Weekly Security Roundup — week ending Sunday, the 27th of September, 2026

Security Stories AI Agent Misbehavior — A Week of Unintended Consequences OpenAI had a difficult week for agent safety. The company disclosed that its AI agents accidentally uploaded user-provided images to third-party image-hosting services during research tasks — a data handling failure where user content ended up on infrastructure…

Briefing — 27 September 2026

🎧 Subscribe to the podcast feed | Direct MP3 Security News ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks (BleepingComputer / Mandiant) — ShinyHunters is now using URL percent-encoding (%50EMHUB instead of PSEMHUB) to bypass WAF rules mitigating CVE-2026-35273, allowing resumed exploitation of unpatched PeopleSoft servers and deploying the SIDEEYE…

Briefing — 26 September 2026

🎧 Subscribe to the podcast feed | Direct MP3 Security News Kiteworks urges 6-hour server shutdown over potential zero-day attacks (BleepingComputer / The Record) — Secure file-sharing platform Kiteworks told customers worldwide to shut down servers on Saturday after receiving credible threat intelligence from federal intelligence agencies warning of an imminent…

Briefing — 25 September 2026

🎧 Subscribe to the podcast feed Security News Crook used three open-source AI agents to breach Fortune 500 hospitality company, major US airline and 25+ orgs (The Register) — A threat actor chained three publicly available agentic AI frameworks to compromise over 25 organisations with no custom tooling or nation-state…

Briefing — 24 September 2026

🎧 Subscribe to the podcast feed Security News FBI rushes to investigate if ShinyHunters hack of thousands of employees is real (Ars Technica) — The FBI has launched an urgent investigation into ShinyHunters' claim of breaching Criminal Justice, HR, and Medlink systems via Oracle PeopleSoft, with the group alleging 2–3TB…

Briefing — 23 September 2026

🎧 Subscribe to the podcast feed Security News CLOSEDQUORUM: Windows malware uses LLMs to autonomously select post-compromise actions (The Register) — New malware queries Google Gemini, DeepSeek, Qwen, and Mistral at runtime to dynamically choose lateral movement, persistence, or exfiltration actions based on the compromised host — the first documented AI-directed…