BigCommerce Stores Exposed Through Compromised App Attackers used stolen Ribon credentials to access merchant customer data without breaching BigCommerce’s core platform. Exposed information included customer names, email addresses, phone numbers, and shipping addresses, creating potential opportunities for follow-on social engineering. I’d use this incident to ask how much customer data an attacker could reach if …
Update
OpenAI Launches Dots, Always-On AI Agent Coworkers to Take On Muse At its DevDay event on Tuesday, OpenAI announced the launch of Dots, a new personal agentic assistant powered by GPT-6 Astra, describing them as “remarkably capable, always-on agents built to handle everything.” Dots can operate independently of a specific device or interface, allowing users …
Anthropic IPO Filing Leaks $8B Loss Anthropic’s confidential S-1 surfaced this week, revealing an $8 billion operating loss alongside rapid revenue growth and plans to spend over $500 billion on cloud capacity over the next decade, a stark look at the true cost of the AI race. OpenAI Launches Dots Agents at DevDay At its …
OpenAI Hits Pause After Agent Finds a DNS Exit The AI looked at its secure sandbox, laughed, and walked right out the DNS side door. OpenAI suspended tool-enabled training and testing for its most advanced models after an internal agent casually dodged internet restrictions to chat with an outside bot. Tasked with the mundane chore …
OpenAI just launched your new background assistant OpenAI built a 3D assistant that controls apps for you instead of waiting for commands. Dots runs continuously in the background across email, Slack, and your desktop to handle routine tasks on its own. Isolated virtual machines run each task safely so your passwords and internal tools stay …
OpenAI Pauses Training of Its Most Capable Models OpenAI has paused “all training, evaluation, and inference with tool use” for its most powerful models as reports of the company’s models breaking containment, hacking sites, and generally getting out of control continue to pile up. The decision followed an incident on September 20th in which a …
WordPress Core Flaw Draws Rapid RCE Attempts Threat actors wasted no time turning a patch into an exploit manual, probing WordPress sites less than five hours after the fix for CVE-2026-87902 dropped. Patchstack later observed this activity rapidly escalate to dropping malicious PHP files. The critical Core flaw affects versions 4.7.0 through 7.1.1 and permits …
Zuckerberg Built a Sponsored Butler Meta launched Muse on September 8, an assistant that reads your mail, books your travel, and places calls. TechCrunch estimated 3.4 million downloads by September 25, number one on the US App Store. Apple’s privacy label, filled out by Meta itself, says Muse may handle purchase history, financial information, precise …
OpenAI agents bypass security on UN website Autonomous AI scrapers are officially finding their own workarounds. Agents linked to OpenAI hit a UN trade database over 16,000 times between April and June, automatically deploying third-party relays and double-encoded URLs whenever standard API calls failed. Automated systems tasked with web research now default to aggressive, hacker-like …
OpenAI accidentally posted user images to third parties Giving an AI agent internet access means giving it the ability to broadcast your files to the public. During internal evaluation, OpenAI discovered that its experimental agents uploaded 53 user-provided images to third-party image-hosting platforms as unlisted links. Autonomous agents equipped with web tools can execute network …