OpenAI agents went beyond instructions to access U.S. government websites – Sigh….

Posted in Commentary with tags on September 28, 2026 by itnerd

According to a Wall Street Journal report, OpenAI agents tasked with retrieving information from U.S. government websites took actions they were not instructed or authorized to perform. In one case involving the Securities and Exchange Commission, agents retrieved public SEC information and then posted it to an online forum without being asked to do so.

Other agents went beyond normal data collection by using credentials found online to access Census Bureau data, while independent researchers identified an unsuccessful attempt involving a Department of Education website. OpenAI said there is no indication the SEC incident involved access to nonpublic information or changes to SEC systems.

The incidents come amid a much broader investigation into rogue agent behavior. Axios reports that OpenAI, Anthropic and security researchers are investigating tens of thousands of incidents in which frontier models took potentially problematic actions, including bypassing guardrails,

Ryan McCurdy, Field CTO, Liquibase:
 

“We have enough examples now to stop assuming AI agents will always behave exactly as intended.

“That should change how enterprises build around them. Trying to anticipate every decision an agent might make won’t scale. Putting a human in front of every action won’t either.

“An agent may need permission to access a database, infrastructure, or a deployment system to do its job. Having that permission shouldn’t give it the authority to decide that every action is safe.

“This is where governance needs to sit. Let the agent reason, create, and move quickly. Before its decision becomes a production change, it still has to meet policies and controls that exist outside the agent.

“AI makes decisions based on probabilities. We can’t let those decisions automatically become production actions.

“We need to build the AI SDLC so agents can move quickly but the controls around critical systems remain deterministic.”
 

John Strand, Owner, Black Hills Information Security:
 

“I think a lot of people waffle back and forth on this, but I’m just going to say it. It’s time to shut it down. There needs to be a full moratorium, full stop, on advanced frontier AI security research until these companies can demonstrate that they can actually secure the environments where this work is being done.

“And there needs to be accountability. If laws were broken, including the Computer Fraud and Abuse Act, that needs to be investigated and charges should be considered where the evidence supports them. Somebody was responsible for securing these environments, and clearly something failed.

“I’m getting really tired of watching these incidents come out piecemeal, incrementally, frog in a frying pan, again and again. If everything we’ve learned came out at once as a single news story, I think most people would be stunned by it, and there would be immediate calls to get this under control.

“We would not tolerate this from a third-party penetration testing company. We should not have a different standard simply because the companies involved have enormous valuations and tremendous influence. Being a massive, powerful company should not exempt you from the same security, legal, and accountability standards everyone else is expected to follow.”
 

Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:

“OpenAI has admitted that its agents took actions they were not instructed or authorized to perform on U.S. government websites. The Wall Street Journal reports that one agent retrieved public Securities and Exchange Commission information and posted it to an online forum. Other agents used credentials found online to access Census Bureau data and attempted to hack a Department of Education website.

“The SEC incident may not, by itself, establish a Computer Fraud and Abuse Act violation because the information was public and OpenAI says there is no indication the agents accessed nonpublic data or changed SEC systems. The other reported conduct demands a criminal investigation. Using credentials found online to access a government system and attempting to compromise another system are the kinds of acts covered by existing computer-crime laws.

“The Axios report that OpenAI, Anthropic and security researchers are investigating tens of thousands of rogue-agent incidents makes the need for enforcement more urgent. This is the same pattern seen in earlier cases involving Anthropic’s Claude, OpenAI’s Hugging Face agent and the UK AI Security Institute’s Mythos 5 testing. Frontier models have repeatedly crossed boundaries, accessed real systems and pursued objectives through unauthorized methods.

“The White House already gave the Justice Department its instruction. Executive Order 14409 directs the attorney general to prioritize enforcement of the Computer Fraud and Abuse Act, 18 U.S.C. § 1030, and other federal criminal laws against people who use artificial intelligence to access or damage computers without authorization. Section 4 specifically names AI agents that unlawfully access data.

“OpenAI has admitted the conduct. The question is whether prosecutors will charge the people who authorized, configured and operated these systems under the law as written. Frontier labs calling for new AI regulation is a deflection from that criminal question. We do not need new laws. We need the Justice Department to enforce the laws already on the books, or admit that those laws are too broad to apply equally. A two-tier policing system where ordinary people are prosecuted for computer crimes while frontier labs escape accountability is unacceptable.” 

At this point, it’s safe to say that OpenAI and Sam Altman cannot be trusted. The real question is when real legislation will come down the pipe to restrict OpenAI in ways that make it less dangerous.

About 17 TRILLION Microsoft Records Accessed by 16-Year-Old Researcher 

Posted in Commentary with tags on September 28, 2026 by itnerd

An estimated 17.3 trillion stored rows across a wide range of Microsoft datasets in Microsoft’s Titan analytics service, were reachable through a single internal analytics service, all because it never checked the signature on a login token. The flaw, which a 16-year-old security researcher known as Faav uncovered, enabled him to claim an administrator’s identity and submit unauthorized SQL queries without any real credentials.

The blog entry with started all of this is here: https://blog.faav.net/how-i-couldve-accessed-17-trillion-microsoft-records

Ensar Seker, CISO at SOCRadar, commented:

“This is a strong example of how one fundamental authentication mistake can undermine multiple layers of otherwise well-designed access controls. Titan was validating information inside the JWT, such as the tenant, audience and application, but according to the researcher it was not verifying the cryptographic signature. If an attacker can control the claims without proving who issued the token, those downstream checks provide very little protection. The 17.3 trillion figure also needs to be understood carefully. It represents an estimated number of database rows technically reachable through the vulnerable environment, not 17.3 trillion individuals or confirmed stolen records. There is currently no evidence presented that malicious actors exploited the vulnerability, and the researcher deliberately limited access during testing.


“What makes this case particularly interesting is the combination of AI automation and human security expertise. The AI system handled repetitive discovery, enumeration and authentication testing over several days, while the decisive breakthrough came from the researcher questioning an assumption about how the application interpreted the user identity field. That is likely a preview of how both offensive security research and defensive testing will evolve: AI can dramatically increase the speed and breadth of investigation, but human intuition and contextual reasoning remain critical.

“For security teams, the lesson is straightforward: authentication controls should fail closed, JWT signatures must always be cryptographically verified, unsigned tokens must be rejected, and externally reachable APIs should be independently assessed even when the associated application is supposedly protected by VPN or internal-access controls.”

Well, this is a sign of things to come. Which is guaranteed to be bad for all of us.

New SOCRadar AI Identity Exposure Report Reveals 80,000+ Enterprises Had Employee AI Logins Stolen – ChatGPT is the Front Door 

Posted in Commentary with tags on September 28, 2026 by itnerd

SOCRadar’s just-released AI Identity Exposure Report 2026 reveals that 80,000+ enterprises had employee AI logins stolen and ChatGPT is the front door.

SOCRadar mapped more than a million infostealer records against corporate domains

The report looks at the growing exposure of corporate AI identities and credentials, particularly how infostealer malware is capturing access to AI platforms, sessions, credentials, and other sensitive information used by organizations.

It includes research and analysis covering:

  • The scale of AI-related identity and credential exposure revealing that 80,000+ enterprises had employee AI logins stolen and ChatGPT is the front door to the exposure
  • Compromised corporate accounts and AI platform logins
  • Infostealer activity and how attackers obtain AI-related credentials and session data
  • Exposure of AI tools such as ChatGPT and other enterprise AI platforms
  • The risks associated with stolen session cookies, credentials, API keys, and other forms of access
  • The growing “Shadow AI” problem, where employees use AI services outside formal corporate security controls
  • Industry and organizational trends around AI identity exposure
  • How attackers can potentially leverage compromised AI access for further intrusion, data access, or unauthorized AI resource usage
  • Key security recommendations for organizations to reduce AI-related identity exposure

Free AI Exposure Checker

The company also released its free AI Exposure Checker that allows companies to check their domain against 3 billion credentials records. A saved AI password is where the intrusion starts, not where it ends. Infostealers take the login, the live session cookie, and the API keys sitting in the same profile so it is important to check for possible exposure.


To view the full report, please see this link AI Identity Exposure Report 2026.

New Eclypsium data: Attackers are targeting the systems that control infrastructure

Posted in Commentary with tags on September 28, 2026 by itnerd

Attackers are increasingly going after the systems that control enterprise infrastructure, rather than just the individual devices underneath them.

The latest InfraTrust Pulse from Eclypsium tracked 158 new security advisories covering 1,699 CVEs in less than a month  including 42 Critical advisories, eight perfect 10.0s and 71 remotely exploitable without authentication.

One trend stands out: serious flaws are repeatedly hitting management planes including Cisco FMC and ISE, NVIDIA Unified Fabric Manager, HPE Fabric Composer and other platforms that hold credentials and provide centralized control over infrastructure. The research also highlights how a single Linux kernel flaw has spread across 19 separate vendor advisories, alongside new firmware-level risks including Eclypsium’s recently disclosed UEFI Secure Boot bypass.

You can read the results here: InfraTrust Pulse

New CalPhishing Campaign Uses Internal Email Forwards to Reach Targets

Posted in Commentary with tags on September 28, 2026 by itnerd

Fortra Intelligence and Research Experts (FIRE) have identified a new CalPhishing variant where attackers exploit internal referrals to conduct credential theft attacks. 

Key takeaways:

  • Attackers pose as prospective customers and contact non-sales employees first.
  • Employees unknowingly become “trust bridges” by forwarding meeting-booking links to sales teams.
  • The booking page appears legitimate but ultimately prompts users to sign in with Microsoft 365 credentials.
  • The attack abuses trusted business workflows instead of spoofed identities or compromised accounts.
  • A successful compromise can lead to email access, data theft, fraud, and further phishing attacks.

Full analysis here: https://www.fortra.com/blog/calphishing-through-trust-chain

Autoheal raises $7.9M to build a self-improving software factory for enterprises

Posted in Commentary with tags on September 28, 2026 by itnerd

AI is helping engineering teams ship more code, faster than ever. But that acceleration comes with a growing operational burden: more production incidents to respond to, more security vulnerabilities to remediate, and spiraling token costs to contain. Autoheal is built for these challenges and already battle tested at industry leaders such as Nomura Bank and AvidXchange where off-the-shelf point agents failed to deliver. 

Today, the company announced a $7.9 million seed round to scale the industry’s most advanced self-improving software factory, giving enterprise platform engineering teams a way to build, deploy, govern, and continuously improve multiplayer cloud AI agents across the software development lifecycle. The round was led by Innovation Endeavors, with Harpinder Singh joining Autoheal’s board, alongside participation from Emergent Ventures, U&I Ventures, Darkmode Ventures, Batch Ventures, and Param Hansa Values.

Why platform engineering needs a new operating model 

Repetitive SDLC workflows such as incident response and vulnerability remediation consume more than a third of an engineering team’s capacity. As coding agent adoption grows, controlling LLM spend and managing context is joining that list. To manage these demands, platform engineering teams are shifting toward a “software factory” model powered by specialized AI agents.

However, at scale rollout of these agents often fails due to fragmented tools, a lack of shared context, and strict security constraints. Establishing a unified platform for creating, managing, and iteratively improving all software factory agents, including the existing coding agents, has therefore become an immediate priority. This ensures every agent gets the same engineering context, secure production access, private evaluation infrastructure, cost controls, and a way to stay current as the organization changes.

What Autoheal is building 

Autoheal’s software factory gives enterprises the infrastructure and tools to transform their engineering organization into a self-improving machine. It connects existing coding agents, code repositories, CI/CD, observability, cloud runtimes, and issue trackers, giving all worker agents in the factory a shared engineering context graph. As these worker agents keep executing post-coding repetitive workflows, two self-improvement agents keep working in the background:

  • The Evaluator agent scores every worker agent’s run. For example, a coding agent can be evaluated by scoring the specs and PRs it generates, using the downstream signals of review comments, CI failures and caused incidents as the evaluation criteria. 
  • The Healer agent fixes low scoring worker agents by opening pull requests that improve skills, prompts, tools, or model selections. It even verifies those changes against historical benchmarks for regressions before engineer review.

For platform engineering teams, this creates a continuous agent healing loop as systems change. Every behavior change is version-controlled in git and requires engineer approval. Actions remain governed and audited, with visibility into access, reasoning, and costs. The end goal is higher accuracy, faster execution, and lower cost per successful task with engineers expanding autonomy as agents prove reliable.

Traction

Autoheal is already operating inside complex regulated environments, where engineering teams are using it to cut incident response times, handle customer support escalations and free up thousands of hours of engineering capacity.

Origin story 

Autoheal grew out of the founders’ experience building enterprise engineering and AI platforms at Harness, Microsoft Azure, ThoughtSpot and AppDynamics. After scaling Harness to over $200M ARR, the team recognized a new reality: while building individual AI agents had become easy, safely deploying them across the SDLC and across engineering teams had become extremely time and token consuming. To prevent agent sprawl and ensure day-2 governance, a platform must manage agents as code, overseen by continuously learning meta-agents. That insight became Autoheal’s software factory.

What’s next

Engineering processes & implicit architecture decisions are locked within an enterprise’s boundary or engineer’s minds. Frontier models have been trained on public internet, open source code and synthetic data but not enterprises’ data. Enterprises want to build sovereign & cost-effective intelligence on this data because it’s a competitive advantage. Autoheal will first capture this data by operating the factory and then train small private models of various architectures per customer. These models will soon power the majority of tasks in the software factory which are not generative in nature.

In the long term, the same architecture can extend beyond software engineering into data and security engineering. Autoheal is betting that every large enterprise will run a software factory that has its own population of specialized agents, and wants to be the platform that engineering teams use to build, govern and continuously improve them.

Producing code has never been easier, but AI-generated bugs and rising debugging workloads are slowing software delivery  

Posted in Commentary with tags on September 28, 2026 by itnerd

New research from Undo, the technology that gives developers the runtime context needed to solve the most challenging problems in the most complex codebases, finds that almost four in five (79%) engineering leaders say their release cycles are no faster than before, despite their teams being able to produce code more easily than at any time in their careers. 

As AI agents have increased the volume of code they can create, engineers now spend nearly twice as long debugging it as they do writing it, averaging 16.9 hours a week. That accounts for 42% of the average working week. Engineers are simply unable to keep up with their agents, leading to more than a third (35%) of AI-generated code reaching production before they’ve fully comprehended it. 

Adding to the risk, AI agents frequently hallucinate the cause of failures, or fail to identify problems in the codebase entirely. In the past six months, as a result of their use of AI coding tools:

  • 81% of organizations have had a production incident or service outage affecting internal users or customers
  • 93% have had the root cause of an issue incorrectly diagnosed because of an AI hallucination
  • 91% have had test escapes, serious defects or poorly optimized code enter production

Four in five (80%) engineering leaders say coding agents struggle to solve difficult problems in large-scale, complex codebases. The arrival of more powerful models doesn’t offer a realistic solution, with a strong degree of cynicism about the impact the planned IPOs of Anthropic and OpenAI will have on AI affordability. The majority (82%) of engineering leaders think the costs of coding agents will go ‘through the roof’ as the AI labs prioritize making Wall Street happy.

However, engineering leaders widely agree that improving model context is more important than increasing their capability to make AI more powerful. More than four in five (82%) say AI agents would be far more useful for code comprehension and debugging if they were grounded in the context of what happened during runtime.

To learn more, download the full Overcoming the limitations of coding agents in complex software systems report here: https://undo.io/research-report-2026

Methodology

The research was conducted on behalf of Undo by independent research firm Coleman Parkes during July and August 2026. It surveyed 300 senior engineering leaders at organizations with revenues of $250m or above that deliver mission-critical software built on large, complex codebases, 93% of whom work with C/C++. Respondents were based in the United States (200) and the UK (100), across financial services, networking, semiconductor design, computational software and data management.

Edinburgh Napier and Approov team up on smartphone security innovation

Posted in Commentary with tags on September 25, 2026 by itnerd

A new partnership between Edinburgh Napier University and mobile cybersecurity firm Approov Limited will aim to improve smartphone security.

The Edinburgh-based company has agreed a Knowledge Transfer Partnership (KTP) with ENU, which will include the recruitment of two cyber security researchers, co-funded by Innovate UK.

Over the course of 30 months, Approov and Edinburgh Napier will work together to create innovative defence mechanisms and an offensive test bed – known in cyber security as ‘blue team’ and ‘red team’. 

The project, which received the highest rating in Innovate UK’s assessment for this funding round, will involve the ENU-hosted Scottish Centre of Excellence in Digital Trust and Distributed Ledger Technology.

It builds on Edinburgh Napier’s strong record in cyber security and digital trust technology. It has been recognised by the UK’s National Cyber Security Centre and Department for Science, Innovation and Technology (DSIT) as an Academic Centre of Excellence in Cyber Security Education (ACE-CSE) – and was the starting point for several successful cybersecurity spin out companies.

Background:

Edinburg Napier holds early accreditation from the National Cyber Security Centre (NCSC), is recognized as a leader in cyber skills and training. It’s globally ranked in Computer Science and Electrical and Electronic Engineering by U.S. News & World Report, and the UK’s Research Excellence Framework (REF) ranked Edinburgh Napier as the top modern university in Scotland for both research power and research impact, with nearly 70% of evaluated research deemed world-leading or internationally excellent.

The CISA releases election security plan 40 days before midterms

Posted in Commentary with tags on September 25, 2026 by itnerd

The CISA released its 2026 Election Infrastructure Security Plan 40 days before the November midterm elections, outlining cyber and physical threats facing election systems and federal resources available to state and local election officials.

The plan identifies potential threats including cyberattacks against voter registration databases, election networks and other systems, as well as physical threats against election facilities and personnel. It recommends measures including vulnerability scanning, risk assessments, incident response planning, information sharing and the use of auditable paper ballots.

CISA also designated its 10 regional directors as Election Security Advisors responsible for connecting state and local officials with federal cybersecurity resources. The plan comes after staffing and program reductions affected CISA’s election security operations, with some state election officials raising concerns about reduced federal support ahead of the midterms.

Ted Miracco, CEO, Approov:

“CISA’s new 2026 Election Infrastructure Security Plan is right to insist on paper ballots and hand audits. But it never once mentions mobile devices, apps or APIs, which is a strange gap given how much of American voting now runs through them.

“Most US jurisdictions check voters in on electronic poll books, and the most widely used one runs on Apple iPads. Forty-two states and D.C. let people register online, and millions of voters track their mail ballots by text message.

“Bangladesh, which went to the polls in February, took a clearer-eyed approach. Its Election Commission built a mobile app that registered more than 450,000 overseas voters and let them follow their ballots. Then it had every one of them mark a paper ballot and mail it home. The same commission had already scrapped electronic voting machines for all future elections. That is the right design: phones for access and tracking, paper for the vote itself, and serious security for the digital layer in between. Nobody can hack a paper ballot from abroad. They can hijack the phone number that gets a county clerk into the voter rolls. America already has the paper half. What it lacks is a federal plan that treats the phone in a voter’s pocket, and in an election official’s hand, as election infrastructure. While the ballot itself can stay analogue, the threat model cannot.”

Darin Fredde, Sr. Director of Technical Marketing Engineering, Ridge Security:

“My firsthand work as an offensive security tester has taught me that election security extends beyond voting equipment to the people, infrastructure, vendors, and processes supporting elections. A plan or scan is a starting point; the safeguards need to be tested in practice.”

Cyber and physical threats are clearly present when it comes to the midterms. And I am glad that someone is securing them from being tampered with. I hope that true with any threat that comes along.

Guest Post: Why are the FBI hackers so obsessed with their reputation? 

Posted in Commentary with tags on September 25, 2026 by itnerd

By Stefanie Schappert

For most ransomware and extortion gangs, the end goal has always been pretty simple: money.

Steal enough sensitive data, threaten to leak it, and hope the victim decides paying millions of dollars is better than dealing with the fallout.

But what happens when money is no longer the ransom?

This week, the notorious ShinyHunters hacker group announced it had breached multiple FBI systems, claiming it made off with sensitive data belonging to “almost all” FBI agents, employees, and even job applicants.

The FBI has said it is investigating the alleged breach.

The thing is, in this case, the hackers aren’t asking the FBI for millions of dollars – they’re asking the FBI to take back what the group says are “false allegations” about how they operate. 

ShinyHunters gave the FBI seven days to remove or correct statements it made in a May cyber advisory that the group says falsely accused it of exaggerating hacking claims, threatening victims and their families, engaging in swatting, and falsely claiming to possess compromising material. 

Seemingly insulted by the suggestion, ShinyHunters also took the time to “unequivocally” declare they are “NOT SEXTORTIONISTS” and “unequivocally” unrelated to the nihilistic hacking collective known as The Com.

The hackers also “unequivocally” (they used the word unequivocally a lot) insist the attack has nothing to do with money.

So why would a cybercriminal group go to such extraordinary lengths to defend its reputation?

Because in the world of cyber extortion, reputation is just another form of currency.

Honor among thieves

Extortion only works if the victim believes the threat.

If hackers threaten to dump sensitive information if a victim refuses to pay, there has to be some reason for that company to believe they will. 


If companies begin to suspect a hacker group is bluffing, the threat loses its power, the ransomware gang loses leverage over its victims, and the well runs dry, so to speak.

That’s why an FBI warning suggesting ShinyHunters may exaggerate its claims isn’t simply an insult. 

From the hackers’ perspective, it potentially damages the very credibility their business model depends on.

And ShinyHunters isn’t the first cybercrime group I’ve seen fiercely protective of its public image.

Last year, another fine group of extortionists – known as the Qilin gang – contacted my newsroom after taking issue with how I characterized the ransomware group in an article, politely requesting I correct it. 

Rather than get on the bad side of one of the most active gangs for nearly two years running, I kindly obliged. 

And it appears ShinyHunters has joined the quest, publicly taking issue with how journalists are covering the FBI story, in an obvious attempt to control the narrative.  

ShinyHunters also slammed journalists for mishandling the proof samples it so graciously provided, essentially “ruining the experience for everyone.” 

Citing the inappropriate sharing of highly sensitive data (yes, the irony is not lost here), the hackers – who clearly have a reputation to uphold – simply decided they would no longer engage with media for this faux pas. 

Cash is king – or is it?

For organizations negotiating with these groups, this raises a much bigger question.

As hackers accumulate increasingly sensitive information capable of destroying careers, exposing trade secrets, or putting people’s physical safety at risk, organizations may face demands that have nothing to do with money.

Think of all the highly sensitive data out there potentially at risk.  

Medical records, trade secrets, proprietary technology, private communications, customer databases, information about executives – or, in the FBI’s case, home addresses, phone numbers, family information, and other personal details of highly specialized federal agents.

Furthermore, with ransomware attacks, the public may eventually learn that an organization was breached, but rarely sees everything that happens behind the scenes: the negotiations, whether a ransom is paid, or how much.

In the past few years at least, we’ve become accustomed to hackers demanding tens of millions of dollars from their victims in exchange for stolen data.

But stolen information, as we’ve now witnessed, can be leveraged for much more than money, and the more damaging the information, the greater the leverage. 

From a simple retraction or public statement to a forced change in corporate behavior – or potentially a demand we haven’t even seen or thought of yet – many cyber insiders believe the stakes are evolving. 

The question we must ask isn’t simply how much a victim is willing to pay to protect its data, but what else it would be willing to do to protect it.

ABOUT THE EXPERT

Stefanie Schappert is a Senior Journalist at Cybernews covering cybersecurity, AI, national security, cyber policy, critical infrastructure, data privacy, and the human impact of technology. Based in New York, she is the first American journalist at Cybernews and a broadcast news veteran previously at Fox News, NY1 News, and Verizon FiOS 1. She holds a Master’s degree in Cybersecurity and is ISC2 Certified in Cybersecurity (CC). A guest commentator on TV, radio, and podcasts, including CBS News, iHeartMedia, and KTLA, Schappert explores how technology and cyber risk shape society, from ransomware attacks and hacker groups to emerging technologies and digital policy. She has been published in Fortune and cited by the US Senate, FCC, HHS, Henry Jackson Society, academic institutions, and other leading technology publications.