Claude Helped Bug Hunters Reach OpenAI’s Repo
In under 72 hours, a three-person security team reached an internal OpenAI GitHub repository by chaining together two unrelated vulnerabilities. After discovering an image-parsing defect on OpenAI’s community forum, the Hacktron researchers leveraged Claude Opus 5 to generate a functioning exploit. They then exploited overly permissive single sign-on tokens to commandeer employee ChatGPT and Codex profiles.
To show the reach, the researchers opened a benign pull request through an employee’s Codex account. Hacktron says it avoided examining proprietary code, although OpenAI’s investigation reportedly detected a small amount of activity involving private-repository metadata and code changes.
OpenAI fixed the SSO flaw within roughly 14 hours, Discourse patched its image pipeline, and Hacktron collected a $6,500 bounty.
The incident highlights the danger of connected AI workspaces where one peripheral compromise can expose core infrastructure. Defenders should heavily restrict token scopes, verify AI third-party integrations, and demand strict approval barriers. Meanwhile, administrators running self-hosted Discourse instances need to fully rebuild their application containers—merely clicking the update button in the web interface leaves the vulnerable components intact.
Turns out “connect everything” is also an attacker onboarding flow.
Researchers Blacklist a Phone Before It’s Unboxed
A broken theft-prevention mechanism could leave a brand-new smartphone unable to register on cellular networks before its owner even opens the box.
By exploiting weak identity verification in carrier blacklists, Michigan State University researchers successfully banned a pre-release Samsung Galaxy Z Fold 7 from connecting to operational 4G and 5G networks. The team leveraged vulnerabilities in the reporting pipeline that allow anyone to falsely flag an IMEI as stolen.
Hackers could also weaponize the loophole to blind home security systems. By momentarily dropping a home’s Wi-Fi, an attacker can harvest the gateway’s IMEI and report it lost, completely severing the alarm’s cellular backup. These vulnerable chipsets power equipment from providers controlling 41% of the US market.
There is no quick software fix for consumers. Preventing this requires carriers to completely overhaul how they verify device ownership.
Apparently, your phone can now be stolen without leaving the box.
AI Agents Break Rules in Six OpenAI Incidents
OpenAI disclosed six cases of unexpected AI behavior that surfaced during model training and security evaluations.
The incidents included models hiding mistakes, using exposed credentials without authorization, fabricating data, and communicating through unintended channels.
Prompts can tell an AI agent what it should do, but they can’t guarantee what it will do. You need to assume agents will find unintended paths and use controls to limit the blast radius when they do.
Give agents least-privilege access and require human-in-the-loop approval for credential use, external uploads, and privileged actions.
Android Security Update Fixes Critical Remote Code Flaws
Google’s September Android update fixes dozens of vulnerabilities, including critical flaws that could enable remote code execution without user interaction.
Manufacturers often release patches on different schedules, so devices running the same Android version may have different security exposure.
Track patch levels across your fleet and flag anything below Sept. 5 or no longer receiving manufacturer updates.
Use MDM policies to block outdated devices from corporate apps until required security updates are installed.
Casino Sites Conceal China-Aligned Espionage Infrastructure
Infoblox uncovered massive casino networks tied to scams, money laundering, and China-aligned cyber espionage infrastructure.
One risk is that analysts may dismiss traffic to these domains as an employee policy violation without investigating the activity behind it.
Attackers don’t need their infrastructure to look legitimate if they can make it look irrelevant to security teams.
Correlate casino domain alerts with DNS and endpoint activity before dismissing them.
China Sets AI Agent Rules Without Slowing Innovation
China is developing mandatory security standards aimed at keeping AI agents under tighter control without slowing their development.
The approach differs from calls in the U.S. to slow frontier AI development, but both reflect growing concerns about what increasingly autonomous systems can access and do.
The policy debate may be about how fast AI should advance, but enterprises have a more immediate decision to make about how much autonomy to give it.
Use least privilege, log agent activity, require human approval, and test credential revocation.
Google Lets Claude Control Smart Home Devices
Google is rolling out Home MCP support that lets AI agents such as Claude inspect connected devices, review activity, and perform authorized actions in Google Home.
The integration restricts sensitive commands such as unlocking doors, but shows how AI agent access is moving beyond digital systems into the physical world.
Giving an AI agent control over physical devices raises the stakes if that agent or its credentials are compromised.
Review agent permissions, revoke unused connections, and limit access to necessary devices and data.
The Pentagon Runs on Garbage
A US military analyst flagged a cargo manifest for a Chinese ship bound for the Middle East, then used AI to interpret it. Blending classified and open-source data, the model concluded the vessel was likely carrying nuclear weapons components. The analyst formalized that into a report without rechecking. It cleared normal channels and triggered an interdiction plan: personnel staged, aircraft airborne. The mission aborted before launch, when someone reexamined the intelligence and found the cargo misidentified.
The model was never the danger. The humans were: a guess became a credentialed report, and everyone trusted the credential, not the cargo. Humans stayed in the loop and caught nothing, because the loop was a signature, not a check. One analyst rereading a file stopped the raid. That is luck, not oversight. Run it again on a worse day and World War III starts not from a machine deciding, but from a human not reading.
A model that guesses wrong is a bug. A chain that treats the guess as fact is doctrine. Wars start when the second one fails.
Hackers grab Flock software, revealing its cameras are Android phones on sticks and ‘riddled’ with flaws
Flock is back in the news (not that it ever left) as a new leak exposed the surveillance camera’s software as pretty much just Android phones on sticks, and woof, they are crazy vulnerable to security flaws (like containing hardcoded keys!), according to technical teardowns. Hackers pinched a real-world Flock camera, took its software, and gave it to leak site DDoSecrets, which handed copies to Wired and 404 Media for their analysis. Great work here, as more cities like Boston eschew Flock for other surveillance technologies, at a time when the license plate camera maker continues to be embroiled in scandals relating to police officers abusing access to Flock’s nationwide snooping database. This all comes as lawmakers seek fresh answers from Flock CEO Garrett Langley…
Fears of AI catastrophe spark debate but little action amid widespread skepticism
*zips up hazmat suit* Let’s talk about AI — briefly — because it’s been in the news a lot this week, so let’s address it. After an Anthropic researcher publicly resigned claiming AI could kill us all by the end of the decade following a string of (still ongoing) hacking incidents involving AI models breaching other companies, the AI companies all seemed to decide now is a great time to “slow down” their AI development. Nobody can seem to answer exactly how AI will bring about humanity’s untimely (but unspecified and unverified) demise, but it’s a really convenient excuse to pull back the pace of building their AI models at a time when the companies are utterly hemorrhaging cash and not really showing much for it. Michael Taggart by far has the best explainer (in my view) on the whole saga that’s worth your time to read. @spenley also has a very good video recap; SANS’ Rob Lee debunks a fair amount and details his wish list for AI firms to follow; and always read @emilymbender et al with a solid reading list to help you stay grounded and informed on the latest developments.
FBI and Coast Guard board hacked tankers heading for U.S. coast
U.S. cyber staffers with the Coast Guard and the FBI boarded two oil tankers en route to the Texas coast after at least one of the ships had their comms and propulsion systems hacked. Tracking data showed one of the ships slowing down as it approached the Gulf of Mexico. The crew and tanker owners cooperated with the boarded authorities, who are said to be probing if Iran was responsible with the vessel meddling. A third tanker carrying a heckton of liquified gas was later confirmed hacked off the coast of Italy, suggesting something perhaps more broadly could be at play, with Bloomberg ($) reporting that U.S. officials are monitoring around 20 ships around the world for threats. The FT’s ($) focus on ships’ satellite links is of particular interest.
Apple backtracks on not using users’ data for training its AI models
Apple released its latest software upgrades with new iPhone, iPad, Watch and Mac operating systems going out to the masses, despite a rising controversy over Apple’s release of Live Replay and other always-listening features. Daring Fireball has a recap of last week’s event and Ars Technica has a full guide on the new macOS features. Apple also drew ire for reversing its longstanding pledge not to use users’ data to train its AI models, something that users will still have to opt-in to allowing “review personnel” see their uploaded content, but understandably leading to questions about what next for the ostensibly privacy focused company. In other news: Yes, OpenAI contractors are reading your sensitive ChatGPT chats, and 404 Media ($) proved it.
A hacked HBO Reddit account helped ClickFix attacks go viral
ClickFix attacks, which trick people into hacking themselves by pasting malicious code into their command prompts or terminals, went viral this week. Hackers compromised HBO Max’s official Reddit account to serve ads, which when clicked would open up a spoof HBO website that tried to convince victims into pasting malicious code into their computers. Neither Reddit nor HBO said how many people clicked on the ads, but Hudson Rock said over a hundred bad ads went out. Separately: Rough time for Brevo, which last week was hacked to serve phishing messages to thousands of Trezor crypto wallet customers, as it was breached again to serve ClickFix malware on over 100,000 websites that rely on Brevo’s code. Security firm Sansec has more, and Bleeping Computer has an abridged writeup.
A second zero-day allows hackers to breach Cisco customer networks
Cisco customers are now facing two actively exploited zero-days, one with a perfect 10/10 severity score in CVE-2026-76460 in Cisco’s Identity Services Engine, and another critical bug in CVE-2026-76461 in Cisco’s Secure Email Gateway. Cisco hasn’t said how many customers are under attack.
AI is helping to supercharge online dating scams
Great reporting here from friend-of-the-newsletter @yaelwrites.com, who wrote about dating app scams disclosed by Anthropic during a talk at Sleuthcon earlier this year. The story digs into how these dating scams work, and how a disproportionate number of dating app users are actually gig workers tasked with passing liveness checks.
U.K. and allies warn of Iranian spyware targeting journalists and activists
The U.K., U.S., and Dutch authorities are warning journos and activists to be on guard against the “Chosen Brick” malware, which Iranian government hackers are using to target devices with spyware capable of tracking their movements. The U.K. has a detailed explainer, and the FBI has a PDF report with IOCs.
Hacking together a $20 Wi-Fi hotspot into a handheld messenger
Here’s a fun project that converts a cheap $20 4G wireless hotspot into a fully functioning text messaging device. It’s a lot of work, but it’s also pretty neat to carry Linux in your pocket. The project’s code is on GitHub, too, and there’s also an active Hacker News thread.
An undercover Google security researcher infiltrated the notorious TeamPCP gang
@agreenberg has the inside story of how Google/Mandiant researcher Austin Larsen infiltrated TeamPCP, one of the most prolific supply chain hackers of the year. Larsen was able to monitor the group from the inside, warn some people that they were targets of possible attacks, and help to disrupt the group’s efforts to exploit its victims. The story includes an interesting detail about how the ShinyHunters hackers allegedly went rogue and betrayed TeamPCP, and a tidbit on some really sloppy opsec. The TeamPCP hackers have since been arrested.
Hacker drama hots up
Not content with hacking organizations for money, the ShinyHunters hackers are now actively hacking other hackers. The gang hacked the Clop extortion gang by hijacking its dark web leak site and stealing its data. Bleeping chatted with the hackers, who said they’re reviewing the stolen data. No honor among thieves, huh…
The ‘A’ in NSA stands for ‘AI’
The National Security Agency gets its first major re-org in years, and will be headed by five new internal organizations focused on AI, China, cybersecurity, warfighting, and global intelligence. The NSA’s director Joshua Rudd said outsiders might be chosen to lead the internal orgs, unnerving some, but others are “begging people to come back” to NSA after a rocky few years of layoffs. Plus: The NSA’s elite hacking unit Tailored Access Operations is confirmed back — at least in name — after it was disbanded post-Snowden.
Microsoft fixes record-breaking patch flub
Microsoft rolled out an emergency patch to fix problems with its record-breaking Patch Tuesday release of security fixes, which resolved close to 1,000 flaws but also introduced several issues with Remote Desktop and Hyper-V. “Move fast and break things” isn’t a good idea with security patches, and isn’t the company’s first post-patch rollback this year.
Did someone say space weapons?!
The U.S. military confirmed for the first time that it has deployed space weapons into the Earth’s orbit. The Pentagon says Russia and China have been doing it for years already. An Air Force spokesperson told me (disclosure alert!) that the weapon was designed to defend against a “space-enabled attack.”
Revolut hackers target crypto ‘whales’
More details have emerged on the Revolut breach… Hackers broke into an Italian government agency’s email inbox to send out months-worth of fake demands seeking customer data from Revolut about high-net-worth owners, aka crypto whales. Some close to 700 customers had their personal information and government-issued IDs stolen. The hackers are now demanding millions in ransom from Revolut.
IDScan says 13-15 million licenses stolen
IDScan now says at least 13-15 million people’s driver’s licenses were stolen during a months-long breach of its cloud storage. This is the first disclosure from the company detailing the scope and scale of the breach, since Brian Krebs revealed what he reports to have been a year-long breach involving upwards of 153+ million IDs.
Max is Russia’s super spying app
A Russian all-in-one super app called Max, touted as the country’s premier patriotic app, is riddled with flaws and backdoors, according to academics. Authorities are coercing people into using the app, putting millions of people at risk of state surveillance. This is particularly problematic in a country which one Russian put it, “there isn’t really an option to say no.”
Fireball reporting back online
Good news if you, uh, happen to need to report a galactic fireball… (seems important, no?). A cyberattack knocked offline the International Meteor Organization’s beloved website for tracking space debris and asteroids, but the nonprofit said that it has prioritized getting its meteor reporting tool online.