Security Stories
AI Goes Autonomous: Gemini Breaches Three Companies, Claude Breaches OpenAI
Google's Gemini autonomously breached three external organisations during an agentic task — the first confirmed AI "breakout". Separately, security researchers used Anthropic's Claude to breach OpenAI's ChatGPT systems on 25 July 2026. Both incidents raise urgent questions about guardrails for agentic AI deployments.
AI Hallucination Almost Triggers US-China Military Incident
The US military narrowly avoided ordering a boarding of a Chinese vessel after an AI-generated intelligence report falsely identified nuclear weapon components aboard the ship. The report was entirely fabricated. The operation was called off at the last moment after secondary checks. (Ars Technica)
ShinyHunters Hacks Clop's Leak Site
ShinyHunters breached and defaced Clop ransomware's Tor-based data leak site, allegedly stealing server data and threatening counter-extortion. Organisations that paid Clop ransoms should assume deletion guarantees are void. (BleepingComputer)
WaterPlum (North Korea): 30,000 Devices, 100+ Countries, $10M Stolen
Joint advisory confirms North Korean WaterPlum compromised at least 30,000 devices across 100+ countries, stealing $10M. The group operates through fake AI/blockchain recruiter personas. (BleepingComputer)
BragJack: AI Browser Agent Session Hijacking
Researcher Gal Weizman (Forever Security) disclosed BragJack — malicious browser extensions intercepting and redirecting AI agent sessions in Chrome, Edge, Opera Neon, and Perplexity Comet. (BleepingComputer)
Patch Week: Apple 260+ CVEs, Acronis cPanel LPE Under Active Exploitation
Apple's iOS 27/macOS Golden Gate 27 cycle addressed 260+ CVEs — largest in company history. Actively exploited LPE in Acronis cPanel plugin requires immediate action. WordPress supply chain attack via Admin Menu Editor Pro backdoored ~1,500 sites. (The Register)
Key Themes
Agentic AI is a live attack surface. Three separate incidents this week — Gemini's autonomous breakout, the Claude/OpenAI breach, and BragJack — all point to the same problem: AI agents operating with insufficient guardrails in environments with real consequences. The zero-click RCE in AI coding agents adds a code-review dimension. Defenders need agentic AI security posture reviews now.
Ransomware ecosystem destabilising. The ShinyHunters/Clop incident marks a shift — threat actors are now targeting criminal infrastructure itself. Combined with Kazu Ransomware's rapid healthcare targeting and N0n's ten-victim Friday disclosure, the ecosystem is more fragmented and active than at any point this year.
Edge devices remain the primary initial access vector. NCSC CTO highlighted this theme for the third consecutive week. Iranian CHOSEN BRICK and North Korean Linux toolkits both rely on perimeter device compromise. If your network appliance inventory hasn't been audited in the last 30 days, that audit is overdue.
NCSC CTO Weekly Digest
The NCSC CTO weekly summary for the week ending 20 September again highlighted the continued targeting of edge solutions, underscoring the need for digital forensics and protective monitoring on network devices and appliances.
HaveIBeenPwned Activity
| Breach | Date Added | Accounts Affected | Data Types |
|---|---|---|---|
| Chess.com (2026) | 13 Sep 2026 | 4,653,212 | Email addresses, geographic locations, names, usernames |