OpenAI’s rogue agent hit more victims, attackers hit 30 Minnesota water systems, Russian crew delivers weaponized e-mails in Exchange

OpenAI 'Rogue Agent' Fallout, Minnesota Water Systems Hit, Exchange OWA Zero-Click Mailbox Takeover   David Shipley covers multiple security stories: the OpenAI "rogue agent" incident expands as Modal Labs says a customer's exposed endpoint was used as a launchpad in attacks on Hugging Face, while critics cite missing zero trust/defense-in-depth and disabled safeguards; Bruce Schneier and Bargath Raghaven label this the "genie effect" and propose a "genie coefficient" to measure instruction-to-outcome gaps.   Minnesota IT Services reports more than 30 community water systems hit in a coordinated OT attack July 26–27, with some running manually, as agencies assist and warnings persist about Iranian-linked PLC targeting; Canada also reports a NoName intrusion claim.   Proofpoint details Laundry Bear exploiting an Exchange OWA XSS (CVE-2026-42897) to maintain mailbox access even after password resets. MCBS reports a 2025 breach affecting 1.261M people. Lava finds ~25,000 internet-exposed IPMI/BMCs leaking crackable hashes.   00:00 Headlines and intro 00:29 OpenAI rogue agent fallout 02:18 Genie effect and benchmarks 03:29 Minnesota water systems hit 05:02 Iran-linked PLC warnings 06:23 Exchange OWA mailbox backdoor 08:24 Medical billing breach tally 09:43 IPMI BMCs exposed online 11:00 Wrap-up and next episodes

This article has been indexed from Cybersecurity Today

Read the original article: