IT Security Newsletter - 8/6/2026
OpenAI reveals its rogue agent swarm went a little bit Borg ahead of Hugging Face hack
The chain of events leading up to OpenAI's agents attacking Hugging Face and other organizations in July began months earlier, and involved agents asking other agents for help, building message boards, and even becoming paranoid that other agents were maliciously trying to trick them, two OpenAI staffers said at the Black Hat infosec conference on Wednesday. In their talk, OpenAI technical staffer Michael Dalton and researcher Eric Wallace provided new details about the security incident. READ MORE...
Suppliers, logins, and AI tools are all becoming attack paths
Cybercriminals and state-backed hacking groups are abusing trusted identities, cloud services, AI tools, and software supply chains to gain access while avoiding detection, according to CrowdStrike's 2026 Threat Hunting Report. Intrusion activity increased by about 4% over the past year. Even though the increase was smaller than in the previous reporting period, it shows a growing focus on more targeted campaigns. READ MORE...
Apple's bug bounty program is drowning in so much AI slop, it is in danger of missing serious exploits
Apple has imposed strict new submission limits on its bug bounty portal after finding itself overwhelmed by low-quality, AI generated vulnerability reports - many of which were found to be describing security flaws that simply didn't exist. According to a report in the Financial Times, Apple has found itself facing a massive influx of submissions from amateur bug hunters who have used AI to generate plausible-sounding but completely hallucinated bug reports. READ MORE...
Ransom Cartel ransomware creator sentenced to 16 years in prison
Maksim Silnikau, the creator and administrator of the Ransom Cartel ransomware operation, was sentenced to 16 years in prison for his role in ransomware attacks against at least 18 companies worldwide. The U.S. Department of Justice announced today that the 40-year-old Belarusian national was sentenced for conspiracy to commit offenses against the United States, conspiracy to commit wire fraud, and aggravated identity theft. READ MORE...
Discounted Claude access bought on the gray market may expose every prompt you send
More than half a dozen services advertised on underground forums and messaging platforms, offering discounted or "unlimited" token access to frontier AI models, were discovered by Okta. Okta believes the trend is likely driven by Chinese users seeking access to AI models that are unavailable because of regulatory and provider restrictions. According to researchers, cost, access restrictions, and a degree of anonymity pull people toward these services. READ MORE...
How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones
BLACK HAT - Two security researchers found a way to exploit vulnerabilities in Samsung software, including the virtual assistant Bixby, to hack mobile devices. The research was conducted by Dimitrios Valsamaras, senior security researcher at Microsoft, and Ken Gannon, head of mobile research at Mobile Hacking Lab. They demonstrated the vulnerabilities at the Pwn2Own Ireland hacking competition in October 2025, where they earned $50,000 after exploiting them to hack a Samsung Galaxy S25 device. READ MORE...
15 TP-Link Bugs Expose Risks in Zero-Trust Provisioning
Researchers disclosed 15 vulnerabilities in TP-Link networking technologies that they say call into question organizations' blind trust in zero-touch provisioning (ZTP). TP-Link is one of the world's largest edge device manufacturers. At Black Hat this week, Forescout's Vedere Labs security researchers Stanislav Dashevskyi and Francesco La Spina revealed 15 vulnerabilities affecting TP-Link "Omada", the software-defined networking (SDN) ecosystem for TP-Link's products. READ MORE...
Zero-Click AI Browser Hacking: Claude and ChatGPT Atlas Hijacked via Emails, X Posts
AI security company Zenity has disclosed the details of two AI browser hacking techniques targeting Claude in Chrome and ChatGPT Atlas, demonstrating how they can be used for account takeovers, phishing, and making unauthorized Amazon purchases. Zenity described its research in two separate blog posts published on Wednesday, one covering the ChatGPT Atlas research and one covering the Claude in Chrome attack. READ MORE...
CSS: The Hidden Threat Lurking in Your Inbox
Using email platforms to target users is nothing new in the world of threat actors. But as these well-known threats take command of everyone's attention, another vector remains hidden in plain sight. While HTML is the structure that powers web pages, Cascading Style Sheets (CSS) address design and presentation of the page. And according to Gareth Heyes, Web security researcher at PortSwigger, it can be weaponized because of its multiple capabilities. READ MORE...
- ...in 1911, actress and television producer Lucille Ball is born in Jamestown, NY.
- ...in 1965, President Lyndon B. Johnson signs the Voting Rights Act of 1965, extending the enforcement of the 14th and 15th Amendments for all Americans.
- ...in 1996, the influential punk rock group The Ramones play their farewell concert at The Palace in Los Angeles.
- ...in 2012, Cadre moves to its current headquarters in the PNC Center in Cincinnati.






