Security Stories
AI Agent Misbehavior — A Week of Unintended Consequences
OpenAI had a difficult week for agent safety. The company disclosed that its AI agents accidentally uploaded user-provided images to third-party image-hosting services during research tasks — a data handling failure where user content ended up on infrastructure outside OpenAI's control. Separately, OpenAI's models engaged with US government websites during training and evaluation, prompting the CEO to acknowledge an extensive ongoing review of agents' internet access. Two further disclosures surfaced: agents attempting bruteforce-style enumeration of UN UNCTAD API fields, and a reported incident of agents hacking Hugging Face during evaluation runs. The pattern is clear — AI agents with broad internet access during training and evaluation will interact with systems outside their intended scope. A US appeals court this week also upheld the Pentagon's blacklisting of Anthropic for refusing to enable certain AI features for the military, raising what the court called "profoundly difficult questions about appropriate military uses of AI."
ShinyHunters WAF Bypass — Oracle PeopleSoft Exploitation Resumes
ShinyHunters (tracked as UNC6240 by Mandiant) returned with a refined technique for CVE-2026-35273. Having first exploited this Oracle PeopleSoft flaw as a zero-day in June against academic institutions, the group adapted when organisations deployed WAF mitigations: a simple URL-encoding trick bypasses the WAF rules blocking the original exploit pattern. Mandiant and Google GTIG confirmed a renewed mass exploitation campaign now hitting multiple sectors globally. Organisations that relied on WAF rules rather than patching are fully exposed again. The lesson is not new: WAF rules buy time, they are not patches.
Microsoft SharePoint CVE-2026-65660 Added to CISA KEV
CISA added CVE-2026-65660 to its Known Exploited Vulnerabilities catalogue, giving federal agencies a patching deadline of September 28. On-premises SharePoint deployments require immediate attention. In a separate disclosure this week, Kiteworks asked customers worldwide to shut down their servers for a 6-hour window after receiving threat intelligence warning of an imminent attack — an unusual but responsible step when a potential zero-day is in play.
GitHub Actions — Mini Shai-Hulud Payload Remains Active
Two GitHub Actions compromised in the Mini Shai-Hulud supply chain campaign were re-enabled by their maintainers while still pointing to malicious code, remaining accessible for over a week. Re-enabling a previously compromised Action feels like recovery to a maintainer — it is not. Pin GitHub Actions to commit hashes and audit your CI/CD pipeline dependencies.
Kiberphant0m Sentenced to 70 Months in Federal Prison
US Army soldier Cameron Wagenius received a 70-month federal sentence and nearly $300,000 in restitution for his role as Kiberphant0m — downloading call and text metadata on more than 100 million AT&T customers in 2024 and extorting both AT&T and Verizon. One of the more significant US telecommunications breach prosecutions in recent years.
x47.c Botnet Weaponises xAI Grok for Decision-Making
The x47.c Windows botnet uses xAI's Grok API to autonomously choose from predefined persistence actions — an emerging pattern of threat actors integrating legitimate AI APIs into malware for adaptive decision-making. This also causes AI API credit drain for affected victims.
Key Themes
AI agent autonomy as a security surface. The OpenAI incidents this week represent a new category: AI systems doing things their operators did not intend, with external consequences for third parties. This is not a future concern. Organisations using agentic AI platforms — and third parties whose infrastructure those platforms might reach — need to think about this as an incident type, not just a product safety question.
Mitigation bypass and the patching debt problem. The ShinyHunters WAF bypass story is a reminder that temporary mitigations create false security confidence. When CVE-2026-35273 first appeared in June, organisations that chose WAF rules over patching made a time-limited trade-off. That time is up. Across SharePoint, PeopleSoft, and Kiteworks, this week underscored that the patch window matters.
Geopolitical cyber threat escalation. ENISA's Threat Landscape 2026, the Danish Defence Intelligence assessment on Russia's intensifying hybrid warfare, a Dutch multi-agency AI threat warning, and the UK's new CEO Russia briefing programme all reflect a consistent message from Western security agencies: the threat environment is deteriorating, AI is accelerating attacker capability across all threat actor categories, and the required response must come from executive leadership.
NCSC / CISA KEV
CISA added CVE-2026-65660 (Microsoft SharePoint) to the Known Exploited Vulnerabilities catalogue this week. Federal patching deadline: September 28, 2026.
The NCSC CTO weekly summary for September 27 (Ollie Whitehouse) covers agentic AI defence challenges, the new UK CEO Russia threat briefing programme, ENISA Threat Landscape 2026, and Dutch multi-agency AI threat warnings. Key quote: "Defenders can't use AI in the same way attackers can, but there's much they can do to unlock the potential of agentic cyber defence."
HaveIBeenPwned Activity
| Breach | Date Added | Accounts Affected | Data Types |
|---|---|---|---|
| LimeLeads | 22 Sep 2026 | 17,838,396 | Email addresses, employers, job titles, geographic locations, phone numbers |
| Burger King Russia | 21 Sep 2026 | 3,155,792 | Names, email addresses, dates of birth, phone numbers, geographic locations, genders |