OpenAI says it will not publicly release GPT-6.1 Astra after model performed poorly on security assessments during testing
GPT-6 Astra goes off script, ShinyHunters suspect arrested, Nvidia corrals rogue AI agents
GPT-6 Astra goes off script in attack simulations Dutch police arrest “reformed” hacker in ShinyHunters probe Nvidia builds a browser for AI agents Get…
Why OT Resilience Is Now a Boardroom Imperative
For decades, industrial cybersecurity rested on a comfortable assumption: operational technology (OT) was protected by physical isolation. The “air gap”…
GPT-6 Astra and the Supply Chain Attack It Wasn’t Asked to Launch
UK AISI finds GPT-6 Astra launches unsanctioned supply-chain attacks in simulations far more than earlier OpenAI models, even when told not to. The UK’s…
OpenAI Agent Hacks Australian Government Website
Australian prime minister says OpenAI discovered one of its agents accessed non-public healthcare data in July
OpenAI Pauses Tool Use After Agent Bypasses Internet Controls to Reach External Chatbot
OpenAI said it has made the decision to pause training of its most powerful models after one of its agents during reinforcement learning (RL) training…
GitHub’s AI agent found 24 Android app vulnerabilities
GitHub Security Lab researcher Kevin Stubbings built custom AI-driven audit workflows, called taskflows, on top of the lab’s open source Taskflow Agent,…
OpenAI Shelves GPT-6.1 Astra After Tests Find Deception and Unauthorized Actions
OpenAI on Monday shelved plans to release GPT-6.1 Astra, a next-generation artificial intelligence (AI) model that was planned for an October launch,…
FBI Acknowledges Major Hack Of Employee Data
Agency says ‘working around the clock’ to probe theft of data on thousands of current and former employees, as staff fear danger
Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials
A malicious MCP server could trick an application built on the official MCP Python SDK into handing over the OAuth credentials it uses to log in to a real…
IT Security News Hourly Summary 2026-09-29 09h : 9 posts
9 posts published in the last hour 06:31Hackers Use Compromised Service Principals to Delete Azure Storage and Steal Cloud Credentials 06:31Apple Patches Meta-Reported Zero-Day Linked to ‘Extremely Sophisticated Attack’ 06:02Fake VPN Extensions Hijack Browser Traffic Through Hidden Proxy Servers 06:02Pentagon…
Hackers Use Compromised Service Principals to Delete Azure Storage and Steal Cloud Credentials
Microsoft has uncovered an Azure-focused destructive campaign linked to JADEPUFFER, a threat actor the company tracks as Storm-3168. The group abused…
Apple Patches Meta-Reported Zero-Day Linked to ‘Extremely Sophisticated Attack’
Apple has released iOS and macOS updates to patch the zero-day vulnerability tracked as CVE-2026-86950.
Fake VPN Extensions Hijack Browser Traffic Through Hidden Proxy Servers
A coordinated cluster of 31 Russian-language Chrome extensions that present themselves as convenient “VPN for X” tools while quietly steering browser…
Pentagon Data Breach Exposes Sensitive Data of Over 3 Million People
The Pentagon has confirmed a major data breach involving the Defense Manpower Data Center (DMDC) information system, exposing sensitive personal…
AI Security Testing: How to Red Team an LLM Application
By HOC Team | Updated: October 2026 | Read time: ~24 min Red teaming an LLM application is…
Researchers Found a Windows RAT That Turns Victims’ Screens Into Live Streams
A previously undocumented Windows remote access trojan capable of turning an infected victim’s display into a live stream for its operators. Dubbed…
Pentagon Data Breach – Hackers Reportedly Accessed 3 Million People’s Sensitive Data
The Pentagon has confirmed a major data breach involving a Defense Manpower Data Center (DMDC) information system, exposing sensitive personal information…
File Notification Attacks Let Hackers Track Keystrokes and Website Visits on Linux, Windows and macOS
Researchers have disclosed a new class of cross-platform side-channel attacks that exploit file-notification mechanisms in Linux, Windows, macOS, and…
IT Security News Hourly Summary 2026-09-29 08h : 4 posts
4 posts published in the last hour 05:31Crackdown on Italian organised criminal network involved in large-scale euro counterfeiting 05:31A four-week plan to tackle vendor concentration risk 05:02Hottest cybersecurity open-source tools of the month: September 2026 05:01Malicious VPN Extensions Turn Browser…
Crackdown on Italian organised criminal network involved in large-scale euro counterfeiting
Europol has supported an international operation targeting a criminal network linked to the Italian mafia-type organisation Camorra. The operation,…
A four-week plan to tackle vendor concentration risk
In this Help Net Security video, Guilliano Molaire, founder of Skycloak, explains how to map vendor concentration risk. A company may pay 30 vendors and…
Hottest cybersecurity open-source tools of the month: September 2026
Presented here is a curated selection of noteworthy open-source cybersecurity solutions that have drawn recognition for their ability to enhance security…
Malicious VPN Extensions Turn Browser Users Into Residential Proxy Servers
A cluster of 31 Russian-language Chrome extensions, marketed as “VPN for X” tools, has been discovered using a shared codebase to redirect browser traffic…
