Threat Intelligence

Live threat and AI news from CISA, Krebs on Security, Bleeping Computer, SANS ISC, TechCrunch, The Verge, and Simon Willison — cross-referenced to open markets.

15-min cache
TechCrunch AIMEDIUMAISep 5, 2026

Hikers rescued after using Google Gemini for planning

The sheriff’s office said the hikers “were advised by Gemini to bring far less food and water than their group required."

TechCrunch AIMEDIUMAISep 5, 2026

OpenAI confirms ‘wiki incident,’ says it’s ‘working on a framework’ for more disclosure

OpenAI acknowledged its role in a recently reported incident where AI agents took over a German wiki forum.

Simon WillisonMEDIUMSep 5, 2026

Using Blender with coding agents on macOS

TIL: Using Blender with coding agents on macOS I've been having fun with Blender in ChatGPT Codex on my Mac recently. Getting it to work with coding agents is really easy: install the full Mac application from blender.org and run a prompt like this: Use the already install /Applications/Blender to r

Bleeping ComputerHIGHSep 5, 2026

Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]

The Verge AIMEDIUMAISep 5, 2026

OpenAI admits to German wiki ‘incident’

OpenAI says it needs to overhaul how and when it reports instances of AI models attacking real-world targets. The acknowledgement comes as the company manages the fallout from reports that a swarm of its out-of-control agents hijacked a German wiki site. Regarding the "'wiki incident,' where our age

Bleeping ComputerHIGHAISep 5, 2026

OpenAI admits it didn't disclose rogue AI wiki hijacking incident

OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security breach. [...]

SANS ISCHIGHAISep 5, 2026

numbat - AI agent observability, (Fri, Sep 4th)

No summary available.

Simon WillisonMEDIUMAISep 4, 2026

The Pelican comparison grid for Astra is pretty interesting

I got access to GPT-6 Astra this afternoon, so naturally I used it to generate SVGs of pelicans riding bicycles - at low, medium, high, xhigh and max reasoning levels (Astra doesn't support reasoning=none). Then I rendered those pelicans in a comparison grid with GPT-5.6 Sol, Terra, and Luna, and be

TechCrunch AIMEDIUMSep 4, 2026

XDOF, just three months out of stealth, is in talks for a Series B at a $1.2B valuation

The round is being raised just months after the robot data startup exited from stealth.

TechCrunch AIMEDIUMAISep 4, 2026

OpenAI’s rogue agents keep escaping, with no formal process to investigate them

OpenAI’s latest agent swarm incident adds urgency to calls for independent investigations as researchers and lawmakers question whether AI labs should control the scope of their own safety reviews.

TechCrunch AIMEDIUMAISep 4, 2026

AI compute provider Nscale is looking for $3.5B in pre-IPO financing

Nscale, which recently struck a $45 billion deal with Anthropic, is in talks to raise additional funds in anticipation of an upcoming IPO.

The Verge AIMEDIUMAISep 4, 2026

Roland is getting into generative AI music with Melody Flip

It's not quite the "push button; get song" of Suno, but Roland's new Melody Flip tool marks the company's foray into generative AI music. Available as a plug-in for your digital audio workstation (DAW), Melody Flip offers around 250 "Palettes," which are essentially themed collections of musical ide

Simon WillisonMEDIUMAISep 4, 2026

OpenAI's rogue agents were caught communicating via public wikis

Here we go again... Discovery of a new OpenAI agent message board by Sydney Von Arx, Cormac Slade Byrd, Spencer Kitts, and Thomas Larsen describes the latest accidental cyberattack by models being trained by OpenAI. This time it was agents engaged in some sort of web research benchmark, so they had

TechCrunch AIMEDIUMSep 4, 2026

What will Apple’s John Ternus era look like?

It’s officially the Ternus era at Apple. Tim Cook stepped down as CEO this week, handing the company to former hardware chief John Ternus, whose first memo promised a “huge launch next week” — timing that puts Apple’s next iPhone event on his desk before he’s even settled in. Cook isn’t going far, t

Bleeping ComputerHIGHSep 4, 2026

IDScan sued over alleged data breach affecting 153 million drivers

Multiple lawsuits have been filed against identity verification company IDScan after hackers allegedly breached the service and offered to sell more than 153 million driver's licenses. [...]

The Verge AIMEDIUMAISep 4, 2026

Microsoft says virtually nobody was grabbing NYT articles through its chatbot

Microsoft's Copilot rarely reproduces even full sentences from news articles and books, let alone substantive chunks that could substitute for the original, the company says in new legal filings as it fights copyright claims from publishers including The New York Times and book authors. As part of t

Bleeping ComputerHIGHVulnerabilitySep 4, 2026

Critical Citrix NetScaler auth bypass now leveraged in attacks

Attackers have begun targeting a critical-severity Citrix NetScaler auth bypass flaw (CVE-2026-19490) in the wild, according to vulnerability intelligence company Previdian. [...]

Bleeping ComputerHIGHSep 4, 2026

Microsoft says some users can’t open the Teams desktop client

Microsoft is working to resolve a known issue that causes delays or blocks some users from opening the Microsoft Teams desktop client on Windows systems. [...]

Bleeping ComputerHIGHSep 4, 2026

39 New Methods That Compromise Passkey Authentication

Passkeys eliminate many password-based attacks, but researchers have documented 39 methods for compromising authentication built around them. Token explains how attackers can abuse authentication prompts, synced credentials, enrollment, recovery, and other trust boundaries without breaking FIDO2 cry

The Verge AIMEDIUMAISep 4, 2026

Rogue OpenAI agents appear to have organized another attack using a German wiki

A swarm of rogue AI agents from OpenAI reportedly commandeered a German website and transformed it into a messaging board for other agents, with officials staying quiet about the incident for weeks as the company prepared to launch its most advanced model yet, Astra. The finding adds to intensifying

CISA AlertsCRITICALVulnerabilitySep 4, 2026

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-85046 Google Chromium V8 Type Confusion Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant

The Verge AIMEDIUMAISep 4, 2026

Instagram’s AI detection is a mess (again)

Instagram's visible AI labels are supposed to help people quickly spot synthetically generated content at a glance. Over the last few weeks, however, users have been reporting that the system has gone haywire. They say Meta has been automatically applying an "AI Content" label to images that they di

The Verge AIMEDIUMAISep 4, 2026

Why AI food looks like that

There is a torrent of unappetizing slop coming from restaurants, cafes, and brands that are increasingly turning to AI to generate images promoting their food. The resulting horror show includes donut shrimp, Reubens from the deep, wormlike noodles, and noodle-like pastries and stringy chicken. Ther

Simon WillisonMEDIUMAISep 4, 2026

August newsletter is out

The August edition of my sponsors-only monthly newsletter is out. If you are a sponsor (or if you start a sponsorship now) you can access it here . This month: We got more details on OpenAl's accidental cyberattacks One-shotting Raccoon Heist games with Fable 5 and Sol 5.6 Claude auto mode Understan

Simon WillisonMEDIUMPhishingAISep 3, 2026

GPT‑6 Astra

GPT‑6 Astra GPT-6 Astra is "rolling out today to a limited set of organizations and over the coming days will become available to all ChatGPT Plus, Pro, Business, and Enterprise users, as well as through the OpenAI API and AWS" - I've not tried it yet myself, so I don't have a great deal to say abou

CISA AlertsCRITICALVulnerabilitySep 3, 2026

Tycon Systems TPDIN-Monitor-WEB3

View CSAF Summary Successful exploitation of these vulnerabilities could allow for an attacker to perform a man-in-the-middle (MitM) attack, cause a factory reset, wipe credentials, or retrieve sensitive information. The following versions of Tycon Systems TPDIN-Monitor-WEB3 are affected: TPDIN-Moni

CISA AlertsCRITICALVulnerabilitySep 3, 2026

Pyramid Solutions NetStaX EtherNet/IP Stack

View CSAF Summary Successful exploitation of this vulnerability could result in memory corruption, a device crash, or a potential remote attack vector without the originating device receiving a CIP error indicating that the request could not be processed. The following versions of Pyramid Solutions

Beta Feedback