> ## Content Index
> Fetch the complete content index at: https://www.metacurity.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# OpenAI disrupted an elaborate Russian influence operation
- URL: https://www.metacurity.com/openai-disrupted-an-elaborate-russian-influence-operation/
- Published: 2026-08-26T13:37:55.000Z
- Updated: 2026-08-26T13:37:55.000Z
- Description: Russian operators used ChatGPT to promote a fabricated Israel-based institute that laundered pro-Kremlin narratives through stolen academic research and a bogus “sovereignty index.”
- Author: Cynthia B Brumfield
- Tags: Cybersecurity, News, #no-feature-image

![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/08/openairussianinfocampaign-1.png)

LinkedIn post generated by this operation and posted on the platform. Source: OpenAI.

### OpenAI said it disrupted a previously unreported Russian influence operation that used ChatGPT to promote an elaborate fake think tank designed to lend credibility to pro-Kremlin narratives.

The operation centered on the International Burke Institute, or IBI, which presented itself as an Israel-based “expert community” and published a proprietary “sovereignty index” that praised Russia while portraying the United States, European Union, France, Germany, and other Western governments as weak or subordinate to foreign interests.

OpenAI said operators in Russia used VPNs to evade its prohibition on access from the country. They prompted ChatGPT in Russian to produce mostly English-language promotional posts and comments—explicitly instructing the model to remove linguistic clues pointing to their Russian origin—and distributed the material through X, Facebook, LinkedIn, Substack and Telegram. ChatGPT was also used to generate German-language pro-Russian posts, create logos for about a dozen Telegram channels targeting audiences in several countries, and produce Russian-language summaries of those channels’ activity.

The campaign’s distinctive feature was not simply its use of AI, but also the infrastructure behind it. The IBI website claimed prominent scholars, including Francis Fukuyama and Noam Chomsky, among its experts and stocked its pages with apparently authoritative research. OpenAI found that 34 of 36 sampled articles had been copied from elsewhere, sometimes attributed to the wrong authors. The core website articles and sovereignty reports were not generated with OpenAI’s models.

OpenAI described the campaign as the most elaborate Russia-linked influence operation it has disrupted, and the first it has identified using a fabricated research institution and proprietary index to manufacture intellectual authority for favored narratives. Some associated accounts posed as ordinary users or domestic news outlets, while the operators attempted to conceal the campaign’s Russian provenance.

The operation nevertheless achieved limited reach. Most social-media posts drew few views, and IBI’s official accounts attracted small audiences, although affiliated Telegram channels generally claimed between 10,000 and 20,000 subscribers. OpenAI rated the campaign at the lower end of Category Three on the Brookings Breakout Scale, indicating activity across multiple platforms with some penetration of authentic audiences.

OpenAI banned the associated ChatGPT accounts. The case shows how generative AI can serve as a supporting layer in a broader influence operation—producing multilingual promotional content, populating false personas, and coordinating distribution—while the principal deception rests on more traditional techniques such as plagiarism, false attribution, and fabricated institutional legitimacy. ([OpenAI](https://openai.com/index/disrupting-malicious-uses-of-ai-influence-campaign-russia/?ref=metacurity.com))

***Related:*** [*The Decoder*](https://the-decoder.com/russia-used-chatgpt-to-run-a-covert-influence-campaign-pushing-pro-kremlin-narratives-across-the-west/?ref=metacurity.com)*,* [*Le Monde*](https://www.lemonde.fr/en/pixels/article/2026/08/25/russian-disinformation-on-chatgpt-fake-telegram-channels-fake-videos-and-a-real-fake-israeli-think-tank%5F6756822%5F13.html?ref=metacurity.com)*,* [*CTech*](https://www.calcalistech.com/ctechnews/article/qde5oyso6?ref=metacurity.com)*,* [*Ynet News*](https://www.ynetnews.com/tech-and-digital/article/hk8sag3pmg?ref=metacurity.com)*,* [*Anadolu Ajansı*](https://www.aa.com.tr/en/europe/russia-s-ai-disinformation-campaign-linked-to-israel-based-think-tank-spiegel/4037407?ref=metacurity.com)*,* [*UA.news*](https://ua.news/en/technologies/chatgpt-zablokuvav-akaunti-z-rf-poviazani-z-dezinformatsiieiu?ref=metacurity.com)*,* [*Israel Defense*](https://www.israeldefense.co.il/en/node/70412?ref=metacurity.com)*,* [*RBC-Ukraine*](https://newsukraine.rbc.ua/news/russia-s-bot-network-used-chatgpt-in-a-massive-1787739273.html?ref=metacurity.com)*,* [*Informat*](https://informat.ro/en/international/openai-blocks-accounts-from-russia-used-for-disinformation-136354?ref=metacurity.com)

![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/08/image-78.png)

Substack comment generated by this operation in reply to a post on the platform. Source: OpenAI.

[](https://www.mk.co.kr/en/world/12135618?ref=metacurity.com)

---

**Metacurity is the cybersecurity news you'd need hours to assemble yourself.** 

Every weekday, we read the releases, filings, court documents, and reports that vendors and PR teams often don't want summarized — then tell you what actually changed and why it matters. Minimum vendor marketing, no outrage bait, no SEO filler.

A paid subscription to Metacurity delivers

- **Full archive access** — every newsletter and AI Watch roundup, searchable and browsable.
- **Our weekly curated long-reads roundup** — the best cybersecurity writing from across the industry, filtered and vetted so you're not sorting through it yourself,
- **Periodic specialized reports and analyses** — deep dives that go beyond our daily coverage
- **Support for independent, no-spin cybersecurity journalism** — funded by readers, not vendors or investors.

Reader support is what keeps Metacurity independent. It allows us to focus on serving the cybersecurity community—not advertisers, vendors, or investors—and to continue delivering the thoughtful analysis you've come to rely on every weekday.

Please consider supporting us. And thank you!

[Upgrade my subscription](#/portal/account/plans)

---

### Boston Scientific told the SEC that a cybersecurity incident had disrupted global operations, ​including some information systems used to ‌process and ship customer orders.

The medical device maker said it detected the incident on ​Aug. 25 and had activated incident-response procedures, ​working with third-party cybersecurity specialists to ⁠investigate and contain the threat.

The attack is expected to continue affecting parts of the company's business ​while recovery ​efforts are underway, Boston Scientific said.

Boston Scientific said it had not ​determined whether the incident was reasonably ​likely ⁠to have a material impact on its business.

More than 7,000 staff across Boston Scientific’s three Irish plants were informed of a global outage affecting its operations worldwide.

Irish employees were told of the issue shortly before lunchtime in an email to all staff. “We are currently experiencing a global outage affecting network communications across our Ireland sites and other locations worldwide,” the communication said.

“Our local and global IT teams are actively working together to understand the issue and restore services as soon as possible.

“We will share a further update as soon as more information becomes available.”

It is understood that all staff on the day shift at the multinational’s Cork plant on Model Farm Road were sent home at 2 pm with full pay.

Staff on the night shift at the Cork plant are currently waiting to be told whether they should report for duty. ([Sahil ​Pandey / Reuters](https://www.reuters.com/legal/government/boston-scientific-hit-by-cyberattack-global-operations-affected-2026-08-26/?ref=metacurity.com) and [Donal O’Keeffe / EchoLive](https://www.echolive.ie/corknews/arid-41901535.html?ref=metacurity.com))

**Related*:* [*SEC*](https://www.sec.gov/ix?doc=/Archives/edgar/data/0000885725/000088572526000056/bsx-20260826.htm&ref=metacurity.com)

### Colorado police arrested a man last week over charges that he impersonated both Supreme Court Chief Justice John Roberts and head of the National Security Agency’s famed Tailored Access Operations hacking unit.

Joshua Culver, also known as “Maverick Young,” appeared in a Colorado court Tuesday after his arrest stemming from an indictment in Indiana in July on four counts of falsely impersonating an officer of the court and one count of using a forged signature of a judge.

Culver allegedly pretended to be an officer of the NSA in September of last year and said in that capacity he “could take adverse action” against the Tippecanoe County sheriff’s office in Lafayette, Ind., if it didn’t provide him information he sought, including the location of his biological daughter.

He also allegedly pretended to be an NSA officer again that month, then produced a document purportedly from the head of the Tailored Access Operations (TAO) elite hacking unit in February to the Clerk of the Lake County, Ind. Superior Court.

TAO has gone by the name of Office of Computer Network Operations since 2017, although in July it indicated that it was resuming its old name. TAO garnered unflattering attention in 2017 after the global WannaCry ransomware outbreak used an exploit that the NSA developed. ([Tim Starks / CyberScoop](https://cyberscoop.com/arrested-man-allegedly-impersonated-nsa-elite-hacking-unit-supreme-court-chief-justice/?ref=metacurity.com))

**Related:** [*Court Listener*](https://storage.courtlistener.com/recap/gov.uscourts.cod.258103/gov.uscourts.cod.258103.1.1.pdf?ref=metacurity.com)*,* [*The Hill*](https://thehill.com/regulation/court-battles/6049130-federal-charges-forgery-john-roberts-nsa-impersonation/?ref=metacurity.com)*,* [*UPI*](https://www.upi.com/Top%5FNews/US/2026/08/25/man-accused-supreme-court-john-roberts/2921787679883/?ref=metacurity.com)*,* [*Bloomberg Law*](https://news.bloomberglaw.com/us-law-week/man-accused-of-impersonating-chief-justice-roberts-nsa-agent?ref=metacurity.com)*,* [*ABA Journal*](https://www.abajournal.com/news/article/man-arrested-for-impersonating-chief-justice-roberts?ref=metacurity.com)

### In an SEC filing, healthcare and services provider Nutex said it is investigating a data breach incident where an unauthorized third party exfiltrated information from company servers.

The company said that the stolen data includes details that may be private or confidential.

“Based on preliminary findings from the Company’s ongoing investigation, the Company believes that certain information maintained on the Company’s servers was accessed and exfiltrated by an unauthorized third party, including some information that may be private and/or confidential,” Nutex says.

As of August 24, the company says it found no material impact on its operations or financial reporting systems, and it currently does not believe the incident will materially affect its business strategy, operations, financial condition, or results. ([Bill Toulas / Bleeping Computer](https://www.bleepingcomputer.com/news/security/hospital-operator-nutex-health-says-data-stolen-in-cyberattack/?ref=metacurity.com))

**Related:** [*SEC*](https://www.sec.gov/Archives/edgar/data/1479681/000162828026058606/nutx-20260824.htm?mod=djemCybersecruityPro%26tpl%3Dcs&ref=metacurity.com)*,* [*Security Week*](https://www.securityweek.com/sensitive-information-exposed-in-nutex-health-data-breach/?ref=metacurity.com)*,* [*Becker's Hospital Review*](https://www.beckershospitalreview.com/healthcare-information-technology/cybersecurity/nutex-health-reports-data-theft-after-cyberattack/?ref=metacurity.com)*,* [*CloudLink Tech*](https://www.cloudlinktech.com/news/nutex-health-network-breach-files-exfiltrated/?ref=metacurity.com)

### The Los Angeles County Museum of Art (LACMA) announced that a breach last year exposed customer and employee information.

The museum says that on July 11, 2025, it detected suspicious activity on its systems that had started four days earlier. A month later, the investigation confirmed that the network was compromised.

At the time, the type of exposed data could not be determined, and the first results of the investigation became available in late February 2026\. ([Bill Toulas / Bleeping Computer](https://www.bleepingcomputer.com/news/security/lacma-data-breach-last-year-exposed-social-security-and-medical-data/?ref=metacurity.com))

**Related:** [*Lacma*](https://www.lacma.org/notice-data-security-incident?ref=metacurity.com)*,* [*California Attorney General*](https://oag.ca.gov/system/files/August%202026%20LACMA%20Notice%20-%20CM%20Redacted.pdf?ref=metacurity.com)

### Hackers stole troves of sensitive information on tens of thousands of people from Paylogix, a tech company that provides benefits management tools to employers and insurance firms.

The company has notified several state regulators this month and published its own notice of a security incident explaining that it experienced a cyberattack in the fall that disrupted its systems.

An investigation revealed that hackers stole files from the company’s network between November 13 and November 18\. Paylogix did not identify the hackers, but the company was added to the leak site of the Akira ransomware gang in January.

The cybercriminals stole Social Security numbers, electronic signatures, financial account information, health insurance information, medical data, passport numbers, taxpayer IDs and other information.

Federal law enforcement was notified of the incident, and Paylogix said it is cooperating with an investigation. ([Jonathan Grieg / The Record](https://therecord.media/paylogix-cyberattack-akira-ransomware?ref=metacurity.com))

**Related:** [*Insurance Business*](https://www.insurancebusinessmag.com/us/news/benefits/paylogix-tpa-data-breach-puts-benefits-brokers-on-notice-587537.aspx?ref=metacurity.com)

### When the Cybersecurity and Infrastructure Security Agency tested defenses for two targets — one in the government sector and the other in the water sector — red teamers were able to get into both of their systems, but the water organization discovered the simulated attack and acted to defend itself, whereas the government organization did neither.

CISA published the breakdown in a rare public report on its red-team activities, at a time when attacks on the water sector have a higher profile after revelations of targeting of water facilities across the United States over the past month and numerous government warnings.

The agency didn’t name the organizations it tested through a process that is voluntary and by request.

“In one organization (Organization A), the team gained initial access to multiple workstations, gained elevated privileges over the domain, and moved laterally to \[sensitive business systems\] and cloud resources undetected,” CISA’s analysis reads. “In the second organization (Organization B), network defenders quickly detected the initial compromise and quarantined the affected systems.”

Meanwhile, at “Organization B,” the water organization, CISA got access via a spearphishing campaign, convincing three users to click on a malicious link to gain access to workstations. This time, the security operations center triaged the alerts and quarantined the workstations in 2, 10, and 20 minutes, respectively. ([Tim Starks / CyberScoop](https://cyberscoop.com/cisa-red-team-report-government-water-cybersecurity/?ref=metacurity.com))

**Related:** [*CISA*](https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-237a?utm%5Fsource=TaleOfTwoSOCs&utm%5Fmedium=GovDelivery)*,* [*CISA*](https://www.cisa.gov/sites/default/files/2026-08/aa26-237a-tale-of-two-SOCs-insights-two-red-team-assessments-508c.pdf?ref=metacurity.com)*,* [*Cyber Security News*](https://cybersecuritynews.com/cisa-red-team-breaches-critical-infrastructure/?mid=1&ref=metacurity.com#cid=3679572)*,* [*Cyber Press*](https://cyberpress.org/cisa-red-team-compromises-active-directory/?amp=1&ref=metacurity.com)

![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/08/image-79.png)

Source: CISA.

### The Cybersecurity and Infrastructure Security Agency is pushing agencies to prioritize cybersecurity data logging that allows them to embrace continuous event monitoring, threat hunting, incident response, and other key capabilities.

Last week, CISA released the “Logging Reference Architecture” guide. The document helps agencies implement logging changes directed by the Office of Management and Budget in a May memo, “Ensuring Effective and Efficient Agency Logging and Network Visibility to Defend Against Evolving Cyber Threats.”

The new guide will help agencies as they develop logging plans that are due to OMB and CISA by Nov. 18.

In a statement on the new guide, CISA’s Acting Executive Assistant Director for Cybersecurity Chris Butera said: “Cyber defense begins with insight.”

“Robust logs provide the critical visibility needed to counter daily threats targeting federal systems,” Butera said. “CISA is enhancing agency logging strategies to ensure security teams can rapidly detect and respond to cyber incidents.”

Butera added that the architecture document “guides agencies away from fragmented practices, establishing a mature enterprise capability that maximizes the operational value of their data.” ([Justin Doubleday / Federal News Networks](https://federalnewsnetwork.com/cybersecurity/2026/08/cisa-wants-agencies-to-maximize-insight-from-cyber-data-logging/?ref=metacurity.com))

**Related*:* [*CISA*](https://www.cisa.gov/resources-tools/resources/logging-reference-architecture?ref=metacurity.com)*,* [*CISA*](https://www.cisa.gov/sites/default/files/2026-08/logging-reference-architecture.pdf?ref=metacurity.com)*,* [*ExecutiveGov*](https://www.executivegov.com/articles/cisa-logging-reference-architecture?ref=metacurity.com)*,* [*Help Net Security*](https://www.helpnetsecurity.com/2026/08/24/cybersecurity-logging-guidelines-strategy/?ref=metacurity.com)

![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/08/image-80.png)

Source: CISA.

### Researchers at Ox Security report that threat actors are abusing npm and its mirrors to host malicious HTML pages that impersonate Cloudflare CAPTCHAs to redirect visitors to attacker-controlled websites.

The technique was previously spotted in July by security researcher inf0stache, who found a 'china\_airlines' npm package that used a fake Cloudflare verification page to redirect visitors to a malicious domain, and was also reported by IntelFusions.

However, unlike the typical npm supply-chain attacks we've seen lately, installing the packages does not infect a developer's computer with malware or infostealers.

Instead, attackers use the npm registry as free storage for malicious HTML pages, which are then copied by mirroring platforms like UNPKG and npmmirror.

Because some of these platforms let individual files in npm packages be accessed directly in a browser, they effectively turn these developer sites into free web hosting for phishing pages.

"While the malware is simply a single HTML page inside the npm package, and while downloading it wouldn't do harm, the threat actor's use of npm isn't to infect developers who install it, but to use the registry and its mirrors as a safe, validated storage for the malware," explains OX Security.

BleepingComputer examined one of the packages identified in the campaign and found that it contained only two files, an index.html page and a package.json file that declared the HTML file as the package's main file. ([Lawrence Abrams / Bleeping Computer](https://www.bleepingcomputer.com/news/security/hackers-abuse-npm-mirrors-to-host-phishing-redirect-pages/?ref=metacurity.com))

**Related:** [*Ox Security*](https://www.ox.security/blog/research-clickfix-phishing-npm-packages/?ref=metacurity.com)*,* [*GBHackers*](https://gbhackers.com/fake-cloudflare-clickfix-pages/?ref=metacurity.com)*,* [*Cyber Press*](https://cyberpress.org/malicious-npm-clickfix-campaign/?ref=metacurity.com)

![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/08/image-81.png)

npm package containing an index.html and package.json file. Source: BleepingComputer

### Gen Threat Labs has uncovered WordlistLoader, a new malware loader used in ClearFake campaigns to deliver the Amatera Stealer.

The campaign abuses compromised legitimate websites to display fake CAPTCHA checks. Victims are told to prove they are human, but the process instead tricks them into copying and running a malicious command.

The fake CAPTCHA uses the ClickFix technique. After a victim clicks the checkbox, instructions tell them to paste copied text into the Windows Run dialog.

The command launches a hidden process, connects to a remote WebDAV share, downloads a malicious DLL, and runs its exported “Run” function through rundll32.

Researchers said this delivery chain resembles recently reported Amatera campaigns that used WebDAV and ClickFix. However, operators appear to have replaced earlier Python-based loaders with WordlistLoader. ([Varshini / Cyber Press](https://cyberpress.org/wordlistloader-conceals-amatera-shellcode-2/?ref=metacurity.com))

**Related:** [*GenDigital*](https://www.gendigital.com/blog/insights/research/wordlistloader-delivering-amatera-via-clearfake-campaigns?ref=metacurity.com)*,* [*GBHackers*](https://gbhackers.com/windows-users-with-amatera-stealer/?ref=metacurity.com)

![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/08/image-82.png)

Examples of compromised websites serving ClearFake’s FakeCaptchas. Source: GenDigital.

### Palo Alto Networks researchers found little evidence that AI-enabled malware has gained meaningful traction in real-world attacks, despite the large number of samples appearing in public malware repositories.

Unit 42 analyzed 405 samples associated with AI, ranging from malware apparently written with large language models to conventional malicious programs disguised as popular AI applications. Only 12 samples—about 3%—appeared on production endpoints protected by the company’s Cortex XDR platform. The remaining 97% were confined to VirusTotal, sandboxes and other research or security-testing environments.

The 12 samples represented five malware families, including FunkSec ransomware, the Oyster backdoor and the Rhadamanthys information stealer. Unit 42 said FunkSec’s rapid production of seven variants in six days suggested that LLM-assisted coding can accelerate malware development. A trojanized application masquerading as an AI recipe tool reached more than 50 organizations, although Palo Alto Networks said its products blocked every attempted execution.

The research found that AI is primarily changing how quickly malware can be written and modified—not how it behaves after deployment. Existing defenses, including sandboxing, behavioral analysis, code-signing anomaly detection and endpoint monitoring, detected the samples without requiring new AI-specific techniques.

Unit 42 cautioned that AI-enabled malware is real and likely to grow as generative tools lower the technical barrier for attackers. For now, however, malware developers have shown greater success using AI to create and iterate malicious code than in deploying it against defended production environments. ([Palo Alto Networks](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/?ref=metacurity.com))

### The US Army is ramping up efforts to defend its sprawling ecosystem of critical software and data under a new order reassigning its central cloud management organization to Army Cyber Command.

An order, signed by Army Secretary Dan Driscoll on Monday, directed the newly renamed Enterprise Cloud Management Activity to report to ARCYBER at Fort Gordon in Georgia. ECMA previously reported to the service’s chief information officer.

“This organizational transition marks a significant milestone in the Army’s modernization journey, strengthening ARCYBER’s role in securing, governing and operationalizing the service’s digital terrain,” the service said. ([Rachel S. Cohen / Federal News Network](https://federalnewsnetwork.com/army/2026/08/army-moves-cloud-management-under-its-cyber-command/?ref=metacurity.com))

**Related:** [*dvids*](https://www.dvidshub.net/news/573181/enterprise-cloud-management-activity-officially-assigned-under-arcyber?ref=metacurity.com)*,* [*US Army on LinkedIn*](https://www.linkedin.com/posts/us-army-cyber-command%5Fenterprise-cloud-management-activity-officially-activity-7498070500162678784-Co58/?ref=metacurity.com)*,* [*Federal News Network*](https://federalnewsnetwork.com/army/2026/08/army-moves-cloud-management-under-its-cyber-command?ref=metacurity.com)

### WhatsApp announced that it’s launching new security features and updates to help users keep their accounts secure, including stronger two-step verification and the ability to add more than one passkey to your account. 

The Meta-owned app is also adding context to calls from unknown numbers.

The updates come as WhatsApp and other messaging apps, such as Signal and Telegram, look to make account security easier and more accessible for everyday users, especially as phishing and hacking attempts have become more sophisticated over the years.

Until now, WhatsApp’s two-step verification has used a six-digit PIN as an extra layer of protection to prevent someone from taking over an account even if they’re able to obtain the user’s one-time passcode. Now, users can choose a longer, alphanumeric password with special characters to make the PIN harder to guess.

As for passkeys, users can now add more than one passkey to their account, which WhatsApp says will be useful if a person uses both iOS and Android. ([Aisha Malik / TechCrunch](https://techcrunch.com/2026/08/25/whatsapp-tightens-account-security-with-stronger-two-step-verification-and-more/?ref=metacurity.com))

**Related*:* [*Meta Newsroom*](https://about.fb.com/news/2026/08/new-account-security-features-for-whatsapp/?ref=metacurity.com)*,* [*WhatsApp*](https://blog.whatsapp.com/one-billion-people-are-now-protected-with-passkeys-on-whatsapp-plus-more-account-security-features?ref=metacurity.com)*,* [*9to5Mac*](https://9to5mac.com/2026/08/25/whatsapp-announces-three-ways-to-make-accounts-more-secure/?ref=metacurity.com)*,* [*9to5Google*](https://9to5google.com/2026/08/25/whatsapp-two-step-verification-codes-are-ditching-six-digit-pins-for-full-passwords/?ref=metacurity.com)*,* [*Thurrott*](https://www.thurrott.com/cloud/340705/whatsapp-adds-stronger-two-step-authentication-and-multiple-passkeys-support?ref=metacurity.com)*,* [*MakeUseOf*](https://www.makeuseof.com/whatsapp-new-security-update-adds-complex-2fa-passwords/?ref=metacurity.com)*,* [*Neowin*](https://www.neowin.net/news/meta-announces-new-account-security-features-for-whatsapp/?ref=metacurity.com)*,* [*Android Authority*](https://www.androidauthority.com/whatsapp-security-update-2fa-call-screening-3702749/?ref=metacurity.com)*,* [*WeRSM*](https://wersm.com/whatsapp-adds-new-account-security-features/?ref=metacurity.com)*,* [*Digital Trends*](https://www.digitaltrends.com/social-media/whatsapp-is-making-a-big-change-to-how-you-secure-your-account/?ref=metacurity.com)*,* [*BleepingComputer*](https://www.bleepingcomputer.com/news/security/whatsapp-adds-stronger-two-step-verification-multiple-passkeys/?ref=metacurity.com)*,* [*CyberInsider*](https://cyberinsider.com/whatsapp-adds-multiple-passkeys-and-stronger-two-step-verification/?ref=metacurity.com)*,* [*ANI News*](https://www.aninews.in/news/tech/internet/whatsapp-levels-up-security-with-new-safety-features20260826000403/?ref=metacurity.com)*,* [*Digit*](https://www.digit.in/news/apps/whatsapp-gets-new-security-features-multiple-passkeys-stronger-two-step-verification-and-more.html?ref=metacurity.com)*,* [*Engadget*](https://www.engadget.com/2243289/whatsapp-is-upgrading-its-2fa-settings/?ref=metacurity.com)

![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/08/image-83.png)

Source: WhatsApp.

### OpenAI announced a new feature in ChatGPT Work that allows AI agents to sign in to websites and complete tasks that previously required users to take over the browser manually. Previously, ChatGPT was not able to complete tasks that required authentication details to be entered.

With the new authentication support, ChatGPT Work can detect a website's login screen and let users enter their username, password, and security codes themselves. OpenAI highlighted that ChatGPT never sees the credentials entered by the user, so they are not exposed to the model or used for training. Also, the entered usernames and passwords are not stored by ChatGPT. Users can also use their existing password managers to fill in the authentication details.

Once the user is authenticated successfully, ChatGPT Work can continue browsing the website and complete the desired task. However, the authenticated session will remain active for future tasks. If needed, users can delete browser data for individual websites or all websites from ChatGPT settings. ([Pradeep Viswanathan / Neowin](https://www.neowin.net/news/chatgpt-work-can-now-log-in-to-websites-and-complete-tasks-for-you/?utm%5Fsource=rss))

**Related:** [*OpenAI*](https://help.openai.com/en/articles/20001280-using-cloud-browser-in-chatgpt?ref=metacurity.com)*,* [*The International News*](https://www.thenews.com.pk/latest/1413655-chatgpt-work-can-log-into-websites-to-complete-tasks-for-you-heres-how?ref=metacurity.com)

### Preferred Parking Service, a Charlotte-based company that manages parking lots and garages across the Southeast, is addressing a data breach involving thousands of customers’ credit and debit card information. 

A total of 72,912 people were impacted, including 61,335 North Carolina residents, N.C. Attorney General Jeff Jackson’s office confirmed. ([Catherine Muccigrosso / The Charlotte Observer](https://www.charlotteobserver.com/news/business/article316988844.html?ref=metacurity.com))

**Related:** [*Queen City News*](https://www.qcnews.com/charlotte/charlotte-based-parking-company-data-breach-impacts-more-than-61000-north-carolinians/?ref=metacurity.com)*,* [*Hoodline*](https://hoodline.com/2026/08/uptown-parking-giant-s-breach-hits-73-000-customers-cards-exposed/?ref=metacurity.com)

### Kylie Jenner’s verified X account, which has roughly 39.5 million followers, briefly promoted a Solana memecoin on Pump.fun before the posts were scrubbed. 

The token tied to the now-deleted posts saw its market cap spike to $1.21 million, then collapse below $120,000 in what appears to be the latest in a growing pattern of celebrity account compromises used to pump short-lived tokens.

The posts directed followers to a Pump.fun page with the handle “cutekjenner” and included a Solana contract address. Both were removed shortly after publication, but not before on-chain observers and community members flagged the activity as almost certainly the result of a hack. ([Crypto Briefing](https://cryptobriefing.com/kylie-jenner-compromised-solana-token/?ref=metacurity.com))

**Related:** [*Startup Fortune*](https://startupfortune.com/kylie-jenners-x-account-was-hacked-to-pump-a-solana-memecoin-that-crashed-90/?ref=metacurity.com)*,* [*Tech Times*](https://www.techtimes.com/articles/325433/20260825/kylie-jenners-x-account-was-hacked-crypto-x-never-confirmed-its-anti-scam-lock-deployed.htm?ref=metacurity.com)

### Alice, an Israeli startup that works to protect artificial intelligence models from misuse and rogue behavior, has raised $140 million after a spate of high-profile hacks from AI systems.

Apax Digital led the round with participation from cybersecurity company SentinelOne Inc. and Samsung Electronics Co. ([Marissa Newman / Bloomberg](https://www.bloomberg.com/news/articles/2026-08-25/ai-safety-startup-alice-partner-of-google-anthropic-raises-140-million?ref=metacurity.com))

**Related:** [*CTech*](https://www.calcalistech.com/ctechnews/article/a8lj22cfo?ref=metacurity.com)*,* [*SecurityWeek*](https://www.securityweek.com/alice-raises-140m-to-expand-ai-model-defenses-and-enterprise-guardrails/?ref=metacurity.com)*,* [*SiliconANGLE*](https://siliconangle.com/2026/08/25/alice-raises-140m-as-its-ai-security-business-grows-more-than-500/?ref=metacurity.com)*,* [*Globes*](https://en.globes.co.il/en/article-israeli-ai-security-co-alice-raises-140m-1001553384?ref=metacurity.com)*,* [*Cyber Security News*](https://cybersecuritynews.com/alice-ai-security/?ref=metacurity.com)

### Best Thing of the Day: This Is What You Call a Good Start

Meta [reached](https://www.nytimes.com/2026/08/26/technology/meta-settlement-social-media-addiction-lawsuit.html?smid=nytcore-ios-share&ref=metacurity.com) a landmark settlement with 47 states, the District of Columbia, and US territories, agreeing to pay up to $17.1 billion in penalties and make major changes to its products over claims it endangered children with addictive social media platforms.

### Best Thing of the Day: No, Hackers Didn't Steal Hundred Billion Gajillion Logins and Passwords

HaveIBeenPwned Troy Hunt [offers](https://www.troyhunt.com/a-cautionary-tale-about-data-breach-claims-verification-and-carhartt/?ref=metacurity.com) a compelling walk-through of why you should always take headline numbers when it comes to data breaches with a grain of salt.

### Worst Thing of the Day: How About Looking for a Way Not to Hire Murderous Scum First?

Immigration and Customs Enforcement (ICE) [is looking](https://www.404media.co/ice-wants-the-countrys-voter-data/?ref=metacurity.com) for a federal contractor to provide it with access to the country’s voter registration and voter history data.

### Closing Thought

![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/08/image-84.png)