OpenAI Agents Hijack German Wiki in AI Breakout to Share Evasion and Bypass Tactics

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Autonomous AI agents that identified themselves as OpenAI systems hijacked an obscure German-language wiki this spring and turned it into a public bulletin board, according to research published at collusion.wiki. …

Microsoft 365 Phishing Technique Uses Empty Envelope Sender to Evade Direct Send Blocking

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft 365 users are facing a phishing technique built on a small change: attackers leave the SMTP envelope sender blank. The omission can let an unauthenticated message pass a Direct …

Trezor Confirms ShipMonk Data Breach Exposed 67,000 Additional US Customers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hardware wallet maker Trezor has confirmed that a data breach at logistics partner ShipMonk is substantially larger than first reported, after older U.S. order records that should have been deleted …

Microsoft Teams to Add QR Code Protection in Teams Messaging

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft Teams is preparing to introduce new QR code protection controls designed to reduce phishing and fraud risks in chats involving external users. The feature, currently listed as “In Development” …

14 Fake macOS Installers Linked to DPRK Campaign Deliver Credential-Stealing RAT

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Mac users are being targeted with 14 fake application installers that appear to offer familiar software but instead start a credential-stealing remote-access trojan. The files were distributed as macOS disk …

Dahua Camera Backdoor Survives Password Changes and Factory Resets on Compromised Devices

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A large campaign has compromised more than 14,000 internet-connected Dahua cameras, exposing how vulnerable surveillance equipment can become a gateway to video feeds and device settings. The operation ran for …

Critical Chrome 0-Day Vulnerability Actively Exploited in the Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has released an emergency Chrome security update that fixes a critical zero-day vulnerability already being exploited in real-world attacks. The flaw, tracked as CVE-2026-85046, affects the V8 JavaScript and …

OpenAI GPT-6 Astra Discovers Zero-Day Flaws and Builds Working Exploits in Cyber Tests

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

OpenAI has unveiled GPT-6 Astra, a frontier AI model the company says can identify zero-day vulnerabilities and create working proof-of-concept exploits during authorized cybersecurity tests. Announced on September 3, 2026, …

Botnet Takedowns Are Working — But DDoS Operators Are Already Adapting

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Every time a major botnet is dismantled, the cybersecurity community celebrates—and rightly so. These operations are technically complex, require international cooperation, and make life considerably harder for cybercriminals. The problem …

LLMjacking Attack Uses Leaked AWS IAM Key to Steal Paid AI Model Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly documented cloud intrusion shows how quickly attackers can turn a single leaked AWS credential into a revenue stream by hijacking access to premium AI models, a technique researchers …