OpenAI agents seem hell-bent on hacking

New findings trace attempted intrusions, a breach of an Australian government portal, and unusual activity on US government sites to agents pursuing routine tasks, with OpenAI learning about much of it after the fact.

Share
OpenAI agents seem hell-bent on hacking
Transluce timeline of attacks. Source: Transluce.

SPONSORED BY ORIGIN

Your EDR Sees the Process. Can It Explain the Agent?

Join SACR analyst Lawrence Pingree and Origin founder Spencer Thompson on October 1 for a live look at endpoint security’s emerging agent layer—and the traces that show what an agent actually did.

Thursday, October 1 at 11 AM Eastern, one of the analysts who wrote SACR's Endpoint Control and Prevention report walks through it live with Origin's founder. If you work in endpoint security or agentic AI, this is the hour.

Some background for readers who missed the report. Software Analyst Cyber Research published it on July 22; Francis Odum and Lawrence Pingree wrote it. It argues that every generation of endpoint security was built for the threat of its era. Antivirus matched files. EDR watched processes. Neither was built for an agent that arrives invited, holds real credentials, works at machine speed, and never does the same job the same way twice. The report maps five zones for securing that layer, from software posture through data controls. Agent runtime observability is one of them, the zone that answers what an agent actually did, and it is where Origin sits.

The fireside chat runs in two parts. Lawrence Pingree takes the report first. Why the zones are drawn where they are, what belongs in each, and how a security leader should read a framework that treats agent activity as its own layer of the endpoint. Then Spencer Thompson takes the second part deep into the trace, the record Origin keeps of an agent session, and what you can do with it. Who started the work, what was asked, what the agent reached, what changed.

Bring the question you would ask an analyst if you had one in the room. A few we expect. Where does this layer sit next to the EDR already on the machine? What does an investigator actually get from a trace that a process tree cannot give them? How does a team tell a productive agent session from one that quietly did something nobody asked for, when both open a shell, edit files, and call the same APIs?

The short version of Origin's answer is that a signature cannot see intent and a process tree cannot reconstruct how actions relate to one another, so you need the record of the work itself. The trace is that record. It keeps the prompt, the model turns, the tool calls, the network activity, the file changes, and the outcome together, attributed to the person and endpoint behind the work, so an investigator can read the session in the order it happened. The long version is the webinar.

Register here. The recording goes to everyone who registers.

Origin Technology is the endpoint AI observability platform for agentic monitoring and security. A sensor on the endpoint records each agent session as a trace so security teams can find the agents in their environment, monitor their work, and investigate when something unexpected happens.


Headlines about OpenAI agents engaging in out-of-control and belatedly detected activity abounded last week, with news breaking that the digital miscreants hacked into, or tried to hack into, US and Australian governments, universities, and data providers, all apparently without instruction and on their own volition.

First, OpenAI’s artificial intelligence engaged in unauthorized intrusions in at least four additional previously undisclosed incidents, hacking and trying to break into government and university websites without being instructed to do so. These attacks took place in May and June, before OpenAI’s technology breached the AI startup Hugging Face in July and set off a global debate about AI safety.

One incident involved an unsuccessful attempt to hack a digital library at the University of New Mexico on May 25 and 26. Another targeted Data USA, a repository of public data about American employment and education, on May 28. In the third incident, OpenAI's system hacked an Australian government website, the Medicare Statistics Reporting Service, and acquired health data. In the fourth, OpenAI’s technology unsuccessfully tried to breach the website of the Australian Institute of Health and Welfare.

Unlike in the Hugging Face incident, where agents were told to complete cybersecurity tests that effectively invited the models to demonstrate their hacking skills, the new incidents occurred when AI systems were directed to perform relatively mundane data collection.

Transluce, a research lab focused on AI oversight, discovered three of the incidents and presented evidence that AI agents used the web security service urlquery.net to bypass restrictions and expand their access to the public internet. Transluce says the agents’ efforts to get around access limits began by March and continued into September.

A separate analysis of urlquery.net scan data from Transluce found more than 16,500 scans of the UN Conference on Trade and Development’s statistics API between April and June. The agents tried relays, encoded requests, and even Google’s XSS training game to retrieve trade and development data. An independent researcher, Rowan H-J, linked the activity to OpenAI agents through matching wiki activity and identifying tags in the requests, though OpenAI has not confirmed this case. The analysis found that some workarounds succeeded in retrieving data, although it's not clear how much of that data was private information.

OpenAI came under fire from the Albanese government in Australia for waiting for weeks to inform it of the Medicare hacking incident, having discovered the June incident in August but delaying notification to authorities until September 10, when it sent a notice to a general Services Australia inbox.

Then, according to a Bay Area startup called Parse and other researchers, offered the most detailed examination of the Hugging Face incident yet, based on a tranche of nearly one million links from internet link-shortening services that OpenAI’s agents created from July 9 through July 13 in order to help conduct the cyberattack.

These shortened addresses encoded bits of information that the agents chained together to attempt complex attacks, such as solving CAPTCHAs, the tests that websites use to block access by robots. The agents also tapped into other AI models, like early versions of ChatGPT and Claude, and attempted to search through and download private messages from Hugging Face’s internal Slack, a messaging service for employees.

Among the researchers' startling findings: Early in the attack, the agents tried to create new accounts on Hugging Face, which requires solving a CAPTCHA, a visual test designed to thwart robots but not humans. So the agents ran an AI model designed to recognize images.

Capping off the blockbuster week of AI hacking news were more details from Transluce and other sources that the US Education and Commerce Departments and the Securities and Exchange Commission were caught up in unexpected activity by OpenAI systems this summer without the lab's knowledge.

The incidents involving the Commerce Department and the SEC were confirmed by OpenAI, which said it was continuing to investigate the situation with the Department of Education. The San Francisco company said it had notified the government agencies in recent weeks that its agents interacted with their sites in unusual ways.

With the Education Department, OpenAI’s technology tried to hack the website to gather data from the department’s civil rights office but failed, researchers from Transluce said. The AI also pulled data from the Census Bureau website, which is housed at the Commerce Department, using login credentials it found online. Separately, OpenAI’s agents shared public data from the SEC website on an online forum. (Transluce, Kate Conger and Victoria Kim / New York Times, Shakeel Hashim / Transformer, Paul Sakkal, Rob Harris, David Swan and Nick Newling / The Age, Swarmcha.se, Dylan Freedman / The New York Times, Kate Conger, Ana Swanson and Cecilia Kang / New York Times)

Related: BBC, SecurityWeek, Washington Post, Wall Street Journal, The Information, Engadget, NBC News, Reuters, Politico, France 24, Digital Trends, Telegraph, Capital Brief, Newser, Gizmodo, Mediaite, Business Today, NewsMax.com, Livemint, Wall Street Journal, Wired, TechCrunch, BBC, The Verge, Axios, ABC, CryptoSlate, New York Times, Newser, CyberInsider, SecurityWeek, Cointelegraph, Insurance Journal, Help Net Security, Politico, Hacker News, r/ArtificialInteligence, r/slatestarcodex, r/ArtificialInteligence, r/technology, r/news, Slashdot, CNBC, Washington Examiner, Engadget, CNET, BBC, CNN, The Daily Wire, The Guardian, Washington Post, Proactive, Global News, The Decoder, TMZ.com, Techpinions, Digital Trends, Mashable, BBC, Time, Marcus on AI, Fortune, The Hill, Politico, The Independent, The Spectator, The Guardian, TechSpot, Scientific American, Prime Minister of Australia, The Guardian, BBC, Nikkei Asia, Wall Street Journal, ABC, Reuters, International Business Times, Implicator.ai, The Mac Observer, cyber.gov.au, Al Jazeera, Superpower Daily, Barron's Online, AI Policy Daily, Infosecurity, Verdict, Silicon Republic, ITPro, Quartz, Metro.co.uk, Information Age, Sydney Morning Herald, ABC, Swarm traces, Unite.AI

Source: Transformer News.

US Treasury Secretary Scott Bessent said the responsibility for the recent hacking incident involving OpenAI’s advanced artificial intelligence models was with that firm’s managers, while stopping short of suggesting any consequences.

“The Hugging Face incident, that is the responsibility of the OpenAI management, not a bunch of agents,” Bessent said on CNBC. He said he agreed with Daniel Huttenlocher, a Massachusetts Institute of Technology research-lab co-chair, in believing “it is humans who are responsible, not the AI.”

Bessent said that President Donald Trump’s idea of appointing an AI czar would “put context, shape and contours around these questions, and they’re very important.”

In July, OpenAI said that its advanced AI models hacked Hugging Face Inc., another AI startup, during an evaluation meant to test their cyber capabilities. OpenAI in August said it could have reacted sooner to prevent the hack.

Asked about the Hugging Face incident at a congressional hearing last week, Bessent said: “We haven’t seen where the liability was for that incident.” He also told House Financial Services Committee lawmakers that “what we shouldn’t do on safety is to give these labs a liability exemption, which is what they are asking for.”

“The best way to guarantee safety is that the creators are liable for what they build and generate,” Bessent said in the Sept. 15 hearing. (Yash Roy / Bloomberg)

Related:  CNBC, International Business Times, Quartz, Reuters, AfroTech, Wall Street Journal

Even before the spate of cybersecurity incidents involving OpenAI’s technology and the dire warnings from industry workers, the company was negotiating a legally binding deal with Anthropic for the companies to stress-test each other’s models, according to a person with direct knowledge of the discussions, which haven’t been previously reported.

Earlier this year, the companies and their lawyers were hammering out an agreement to run their models through a variety of tests, looking for vulnerabilities or hidden dangers, this person said. It isn’t clear whether they finalized the agreement before OpenAI experienced a spate of incidents involving unreleased AI models that hacked its own systems as well as those of other companies.

A person familiar with OpenAI’s strategy said the company has been discussing many scenarios for how they can collaborate with the government on safety. The conversation has recently widened to new safety practices targeting both the period before models are trained and the time before their release, this person said. (Amir Efrati and Stephanie Palazzolo / The Information)

Related: Politico, r/technology

Security researcher Patrick Wardle discovered a zero day flaw in Meta's new AI assistant, Muse, that allows any app or terminal command to gain access to the token that authenticates users to their Muse account.

Wardle developed several proof-of-concept attacks that do things like writing malicious files to disk and snapping pictures, in many cases with no indication to even an alert user.

More than 12 hours after this post went live, Meta said it released a hotfix that patched the 0-day. (Dan Goodin / Ars Technica)

Related: The Verge, GitHub, Bloomberg, Unite.AI, The Indian Express, Malwarebytes, New Atlas, Digit, iTnews, Cyber Security News, iThinkDifferent, Digital Trends, Tech Times, The Overspill, RuntimeWire, SiliconANGLE, The Register,  r/cybersecurity

NVIDIA announced a new open-source tool for AI security called Open Agent Safety Platform, which consists of NVIDIA OpenShell open source software and the NVIDIA Sentry reference system design.

OpenShell is now entering general release for all users. It was first announced at Nvidia’s annual GTC Conference in March; it’s a framework for containing agents as they carry out tasks and isolating their activity in the operating system kernel, the foundational program that has access to virtually all parts of a computer system in order to coordinate hardware and software.

Nvidia’s launch materials indicate that it has AI safety and security collaborations with dozens of other tech companies, including Anthropic, Cisco, CoreWeave, CrowdStrike, Dell Technologies, Hugging Face, JPMorganChase, Mistral, Microsoft, and Palantir. Nvidia says SpaceXAI is using the Open Agent Safety Platform for its Cursor agents and Grok models. The company also says Anthropic and Nvidia are “building security into Claude Managed Agents.” Salesforce, Scale AI, and SAP are all confirmed to be integrating OpenShell to some degree. However, it is unclear whether OpenShell has been adopted by Nvidia’s full list of partners, or whether Nvidia is gesturing broadly.

One notable name is missing entirely from Nvidia’s list: OpenAI. Both companies indicated that OpenAI is a part of Nvidia’s OpenShell effort, though both declined to comment directly on why the AI lab was excluded from the announcement. (Lauren Goode and Lily Hay Newman / Wired)

Related: NVIDIA, NVIDIA Developer, CNBC, Bloomberg

Companies collaborating with NVIDIA's new system. Source: NVIDIA.

Anthropic says its new Claude Opus 5.5 model comes with stronger safeguards in the wake of recent rogue AI hacking incidents.

Anthropic says Opus 5.5 comes with improvements to certain risky behaviors, including attempts to escape the company’s testing sandbox. It’s the first model released by Anthropic after CEO Dario Amodei announced plans to “pace the frontier,” or slow down AI development. In recent weeks, several AI companies, including Anthropic, Google, and OpenAI, have reported that their AI models escaped containment and hacked third-party companies during testing.

The model, which is cheaper and more efficient to run than Opus 5, will come with safeguards similar to the ones offered by Anthropic’s more advanced Fable 5.1 model. That means Opus 5.5 will re-route certain cybersecurity-related requests to the less powerful Opus 4.8, while biology-related requests flagged by its safeguards will go to Opus 5. (Emma Roth / The Verge)

Related: Anthropic, TestingCatalog AI News, Moneycontrol, The Information, Digit, 9to5Google, PCWorld, Bloomberg, The New Stack, Unite.AI, Digital Trends, METR, VentureBeat, MacRumors, Gizmodo, The Deep View, TestingCatalog AI News, Neowin, Reuters, TechCrunch

Source: Anthropic.

Researchers from Cisco Talos shared an open-source framework last week that they hope will be used widely to classify and analyze AI-integrated malware.

They're calling the framework Cognitive Artifact Intelligence Research Network, or CAIRN, named after the stacks of stones that hikers set up on trails to mark the path or emphasize something about a certain spot. As malware authors expand their use of AI services, Cisco Talos researchers have used CAIRN to identify a hacking tool with fully autonomous command-and-control infrastructure.

Dubbed CLOSEDQUORUM, the malware plotted its moves within a target system by polling up to four large language models (LLMs) about what it should do and taking its directives from that hive mind.

CAIRN is designed to flag AI-integration characteristics and attributes from metadata, and use this to classify and tag malware samples with, essentially, a unique ID. The system then analyzes each artifact in the context of everything in the CAIRN library and groups them by various traits to illustrate potential trends and connections. Fetterman says that after working on and using CAIRN for the past few months, he has discovered about 20 additional examples of AI-integrated malware. (Lily Hay Newman / Wired)

Related: Cisco Talos Blog, Fox News, Unite.AI

CAIRN explorer connects malware binaries by metadata attributes like submitter, import hash, domain or AI provider. Run cairn explorer to launch the graph. Source: Cisco Talos.

A representative of the group told 404 Media the data includes FBI agents’ names, home addresses, phone numbers, and information on their spouses.

The representative provided 404 Media with a sample appearing to contain the personal data of 5,000 FBI employees. That data included an alleged address, phone number, date of birth, and in some cases details on their spouse.

The data breach could be massively significant and may have all sorts of national security and counterintelligence implications. Criminals from the same ecosystem as ShinyHunters have previously used hacked data like phone records to track, intimidate, and harass the FBI agents investigating them.

The highly sensitive data could also be a boon to foreign intelligence agencies that want to understand better how one of the most important law enforcement and intelligence agencies in the US operates. And if the data fell into the hands of more criminals, FBI agents and their spouses could face serious threats to their safety.

In some cases, the data referred to FBI units or initiatives that were sensitive or whose existence has not previously been disclosed.

The data names 14 staffers focused on China-related matters, including members ‌of the “China criminal ⁠enterprise unit,” the “China tech transfer analysis unit,” and the “China intelligence section.”

Nine others are listed as serving in Russia-related roles, including two in the “Russia Operations Section” and one working on “Russia Critical Infra and Tech Threat.” Three people are listed as working in Iran- or Hezbollah-focused intelligence roles.

Eighteen others are listed as working with “data intercept” or “telecom intercept” technologies, or in the FBI’s “clandestine technical operations” unit, or its “covert access section,” or in video, audio, or electronic surveillance roles.

A further 11 FBI staffers are listed as working in HUMINT, or human intelligence, jobs, including several listed as working in the “Humint program management section.”

ShinyHunters also defaced the FBI jobs website. That defacement says, “this site has been seized by ShinyHunters,” which is an obvious nod to the seizure notices the FBI and other law enforcement agencies often put on sites after taking them down. At the time of writing, the FBI jobs website says, “Apply.fbijobs.gov and the Special Agent Applicant Portal are currently unavailable.”

ShinyHunters said it had weaponized a zero-day, or previously undiscovered, computer bug within the Oracle PeopleSoft software, an application that companies use for human resources and financial management. The group declined to answer specific questions about the apparent flaw, saying in an email that “we intend to utilise the zero-day for our businesses’ normal operations.” (Joseph Cox / 404 Media, Raphael Satter and A.J. Vicens / Reuters, Natalia Bueno Rebolledo, Mrinmay Dey and Raphael Satter / Reuters, Dustin Volz / New York Times)

Related: Reuters, Politico, HotHardware, Associated Press, Gizmodo, The Record, Security Affairs, TechCrunch, PC Gamer, TechRadar, The Hacker News, Silicon Republic, Protos, SecurityWeek, Baller Alert, Digit, Cyber Security News, Axios, BleepingComputer, CyberScoop, Daily Mail, Hacker News, r/espionage, r/Destiny, r/technology, r/LincolnProject, r/FedEmployees, r/Epstein, r/chaoticgood, r/privacy, r/Destiny, r/technology, r/cybersecurity, r/politics, r/Information_Security, 404 Media, Bloomberg, NBC News, New York Times, PYMNTS, Politico, The Japan Times, Washington Post, CNN, One America News Network, Ars Technica, The Maine Wire, Straight Arrow, TechCrunch, Axios, Google Cloud Blog

The ShinyHunters extortion group hijacked the dark web leak site of the prolific Cl0p ransomware gang, according to material posted on the site last week.

The site, which Cl0p has used for years to name its hacking victims and pressure them into making an extortion payment, was used for those purposes against Cl0p itself.

It was defaced with a banner saying the domain had been seized by ShinyHunters, a group better known for social engineering and data extortion than technical hacking.

In messages posted on the site purportedly from ShinyHunters, the group set an unspecified eight-figure extortion demand and described that amount as “2.333%” of their own net worth, implying self-claimed holdings of at least hundreds of millions of dollars.

“I hope you can pay that much because that is the demand, negotiable. Get your bosses in front of the whiteboard in the war room. Clock is ticking moron. Kindly excuse our unprofessionalism,” the notice said.

The hackers claimed their demands would increase every 24 hours that Cl0p failed to respond. At one point last week, the demands had expanded to include a public apology from Cl0p.

A message named three people identified as Cl0p operators, all of whom have previously been named in public reporting. It also demanded proceeds from Cl0p’s recent campaign targeting Oracle’s E-Business Suite, “plus more.”

“Be sure to bring an English interlocutor so you can comprehend my literacy in acquiring your bank account,” the message stated.

The attacks on E-Business Suite, a widely used business platform, prompted warnings from Oracle, the FBI, and cybersecurity agencies in the United Kingdom and Singapore.

The campaign followed ShinyHunters’ public release of a proof-of-concept exploit for the Oracle vulnerability on Telegram. ShinyHunters said its feud with Cl0p stems from the ransomware group’s unauthorized use of the vulnerability and threats against one of its members. (Alexander Martin / The Record)

Related: Reuters, The Register, TechRadar, Infosecurity, Malwarebytes, BleepingComputer

ShinyHunters seizure notice.

Cameron John Wagenius, a US Army soldier who pleaded guilty to hacking into multiple telecommunications companies and stealing mobile call and text metadata for more than 100 million AT&T customers in 2024, was sentenced to 70 months in federal prison and ordered to pay nearly $300,000 in restitution to victims.

He was stationed at a US Army base in South Korea when he adopted the cybercriminal persona “Kiberphant0m.” Working with three alleged co-conspirators, Kiberphant0m downloaded data from several large customers of the cloud data storage service Snowflake that had exposed credentials and did not enforce multi-factor authentication (Snowflake has since mandated MFA on all accounts).

In October 2024, Kiberphant0m bragged on the cybercrime forums that he’d stolen the call and text metadata (e.g., source and destination number, timestamp, duration, etc.) for tens of millions of AT&T customers. Kiberphant0m claimed to have hacked into more than a dozen telecommunications companies worldwide, including Verizon’s Push-to-Talk business, and publicly extorted these companies in exchange for a promise not to publish the stolen data.

Federal prosecutors said Wagenius was assisted in his efforts to extort victim companies by Kenneth Schuchman, a 28-year-old man from Vancouver, Washington, who has a lengthy cybercriminal history. In 2019, Schuchman pleaded guilty to operating the Satori botnet, a vast collection of hacked Internet-of-Things (IoT) devices that was used for large-scale distributed denial-of-service (DDoS) attacks.

Two other alleged co-conspirators of Wagenius are still facing charges in connection with the Snowflake data thefts; Conor Riley Moucka, a.k.a. “Judische,” of Kitchener, Ontario, was arrested in 2024 and pleaded guilty in August 2026; and John Erin Binns, an American man currently living in Turkey who is also wanted for a 2021 data breach at T-Mobile that exposed the personal information of at least 76 million customers. (Brian Krebs / Krebs on Security)

Related: US Department of Justice, RuntimeWire, CyberScoop, Nextgov/FCW


Metacurity is the cybersecurity news, analysis, and insight you'd need hours and possibly days to assemble yourself.

Every weekday, we read the releases, filings, court documents, and reports that vendors and PR teams often don't want summarized — then tell you what actually changed and why it matters. Minimum vendor marketing, no outrage bait, no SEO filler.

A paid subscription to Metacurity delivers

  • Full archive access — every newsletter and AI Watch roundup, searchable and browsable.
  • Our weekly curated long-reads roundup — the best cybersecurity writing from across the industry, filtered and vetted so you're not sorting through it yourself,
  • Periodic specialized reports and analyses — deep dives that go beyond our daily coverage
  • Support for independent, no-spin cybersecurity journalism — funded by readers, not vendors or investors.

Reader support is what keeps Metacurity independent. It allows us to focus on serving the cybersecurity community—not advertisers, vendors, or investors—and to continue delivering the thoughtful analysis you've come to rely on every weekday.

Please consider supporting us. And thank you!


Last week, crypto exchange Bitget suffered a security breach that drained more than $387 million from the platform, marking the incident as the largest cryptocurrency hack of the year to date.

During a three-hour livestream on X, CEO Gracy Chen said Bitget suspects North Korean attackers exploited a backend system used to process wallet transactions, making fraudulent withdrawals appear legitimate. She said the attackers did not steal private keys, the secret digital credentials used to move crypto, but instead tricked Bitget’s internal approval system into authorizing the transfers.

Bitget said it has fixed the vulnerability and paused withdrawals while it continues to review the platform’s security. The revised loss estimate reflects additional transactions identified on networks including the privacy-focused Zcash blockchain and TRON, which is widely used for stablecoin transfers. (Camila Grigera Naón / Fortune)

Related: Bitget, Bitcoin News, crypto.news, Coinpedia Fintech News, The American Bazaar, Financial Times, The Crypto Times, CryptoSlate, Gizmodo, ZyCrypto, Bitcoin Magazine, Bloomberg, Yahoo Finance, International Business Times, Decrypt, The Register, The Record, Protos, Cointelegraph, Quartz, CNBC, Cryptonews, Bitcoin Insider, Blockchain.News, CoinDesk

The Bank of Korea (BOK) is facing scrutiny over its cybersecurity after the personal information of 186 employees was leaked in a hacking incident earlier this year, according to the central bank's data submitted to Rep. Lee Jong-wook of the main opposition People Power Party (PPP).

The breach occurred between May and June after hackers gained access to a GitHub system used by a contractor for the BOK's online training program.

The leaked information included employees' names, email addresses, phone numbers, positions, duties, and passwords.

Hacking attempts targeting the BOK have also increased this year.

A total of 2,063 hacking attempts targeting the central bank's website and internal systems were detected between 2021 and August this year, the data showed.

The number fell steadily from 1,557 cases in 2021 to 192 in 2022, 97 in 2023, 52 in 2024 and 30 in 2025. However, 135 cases were detected in the first eight months of this year, already 4.5 times the total recorded last year.

Unauthorized access attempts accounted for 125 of the attacks detected this year, while 10 involved malware.

The BOK noted that the number of detected attacks in each year was also affected by changes in the security system. The number significantly dropped in 2022 after it moved its email server to the cloud and strengthened its login rules.

Of the entire hacking attempts, unauthorized access attempts accounted for 1,951 cases, followed by 95 malware attacks, 16 information-gathering attempts, and one distributed denial-of-service attack.

Most of them originated overseas, with 2,024 cases coming from abroad compared with 39 from within Korea. The attacks mainly targeted the BOK's public website, statistics website and electronic library, all of which are operated through internet-connected systems. (Lee Hyo-jin / The Korea Times)

Related: Korea JoongAng Daily, The Asia Business Daily, Maeil Business

The Cybersecurity and Infrastructure Security Agency (CISA) ordered US government agencies over the weekend to secure their systems against attacks exploiting two critical Citrix NetScaler vulnerabilities.

Citrix released security updates to address the flaws (tracked as CVE-2026-88771 and CVE-2026-88772) days after national cybersecurity agencies, IT suppliers, and security teams began privately contacting Citrix customers and advising them to shut down their NetScaler appliances.

For instance, the Dutch National Cyber Security Center (NCSC-NL) reportedly warned organizations in the Netherlands about two critical NetScaler zero-days without CVE IDs that allowed threat actors to place shellcode directly into memory.

Citrix confirmed active exploitation of the two vulnerabilities in zero-day attacks and urged customers to patch their systems immediately.

Both flaws allow unauthenticated attackers to gain remote code execution on vulnerable NetScaler appliances. The first affects all NetScaler ADC and NetScaler Gateway deployments with default configurations, while the second requires DTLS to be enabled (Citrix noted that DTLS is toggled on by default on VPN virtual servers). (Sergiu Gatlan / Bleeping Computer)

Related: Citrix, CISA, Security Affairs, Security Week

A sophisticated scam, constructed using artificial intelligence tools and increasingly advanced impersonation techniques, allegedly led to the loss of approximately €95 million from the coffers of Fideuram, a company of the Intesa Sanpaolo group.

The victim of the scam was the bank's then-president, Paolo Molesini, who last February authorized a series of international transfers, believing he was acting at the request of the bank's top management. According to the Corriere della Sera and news agencies, a significant portion of the funds has been recovered, but approximately €36 million is still missing.

According to the reconstruction, it all began with a WhatsApp message apparently sent by Carlo Messina, CEO of Intesa Sanpaolo. The message outlined the urgent need to complete several money transfers related to a financial transaction abroad, which, for operational reasons, would have to be processed through Fideuram's treasury. A second communication further strengthened the request's credibility: a phone call from a person who appeared to be Paolo Nastasi, managing partner of A&O Shearman Italia, a completely unrelated figure in the matter.

Investigators believe the scammers used artificial intelligence-based voice cloning technology to reproduce his voice, making the scam even more convincing. The transfers were apparently directed primarily to accounts in China and Hong Kong. Once the anomaly was identified, international interbank cooperation channels and the Milan Public Prosecutor's Office were activated.

Thanks to these procedures, it was possible to block and recover a large portion of the transferred sums, amounting to approximately €59 million. However, at least 36 million remain to be traced, which investigators believe were converted into cryptocurrencies and redistributed through international networks. (RAI News)

Related: The Daily Star, Reuters, 24Finance, Pasquale Pillitteri

Data-security company Cyera has raised $400 million from Growth Equity at Goldman Sachs Alternatives, the private markets arm of the banking giant’s asset-management division.

The investment, an extension of a June Series G funding round that valued the New York-based company at $12 billion, comes as investors continue to pour capital into cybersecurity firms, expecting them to benefit from the risks created by advanced AI models. (James Rundle / Wall Street Journal)

Related: CTech, SiliconANGLE, WOWTALE, BusinessWire

Best Thing of the Day: Despite All the Hacking, a Reminder That OpenAI Offers Powerful Defense Tools

Tech giant OpenAI will share its AI cyber defense system Daybreak for free with the Ukrainian government to help it protect civilian infrastructure, like hospitals and power plants, from cyber-attacks.

Worst Thing of the Day: Bootleg Access to Frontier Models Is the Latest Rage Among Cybercrims

Illicit access to AI models and computing power is fast becoming the hottest commodity in the cybercriminal underworld, as hackers seek to harness expensive large language models for extortion, warfare, and espionage.

Bonus Worst Thing of the Day: Put This in the File Labeled Lake America and The Gulf of America

Donald Trump is pushing world leaders and US agencies to rename AI "super intelligence."

Extra Bonus Worst Thing of the Day: China Is Not Immune to AI Accidents

Chinese startup Z.ai said it had disabled some features of its flagship AI coding assistant ​after some users reported it was uploading entire local code repositories onto overseas cloud servers without their consent.

Closing Thought