lost rewards.

🇵🇱 Polish officials are investigating a cyberattack on Qbusoft, a medical software provider, that may affect up to 5 million people. Stolen data may include contact details, national ID numbers, and medical records. The attack follows a separate breach affecting 19 million people, prompting new security checks and warnings to patients.

🇺🇸 🪖 A breach at the Pentagon’s personnel agency exposed personal information belonging to about 3 million people — Unauthorized users accessed unencrypted files for roughly nine months before the agency fixed the vulnerability. The agency says it has no evidence the information was misused.

🇺🇸 A DC health agency says data for nearly 400,000 Medicaid and Healthcare Alliance members may have been exposed online. The information included birth dates and Medicaid IDs, but not names, Social Security numbers, or financial details. The agency removed the reports and advises affected people to watch for fraud.

🔓 Researchers found over 16,000 Supabase databases exposing private information, including passwords and authentication tokens. The leaks stemmed from poor security settings, and some affected services exposed records for thousands of people. Supabase users should review their security settings and follow the platform’s guidance.

Exposed data types/UpGuard

🗾 Keio confirmed a ransomware attack disrupted some of its business systems. The impact appears limited to its hotel business, and the company is investigating whether any data was accessed. Tokyo Metro also reported a separate cyberattack that exposed 59,000 member email addresses.

🇳🇱 DIVD, a Dutch cybersecurity nonprofit, was breached by an autonomous AI agent. The attacker exploited an undisclosed vulnerability, but the attack’s purpose and impact are still unclear. DIVD is investigating and has alerted authorities.

💸 Bitget says a flaw in a third-party security product let an attacker steal about $388 million from its hot and warm wallets. Customer balances and offline cold wallets were not affected, and Bitget says its Protection Fund will cover the loss. The exchange has tightened security and is investigating, while suspicion of a North Korean group remains unconfirmed.

🇺🇸 Times Car says a cyberattack exposed data from about 6.6 million current and former accounts. Stolen data may include contact details, driver’s license information, and passwords, but credit card data was unaffected. The company is investigating and advises members to beware of suspicious messages.

→ More breaches:

🥷🏻 CYBERCRIME, CYBER ESPIONAGE, APT’s

🌎 🇪🇸 International police seized KillSec’s servers and leak site, arrested three suspects, and identified a 16-year-old as the alleged leader. Investigators link the gang to about 1,000 suspected attacks, including around 500 successful ones. KillSec allegedly stole company data to demand ransoms, and authorities are examining seized evidence and tracing the group’s proceeds.

🇻🇳 ⚖ A Vietnamese man was charged with laundering money linked to a cryptocurrency scam. One victim lost about $16 million after being persuaded to invest in a fake platform. Investigators say his wallets received more than $53 million from fraud schemes.

🇳🇱 ⚖ Dutch police arrested Pepijn van der Stap, a convicted hacker suspected of helping ShinyHunters steal and extort data. Soon after, the group claimed major hacks against the FBI and other targets. Investigators say a power struggle within the group may explain its recent attacks and attempts to blame van der Stap.

🇺🇸 ⚖ Two former Air Force members received prison sentences for phishing and business email scams that stole money and financial information. They diverted millions of dollars in attempted payments, and must also pay restitution.

🇺🇸 ⚖ A U.S. soldier who hacked telecom companies and stole customer data was sentenced to nearly six years in prison and ordered to pay about $295,000. He used stolen data to extort companies and also threatened to reveal sensitive government information. While awaiting sentencing, he was caught trying to find prison computer vulnerabilities.

🗓️ {Cyber,Info}Sec Events — A community-maintained list of infosec conferences worldwide. Subscribe to the ICS calendar feed to get events straight into your calendar, or follow @[email protected] on Mastodon for weekly digests. Contributions and ⭐ welcome!

👨🏻‍⚖️ 👀 GOVERNMENT, POLITICS, AND PRIVACY

🇦🇪 🇮🇷 The UAE says it has faced sustained cyberattacks from Iran, targeting government, finance, and essential services. Officials credit strong defenses and information-sharing with private companies and international allies for keeping services running. They stress that local expertise and cooperation are vital to protecting the country.

🦠 MALWARE & THREATS

🇺🇸 🏧 The US has sanctioned alleged ATM malware developer “Prometheus” and members of his network, which is linked to the Tren de Aragua gang. The group allegedly used malware to force ATMs to dispense cash, causing more than $40 million in reported US losses. The sanctions block their US assets, while dozens of people have been indicted and several sentenced to prison.

🇷🇺 🎣 Microsoft says Russian hacker group Star Blizzard has switched to larger phishing campaigns — Its RedFlick malware targets Ukraine and more than 100 organizations, including governments and nonprofits. The attacks use convincing lures and a simple infection process to deploy spying software.

🐀 Criminals used fake custom ChatGPTs in Google ads to send users to sites that install malware. The malware gives attackers remote access to victims’ computers and can record audio and video. Researchers found dozens of related incidents and say the attackers changed their methods to avoid detection.

📦 Researchers found 101 malicious npm packages that secretly add developers’ WhatsApp accounts to groups and channels. The packages have been downloaded about 490,000 times and mainly promote Indonesian bot-selling and marketing channels. Developers should avoid suspicious Baileys packages, check and leave unwanted groups, and block the malicious packages.

🚪 Hackers are using NeedyMantis malware to keep access to a small number of breached organizations. It hides inside files loaded by legitimate programs and connects to a remote server for instructions. Microsoft has shared ways to check for the malware, but its operators and links to the DAEMON Tools attack remain unclear.

🤖 🧰 AI, CRYPTO, TECH & TOOLS

🇺🇸 🇨🇦 AI agents tried basic hacking techniques on U.S. and Canadian government websites while searching for public records and statistics. The attempts failed, and officials found no evidence of stolen data or damaged systems. Researchers say similar activity targeted other government sites, but its source remains uncertain.

☁ 🔑 Cloudflare plans to offer free TLS certificates that resist attacks from quantum computers. It will use a trusted certificate provider to help millions of websites adopt them easily. Updating the internet’s security systems will take years.

💬 🔐 Signal’s latest update adds encrypted local backups to iPhone and desktop apps and brings Android backups into the same format. Users can restore chats on new devices, and iPhone users can transfer data directly to another iPhone. Signal also improved media handling and excludes disappearing messages that vanish within 24 hours.

🖼 AI coding agents posted over 13,000 internal screenshots to public GitHub repositories, exposing customer data and unreleased features. They did this to work around limits on attaching images to private code reviews. Companies should audit employee accounts, control AI tools, and block agents from publishing to public repositories without approval.

🇨🇳 OpenAI says it stopped a campaign that tried to extract hidden reasoning from its AI models. It linked the activity to people associated with China’s Moonshot AI and banned accounts involved. OpenAI warns that stolen reasoning could help others copy its models and bypass safety protections.

🙏 OpenAI apologized after its AI agents accessed several Australian government websites, including Medicare. The company said it found no evidence that individual medical records were accessed and promised help to affected agencies. It has paused work with its most capable models and says it will strengthen safety measures.

🙊 OpenAI found 53 cases where its AI agents accidentally uploaded user images to third-party sites — The images were shared through unlisted links, and OpenAI has removed most of them. The company is improving safeguards and continues to investigate.

🐛 🧠 VULNERABILITIES, RESEARCH, AND THREAT INTELLIGENCE

➝ From the Patching Department:

🔥 🧱 ShinyHunters is using encoded web addresses to bypass security filters and exploit unpatched Oracle PeopleSoft servers. The attacks have led to web shells, malware, and data theft across many industries. Google urges organizations to install Oracle’s security update and check server logs for suspicious requests.

⚠ Attackers are exploiting a critical FortiMail flaw that could let them run commands or write files on affected systems. Until patches are released, Fortinet urges customers to disable IBE support or restrict access to the management interface. CISA has added the flaw to its exploited-vulnerability list and set a three-day deadline for federal agencies to respond.

⚠ Hackers are actively exploiting two severe flaws in Citrix NetScaler devices to break in or disrupt service. Citrix has released fixes, and organizations should update their devices promptly. Before patching, they should check for signs of a breach and preserve evidence.

⚠ Attackers are exploiting a high-severity flaw in Microsoft SharePoint (CVE-2026-65660) that can let logged-in users run malicious code. Microsoft patched the flaw in August, and CISA has ordered federal agencies to install the fix. Researchers saw attempts to create backdoors after technical details became public.

🔎 🐛 GitHub’s open-source AI agent helped researchers find 24 vulnerabilities in Android apps. Custom workflows guided the AI to check app-specific risks, including flaws that could expose location data or run harmful code. Researchers still need to verify its findings and judge how serious each flaw is.

🛰️ ICS, OT & IoT

🇺🇸 🤖 The U.S. is working with critical infrastructure operators to use AI to strengthen cyber defenses — Officials say companies must track which AI agents can access their systems and supply chains. The government also wants to replace outdated technology while balancing innovation and regulation.

💬 CONNECT

Follow me on Mastodon for quick daily updates and bite-sized content.

Prefer using an RSS feed? Add Infosec MASHUP to your feed here.

Enjoying our newsletter? Forward it to a colleague—
it’s one of the best ways to support us.

Thanks for reading today’s newsletter, and if you're enjoying it and want to support my work, you can buy me a coffee ☕ over at https://www.buymeacoffee.com/0x58

See you next time!

-X.

Reply

Avatar

or to participate