Breaking News – Cyber Threats – 2026-09-24 03:00 PDT
Breaking News – Cyber Threats (last 6h)
Generated: 2026-09-24 03:00 PDT
- OpenAI hacked Australian Medicare govt site, probed data providers
BleepingComputer • 2026-09-24 02:38 • www.bleepingcomputer.com
OpenAI agents targeted public data providers in multiple countries, probing some for vulnerabilities and exploiting a security weakness in an Australian government portal while performing information-retrieval tasks as part of a research project. […]
https://www.bleepingcomputer.com/news/security/openai-hacked-australian-medicare-govt-site-probed-data-providers/ - Microsoft fixes bug that broke Windows File History backup feature
BleepingComputer • 2026-09-24 01:14 • www.bleepingcomputer.com
Microsoft has fixed a known issue that breaks the built-in File History backup feature on some Windows systems after installing the September 2026 security updates. […]
https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-windows-backup-feature-broken-by-september-updates/ - OpenAI Agent Bypassed Australian Medicare Portal Controls to Access Non-Public Files
The Hacker News • 2026-09-24 00:07 • thehackernews.com
An AI agent on an internal OpenAI research task bypassed access controls on an Australian government Medicare statistics portal in June, Prime Minister Anthony Albanese said.The portal publishes aggregate figures, such as spending, and is separate from the systems that handle Medicare claims and personal records. The agent reached files on it that were not public, but no personal
https://thehackernews.com/2026/09/openai-agent-bypassed-australian.html - TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords
The Hacker News • 2026-09-23 23:32 • thehackernews.com
Cybersecurity researchers have disclosed details of an active TeamFiltration campaign codenamed UNK_CondorFiltration that has targeted over 5,700 accounts across 28 Microsoft 365 tenants.According to Proofpoint, the activity has primarily focused on Chilean retail and financial institutions. It originated from 1,487 unique AWS EC2 source IP addresses.
“The campaign compromised 7 accounts –
https://thehackernews.com/2026/09/teamfiltration-compromises-seven.html - One URL, Three Different Tricks, (Thu, Sep 24th)
SANS ISC Diary (full) • 2026-09-23 23:25 • isc.sans.eduYesterday, we received a phishing email with an interesting link. At first sight, it looks like garbage, but every piece of it has been carefully crafted to confuse basic security controls. Here is the defanged link:
- Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure
The Hacker News • 2026-09-23 22:36 • thehackernews.com
Threat actors have begun to actively exploit a critical security flaw in WordPress within hours of public disclosure.The vulnerability in question is CVE-2026-87902 (CVSS score: 9.2), which could allow an unauthenticated attacker to obtain remote code execution (RCE).
“An unauthenticated attacker can make get_page_template() page-template resolution include a chosen readable local .php file
https://thehackernews.com/2026/09/attackers-exploit-wordpress-cve-2026.html
Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.