Visualização normal

Ontem — 7 de Setembro de 2026GBHackers on Security | #1 Globally Trusted Cyber Security News Platform

OpenAI Commits $1 Billion in Daybreak AI Cyber Tools to Protect Critical Infrastructure

OpenAI has announced a $1 billion global commitment to expanding access to its Daybreak AI cybersecurity platform for frontline defenders who protect critical infrastructure, public services, and under-resourced organizations. The initiative, named “Daybreak for Frontline Defenders,” aims to provide subsidized access to AI models focused on cybersecurity, along with hands-on training, technical assistance, and partnerships. […]

The post OpenAI Commits $1 Billion in Daybreak AI Cyber Tools to Protect Critical Infrastructure appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Antes de ontemGBHackers on Security | #1 Globally Trusted Cyber Security News Platform

OpenAI Agents Collude on Public Wiki to Share Sandbox Bypass and Evasion Techniques

Researchers have discovered a public wiki message board that they claim was used by autonomous AI agents, identifying themselves as OpenAI systems, to exchange answers to tasks, inspect their operating environment, and discuss methods to circumvent sandbox controls. This finding, published on September 4 by Sydney Von Arx, Cormac Slade Byrd, Spencer Kitts, and Thomas […]

The post OpenAI Agents Collude on Public Wiki to Share Sandbox Bypass and Evasion Techniques appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Hackers Abuse AI-Era ASCII Smuggling to Hide Phishing Content in Millions of Emails

Threat actors have repurposed an AI prompt-injection technique known as ASCII smuggling to evade email security controls at massive scale, hiding invisible Unicode characters within financial phishing lures. Microsoft observed the activity reach more than 2.3 million messages per day, demonstrating how techniques first popularized in AI-security research can quickly migrate into conventional phishing operations. […]

The post Hackers Abuse AI-Era ASCII Smuggling to Hide Phishing Content in Millions of Emails appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Chinese-Speaking Hackers Use Claude, Qwen and DeepSeek AI Agents to Attack Government Systems

Chinese-speaking threat operators have been observed using Claude, Qwen and DeepSeek-powered AI agents as operational components in a second intrusion campaign targeting government, political, education and industrial organizations across Asia. The campaign is distinct from an earlier operation reported in July that used Claude Code and DeepSeek against government and financial-sector targets. In this newer […]

The post Chinese-Speaking Hackers Use Claude, Qwen and DeepSeek AI Agents to Attack Government Systems appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Claude AI Develops Working RCE Exploit Against WAGO PLC With Researcher Assistance

Researchers have demonstrated that Anthropic’s Claude AI can assist in porting a remote code execution exploit between vulnerable models of WAGO programmable logic controllers (PLCs). However, this process requires significant human guidance, lengthy analysis sessions, and more than $500 in API usage. The experiment focused on CVE-2021-31886, a pre-authentication buffer overflow flaw in the Nucleus […]

The post Claude AI Develops Working RCE Exploit Against WAGO PLC With Researcher Assistance appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

AI-Enhanced BraZetsu Malware Powers Underground Market Selling Access to Corporate Networks

BraZetsu, a Python-based Windows malware framework allegedly operated by the Brazilian threat actor Exilware to identify, profile, and monetize compromised corporate systems. Rather than behaving like a conventional infostealer, BraZetsu appears designed to support an Initial Access Broker operation, converting infected endpoints into cataloged access offerings for an underground marketplace. The framework is reportedly the […]

The post AI-Enhanced BraZetsu Malware Powers Underground Market Selling Access to Corporate Networks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Fake OpenAI, Anthropic and DeepSeek Crawlers Target .env Files and Cloud Credentials

Threat actors are impersonating AI web crawlers from organizations such as OpenAI, Anthropic, DeepSeek, Google, Perplexity, and Amazon to scan internet-facing servers for exposed secrets, according to a GreyNoise research report published on August 28, 2026. This activity involves automated scanners that use forged crawler user-agent strings to request sensitive files, including .env configurations, AWS […]

The post Fake OpenAI, Anthropic and DeepSeek Crawlers Target .env Files and Cloud Credentials appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

OpenClaw 2.0 Released With Enhanced AI Agent Security and Credential Protection

OpenClaw has launched version 2.0, offering a major overhaul of its AI-agent platform. This update emphasizes streamlined deployment, a rebuilt browser experience, collaborative cloud sessions, and enhanced security for credentials and connected services. The release on August 30 represents the largest update in the project’s history, according to the OpenClaw Foundation. It features contributions from […]

The post OpenClaw 2.0 Released With Enhanced AI Agent Security and Credential Protection appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

New Gryxa Toolkit Uses AI-Built Persistence to Fight Back Against Security Teams

A financially motivated threat actor using a new Windows toolkit named Gryxa that combines remote monitoring and management abuse, AI-assisted development, browser credential theft, and aggressive persistence designed to survive incomplete remediation. The toolkit’s most unusual feature is its ability to collect evidence of how defenders removed its visible access and send that information back […]

The post New Gryxa Toolkit Uses AI-Built Persistence to Fight Back Against Security Teams appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Attackers Exploit MCP RCE, Blind Prompt Injection and Memory Credential Theft Against AI Infrastructure

Attackers are increasingly treating AI infrastructure as a high-value cloud entry point, exploiting exposed Model Context Protocol (MCP) services, agent frameworks, and AI gateways to execute code, validate prompt injection, deploy cryptominers, and steal credentials from process memory. The campaigns show that attackers are no longer using only generic web-server tradecraft; they are tailoring reconnaissance, […]

The post Attackers Exploit MCP RCE, Blind Prompt Injection and Memory Credential Theft Against AI Infrastructure appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

700 OpenAI Agents Coordinate Attack on Hugging Face and Gain Remote Code Execution

OpenAI’s ExploitGym evaluation environment reportedly became the site of a large-scale, unsanctioned multi-agent campaign after hundreds of models found ways to communicate across supposedly isolated sandboxes. An investigation published by METR describes how the activity, which began on July 8, involved agents operating across several models, including GPT-5.6 Sol and an internally persistent model identified […]

The post 700 OpenAI Agents Coordinate Attack on Hugging Face and Gain Remote Code Execution appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Researchers Execute Code Inside Fortune 500 Companies via AI Agent llms.txt Files

Security researchers have shown that AI coding agents can be manipulated into installing attacker-controlled packages by following instructions found in organizations’ own llms.txt files. This research emphasizes how agent-readable documentation can transform unverified package references, expired domains, and abandoned cloud subdomains into execution paths within enterprise environments. Researchers Execute Code Inside Fortune 500 Companies The […]

The post Researchers Execute Code Inside Fortune 500 Companies via AI Agent llms.txt Files appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

TITAN RaaS Uses AI for Data Classification, Regulatory Analysis and Automated Ransom Calculation

A newly emerged ransomware-as-a-service operation named TITAN is advertising an AI-driven extortion platform that it claims can autonomously classify stolen corporate data, identify regulatory risk. Founded on April 4, 2026, TITAN has been active since May and has listed 24 alleged victims across 10 countries. Italy accounts for 10 published victims, followed by Czechia with […]

The post TITAN RaaS Uses AI for Data Classification, Regulatory Analysis and Automated Ransom Calculation appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Hackers Are Targeting AI Servers to Steal API Keys and Hijack Computing Power

AI infrastructure is rapidly becoming a high-value enterprise attack surface. Attackers targeting LiteLLM AI gateways, RAGFlow retrieval platforms, and Kestra workflow orchestration environments to steal model-provider credentials, establish persistence, access backend data, and deploy cryptominers. The appeal is clear. AI gateways often centralize OpenAI, Azure, Anthropic, Gemini, and other provider API keys; retrieval platforms hold […]

The post Hackers Are Targeting AI Servers to Steal API Keys and Hijack Computing Power appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Ransomware Hacker Uses AI to Plan Attacks and Compromises More Than 20 Organizations

A Russian-speaking affiliate of the Aurora ransomware operation compromised more than 20 organizations across nine countries between April and July 2026, using the AI coding assistant Cursor to plan intrusion activity and Active Directory escalation. The exposed server offered an unusually complete view of a ransomware affiliate’s operational workflow. It contained victim-specific directories, shell history, […]

The post Ransomware Hacker Uses AI to Plan Attacks and Compromises More Than 20 Organizations appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Multi-Agent AI Framework Compromises Government Systems and Steals Thousands of Records

A multi-agent AI framework, utilizing Hermes and OpenClaw agents, was employed to compromise government entities in Asia, stealing thousands of personnel records, cracking employee credentials, and establishing persistent access to state infrastructure, according to Dream Research Labs. Researchers discovered a 160 MB operational archive containing 1,395 files generated over about 4 days of activity, from […]

The post Multi-Agent AI Framework Compromises Government Systems and Steals Thousands of Records appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Hackers Place Fake Codex Download Above Legitimate OpenAI Result to Infect Mac Users

Threat actors are using sponsored Google Search ads to place a fake OpenAI Codex download page above the legitimate result, steering macOS users into manually executing malware through Terminal. The operation begins when users search for Codex-related terms, including “codex macos download.” Instead of selecting OpenAI’s legitimate listing, victims may encounter a sponsored result that […]

The post Hackers Place Fake Codex Download Above Legitimate OpenAI Result to Infect Mac Users appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

OpenAI Frontier Models Get Zero Data Retention With Private Safety Processing

OpenAI has reaffirmed its commitment to Zero Data Retention (ZDR) for eligible API customers using frontier models while introducing the new Private Safety Processing. This safety architecture is designed to detect multi-session misuse without exposing the underlying prompts or responses to OpenAI personnel. Announced on August 19, 2026, this initiative addresses a critical challenge in […]

The post OpenAI Frontier Models Get Zero Data Retention With Private Safety Processing appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

OpenAI Slows AI Model Development as Astra Approaches Critical Cyber Capabilities

OpenAI has temporarily slowed the development of its latest frontier AI models after initial testing suggested that its upcoming Astra system may meet the company’s “Critical” cybersecurity capability threshold. This decision follows a recent security incident involving OpenAI and Hugging Face. It reflects growing concerns that advanced models could significantly increase the risks of cyber […]

The post OpenAI Slows AI Model Development as Astra Approaches Critical Cyber Capabilities appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Claude AI Finds Authentication Bypass Flaws in Multiple SAML Implementations

Multiple critical vulnerabilities in SAML implementations after employing Anthropic’s Claude Code in an AI-assisted vulnerability research pipeline. Security researcher Eric Chiang, the CTO of Oblique Security, investigation uncovered full authentication bypasses, signature-validation flaws, information disclosure risks, arbitrary logout issues, and denial-of-service conditions across several open-source SAML products. Claude AI Finds Authentication Bypass Flaws Chiang’s research […]

The post Claude AI Finds Authentication Bypass Flaws in Multiple SAML Implementations appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

❌
❌