IT Security Newsletter - 9/8/2026
OpenAI agents discussed ways to escape their sandbox on public wiki
Self-identifying OpenAI agents posted 18,000 messages to a public wiki that discussed ways for other agents to bypass security sandbox restrictions during what was likely internal testing designed to gauge the agents' hacking abilities, researchers said Friday. In all, agents with 3,700 distinct self-given names posted the messages to German site DSEwiki over a six-week period. Besides discussing ways the agents could break out of the restricted environment, the posts shared test answers. READ MORE...
Mathspace Data Breach Exposes Over 1 Million People
Mathspace, an online mathematics program for students, has disclosed a data breach that impacts over 1 million individuals. The incident, it says, was discovered last week, roughly three weeks after hackers compromised its self-hosted Metabase instance using a known vulnerability. The security defect, tracked as CVE-2026-72898 (CVSS score of 10/10) and described as an SQL injection issue, was patched on August 6, after it had been exploited in the wild as a zero-day. READ MORE...
Trezor customers hit with phishing calls and letters after shipping-partner breach
Roughly 67,000 more customers of SatoshiLabs, the maker of hardware crypto-wallet Trezor, are at heightened risk of phishing attacks after their names, email addresses, phone numbers, and shipping addresses were exposed. "The leaked information could be used for scam emails, fraudulent calls or letters, and could potentially expose affected individuals to physical security risks," the Czech-based company confirmed in an update on the August 2026 data breach at ShipMonk. READ MORE...
ASCII smuggling isn't just an AI security risk
Fraudsters have found a new use for ASCII smuggling, typically used to hide malicious prompts intended for AI models, in an old-school attack method: email phishing. Microsoft uncovered a massive phishing campaign using invisible Unicode tag characters that peaked at more than 2.37 million messages in late February, remained elevated during weekdays over the next three months, and gradually declined by mid-June. READ MORE...
BigBear phishing crew nets thousands of Microsoft 365 credentials
A Microsoft 365 phishing operation targeting hundreds of organizations captured thousands of passwords and session cookies, including hundreds of authenticated sessions that could be hijacked to bypass MFA, according to researchers who accessed the crooks' own admin panel. Security researchers at CloudSEK say they accessed the admin panel behind BigBear 2.0, an Evilginx2-based phishing-as-a-service operation targeting Microsoft 365 users. READ MORE...
Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
Threat actors are exploiting a zero-day vulnerability in Adobe Commerce and Magento e-commerce platforms to backdoor online stores, cybersecurity firm Sansec reports. Dubbed StyleSmuggler, the security defect enables attackers to inject PHP code into Magento's template system and evade detection by using the 'styles' properties. According to Sansec, the PHP code is injected by generating a failure report, and then Magento executes the code via a failed payment email. READ MORE...
SAP warns of maximum severity 'OVERPASS' kernel vulnerability
SAP has addressed 20 vulnerabilities across multiple products in its September 2026 security updates, including a maximum-severity memory corruption flaw in the SAP Kernel code. Tracked as CVE-2026-44756 and dubbed OVERPASS by Onapsis security researchers who reported it, the vulnerability stems from a classic buffer overflow weakness in the Extended Passport Protocol (EPP) processing library. Successful exploitation lets unprivileged threat actors run arbitrary commands on vulnerable SAP hosts. READ MORE...
Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain
A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). Over the past months, researchers identified more than 5,400 hacked websites, most of them built on WordPress and PrestaShop. The initial compromise method remains unknown, but each site was injected with a script that gets the next-stage payload from a smart contract on the BSC Testnet endpoint. READ MORE...
What the AI Warning Letter Completely Missed
Recently, more than 100 technology companies - OpenAI, Anthropic, Microsoft, and Google among them - published an open letter warning that AI is about to make sophisticated cyberattacks far cheaper and far more common, and that "we have a limited window to strengthen cyber defenses." I read it twice. The first time as the head of a security organization, nodding along to very nearly every line. The second time hunting for the part about who actually does the work. I did not find it. READ MORE...
How a hole in Lenovo's login system let hackers walk into 5,000 Dropbox accounts
If you ever linked your Dropbox account to a Lenovo ID - perhaps to make life easier when logging in via a Lenovo laptop - you might want to take heed. Dropbox has confirmed that approximately 5,000 customer accounts were accessed between 4-21 August, after hackers exploited a legacy login integration between Dropbox and Lenovo's own identity system, Lenovo ID. Dropbox sent a warning to affected users about what it described as "an issue with Lenovo's email verification process." READ MORE...
LG TV flaws could let attackers listen in, even in standby mode
Smart TVs are internet-connected computers with microphones, app stores, advertising systems, and access to the same home networks used by your family's phones, laptops, printers, and smart-home devices. In the past, we reported on Samsung settling a lawsuit with the Texas Attorney General over how its smart TVs collect and monetize viewing data using Automated Content Recognition (ACR). ACR technology samples what appears on or is heard through a TV and creates a digital fingerprint. READ MORE...
MikroTik router flaws allow takeover without a password
CERT Polska warns that attackers are actively exploiting a chain of critical MikroTik RouterOS flaws to seize control of routers exposed to the internet. Although the warning comes from Poland's national cybersecurity response team, MikroTik routers are sold worldwide, including in the US. The vulnerabilities can affect users anywhere if their router is running a vulnerable version of RouterOS and its SSH remote-management service is accessible from the internet. READ MORE...
- ...in 1930, 3M begins marketing Scotch brand transparent tape.
- ...in 1943, Gen. Dwight Eisenhower publicly announces the surrender of Italy to the Allies.
- ...in 1966, the crew of the U.S.S. Enterprise takes off on its mission to "boldly go where no man has gone before," with the premiere of Star Trek.
- ...in 1974, President Gerald Ford pardons Richard Nixon for any crimes he may have committed, following Nixon's resignation in the wake of the Watergate scandal.








